Google Search

Showing posts with label break. Show all posts
Showing posts with label break. Show all posts

Saturday, September 21, 2013

NYPD detective charged with hiring email hackers to break into colleagues' personal accounts

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

NYPD logoNew York City police have arrested a NYPD detective for hiring an email hacking service to pinch the login details for at least 43 personal email accounts and one cell phone belonging to at least 30 individuals.

Edwin Vargas, 42, of Bronxville, New York, is accused of having paid $4,050 via PayPal to an illicit hacking service between March 2011 and October 2012.

According to a statement from Preet Bharara, the US Attorney for the Southern District of New York, Federal Bureau of Investigations (FBI) agents arrested Vargas outside his home on Tuesday.

Officials said that 19 of Vargas' alleged targets are current NYPD officers, one is retired from the NYPD, and another is an administrative staff member of the NYPD.

Vargas allegedly used the login credentials to peek into at least one personal email account belonging to a current NYPD officer. He also allegedly accessed another victim's online cellular telephone account.

Law enforcement officials said that when they checked out the hard drive on Vargas' NYPD computer, they also found that his Gmail account Contacts section included a list of at least 20 email addresses, along with what looks like telephone numbers, home addresses, and vehicle information corresponding to those email addresses.

The list also contained what seem to be passwords for the email addresses.

Vargas also allegedly accessed the federal National Crime Information Center (NCIC) database to get information about at least two NYPD officers and then paid email hacking services to filch their logins.

Login screen. Image from ShutterstockThe detective has been charged with one count of conspiracy to commit computer hacking and one count of computer hacking. Each count carries a maximum sentence of one year in prison.

US Attorney Bharara said in the statement that it's pretty darn bad when the cops themselves are the ones breaking the laws they're paid to enforce:

As alleged, Detective Edwin Vargas paid thousands of dollars for the ability to illegally invade the privacy of his fellow officers and others.

He is also alleged to have illegally obtained information about two officers from a federal database to which he had access based on his status as an NYPD detective.

When law enforcement officers break the laws they are sworn to uphold, they do a disservice to their fellow officers, to the Department, and to the public they serve, and it will not be tolerated.

FBI Assistant Director-in-Charge George Venizelos also said in the statement that gosh, you'd think you'd be able to trust your coworkers if your workplace is a police department:

As alleged, the defendant illegally acquired log-in information for the email accounts of dozens of people, including police department co-workers.

Of all places, the police department is not a workplace where one should have to be concerned about an unscrupulous fellow employee.

Unlike the email accounts, the defendant didn't need to pay anyone to gain access to the NCIC database. But access is not authorization, and he had no authorization.

Let's assume that Naked Security readers won't fall for pitches from such email hacking services, such as this charmingly misspelled/garbled one:

If you want to know someone's email password than get it right now. How to hack? No, you don't have to do that, let our experts to hack your requested password in less than 48 hrs and you will be charged with $100

How do these services work?

Some of them, in their marketing materials, put up lists of techniques that include brute-force attack, keylogger installation, dictionary attacks, sniffing (if the hacker and the victim share the same wireless network, such as in a workplace or cyber cafe), and/or social engineering techniques.

Unfortunately, if the allegations prove true, it sounds as though the NYPD not only harbored one bad apple; it also has plenty of staff who might well have fallen for one or more of the email hacking services' techniques.

As far as protecting ourselves from having our accounts breached, the tried and true advice holds: keep on top of patches; don't click on phishy links or open phishy email; make sure you're using a password management program to generate convoluted, hard-to-guess passwords; and/or read Graham Cluley's piece about cooking up your own.

(Enjoy this video? You can check out more on the SophosLabs YouTube channel and subscribe if you like.)

Better still, follow the advice I saw on a cartoon on Wednesday:

Sorry, your password must contain a capital letter, two numbers, a symbol, an inspiring message, a spell, a gang sign, a hieroglyph and the blood of a virgin.

Bravo!

Follow @LisaVaas
Follow @NakedSecurity

Image of login screen courtesy of Shutterstock.


View the original article here

Monday, August 22, 2011

Hackers can use text messaging to break into cars

By Jordan Robertson August 19, 2011 11:38PM

Story Image Security consultants Don Bailey (left) and Mathew Solnik, of iSEC Partners, demonstrate with a computer how they force cars with certain alarm systems to unlock their doors and start their engines by sending them text messages. | AP

Updated: August 20, 2011 2:05AM

SAN FRANCISCO — Texting and driving don’t go well together — though not in the way you might think.

Computer hackers can force some cars to unlock their doors and start their engines without a key by sending specially crafted messages to a car’s anti-theft system. They can also snoop at where you’ve been by tapping the car’s GPS system.

That is possible because car alarms, GPS systems and other devices are increasingly connected to cellular telephone networks and thus can receive commands through text messaging. That capability allows owners to change settings on devices remotely, but it also gives hackers a way in.

Researchers from iSEC Partners recently demonstrated such an attack on a Subaru Outback equipped with a vulnerable alarm system, which wasn’t identified. With a laptop perched on the hood, they sent the Subaru’s alarm system commands to unlock the doors and start the engine.

Their findings show that text messaging is no longer limited to short notes telling friends you’re running late or asking if they’re free for dinner.

Texts are a powerful means of attack because the devices that receive them generally cannot refuse texts and the commands encoded in them. Users can’t block texts; only operators of the phone networks can.

These devices are assigned phone numbers just like fax machines. So if you can find the secret phone number attached to a particular device, you can throw it off by sending your own commands through text messaging.

Although these numbers are only supposed to be known by the devices’ operators, they aren’t impossible to find. Certain network-administration programs allow technicians to probe networks to see what kinds of devices are on them. Based on the format of the responses, the type and even model of the device can be deduced. Hackers can use that information to craft attacks against devices they know are vulnerable. (In this case, the researchers bypassed these steps and simply took the alarm system out of the car to identify the secret phone number.)

Actually stealing a car wouldn’t be so easy.

You’d have to ensure that the phone number you found is attached to the car you’re standing in front of, for instance. There are hacking tools to do that — they listen for cellular traffic around a particular vehicle — but in many cases it’s easier to take a car that doesn’t have an alarm.

The research from Don Bailey and Mat Solnik is unsettling because it shows that such attacks are possible on a variety of other devices that use wireless communications chips. Those include ATMs, medical devices and even traffic lights. Hackers have already sent specially crafted texts with commands to instantly disconnect iPhones from the cellular network.

Bailey, whose specialty is cell phone network security, also found that similar techniques can be used to get a certain type of GPS system to cough up its location data. Such information can be used by stalkers or home burglars, for instance. AP

© 2011 Sun-Times Media, LLC. All rights reserved. This material may not be copied or distributed without permission. For more information about reprints and permissions, visit http://www.suntimesreprints.com/. To order a reprint of this article, click here.

View the original article here

Monday, July 11, 2011

Hackers break into Washington Post jobs site

(Reuters) - Hackers broke into the Washington Post Co's jobs website in two incidents last month, affecting more than a million user IDs and emails, the company said on its website.

The company said about 1.27 million users' IDs and email addresses were affected but no passwords or other personal information was accessed.

The company said the jobs accounts of users whose email addresses were accessed remained secure.

This latest breach comes amid a spate of hack attacks against high profile targets including Sony Corp and Citigroup.

Washington Post said it quickly identified the attack and took action to shut it down. It is pursuing the matter with law enforcement and conducting an audit of the security of its jobs site.

(Reporting by Abhishek Takle in Bangalore; Editing by)


View the original article here

Thursday, June 23, 2011

Hackers break into computer system at Conor O'Neills Irish pub in Ann Arbor ... - Detroit Free Press

Ann Arbor police say hackers broke into the computer system of a popular Irish restaurant, stealing numerous credit card and debit card numbers to make purchases.

The case came to light after the credit and debit cards were fraudulently used in the state of Texas between April 22 and June 10, police said.

Local banks traced the fraud back to Conor O?Neills Restaurant at 318 S. Main St. in Ann Arbor, and management there contacted police.

?The banks were receiving information about these fraudulent transactions and did a little digging and discovered the common point of purchase between the cases was Conor O?Neills,? Ann Arbor Police Det. Sgt. Pat Hughes said.

According to police, the restaurants? credit card processing computer was vulnerable to computer hackers, possibly from Europe, allowing them to infiltrate the system and gain access to all of the credit/debit card numbers that had been used at the business.

Police say it?s not yet known how many customers? credit and debit cards were accessed. Because the charges have taken place in other states, Ann Arbor police don?t know the total number of fraudulent credit card purchases involved, Hughes said.

Hughes said police have tracked some of the fraud to Europe and Texas and are working with authorities in other jurisdictions on the case. But, he said, these types of cases are typically complex and difficult to solve.

According to police, Conor O?Neill?s has taken the necessary measures to protect and ensure the security of its customers? credit and debit card account numbers from any future hacking attempts.

Among the numbers stolen were credit and debit cards issued by the Bank of Ann Arbor and the University of Michigan Credit Union, police said.

Ann Arbor police say the investigation is continuing.

Hughes said people should be vigilant in checking their monthly credit card statements for suspicious charges. If they discover any charges they didn?t make, they should contact the bank or credit card company, he said.


View the original article here