Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
A 17-year-old London schoolboy who was arrested last year has pleaded guilty to a distributed denial of service (DDoS) attack of unprecedented ferocity launched against the Spamhaus anti-spam service and internet exchanges, including the London Internet Exchange.
Given that he's a minor, he can't be named.
The Register quoted a police statement that said that the boy also admitted last week to money laundering and possessing child abuse images.
He's out on bail pending sentencing on 9 January, the statement said:
A 17-year-old male from London has this week (Wed 10 Dec) pleaded guilty to [offences under the] Computer Misuse Act, money laundering and making indecent images of children offences, following a National Crime Agency investigation. He was arrested in April 2013 after a series of distributed denial of service (DDoS) attacks which led to worldwide disruption of internet exchanges and services. On his arrest officers seized a number of electronic devices. He has been bailed until 9 January 2015 pending sentencing.
He's admitted to having a hand in the biggest DDoS ever recorded: one that at times was reported to be as large as 300 gigabits per second.
Traditionally, even large botnets are only able to deliver hundreds of megabits or a few gigabits per second, as Naked Security noted at the time.
The attackers used large-scale DNS reflection, taking advantage of misconfigured DNS servers to amplify the power of a much smaller botnet.
It was very effective. While the attack didn't break the internet's backbone when it launched in March 2013, it managed to slow the internet around the world.
But the 17-year-old didn't pull all that off all on his lonesome. He was reportedly one of multiple arrests.
In April 2013, another suspect was arrested in Spain.
In fact, the teenager's arrest, by detectives from the National Cyber Crime Unit, followed an international police operation against those suspected of carrying out the massive DDoS.
We're on the brink of a new year. Unfortunately, this kid has made choices to put his talents to use in a way that means he'll be in court soon into the coming new year.
Bad choice. Regrettable choice.
Will he do jail time? Will he cough up names of others involved in the attack?
Time will tell.
But if I had been in on this caper, I'd be very, very worried about getting a knock on the door.
Stopping massive data breaches like the one that hit Target will require a more sophisticated, collaborative approach by law enforcement agencies around the world, a Michigan State University cyber security expert argues.
In a new research report for the National Institute of Justice, Thomas Holt found many hackers and data thieves are operating in Russia or on websites where users communicate in Russian, making it easier to hide from U.S. and European authorities. All countries need to better work together to fight hacking and data theft campaigns, he said, and use undercover stings in which officers pose as administrators of the Internet forums where stolen data is advertised.
The Target breach, which comprised 40 million credit- and debit-card accounts during the 2013 holiday shopping season, may have originated in Russia, the Wall Street Journal recently reported.
"This is a truly global problem, one that we cannot solve domestically and that has to involve multiple nations and rigorous investigation through various channels," said Holt, associate professor of criminal justice.
Holt authored the 155-page report with Olga Smirnova from Eastern Carolina University. The National Institute of Justice funded their research, the largest to date on this crime, with a $280,000 grant.
Holt and Smirnova analyzed 13 Internet forums through which stolen credit data was advertised. Specifically, they found:
Ten of the forums were in Russian and three were in English, though the forums were hosted across the world.Visa and MasterCard were the most common cards for sale.The average advertised price for a stolen credit- or bank-card number was about $102.The average price for access to a hacked eBay or PayPal account was about $27.
Skilled hackers who steal thousands or even millions of cards generally attempt to quickly dump the data to buyers found through advertisements the hackers create in Internet forums. The buyers then assume the risk of making purchases or taking cash advances on the cards in return for a potentially large profit.
In the United States, Holt said it is imperative more money and resources -- such as Russian-speaking analysts and new technology -- be allocated to the FBI, Secret Service and other federal agencies to more effectively combat cybercrime.
Tougher state and federal cybercrime laws should also be passed to promote security and corporate responsibility. While 46 states currently require companies to disclose any loss of sensitive personal information in the event of a security breach, Holt suggested the laws generally don't go far enough to protect consumers.
"Greater transparency is needed on part of both corporations and banks to disclose the true number of customers affected and to what degree as quickly as possible in order to reduce the risk of customer loss and economic harm," he said.
Consumers also need to be more vigilant.
"There is a big need for public awareness campaigns to promote basic computer security principals and vigilance against identity theft," Holt said. "Consumers need to understand the potential harm from responding to unsolicited email and clicking on suspicious web links as well as the need to run anti-virus and security tools on their computers."
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
The Bank of England this year will hire penetration testers to poke and kick at the computer-system defences of more than 20 major UK banks and other financial players.
Sources familiar with the programme told the Financial Times (registration required to view article) that it's going to enlist testers certified by CREST, a not-for-profit organisation that represents the infosec industry.
Financial institutions have already proved susceptible to what's being called the latest, biggest security threat since the birth of the internet: the OpenSSL Heartbleed buffer overflow vulnerability.
One such was American Funds, the third largest US mutual fund family, which last week advised some customers to change user names and passwords.
According to Business Recorder, the company emailed about 825,000 clients to tell them that they'd been exposed to "a very narrow window of risk" and advised that they change user names, passwords, and security questions and delete their browsing histories.
Canada's tax agency, the Canada Revenue Agency, also recently announced that 900 social insurance numbers (SINs) were stolen by hackers exploiting Heartbleed over a six-hour period.
Andrew Gracie, the director of the UK's special resolution unit within the Bank of England, will reportedly oversee the UK pen testing programme.
The Financial Times reports that the testing will build on the lessons of Operation Waking Shark 2, a simulation of a major cyber attack on UK financial firms that was carried out in London on 12 November 2013.
The four-hour exercise simulated attack by a hostile nation state on the UK's financial sector, set to cover a three-day period, the last day of which coincided with "Triple Witching" (when contracts for stock index futures, stock index options and stock options all expire on the same day).
BoE reported (PDF) the lessons learned from Waking Shark 2 in February.
The exercise pointed to three main areas for future work:
The need to identify a single industry body to coordinate communications.Making sure that firms know that they need to report major incidents to regulators right away. Fine-tuning and getting used to working with the Cyber Security Information Sharing Partnership (CISP) platform - a data threat sharing platform - used during the exercise.
According to The Financial Times, Waking Shark 2 involved 220 people, 20 institutions and infrastructure providers, and a host of government agencies, but it didn't target individual companies' systems.
In fact, this is the first time that UK banking authorities are taking on the task of testing for vulnerabilities in this broad fashion, as opposed to the typical scenario of having firms conduct their own, internal penetration testing, the news outlet reports.
Is your own organisation looking at pen testing? Perhaps while casting a frightened eye toward Heartbleed, in particular?
As Sophos' Ross McKerchar pointed out when he gave these tips on how to manage cost-effective pen testing, this stuff can very quickly get very pricey.
Focusing on testing the right things in the right manner is key to getting the best bang for your buck, he says.
What about us security civilians? Can we pen-test our own systems?
Well, yes... carefully.
Serious penetration testing can really mess up a site. When done on a business level, nightmares such as crashing servers, exposing sensitive data, corrupting crucial production data or causing other damage by mimicking the actions of malicious attackers can ensue.
Home users don't have such broad risk areas, but it's still wise to proceed with caution.
Naked Security has these tips for home users to penetration test their own computers.
As Lee Munson notes, pen testing can be as simple as asking somebody to try to guess your passwords. If even a technically unsophisticated person can guess that you're using "password" or "123456" (please tell us you're not), you know you've got some work to do!
Check lists of the most commonly used passwords.
See any of yours on there? Change them! Use upper and lowercase letters, numbers and special characters, and make them as long as possible.
And yes, I know, that list dates back to 2010. Unfortunately, the top favorites haven't changed much!
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
News, opinion, advice and research: Chet and Duck (Chester Wisniewski and Paul Ducklin) bring you their unique and entertaining combination of all four in their regular quarter-hour programme.
Chester's been on the road, so this epsiode of the Chet Chat is a couple of days late for logistical reasons.
We apologise for that, but Chet and Duck think it's no less interesting nevertheless!
In fact, this week's main story - the two-in-a-row exploits against Android code verification - intrigued your presenters so much that they resolved to link up and record this show, come what may.
And so, here it is: SSCC Episode #113.
(You can keep up with our podcasts via RSS or iTunes, and catch up on previous Chet Chats and other Sophos podcasts by browsing our podcast archive.)
The news wires have been buzzing with the "master keys" attack, and the "extra field" attack, both of which let you create Android Package files (APKs) that show one set of content to Google's cryptographic verification, and another to the installer.
Chet and Duck explain what happened, come up with some ideas that would have avoided the problem in the first place, explain what to do about it, and wonder how long before the fixes are on your handset.
From Android to iOS, where Tumblr published a version of its app that somehow managed to leave out the part that encrypts your PII before sending it over the internet.
Chet wonders how the average user is supposed to spot that sort of bug.
Nintendo got pounded by crackers who mounted a month-long password guessing attack.
The crooks only got hold of 24,000 passwords as a result (only!), and it looks as though those successes were largely down to using dictionaries of usernames and passwords from earlier hacks.
What to do? Federated identity? Password managers? A slimmer digital lifestyle?
Chet and Duck discuss the pros and cons of various ways to address the problem of password re-use.
And Chet's going to be at BlackHat 2013, and at DEF CON, so be sure to look him up in Vegas and say, "Hi."
Duck won't be there in body but you will find him present in mind and spirit, as he's putting together a special #sophospuzzle for the occasion.
The puzzle will go up on Naked Security, so everyone can have a go, but BlackHatters can enter at Sophos's booth at the trade show and win a secret prize!
(It's a cool secret prize, which Duck lets slip in the podcast, and Chester bemoans being ineligible to win.)
Don't forget: for a regular Chet Chat fix, follow us via RSS or on iTunes.
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
About a month ago, veteran anti-spam campaigners Spamhaus became embroiled in a massive DDoS attack.
A DoS, or denial of service, is where you deliberately waste the resources of a legitimate online service, for example by sending lots of pointless emails or purposely uploading files that you know cause processing problems for someone's server.
(It's a bit like phoning someone you don't like over and over throughout the night, even though you have nothing to say, just so they keep waking up.)
A DDoS is a distributed DoS, where you persuade or trick a raft of other people to join in the attack, each one starting what amounts to a DoS in its own right.
(Your victim's phone, in our old-school analogy above, just never stops ringing. Indeed, it rings so much he can't make outgoing calls of his own, or get to sleep at all, or do anything purposeful.)
The attacks against Spamhaus used what techies call "DNS amplification".
This relied on your home firewall, or your router at work, being wrongly configured.
The attackers could then exchange tiny packets of data with you, asking you to get DNS information from Spamhaus; you'd then convert that into a much larger exchange of data packets with Spamhaus itself.
By dispersing a few hundred bytes each to a few hundred misconfigured routers, the attackers could produce tens of megabytes of network traffic focused back onto Spamhaus's servers.
And data from the OpenDNS project suggests that there are not merely a few hundred misconfigured routers worldwide, but tens of millions.
So, whoever attacked Spamhaus was able to muster a lot of bogus traffic, with some estimates putting the peak malevolent bandwidth at 300Gbit/sec.
According to reports back in March 2013, the attack boiled down to a dispute between Spamhaus, which fights spam, and countercultural ISP Cyberbunker, which caters to customers who are unwanted by, or afraid to use, traditional web hosts because of the activities they are involved in.
Cyberbunker, amongst others, despises Spamhaus for operating an email blocklist service.
This aims to maintain lists of suspected dodgy email senders so that Spamhaus customers can jettison email that they almost certainly aren't going to want.
Spamhaus doesn't actually prevent anyone sending email, or deny anyone the right to receive lawful email of their choice.
But it does provide an online assessment service - what's known as a realtime blocklist - that you can query before you accept an email.
Cyberbunker, it seems, doesn't like that at all. (So much for freedom of choice.)
Anyway, a 35-year-old man identified only as S.K. has been arrested in Barcelona, Spain, in connection with the March attacks:
A 35-year-old Dutch national, S.K., was arrested in Spain on Thursday in an investigation into large-scale cyberattacks. A European arrest warrant was issued by the Dutch National Prosecutor.
K. is accused of serious attacks against the non-profit organisation Spamhaus, which maintains anti-spam databases. These so-called DDoS attacks, carried out last month, also took place against Spamhaus partners in the USA, the Netherlands and the UK.
Who is S.K.?
The Dutch prosecutors and the Spanish cops know for sure; the rest of us can only guess.
But I can tell you that one of Cyberbunker's leading personalities is a Dutchman by the name of Sven Olaf Kamphuis.
Kamphuis, as it happens, gave an online interview late last month to online "urban lifestyle" video site Heavy.com.
Entitled "Meet the Man Behind the Biggest Cyberattack in History," the interview quotes Kamphuis claiming to be the spokesperson for Stophaus, a group of anti-Spamhaus hacktivists.
He also states that "a few people from the Stophaus group...decided it was a very good idea to take down Spamhaus. And they did," but denies that anyone from Cyberbunker was involved.
Kamphuis even claims, in the interview, that Cyberbunker itself, a NATO military bunker left over from the Cold War, isn't Dutch territory at all - his implication seems to be that it is a sovereign independent state of its own.
But if S.K. really is Sven Olaf Kamphuis, you have to wonder why he didn't hole up in the Republic of Cyberbunker in the aftermath of the attack, in order to spare himself the inconvenient attention of EU law enforcement officials.
An intriguing saga, I'm sure you'll agree.
We'll tell you more as the facts emerge...
Follow @duckblog
Image of orange bloke with megaphone courtesy of Shutterstock.
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
Even if you are used to phishing scams, it still pays to take the occasional look at a scam campaign, just to remind yourself not to let your guard down.
So here's a recent scam in which the crooks are targeting customers of Absa, one of the Big Four banks in South Africa.
The email used in the scam pretends to be a refund from the South African Revenue Service (SARS):
The South African tax year ended on 28 February, so the timing is right, and with the Revenue Service's eFiling system available this year even from mobile phones, more South Africans than ever will be expecting to deal with the tax office electronically.
Of course, even if you are an ABSA customer and expecting a tax refund, you should still be suspicious, not least because your bank won't send you login links via email.
Banks avoid sending you links to their secure banking sites precisely so they can tell you, "Never click on emailed login links, because they won't be from us."
There are other tell-tale scam signs here, too, if you are alert to orthographic (writing and spelling) clues, such as these:
The Revenue's online service is called eFiling, not EFilling.Dates in South Africa are written with the month in the middle, where it jolly well belongs, so 18 April 2013 is 18/04/2013, not 04/18/2013.
Note that you shouldn't rely on spotting phishing emails and websites only by looking out for errors of this sort, because there is nothing to stop the crooks being careful.
But if you spot something that obviously doesn't look right, assume the worst.
If you do click the link without thinking, you won't go to Absa's website, but instead to a hacked website in Korea.
The server itself isn't owned by the criminals - it's just being "borrowed" to provide free IT services for this phish.
The Korean site doesn't actually host the fake banking pages, but instead simply bounces you, using an HTTP redirect, to a hacked site in the Netherlands, where the fraudulent login process begins.
The visual appearance of the fake pages is professional, largely because the crimimals have ripped off Absa's own HTML and JavaScript code to reproduce the look and feel of the real thing, right down to the virtual keyboard asking for your PIN:
Then you are asked to enter your password:
Note that Absa's login system usually only asks you for a randomly-selected subset of the characters in your password, as a precaution to stop a crook from learning your entire password from a single login attempt.
This doesn't improve security enormously, but it does make things harder for a cybercriminal or a shoulder-surfer, and it is a designed-in part of Absa's login process.
So, take the trouble to familiarise yourself with what your bank advises you to look out for.
In this case, the phishers are greedily asking for your entire password in one shot, presumably so they know all the possible characters for next time; this should be a tell-tale sign that something is wrong.
The next screen asks you to put in the Random Verification Number (RVN) code that Absa sends to your mobile phone as a one-time password:
This should ring alarm bells even more loudly.
Absa specifically documents that the RVN is used only in special cases involving more than simply looking at your balance, which is what the original email was inviting you to do:
When creating a new beneficiary, changing transfer limits, or other kinds of sensitive transactions, a special one-time password, called a Random Verification Number (RVN), will be sent to your cellphone. You must type this into the indicated field for verification. Just before the payment is made, another one-time password will be sent to your cellphone, called a Transaction Verification Number (TVN) to confirm the transaction. These passwords can only be used once, and dramatically decrease the risk of being defrauded.
The only plausible reason you'd be asked for an RVN code when you thought you were just checking your balance is that you aren't talking to the bank's real site, but to an imposter site that is attempting a Man-in-the-Middle (MiTM) attack.
The idea is that you perform what you think is an innocent transaction with the bank, while the Man-in-the-Middle commences a simultaneous sensitive transaction with the real banking site - such as telling the bank that you just agreed to pay out money to him.
When the bank asks the Man-in-the-Middle a question he can't answer, he asks you. And what you tell him, he tells to the bank as if he knew it all along.
You think you're talking to the bank and asking it to do X, but you're really talking to the MiTM, who uses the security information innocently submitted by you to ask the bank to do Y.
This is why it is vital to keep checking, throughout any online banking session, that you are on the bank's real site.
If you're an Absa customer, for example, you need to know that Absa's internet banking site is called https://ib.absa.co.za/, and that it uses HTTPS, or secure HTTP.
Don't look in the web page itself for "proof" that the site is secure, because the crooks try to fill their fake pages with security reassurances.
In this phish, for example, the first page in the fraudulent login sequence advises you to watch out for phishing scams, and even correctly advises you never to login from links sent via email:
Always look in the address bar (which can't be directly modified by a web page, only by the browser itself) for the tell-tale HTTPS padlock.
In most modern browsers, you can also click on the padlock in the address bar to double-check who owns the secure website:
The identification information in an HTTPS transaction isn't infallible - it's a bit like the certification stamp on a certified copy - but if it is wrong or missing, then you can be certain you are being tricked.
Finally, you're asked for the Transaction Verification Number (TVN):
With your PIN, password and a TVN, the crooks could, at least in theory, pay out money, but only to someone who is already setup up as a beneficiary on your account (a person you pay money to).
So they might be able to pay your electricity bill, or send a gift to your mother.
But with a one-time RVN as well, the crooks could, at least in theory, add themselves as a beneficiary first, and then use the TVN to send themselves some of your money.
So always be on your guard.
In this phish, any one of these signs should have been enough to put you off, even if you were an Absa customer awaiting a taxation refund:
Orthographic (writing and spelling) errors in email.Clickable link to login page in email.Wrong link, going to a site in Korea.Link redirects to wrong location, going to a site in the Netherlands.Login site not correct for Absa.Login site not encrypted with HTTPS.Non-standard procedure for password entry.Inappropriate request for Random Verification Number (RVN).
If you detect the smell of phish at any point in the process, pull the plug.
The longer you stay "on the hook," the more security information the crooks will end up getting out of you.
Seoul, April 10 (IANS) The South Korean government Wednesday confirmed that North Korea was behind the March 20 cyber attack that paralyzed computer networks at banks and broadcasters.
"The series of cyber attacks last month resembled North Korea's past hacking patterns," the Ministry of Science, ICT & Future Planning said at a press briefing.
"Evidences (showed) that North Korea's reconnaissance general bureau did the act."
On March 20, computer networks at three banks and three broadcasters suffered the cyber attack, crippling about 48,700 PCs and servers, reported Xinhua.
On March 25, there was an attempt to hack PCs of the ordinary people, while computer files at the broadcaster YTN's 58 PCs were destroyed and data at anti-North Korean organizations' homepage were deleted the following day.
Based on 76 malicious codes used for the hacking and Internet access records collected, the March cyber attack was planned at least eight months ago by indirectly planting malware in advance, according to the probe results by the government-led investigation team.
The investigation team found that six PCs in North Korea directly or indirectly accessed the infected computers some 1,590 times, among which Internet Protocol (IP) address linked directly to North Korea was spotted 13 times.
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
If you have a web service that supports remote users, you will know that malevolent login attempts are an everyday occurrence.
Even on my own home-hosted SSH server, listening unassumingly on an IP number on a DSL line, I've seen thousands of login attempts from dozens of different IP numbers in the course of a single day.
But hosting providers worldwide are reporting that they've been seeing systematic attempts, over the last 48 hours or so, to breach blogs and content management systems (CMSes) at well above average levels.
The primary target seems to be WordPress, with Joomla users also reportedly getting a bit of a hammering.
Word from the anti-DDoS world is that a botnet is responsible, with estimates of "up to 90,000," "more than tens of thousands," and "up to 100,000" infected computers (all those figures can be true at the same time, of course) orchestrating the felonious login attempts.
Since it would take too long to try every possible username and password on every known WordPress or Joomla server, this onslaught is using what is known as a dictionary attack.
That's where a crook settles on a list of the most likely usernames and passwords, and tries those in quick succession.
The idea is simple: automate the password guessing, speed up the attack, and don't spend too long on any individual site.
Look for the low-hanging fruit, and harvest it as quickly as you can; if you can't get in within a few hundred or thousand attempts, move on to the next potential victim.
It's doorknob rattling, but on an industrial and international scale.
Tireless cybercrime and underweb reporter Brian Krebs has published a list of sample WordPress usernames and passwords used in this attack, courtesy of security breach cleanup company Sucuri.
The top thirteen generically-chosen dictionary entries for username and password are as follows:
It's worth a look at the list (click on the image above), if only to reassure yourself that you haven't taken chances with any of your own passwords.
Notice also that the attackers are focusing on the username admin, used in 90% of the login attempts, because it's the default WordPress administrative username.
A username shouldn't be considered a secret (that's what the password is for), but you can avoid unwanted attention from low-hanging-fruit attacks by choosing something other than the default, as WordPress founder Matt Mullenweg himself advises.
Matt's suggestions are pithy and clearly put, so I'll repeat them here; they make up good advice for any web service product, whether you're blogging, file sharing, or running a CMS:
Almost 3 years ago we released a version of WordPress (3.0) that allowed you to pick a custom username on installation, which largely ended people using "admin" as their default username. Right now there’s a botnet going around all of the WordPresses it can find trying to login with the "admin" username and a bunch of common passwords, and it has turned into a news story (especially from companies that sell "solutions" to the problem).
Here’s what I would recommend: If you still use "admin" as a username on your blog, change it, use a strong password, if you’re on WP.com turn on two-factor authentication, and of course make sure you're up-to-date on the latest version of WordPress. Do this and you'll be ahead of 99% of sites out there and probably never have a problem. Most other advice isn't great — supposedly this botnet has over 90,000 IP addresses, so an IP limiting or login throttling plugin isn't going to be great (they could try from a different IP a second for 24 hours).
There you have it.
Not being the low-hanging fruit isn't a generic solution to this problem, as it's a bit like outrunning your buddy when you are chased by a hungry lion: it saves you, but leaves someone else to take the hit.
But that is no reason not to move your fruit to higher branches.
Remember that if someone breaks into your server, that's bad for you, but it is also bad for everyone else.
It gives the crooks a free ride for hosting malware, launching further attacks, publishing phishing pages, disseminating fake updates or bogus information, and much more.
All with your imprimatur, and, in the end, with your services blocklisted by anyone who's security conscious.
Remember, password-guessing attacks of this sort happen all the time.
The attack volume in this case has been sufficient to attract global attention, which is a good thing, but it's currently thought to be only about three times the usual level.
In other words, even when "normal service" is resumed, we'll all still be firmly in the sights of the cybercriminals, so take this as a spur to action!
Follow @duckblog
Image of Dictionary with magnifying glass courtesy of Shutterstock.
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
Brian Krebs
Thankfully, award-winning US computer security reporter Brian Krebs is safe.
Nobody was harmed. But they could have been.
Given a DOSed website, a fake and libelous FBI letter sent to his website host, and a dinner party delayed by a SWAT team training guns on him and ordering him to "Put your hands in the air!", Krebs last week surely endured the most dramatic retribution ever meted out to a security blogger.
Krebs has a good idea of the specific criminal element behind the trio of attacks. Since the dramatic events of Thursday, he's traced the denial-of-service attack to a common operator who apparently launched a similar attack on Ars Technica following its coverage of Krebs's victimization.
As described by his fellow security scribe Dan Goodin at Ars Technica, Krebs is known for work that includes:
In short, Krebs has enemies.
Last week, one or more of those enemies targeted him, likely in retaliation for his most recent investigation.
On Friday, Krebs detailed in a post how the ordeal started the day before, when his site was targeted with "a fairly massive denial of service attack."
That same afternoon, a technician from Prolexic called. Prolexic is a company that Krebs hired to protect his site, KrebsOnSecurity.com, from DOS attacks.
Prolexic forwarded a letter they'd received earlier that day, purporting to come from the US Federal Bureau of Investigation.
The letter, which Krebs reprinted here, falsely claimed that Krebs's site was "hosting illegal content, profiting from cybercriminal activity, and that it should be shut down," Krebs writes.
Both Prolexic and Krebs dubbed it a hoax - an assumption Krebs confirmed with a quick call to the FBI.
As Prolexic tidied up his DOSed site, Krebs got to work tidying up his home in anticipation of dinner guests. His office phone rang while he was vacuuming, but he ignored it.
That, it turns out, was an unfortunate choice, given that the call came from law enforcement who were trying to verify what would turn out to be a spoofed emergency call showing Krebs's number on caller ID.
As he was vacuuming, Krebs noticed plastic tape on the front-door threshold, left over from securing an extension cord. He opened the door to unpeel it.
He tells of what happened next:
"When I opened the door to peel the rest of the tape off, I heard someone yell, 'Don't move! Put your hands in the air.' Glancing up from my squat, I saw a Fairfax County Police officer leaning over the trunk of a squad car, both arms extended and pointing a handgun at me. As I very slowly turned my head to the left, I observed about a half-dozen other squad cars, lights flashing, and more officers pointing firearms in my direction, including a shotgun and a semi-automatic rifle. I was instructed to face the house, back down my front steps and walk backwards into the adjoining parking area, after which point I was handcuffed and walked up to the top of the street.
"I informed the responding officers that this was a hoax, and that I’d even warned them in advance of this possibility. In August 2012, I filed a report with Fairfax County Police after receiving non-specific threats. The threats came directly after I wrote about a service called absoboot.com, which is a service that can be hired to knock Web sites offline."
Krebs had filed a police report last year on the suspicion that he would be SWATted.
SWATting is the practice of falsely reporting an emergency, as a prank or as revenge against a victim upon whom descends emergency services - or, in Krebs's case, armed law enforcement.
Krebs' persecutors had, in fact, spoofed an emergency call to make it appear that it had come from his phone.
As Sophos's Chester Wisniewski noted last April when he wrote about fraudulent calls targeting US banks, caller ID spoofing can be particularly convincing in the US, given that the call display service used by most phone companies here does a reverse lookup for the name information based on the caller ID number provided by the call.
Once a criminal determines the phone number he wants to have fraudulently show up as his caller ID number - Krebs's phone number, in this case - it's trivial to display that number on the call recipient's display.
Caller ID spoofing has been around for years through various technologies: ISDN PRI circuits used by collection agencies, law enforcement, and private investigators, all of whom have used it with varying degrees of legality; spoofing services such as Star38.com; and through Voice over IP (VoIP) technology.
Given how trivial it is to spoof caller ID, it's surprising that people put any faith at all in the technology - most particularly that law enforcement do.
In fact, the police who took Krebs's report warning that he might be targeted by SWATting hadn't even heard of the practice.
All too readily, we tend to put faith in appearances. We believe caller ID identifies the true identity of a caller.
Or somebody flashes a piece of silver and we obediently hand over our licenses or wallets, or we open a door and allow strangers inside our home or our cars, without verifying whether what we've seen was an authentic emblem or a plastic toy badge.
We - the police included - trust in the technology we use. Criminals will always exploit that trust.
Krebs's work, along with other security reporters and researchers, is to poke sticks into hornets' nests, to borrow a friend's analogy.
In this case, the sting from angry hornets could have had fatal consequences, as Krebs points out:
"I have seen many young hackers discussing SWATing attacks as equivalent to calling in a bomb threat to get out of taking exams in high school or college. Unfortunately, calling in a bomb threat is nowhere near as dangerous as sending a SWAT team or some equivalent force to raid someone’s residence. This type of individual prank puts peoples’ lives at risk, wastes huge amounts of taxpayer dollars, and draws otherwise scarce resources away from real emergencies. What’s more, there are a lot of folks who will confront armed force with armed force, all with the intention of self-defense.
"The local police departments of the United States are ill-equipped to do much to stop these sorts of attacks. I would like to see federal recognition of a task force or some kind of concerted response to these potentially deadly pranks. Hopefully, authorities can drive the message home that perpetrating these hoaxes on another will bring severe penalties. Who knows: Perhaps some of the data uncovered in this blog post and in future posts here will result in the legal SWATing of those responsible."
Well said, Brian. We all hope so too, for your sake and for the sake of all security researchers, law enforcement personnel and victims of attacks like the one you experienced.
Follow @LisaVaas Follow @NakedSecurity
SWAT team and telephone image courtesy of Shutterstock.
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
A particularly vociferous malware campaign has been forcefully spammed out in the last 24 hours, targeting German internet users.
The malicious emails, which have are intercepted by Sophos security products, contain an attachment which pretends to be a PDF file, and claim to come from an air shipment company and use the subject line "Luftfrachsendung AWB".
Here is an example of a typical email that was intercepted by the team at SophosLabs:
Hallo,
anbei der AWB bitte bestätigen ob alles Ok ist.
Danke
Mit freundlichen Grüßen
Attached to the emails is a file called AWB-Avis 123-12345678.pdf.zip (the numbers can vary) which carries the malicious payload.
Sophos products detect the attack as the Troj/Agent-AAJO and Troj/Agent-AANK Trojan horse.
Astrid, one of the translators here at Sophos, tells me that the German used in the emails isn't perfect (which might help raise suspicions) - but here's a rough translation for non-German speakers:
Hi,
Please confirm the enclosed AWB is OK.
Thank you
Yours sincerely
What makes the attack stand out from all of the other attacks that we have intercepted in the last few days is its sheer scale, dwarfing all the other malware attacks that SophosLabs has seen sent out via email in recent days.
The shipping company referenced in the email has posted a message on its website saying that it has had to suspend its normal info@ email address because of the sheer number of emails it is receiving, and has offered an alternative address for contact instead.
ATTENTION! Email Spam and Virus warning: Unknown parties are currently sending large quantities of spam emails with the false sender address of info@first-class-zollservice.de. The subject line reads "Airfreight shipment AWB". The email has an attachment that is infected with a Trojan!
We therefore advise that if you receive such an email, you delete it without opening. Please do not try to open the attachment!
For this reason, the info@email address has been disabled info@first-class-zollservice.de until further notice. You can contact us in the meantime, using the email address "24stunden@first-class-zollservice.de"
You have to feel some sympathy for an innocent company which has had its business disrupted by a cybercriminal scheme.
Make sure that you are reducing the risk of your computers being infected by malware in an attack like this.
As well as keeping your wits about you, and ensuring that you and your colleagues never open unsolicited attachments, always ensure that all of your computers are running up-to-date anti-virus software.
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
It's a brand new year and you would like to think that computer users are getting smarter about securing their systems, and not falling for the age-old tricks used by cybercriminals.
However, we still see our fair share of elementary unsophisticated attacks designed to steal credentials from the unwary.
Take this example, an email which claims to come from the "Windows Live Team" and warns Hotmail/MSN users that their account is at risk of immediate closure after different computers logged into it, and multiple attempts were made to guess the password:
Part of the email reads:
VERIFY THIS EMAIL ADDRESS TO AVOID IMMEDIATE CLOSURE
We have recently confirmed that different computers have logged onto your Hotmail and Msn account and multiple password errors have been entered. We are hereby suspending your account; as it has been used for fraudulent purposes.. Now we need you to reconfirm your account information to us. Click your reply tab, fill in the columns below and send it back to us or your email account will be suspended permanently.
The email, which has the subject line "CONFIRMATION ALERT RESET (2013)" and comes from an unofficial-looking @msn.com email address, urges the user to reply via email with their full name, username, password, date of birth, and country in order to confirm their identity.
In case that seems a little brusque, the would-be thieves who spammed out this email provided some helpful tips at the end of the email about managing email accounts.
Of course, Microsoft would never ask you to confirm your identity in this fashion - especially not by sending your password in an (unencrypted) email.
But less security-savvy computer users might be duped into believing it is true, and respond with all the information the cybercriminals want, before having a chance to think twice.
It's a highly unsophisticated attack - but if it works against just a small number of people that the spammers send it out to, what does that matter?
Don't be a cybercrime statistic, make sure that you, your friends and your family are wise to such tricks and don't share your login information with anybody.
Follow @gcluley
Hat-tip: Thanks to Naked Security reader Jack for forwarding us this phishing email.
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
The Better Business Bureau (BBB) is well known in North America for championing consumer rights, so if you run a company in the United States or Canada and receive a complaint from the organisation chances are that you will want to take it seriously.
Which is precisely what the cybercriminals behind the latest malware attack being spammed around the world are banking on.
Email messages have been sent to addresses around the world, posing as a communication from the BBB.
Here's a typical example (click on the image below for a larger version):
Here is the full text of the message:
Owner/Manager
The Better Business Bureau has received the above-referenced complaint from one of your customers regarding their dealings with you. The details of the consumer's concern are included on the reverse. Please review this matter and advise us of your position.
As a neutral third party, the Better Business Bureau can help to resolve the matter. Often complaints are a result of misunderstandings a company wants to know about and correct.
In the interest of time and good customer relations, please provide the BBB with written verification of your position in this matter by December 11, 2012. Your prompt response will allow BBB to be of service to you and your customer in reaching a mutually agreeable resolution. Please inform us if you have contacted your customer directly and already resolved this matter.
The Better Business Bureau develops and maintains Reliability Reports on companies across the United States and Canada . This information is available to the public and is frequently used by potential customers. Your cooperation in responding to this complaint becomes a permanent part of your file with the Better Business Bureau. Failure to promptly give attention to this matter may be reflected in the report we give to consumers about your company.
We encourage you to print this complaint (attached file), answer the questions and respond to us.
We look forward to your prompt attention to this matter.
Sincerely,
The Better Business Bureau Complaint Department
You can probably understand that some firms (who don't employ security-savvy staff like yourself) might be tempted to open the attached file.
Sophos security products detect the attached malware as Troj/Agent-ZGD - a Trojan horse designed to take remote control of your Windows computer, and allow a remote hacker to gain access and steal information or install more malware onto your PC.
If you use a security product from a different vendor, you should check that your systems are properly protected from this attack.
We've seen similar malware attacks in the past which pose as messages from the Better Business Bureau. If you receive one either now, or in the future, please exercise caution.
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
Two months ago, we wrote about the conclusion of the NIST Cryptographic Hash Algorithm Competition.
The winner was Keccak - now officially dubbed SHA-3.
Despite the formal ratification of this new standard, NIST's earlier hashes remain commonly used. Indeed, we can expect to see SHA-1 and SHA-2 in the wild for years - possibly even for decades.
SHA-1, in particular, is still widely encountered in password hashing.
Password hashing is where you use a cryptographic hash function in some part of your password archival system to create a one-way function.
A one-way function is a process that's easy to compute in one direction, but complex - or, better yet, computionally infeasible - to work out in reverse.
So, if you store one-way password hashes instead of the actual passwords, attackers who steal your database can't directly recover those passwords. They have to try password after password themselves, until they get lucky.
? Using a one-way function to store passwords is not a replacement for keeping your password database secure. It's additional security that offers a touch of defence-in-depth, just in case your server does get broken into.
Because one-way functions can't be computed in reverse, cracking cryptographically-hashed passwords is inevitably a brute-force affair. It means computing a one-way function over and over again.
As a result, password cracking experts put a lot of effort into improving the performance of widely-used password hashing algorithms, notably including SHA-1.
In June 2012, for example, researchers magnum and JimF (Jim Fougeron) contributed code to the password cracker John the Ripper that boosted raw SHA-1 password hashing speeds by 80%.
And, for the same release, Tavis Ormandy came up with an optimised implementation offering a 115% performance improvement, albeit limited to passwords under 15 characters.
? Password crackers are easily abused. You probably want to control their use inside your organisation. But they have a legitimate defensive purpose: to find poor password hygiene on your own network before the bad guys do.
Now, Jens Steube, author of the pasword cracking tools in the hashcat family, has added to the optimisations against SHA-1 when cracking passwords.
Steube described his work in a paper at the recent Passwords^12 conference in Oslo, Norway.
Steube's password cracking improvements reduce by 21% the number of computer instructions needed to compute a SHA-1 hash. This may allow previous optimisations - such as the the ones described above - to be tweaked yet further for additional speed.
Steube noticed that SHA-1's "inner loop" can be usefully slimmed down if you are repeatedly computing hashes from input data in which only the first input word (32 bits, or four bytes) changes each time.
For a password attack, this can easily be arranged.
Greatly oversimplified, the SHA-1 algorithm consumes its input in blocks of sixteen 32-bit words (512 bits, or 64 bytes), mixing each block into a cumulative hash of five 32-bit words (160 bits, or 20 bytes).
for block in blocks() do for i = 17 to 80 do -- each step here extends the original 16-word input -- block to 80 words by adding one word made by mixing -- together four of the previous sixteen words. block[i] = minimixtogether(block,i) end for i = 1 to 80 do -- each step here mixes one of the words from the 80-word -- "extended block" into the five-byte hash accumulator hash = giantmixtogether(block,i) endend
The giantmixtogther() function that scrambles the extended input into the hash uses a range of different operations, including NOT, AND, OR, XOR, ADD and ROL (rotate left).
But the minimixtogether() function used to condition the input data uses only XOR and ROL. Because of its relative simplicity, Steube found a way to skip the minimixtogether() loop, and to calculate the "expanded" input values block[17] to block[80] directly inside the giantmixtogether() loop.
Steube's method still needs some precalculation, but multiple separate hash evaluations can share this precalculated data if only the first block (i.e. the first four characters) of the input has changed.
If you were hashing a randomly-selected series of files, for example, this would do you no good.
But when conducting a brute force attack against passwords, it's a simple matter to put your input into a suitable sequence so that the first four characters change most rapidly, followed by the rest of the password. (Just imagine a car odometer with the digits reversed.)
If you can do this, then implemeting Steube's tweaks will make your code run 25% faster. Just like that.
And there you have it: yet another reminder that security is an arms race.
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
Bogus hotel reservation emails have been spammed out widely, which claim to come from Booking.com but in reality carry malware designed to infect Windows computers.
Even if recipients haven't booked a hotel room they might be tempted to open the dangerous attachments, in fear that their credit card has been charged.
Here's what a typical malicious email looks like:
The emails are not entirely convincing, as they use a subject line in somewhat broken English:
Subject: you receive the electronic reservation [random number] From: "Booking.com" Attached file: Your electronic reservation ID[random].zip
Here's another example, which claims that you have booked a vacation at the Mandarin Oriental hotel in London's Hyde Park:
As you can see, the cybercriminals behind the campaign have attempted to make their attack harder to block by varying subject lines, attached filenames and the vacation details included in the body of the email.
For instance, a wide variety of hotel names are used in the bogus reservation emails. Here are just a handful of the names used:
Four Seasons HotelMandarin Oriental Hyde ParkShangri-La HotelHotel ImperialMara Safari ClubThe Sanctuary At Kiawah IslandIl San Pietro di PositanoFour Seasons Resort Maui at WaileaGrand Hotel TimeoHotel Ritz-Carlton
If you do receive one of these emails, delete it from your inbox. The one thing you shouldn't do is open the ZIP file and attempt to access the file contained within, as it is designed to infect your Windows computer.
Sophos security products detect the attack as both spam and malware (identifying the attachment proactively as Mal/DrodZp-A).
Of course, this is far from the first time that malware authors have distributed their attack posing as a hotel booking, and it's unlikely to be the last. The reason they use disguises like this is that the social engineering works so well at tricking people into clicking on the dangerous attachment or a malicious link.
It's time to wise up, and tell your friends not to fool for such traps.
You should always be suspicious of email attachments that are sent to you out of the blue. Make sure that your anti-virus product is updated, that you have the latest security patches, and tell your friends to think twice before opening unknown attachments.
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
Hackers used the American Thanksgiving holiday to launch a crafty attack against a local school district in the state of Wisconsin, compromising a direct deposit system, and stealing $150,000 intended for teachers.
Administrators in the Stanley-Boyd school district in the western part of Wisconsin were alerted to the attack by their bank on November 21, according to a report in the Chippewa Herald.
According to the newspaper, the attackers compromised the district's network and altered its direct deposit file, supplanting employee bank account information with accounts belonging to the attackers.
AnchorBank, based in Madison, Wisconsin, noticed the unusual activity and alerted the district. The district has notified the FBI, which is investigating.
In the meantime, AnchorBank said it had been able to retrieve a portion of the stolen payroll as of November 27, and believed it could recover most of the lost funds.
Hacking school districts isn't about changing grades "War Games"-style.
(Though that still happens, too!) .
Rather, school districts and municipalities are a prime target for cybercriminal gangs, many based outside the United States.
Hackers are attracted to the small towns because they often are short on IT security expertise, but have easy access to cash through bank accounts and lines of credit. Beyond that, the decentralized nature of many municipal operations can make detection difficult.
In just the latest incident, in October, the town of Burlington, Washington, disclosed that hackers had compromised a number of town systems used to operate an online utility billing system and stolen $400,000 from a city bank account.
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
A 20-year-old British man will appear in court next month, charged with attempting to bring down the websites of Oxford and Cambridge universities.
Lewys Martin, from Kent, faces a total of 17 counts following an investigation by Kent Police's Special Branch investigations team, and the Kent Police Digital Forensic Unit.
The charges brought against the 20-year-old relate to denial-of-service attacks on various websites, including a website belonging to the Kent police force, theft of personal data and failure to disclose passwords for encrypted computer equipment.
Martin is scheduled to appear at Maidstone Magistrates Court on December 20th in relation to the charges.
This feels like an appropriate time to remind all readers that denial-of-service attacks are against the law in many countries around the world, and can lead to a jail sentence.
Lewys Martin is currently serving a sentence in prison, after writing malware disguised as a patch for the "Call of Duty" video game, and attempting to break into local colleges to steal computer equipment.
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
A malware attack has been spammed out widely via email to internet users, posing as a message about photos.
In the attack, cybercriminals attempt to trick unsuspecting users into opening an attached file in their browser, redirecting them to a webpage hosted on a Russian website that takes advantage of the Blackhole exploit kit.
The notorious Blackhole exploit kit then attempts to infect visiting computers through a wide number of vulnerabilities.
Here's a typical message that has been spammed out - in this case, pretending to come from a LinkedIn user:
Subject: Your Photos
Message body: Hi, I have attached your photos to the mail (Open with Internet Explorer)
The attached file has a name of Image_DIG[random number].htm. If you make the mistake of opening the file attachment in your web browser you will see a "please wait" message:
Please wait a moment. You will be forwarded..
Internet Explorer or Mozilla Firefox compatible only
Sophos detects this HTML file proactively as Mal/JSRedir-M. What isn't obvious to most computer users is that behind-the-scenes obfuscated JavaScript code is redirecting the user's browser to a Blackhole exploit site.
More and more of the attacks that the folks at SophosLabs are intercepting involve the Blackhole exploit kit, underlining the importance of keeping your computer's anti-virus software and software patches up-to-date as well as learning to exercise caution about opening unsolicited attachments or clicking on unknown links.
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
HSBC has successfully recovered from a distributed denial-of-service (DDoS) attack which saw a number of its websites brought down, making it impossible for customers to use internet banking services.
The international bank stressed that no customer data was impacted by the attack in a statement posted on its website:
On 18 October 2012 HSBC servers came under a denial of service attack which affected a number of HSBC websites around the world.
This denial of service attack did not affect any customer data, but did prevent customers using HSBC online services, including internet banking.
We are taking appropriate action, working hard to restore service. We are pleased to say that some sites are now back up and running.
We are cooperating with the relevant authorities and will cooperate with other organisations that have been similarly affected by such criminal acts.
We apologise for any inconvenience caused to our customers throughout the world.
According to an update posted on its website, HSBC restored all of its websites globally to full accessibility as of 3:00am UK time.
DDoS attacks, which are illegal, occur when a criminal commands a number of computers to bombard a website with unwanted traffic.
In many cases, the computers used in an attack will have been hijacked by hackers using malware, and will be taking part in the assault without the knowledge of their owners. In other cases, people will willingly participate in a DDoS attack.
A co-ordinated deluge of web traffic can effectively clog up a website, preventing legitimate visitors from reaching the site, and bring it to its knees.
You can picture a distributed denial-of-service attack as being something like 15 fat men trying to get through a revolving door at the same time. Nothing moves.
Of course, denial-of-service attacks are no laughing matter.
Some DDoS attacks have been perpetrated for political or hacktivist reasons, while others have tried to blackmail money out of large companies.
Don't allow your computer to be caught up in a denial-of-service attack. Now would be a good time to ensure that you have good defences in place to prevent your personal computer from being recruited for someone else's online fight.
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
Raynaldo Rivera, from Tempe, Arizona, has admitted hacking into computer systems belonging to Sony Pictures, and stealing the personal information and passwords of thousands of innocent internet users
The attack, which took place in May last year, was part of a concerted attack against Sony websites by LulzSec and Anonymous hackers during 2011.
Rivera, who was arrested by the FBI in August, admitted his guilt in the form of a plea agreement filed with Los Angeles Federal Court.
Rivera - who used online nicknames including "neuron", "royal", and "wildicv" - admitted launching an SQL injection attack against the Sony Pictures website, extracting confidential and personal user information - such as the names, birth dates, addresses, emails, phone numbers and passwords of people who had entered Sony contests.
The stolen information was subsequently published online by the LulzSec hacking gang, compounding the risk to innocent users.
The hack is said to have cost Sony more than $605,000 in losses.
In an attempt to hide his true identity during the attack, Rivera used the HideMyAss anonymising proxy service to disguise his IP address as he probed the Sony Pictures' website for vulnerabilities.
However, Rivera had not been careful enough in disguising his tracks - and HideMyAss co-operated with the authorities when a court order was received by the anonymising proxy service.
Others considering committing crimes on the net might be wise to stop believing that using an anonymising proxy service will necessarily keep them out of the clutches of the law.
Under the plea agremement, Rivera will pay restitution to his victims. He also faces a maximum five year prison sentence, and a fine of at least $250,000.
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
If Skype users didn't have enough to worry about this week security-wise (with a worm spreading across the system), there's now another threat to warn about.
Emails have been spammed out by cybercriminals, posing as messages from Skype, claiming that you have changed your password on the service.
Here's an example of one such email (click on it for a larger version):
If you look carefully, you may spot that the spammers made a clumsy spelling mistake:
Password successfully changed Your new Skype password has been set.
You can now view your attached call history and inscturtions how to change your account settings. If the changes described above are accurate, no further action is needed. If anything doesn't look right, follow the link below to make changes: Restore password Talk soon, The people at Skype
Perhaps surprisingly, the links really do point to the genuine Skype website at skype.com.
However, a file (Skype_Password_insctructions.zip) is attached to the email, and if you make the mistake of unzipping and executing its contents (Skype_Password_inscructions.pdf.exe) you run the risk of infecting your Windows computer.
The malware, which is detected by Sophos products as Troj/Backdr-HN, opens a backdoor onto your computer, giving remote hackers access to your system.
The danger is, of course, that users worried by the recent worm will be frightened that their Skype password has been changed without their consent, and open the attachment - and thus infect their PC.
As always, be on the lookout for unsolicited suspicious emails and always be wary of opening attachments which arrive out of the blue. In this case, the file is using the well-known "double extension trick" to dupe the unwary into believing that they might be clicking on a PDF rather than executable code.
Follow @gcluley
Thanks to SophosLabs researcher Julie Yeates for her assistance with this article.