Google Search

Showing posts with label hackers. Show all posts
Showing posts with label hackers. Show all posts

Wednesday, June 18, 2014

Ransom-taking iPhone hackers busted by Russian authorities

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

iphone-lock-170The mystery of the ransom messages from "Oleg Pliss," and the iDevice locking attack that popped up in Australia and the US last month, appears to have been solved.

Authorities in Russia said they detained two criminals behind ransom attacks on Apple users that locked their devices remotely and demanded payment to unlock them.

I say "seems to have been solved" because Russian police said the hackers were responsible for the same scam on users in Russia, without mentioning victims in other countries.

The two Russian hackers - a 23-year-old and a 17-year-old from Moscow - reportedly confessed to scamming users into giving away their Apple IDs and using the Find My iPhone feature to lock the devices until the victims paid a ransom of up to $100 USD.

According to The Sydney Morning Herald, Russian media reported the pair of hackers were caught on CCTV when they withdrew victims' payments from an ATM.

Russia's Ministry of Internal Affairs stated on its website that agents searched the hackers' apartments and seized computers, phones, SIM cards and "literature" on hacking.

Russian authorities said the hackers used "two well-known schemes" to perpetrate their attacks, which affected Apple users in Russia.

It seems the two hackers tricked Apple users into giving away their Apple IDs with a phishing scam that asked them to sign up for an online video service that required their Apple IDs.

If a hacker gets hold of your Apple ID they can create an iCloud account which they can then use then lock your iPhone, iPad, iPod or iMac device remotely.

The Sydney Morning Herald reports that victims who locked their phones with passcodes could simply enter it, change their iCloud password and avoid having to pay a ransom.

Users who didn't set passcodes were less fortunate and had to resort to wiping their devices and restoring them from backups.

If you've been hacked by 'Oleg Pliss' then we recommend you follow the advice in our earlier article Apple ransomware strikes Australia.

In the security industry we call cyber attacks that take over your computer and demand payment "ransomware".

The most famous ransomware is the notorious CryptoLocker, which authorities recently knocked out by taking over the cybercriminals' command and control servers.

Only recently, however, have crooks figured out how to turn the success of ransomware for PCs into a lucrative racket on mobile devices.

Technically, since the "Oleg Pliss" hackers didn't drop any malware onto the devices of their victims, the iDevice-locking attack isn't a real example of ransomware, but it has the same devious purpose - to extort victims for money.

It's a much different story for Android, which is more susceptible to mobile malware.

A file-encrypting ransomware for Android called Simplelocker was recently discovered, and another kind of ransomware known as a "police locker" has hit Android users who download an infected file claiming to be a video player.

iphone-5-lock-screen-170As a security precaution, you should make sure you lock your phone with a secure passcode.

Your Apple ID is the key to your iDevices, so make sure you hold onto it tight (don't use your Apple ID for a suspicious media-download website, for example).

You should also make sure your iDevices are up to date with the latest iOS software version to stay safe from known exploits.

For Android users, we also recommend using an anti-virus such as Sophos Antivirus and Security, our free app for smartphones and tablets.

For more information on keeping your phones and tablets safe take a look at our 10 tips for securing your smartphone.

Follow @JohnZorabedian
Follow @NakedSecurity

Image of locked iPhone courtesy of Shutterstock.

Tags: apple ID, hacking, iCloud, ios, iPhone, Ministry of Internal Affairs, oleg pliss, passcode, phishing, ransomware, russia


View the original article here

Wednesday, May 21, 2014

Black markets for hackers increasingly sophisticated, specialized, maturing

Black and gray markets for computer hacking tools, services and byproducts such as stolen credit card numbers continue to expand, creating an increasing threat to businesses, governments and individuals, according to a new RAND Corporation study.

One dramatic example is the December 2013 breach of retail giant Target, in which data from approximately 40 million credit cards and 70 million user accounts was hijacked. Within days, that data appeared -- available for purchase -- on black market websites.

"Hacking used to be an activity that was mainly carried out by individuals working alone, but over the last 15 years the world of hacking has become more organized and reliable," said Lillian Ablon, lead author of the study and an information systems analyst at RAND, a nonprofit research organization. "In certain respects, cybercrime can be more lucrative and easier to carry out than the illegal drug trade."

The growth in cybercrime has been assisted by sophisticated and specialized markets that freely deal in the tools and the spoils of cybercrime. These include items such as exploit kits (software tools that can help create, distribute, and manage attacks on systems), botnets (a group of compromised computers remotely controlled by a central authority that can be used to send spam or flood websites), as-a-service models (hacking for hire) and the fruits of cybercrime, including stolen credit card numbers and compromised hosts.

In the wake of several highly-publicized arrests and an increase in the ability of law enforcement to take down some markets, access to many of these black markets has become more restricted, with cybercriminals vetting potential partners before offering access to the upper levels. That said, once in, there is very low barrier to entry to participate and profit, according to the report.

RAND researchers conducted more than two dozen interviews with cybersecurity and related experts, including academics, security researchers, news reporters, security vendors and law enforcement officials. The study outlines the characteristics of the cybercrime black markets, with additional consideration given to botnets and their role in the black market, and "zero-day" vulnerabilities (software bugs that are unknown to vendors and without a software patch). Researchers also examine various projections and predictions for how the black market may evolve.

What makes these black markets notable is their resilience and sophistication, Ablon said. Even as consumers and businesses have fortified their activities in reaction to security threats, cybercriminals have adapted. An increase in law enforcement arrests has resulted in hackers going after bigger targets. More and more crimes have a digital component.

The RAND study says there will be more activity in "darknets," more checking and vetting of participants, more use of crypto-currencies such as Bitcoin, greater anonymity capabilities in malware, and more attention to encrypting and protecting communications and transactions. Helped by such markets, the ability to attack will likely outpace the ability to defend.

Hyper-connectivity will create more points of presence for attack and exploitation so that crime increasingly will have a networked or cyber component, creating a wider range of opportunities for black markets. Exploitations of social networks and mobile devices will continue to grow. There will be more hacking-for-hire, as-a-service offerings and cybercrime brokers.

However, experts disagree on who will be the most affected by the growth of the black market, what products will be on the rise and which types of attacks will be more prevalent, Ablon said.

The study, "Markets for Cybercrime Tools and Stolen Data: Hackers' Bazaar," can be found at http://www.rand.org/pubs/research_reports/RR610.html.

Story Source:

The above story is based on materials provided by RAND Corporation. Note: Materials may be edited for content and length.


View the original article here

Sunday, May 18, 2014

Cybersecurity researchers roll out a new heartbleed solution: Red Herring creates decoy servers, entraps, monitors hackers

As companies scrambled in recent days to address the latest cybersecurity bug known as Heartbleed, researchers at The University of Texas at Dallas had a solution that fixes the vulnerability, and also detects and entraps hackers who might be using it to steal sensitive data.

The advanced technique -- dubbed Red Herring -- was created by a team led by Dr. Kevin Hamlen, an associate professor of computer science in the Erik Jonsson School of Computer Science and Engineering. It automates the process of creating decoy servers, making hackers believe they have gained access to confidential, secure information, when in fact their deeds are being monitored, analyzed and traced back to the source.

"Our automated honeypot creates a fixed Web server that looks and acts exactly like the original -- but it's a trap," said Hamlen, a member of the UT Dallas Cyber Security Research and Education Institute (CSI). "The attackers think they are winning, but Red Herring basically keeps them on the hook longer so the server owner can track them and their activities. This is a way to discover what these nefarious individuals are trying to do, instead of just blocking what they are doing."

The Heartbleed bug affects about two-thirds of websites previously believed to be secure. These are websites that use the computer code library called OpenSSL to encrypt supposedly secure Internet connections that are used for sensitive purposes such as online banking and purchasing, sending and receiving emails, and remotely accessing work networks. Heartbleed became public last week.

In 2012, a new feature named Heartbeat was added to software primarily for slow Internet connections. Heartbeat allowed connections to be held open, even during idle time. A flaw in the implementation allowed confidential information to be passed through the connection, hence the name Heartbleed.

Even though Heartbleed is now in the process of being fixed, victims face the challenge of not knowing who may already be exploiting it to steal the information, and what information they may be going after. A common fix for this type of problem is to create a trap, a honeypot that lures and exposes attackers. Typically this can involve setting up another Web server somewhere else.

"There are all sorts of ad hoc solutions where people try to confuse the attacker by deploying fake servers, but our solution builds the trap into the real server so that attacks against the real server are detected and monitored," Hamlen said. "Our research idea can build this honeypot really quickly and reliably as new vulnerabilities are disclosed."

The Red Herring algorithm created by Hamlen automatically converts a patch -- code widely used to fix new vulnerabilities like Heartbleed -- into a honeypot that can catch the attacker at the same time.

"When Heartbleed came out, this was the perfect test of our prototype," Hamlen said.

Red Herring doesn't stop at being a decoy and blocker; it can also lead to catching the attacker. As the attacker thinks he or she is stealing data, an analyst is tracking the attack to find out what information the attacker is after, how the malicious code works and who is sending the code.

"In their original disclosure, security firm Codenomicon urged experts to start manually building honeypots for Heartbleed," Hamlen said. "Since we already had created algorithms to automate this process, we had a solution within hours."

When news of Heartbleed became public on April 8, software engineering doctoral student Frederico Araujo started researching the vulnerability and had implemented Red Herring by 2:30 a.m. April 9.

"I was very proud that he had taken the initiative before I'd even gotten to it," Hamlen said. "Normally, I personally would have started working on it sooner, but I'd been up all night grading papers the night before."


View the original article here

Monday, October 14, 2013

EU to vote on harsher penalties for hackers

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Gavel and EU, image courtesy of ShutterstockThe EU has drafted a new directive that includes harsher penalties for those convicted of hacking.

The European Parliament last week approved a draft of the proposal and will vote on it in July.

Those found guilty of the following types of illegal hacking will face at least two years in prison, if they do so with criminal intent and cause serious harm, if they breach a security measure while doing so, and if they neglect to tell a system operator all about the vulnerability in a timely manner:

Illegal, intentional access to an information system. Illegally interfering with data.Illegally intercepting communications. This includes recording communications and covers the time spanning data transfer from the sender to the receiver, by cable or wireless, and the devices and technologies that record, including software, passwords and codes. Intentionally producing and selling tools used to commit these offenses.

The proposal calls for a minimum of five years imprisonment for attacks against critical infrastructure and also applies if an attack is carried out by a criminal organisation or if it causes serious damage.

Botnet creators and herders will face at least three years in prison under the new directive.

The directive, approved by the European Parliament's Committee on Civil Liberties, Justice and Home Affairs, also stipulates that EU member states respond within 8 hours, maximum, 24 hours a day, 7 days a week, to urgent security requests from other member states experiencing cyber attacks, to at least let somebody know how and when they plan to answer the request for help.

EU cyber attack, image courtesy of ShutterstockThe directive also calls for penalties for actions such as hiring hackers to disrupt the competition, in which case companies could lose their public benefits or even get shut down.

The directive is clear about distinguishing attacks that lack criminal intent, which would cover testing or protection of information systems and thereby shield whistleblowers.

That's reassuring. Pen testing and whistleblowing are essential activities that deserve legal protection.

Follow @LisaVaas
Follow @NakedSecurity

Image of EU and gavel and Euro attack courtesy of Shutterstock.


View the original article here

Saturday, September 21, 2013

NYPD detective charged with hiring email hackers to break into colleagues' personal accounts

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

NYPD logoNew York City police have arrested a NYPD detective for hiring an email hacking service to pinch the login details for at least 43 personal email accounts and one cell phone belonging to at least 30 individuals.

Edwin Vargas, 42, of Bronxville, New York, is accused of having paid $4,050 via PayPal to an illicit hacking service between March 2011 and October 2012.

According to a statement from Preet Bharara, the US Attorney for the Southern District of New York, Federal Bureau of Investigations (FBI) agents arrested Vargas outside his home on Tuesday.

Officials said that 19 of Vargas' alleged targets are current NYPD officers, one is retired from the NYPD, and another is an administrative staff member of the NYPD.

Vargas allegedly used the login credentials to peek into at least one personal email account belonging to a current NYPD officer. He also allegedly accessed another victim's online cellular telephone account.

Law enforcement officials said that when they checked out the hard drive on Vargas' NYPD computer, they also found that his Gmail account Contacts section included a list of at least 20 email addresses, along with what looks like telephone numbers, home addresses, and vehicle information corresponding to those email addresses.

The list also contained what seem to be passwords for the email addresses.

Vargas also allegedly accessed the federal National Crime Information Center (NCIC) database to get information about at least two NYPD officers and then paid email hacking services to filch their logins.

Login screen. Image from ShutterstockThe detective has been charged with one count of conspiracy to commit computer hacking and one count of computer hacking. Each count carries a maximum sentence of one year in prison.

US Attorney Bharara said in the statement that it's pretty darn bad when the cops themselves are the ones breaking the laws they're paid to enforce:

As alleged, Detective Edwin Vargas paid thousands of dollars for the ability to illegally invade the privacy of his fellow officers and others.

He is also alleged to have illegally obtained information about two officers from a federal database to which he had access based on his status as an NYPD detective.

When law enforcement officers break the laws they are sworn to uphold, they do a disservice to their fellow officers, to the Department, and to the public they serve, and it will not be tolerated.

FBI Assistant Director-in-Charge George Venizelos also said in the statement that gosh, you'd think you'd be able to trust your coworkers if your workplace is a police department:

As alleged, the defendant illegally acquired log-in information for the email accounts of dozens of people, including police department co-workers.

Of all places, the police department is not a workplace where one should have to be concerned about an unscrupulous fellow employee.

Unlike the email accounts, the defendant didn't need to pay anyone to gain access to the NCIC database. But access is not authorization, and he had no authorization.

Let's assume that Naked Security readers won't fall for pitches from such email hacking services, such as this charmingly misspelled/garbled one:

If you want to know someone's email password than get it right now. How to hack? No, you don't have to do that, let our experts to hack your requested password in less than 48 hrs and you will be charged with $100

How do these services work?

Some of them, in their marketing materials, put up lists of techniques that include brute-force attack, keylogger installation, dictionary attacks, sniffing (if the hacker and the victim share the same wireless network, such as in a workplace or cyber cafe), and/or social engineering techniques.

Unfortunately, if the allegations prove true, it sounds as though the NYPD not only harbored one bad apple; it also has plenty of staff who might well have fallen for one or more of the email hacking services' techniques.

As far as protecting ourselves from having our accounts breached, the tried and true advice holds: keep on top of patches; don't click on phishy links or open phishy email; make sure you're using a password management program to generate convoluted, hard-to-guess passwords; and/or read Graham Cluley's piece about cooking up your own.

(Enjoy this video? You can check out more on the SophosLabs YouTube channel and subscribe if you like.)

Better still, follow the advice I saw on a cartoon on Wednesday:

Sorry, your password must contain a capital letter, two numbers, a symbol, an inspiring message, a spell, a gang sign, a hieroglyph and the blood of a virgin.

Bravo!

Follow @LisaVaas
Follow @NakedSecurity

Image of login screen courtesy of Shutterstock.


View the original article here

Tuesday, September 10, 2013

22 million user IDs may be in the hands of hackers, after Yahoo Japan security breach

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Yahoo JapanThe call has gone out to Yahoo Japan's 200 million users to change their passwords, after the company warned that it suspected hackers had managed to access a file containing 22 million user IDs.

Yahoo Japan says that it detected an attempt to gain unauthorised access to its administrative systems on Thursday at approximately 9pm local time.

Although the information taken from Yahoo Japan's servers is said not to contain passwords, or other personal identifying information required to hijack an account (such as the answers to secret questions), the site has decided that users should reset their passwords regardless.

In a press statement published on Yahoo Japan's website, the number one search engine in Japan stressed that it had not confirmed that the data had definitely leaked to the outside world, but that it deeply apologised for any inconvenience caused.

Yahoo Japan statement

Fingers crossed, only user IDs were exposed during the security breach and nothing more serious. But even user IDs should be private, and kept out of the hands of cybercriminals.

Potentially, online criminals now have a database of 22 million Yahoo Japan email addresses - and there are surely slimebags out there who would get a real kick out of spewing out a spam campaign, sending a phishing attack to Yahoo users, posing as a legitimate email from the company, or launching a targeted malware attack.

Hopefully Yahoo Japan will be investigating how the security breach occurred, and putting strong defences in place to prevent it - or anything worse - happening in future.

Follow @gcluley

View the original article here

Sunday, August 4, 2013

From hackers to security experts, the Balkan IT sector is booming

By Radu Marinas and Tsvetelia Tsolova

BUCHAREST/SOFIA (Reuters) - After hacking the Pentagon, NASA and Britain's Royal Navy for fun, TinKode got a real job as a computer security expert for a Romanian cyber safety consultancy.

TinKode was the name used by Romanian Razvan Cernaianu when he revealed security holes in government and corporate systems across the world, earning him a two-year suspended prison sentence.

"I was really passionate about carrying out what I call security audits," Cernaianu told Reuters "It's a hobby, so I did it for free. Moreover, I've always sent emails to those institutions to fix their problems."

Cernaianu, 21, is an example of a deep well of talent in Romania and Bulgaria. They may be the European Union's two poorest members, but their low labour costs, skilled workers and strategic location are underpinning a technology boom.

Multinational companies are using their expertise for customer support, software development and business process outsourcing. Oracle, SAP, IBM, Hewlett Packard and Siemens all have business centres or operations in the region.

Romania-founded GeCaD developed Microsoft's RAV antivirus software and Bucharest-based Softwin created BitDefender internet security technology more than a decade ago, reaching half a billion users worldwide last year.

The expertise is partly accidental - in the 1980s, Romania's communist dictator Nicolae Ceausescu backed computer research and technical education to promote pride in the nation. Piracy flourished after the 1989 revolution as people who could not afford proprietary content bought cheap copies instead.

EXCEPTIONAL GROWTH

On the other side of the Danube, Bulgaria's communists focused on hardware, at one point producing and supplying 40 percent of all computers used in the Soviet bloc.

The tech sector accounts for up to 10 percent of the two economies, according to business associations - a rare bright spot in the recession-hit Balkan region.

Growth of the Romanian and Bulgarian IT sectors far outpaced the rest of ex-communist Europe, jumping by 45 percent and 80 percent respectively since their 2007 EU entry. Meanwhile, the tech sectors in Poland, Hungary and the Czech Republic each grew by about 20 percent.

Romania's tech sector achieved year-on-year growth of 40 percent in the final quarter of 2012, which helped the country to avoid slipping back into recession.

Cernaianu, one of the world's most-wanted hackers until his arrest last year after a joint investigation by Romanian police, the FBI and NASA, now has a well-paid job and is co-owner of computer network security company CyberSmartDefence.

But the dirty side of the expertise still lingers.

Working from a tidy desk in a downtown Bucharest office, Cernaianu is from the same generation as the youngsters responsible for the Romanian town of Ramnicu Valcea becoming known as a global hacking hub.

Romanian hackers stole about $1 billion from U.S. accounts in 2012, according to the U.S. embassy in Bucharest. A report by Verizon this week said that Romania is the world's second-biggest hacking centre behind China.

The FBI has even set up an office in Romania and helped to train specialist police agents.

Cernaianu says he never attacked a computer to steal money.

"We won't hire thieves," said CyberSmartDefence CEO Madalin Dumitru. "We're not afraid of such people (as Cernaianu); we use their intelligence and expertise."

BRAIN DRAIN

The investment in business outsourcing has created an estimated 15,000 jobs in Bulgaria, where an otherwise depressed economy has sparked nationwide protests that toppled the government in February.

"Why would you choose Bulgaria? Because it offers complex outsourcing and high-end software solutions," said Plamen Tilev, managing director of SAP Labs Bulgaria, which develops core software for the Germany company. "For low-end solutions, like code writing and checking, you'd go to east Asian countries."

The biggest fear is that Romania and Bulgaria become victims of their own success and suffer a brain drain. Tens of thousands of Romanians and Bulgarians have already left to work as IT specialists in the United States.

The populations of the two countries have plunged in the past decade and companies are pushing the governments to improve education, train more engineers and make it easier to bring in workers from neighbours such as Moldova, Serbia, Macedonia and Ukraine.

"There has been zero unemployment in the sector in the past 10 years," said Elena Marinova, who runs software business Musala Soft, which is now struggling to find qualified staff despite salaries about three times the national average.

Bulgarian universities produce about 2,000 IT specialists a year, but the industry says it creates 6,000 jobs a year in the country.

"The software industry is struggling to breathe because of the lack of people," said Petar Statev, head of the Bulgarian business association ICT Cluster.

(Editing by Sam Cage and David Goodman)


View the original article here

Sunday, July 28, 2013

Warning! Hackers are exploiting Texas explosion news to spread malware

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Once again, cybercriminals are leaping at the opportunity to take advantage of breaking news stories to spread malware.

The latest example, coming just days after malware authors exploited interest in the Boston Marathon bombings, concerns the fatal explosion in the small community of West, Texas, of a fertiliser plant.

Here's an example of one of the malicious emails intercepted by SophosLabs, with the subject line "CAUGHT ON CAMERA: Fertilizer Plant Explosion Near Waco, Texas".

Malicious email

Other messages have been seen using the subject line "Raw: Texas Explosion Injures Dozens".

Clicking on the link contained inside the emails takes unsuspecting computer users to a webpage that contains a series of embedded YouTube videos.

Video website designed to infect visiting computers

Harmless enough, you might think. However, the webpage also contains a 640x360 pixel iFrame, that attempts to suck in malicious content from another site, designed to infect your computer. The attack uses the Redkit exploit kit to take advantage of vulnerabilities on visiting PCs in order to infect them with malware.

The Redkit exploit kit uses a PHP shell hosted on compromised websites to run its operations.

Firstly, Redkit bounces first level redirects to the next compromised server, and then malicious content delivering PDF or JAR (Java Archive) exploits are served up from a command & control server.

Sophos protects against the attack, detecting the injected malicious iFrames as Troj/ExpJS-II and Troj/Iframe-JG.

It seems clear that whoever is behind this malware attack was also being the attempt to infect computers with malware using the disguise of a news story about the Boston bombing earlier this week.

The criminals behind this attack couldn't care less that innocent people have died in Texas and Boston. Their only interest is making money by exploiting the computers of news-hungry internet users.

Don't make life easy for malicious hackers - and always go to legitimate news outlets for breaking news rather than rely upon unsolicited emails.

Follow @gcluley

Thanks to SophosLabs researchers Paul Baccas and Fraser Howard, and Naked Security reader Nick Burns, for their assistance with this article.


View the original article here

Tuesday, July 9, 2013

Major computer crash in SKorea; hackers suspected

SEOUL, South Korea (AP) — Computer networks at major South Korean banks and top TV broadcasters crashed en masse Wednesday, paralyzing bank machines across the country and prompting speculation of a cyberattack by North Korea.

Screens went blank at 2 p.m. (0500 GMT), with reports of skulls popping up on some computer screens, the state-run Korea Information Security Agency said — a strong indication that hackers planted a malicious code in South Korean systems. Some computers came back online more than 2 ½ hours later.

Police and South Korean officials couldn't immediately determine the cause. But experts said a cyberattack orchestrated by Pyongyang was likely to blame. The rivals have exchanged threats following U.N. sanctions meant to punish North Korea over its nuclear test last month.

The shutdown appeared to be more of an inconvenience than a source of panic. There were no immediate reports that bank customers' records were compromised. It also didn't affect government agencies or networks essential to the country's infrastructure, such as power plants or transportation systems.

Still, it raised worries about the overall vulnerability to attacks in South Korea, a world leader in broadband speed and mobile Internet access. Previous hacking attacks at private companies compromised millions of people's personal data. Past malware attacks also disabled access to government agency websites and destroyed files in personal computers.

The shutdown comes amid rising rhetoric and threats of attack from Pyongyang in response to U.N. punishment for its December rocket launch and February nuclear test. Washington also expanded sanctions against North Korea this month in a bid to cripple the regime's ability to develop its nuclear program.

North Korea has threatened revenge for the sanctions and for ongoing routine U.S.-South Korean military drills it considers rehearsals for invasion.

Seoul believes North Korea runs an Internet warfare unit aimed at hacking U.S. and South Korean government and military networks to gather information and disrupt service.

Seoul blames North Korean hackers for several cyberattacks in recent years. Pyongyang has either denied or ignored those charges. Hackers operating from IP addresses in China have also faced blame.

The latest network paralysis took place just days after North Korea accused South Korea and the U.S. of staging a cyberattack that shut down its websites for two days last week. Loxley Pacific, the Thailand-based Internet service provider, confirmed the outage but did not say what caused the shutdown in North Korea.

Shinhan Bank, a major South Korean lender, reported a two-hour system shutdown Wednesday, including online banking and automated teller machines. It said networks later came back online, and that banking was back to normal at branches and online. Shinhan said no customer records or accounts were compromised.

The other bank, Nonghyup, also a major lender, said its system eventually came back online. Officials didn't answer a call seeking details on the safety of customer records.

Jeju Bank said some of its branches also reported network shutdowns.

At one Starbucks in downtown Seoul, customers were asked to pay for their coffee in cash, and lines were forming outside disabled bank machines. Seoul is a largely cashless city, with many people relying on debit and credit cards to pay for goods and services.

Broadcasters KBS and MBC said their computers went down at 2 p.m., but officials said the shutdown did not affect daily TV broadcasts. Computers were still down more than three hours after the shutdown began, the news outlets said.

The YTN cable news channel also said the company's internal computer network was completely paralyzed. Footage showed workers staring at blank computer screens.

KBS employees said they watched helplessly as files stored on their computers began disappearing as the computer went into shutdown mode.

"It's got to be a hacking attack," Lim Jong-in, dean of Korea University's Graduate School of Information Security. "Such simultaneous shutdowns cannot be caused by technical glitches."

The South Korean military raised its cyberattack readiness level but saw no signs of cyberattacks on its networks, the Defense Ministry said.

No government computers were affected, officials said. President Park Geun-hye called for quick efforts to get systems back online, according to her spokeswoman, Kim Haing.

In 2011, computer security software maker McAfee Inc. said North Korea or its sympathizers likely were responsible for a cyberattack against South Korean government and banking websites earlier that year.

The analysis also said North Korea appeared to be linked to a 2009 massive computer-based attack that brought down U.S. government Internet sites.

Pyongyang denied involvement.

But the accusations from both sides show that the warfare between the foes has expanded into cyberspace.

Last week, North Korea's official Korean Central News Agency accused South Korea and the U.S. of expanding an aggressive stance against Pyongyang into cyberspace with "intensive and persistent virus attacks."

South Korea denied the allegation and the U.S. military declined to comment.

Lim said hackers in China were likely culprits in the outage in Pyongyang.

But signs Wednesday pointed to North Korea, he said.

"Hackers attack media companies usually because of a political desire to cause confusion in society," he said. "Political attacks on South Korea come from North Koreans."

Last week, North Korea's Committee for the Peaceful Reunification of Korea warned South Korea's "reptile media" that the country was prepared to wage a "sophisticated strike" on the country.

Orchestrating the mass shutdown of the networks of major companies would take at least one to six months of planning and coordination, said Kwon Seok-chul, chief executive officer of Seoul-based cyber security firm Cuvepia Inc.

The company that provides network services for the companies that suffered outages said it did not spot signs of a cyberattack on its networks, said Lee Jung-hwan, a spokesman for LG Uplus Corp.

Lim said tracking the source of the outage would take months.

___

Associated Press writers Sam Kim and Foster Klug contributed to this report.


View the original article here

Tuesday, May 28, 2013

Hackers launch DDoS attack on security blogger's site, send SWAT team to his home

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Brian Krebs Brian Krebs

Thankfully, award-winning US computer security reporter Brian Krebs is safe.

Nobody was harmed. But they could have been.

Given a DOSed website, a fake and libelous FBI letter sent to his website host, and a dinner party delayed by a SWAT team training guns on him and ordering him to "Put your hands in the air!", Krebs last week surely endured the most dramatic retribution ever meted out to a security blogger.

Krebs has a good idea of the specific criminal element behind the trio of attacks. Since the dramatic events of Thursday, he's traced the denial-of-service attack to a common operator who apparently launched a similar attack on Ars Technica following its coverage of Krebs's victimization.

As described by his fellow security scribe Dan Goodin at Ars Technica, Krebs is known for work that includes:

In short, Krebs has enemies.

Last week, one or more of those enemies targeted him, likely in retaliation for his most recent investigation.

On Friday, Krebs detailed in a post how the ordeal started the day before, when his site was targeted with "a fairly massive denial of service attack."

That same afternoon, a technician from Prolexic called. Prolexic is a company that Krebs hired to protect his site, KrebsOnSecurity.com, from DOS attacks.

Prolexic forwarded a letter they'd received earlier that day, purporting to come from the US Federal Bureau of Investigation.

The letter, which Krebs reprinted here, falsely claimed that Krebs's site was "hosting illegal content, profiting from cybercriminal activity, and that it should be shut down," Krebs writes.

Fake FBI message

Both Prolexic and Krebs dubbed it a hoax - an assumption Krebs confirmed with a quick call to the FBI.

As Prolexic tidied up his DOSed site, Krebs got to work tidying up his home in anticipation of dinner guests. His office phone rang while he was vacuuming, but he ignored it.

That, it turns out, was an unfortunate choice, given that the call came from law enforcement who were trying to verify what would turn out to be a spoofed emergency call showing Krebs's number on caller ID.

As he was vacuuming, Krebs noticed plastic tape on the front-door threshold, left over from securing an extension cord. He opened the door to unpeel it.

He tells of what happened next:

"When I opened the door to peel the rest of the tape off, I heard someone yell, 'Don't move! Put your hands in the air.' Glancing up from my squat, I saw a Fairfax County Police officer leaning over the trunk of a squad car, both arms extended and pointing a handgun at me. As I very slowly turned my head to the left, I observed about a half-dozen other squad cars, lights flashing, and more officers pointing firearms in my direction, including a shotgun and a semi-automatic rifle. I was instructed to face the house, back down my front steps and walk backwards into the adjoining parking area, after which point I was handcuffed and walked up to the top of the street.

"I informed the responding officers that this was a hoax, and that I’d even warned them in advance of this possibility. In August 2012, I filed a report with Fairfax County Police after receiving non-specific threats. The threats came directly after I wrote about a service called absoboot.com, which is a service that can be hired to knock Web sites offline."

SWAT team. Image from Shutterstock

Krebs had filed a police report last year on the suspicion that he would be SWATted.

SWATting is the practice of falsely reporting an emergency, as a prank or as revenge against a victim upon whom descends emergency services - or, in Krebs's case, armed law enforcement.

Krebs' persecutors had, in fact, spoofed an emergency call to make it appear that it had come from his phone.

As Sophos's Chester Wisniewski noted last April when he wrote about fraudulent calls targeting US banks, caller ID spoofing can be particularly convincing in the US, given that the call display service used by most phone companies here does a reverse lookup for the name information based on the caller ID number provided by the call.

Once a criminal determines the phone number he wants to have fraudulently show up as his caller ID number - Krebs's phone number, in this case - it's trivial to display that number on the call recipient's display.

Caller ID spoofing has been around for years through various technologies: ISDN PRI circuits used by collection agencies, law enforcement, and private investigators, all of whom have used it with varying degrees of legality; spoofing services such as Star38.com; and through Voice over IP (VoIP) technology.

Given how trivial it is to spoof caller ID, it's surprising that people put any faith at all in the technology - most particularly that law enforcement do.

In fact, the police who took Krebs's report warning that he might be targeted by SWATting hadn't even heard of the practice.

Telephone. Image from Shutterstock

All too readily, we tend to put faith in appearances. We believe caller ID identifies the true identity of a caller.

Or somebody flashes a piece of silver and we obediently hand over our licenses or wallets, or we open a door and allow strangers inside our home or our cars, without verifying whether what we've seen was an authentic emblem or a plastic toy badge.

We - the police included - trust in the technology we use. Criminals will always exploit that trust.

Krebs's work, along with other security reporters and researchers, is to poke sticks into hornets' nests, to borrow a friend's analogy.

In this case, the sting from angry hornets could have had fatal consequences, as Krebs points out:

"I have seen many young hackers discussing SWATing attacks as equivalent to calling in a bomb threat to get out of taking exams in high school or college. Unfortunately, calling in a bomb threat is nowhere near as dangerous as sending a SWAT team or some equivalent force to raid someone’s residence. This type of individual prank puts peoples’ lives at risk, wastes huge amounts of taxpayer dollars, and draws otherwise scarce resources away from real emergencies. What’s more, there are a lot of folks who will confront armed force with armed force, all with the intention of self-defense.

"The local police departments of the United States are ill-equipped to do much to stop these sorts of attacks. I would like to see federal recognition of a task force or some kind of concerted response to these potentially deadly pranks. Hopefully, authorities can drive the message home that perpetrating these hoaxes on another will bring severe penalties. Who knows: Perhaps some of the data uncovered in this blog post and in future posts here will result in the legal SWATing of those responsible."

Well said, Brian. We all hope so too, for your sake and for the sake of all security researchers, law enforcement personnel and victims of attacks like the one you experienced.

Follow @LisaVaas
Follow @NakedSecurity

SWAT team and telephone image courtesy of Shutterstock.


View the original article here

Saturday, May 25, 2013

Reuters journalist who allegedly conspired with Anonymous hackers is suspended

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Matthew KeysA Reuters journalist has been indicted by a US federal grand jury for allegedly handing over the login credentials of his former employer, Los Angeles Times parent company Tribune Co., to people claiming allegiance to the hacker movement Anonymous.

Reuters.com, which currently employs 26-year-old Matthew Keys as a deputy social media editor, suspended him with pay on Friday.

An employee at the company's New York office said that Keys's workstation was being dismantled and that his security pass had been deactivated, according to subsequent reporting from Reuters.

The US Department of Justice announced the indictment [PDF] on Thursday.

Keys was indicted on three criminal counts:

Conspiracy to transmit information to damage a protected computer, Transmitting information to damage a protected computer, and Attempted transmission of information to damage a protected computer.

Prosecutors claim that Keys promised to give hackers access to Tribune Co. websites, and that one went on to deface a story on the company's Los Angeles Times website.

From a Department of Justice statement:

"Keys identified himself on an Internet chat forum as a former Tribune Company employee and provided members of Anonymous with a login and password to the Tribune Company server... After providing log-in credentials, Keys allegedly encouraged the Anonymous members to disrupt the website."

The exact wording of said encouragement, according to the indictment, being Keys telling the hackers to "go f**k some s**t up."

Part of indictment against Matthew Keys

On Thursday, Keys tweeted that he had found out about the indictment the same way most of us did: via Twitter.

The story told by court filings is of a disgruntled former employee who acted as a double agent with Anonymous hackers, working both with them and against them.

The case began in December 2010, when Keys allegedly provided the login credentials for a computer server belonging to KTXL FOX 40's corporate parent, the Tribune Company.

The indictment maintains that Keys identified himself on an Internet chat forum as a former Tribune Company employee and that he handed over a login and password for the server.

According to the indictment, the hacker ultimately defaced a Los Angles Time news story, changing its headline, byline and sub-headline to include the name "CHIPPY 1337".

Also, a line in the article was changed to read:

"House Democratic leader Steny Hoyer sees 'very good things' in the deal cut which will see uber skid Chippy 1337 take his rightful place, as head of the Senate, reluctant House Democrats told to SUCK IT UP."

The indictment further claims that Keys chatted with the hacker who claimed credit for the defacement, offering to try to regain access for him after system administrators fended off the hacker and locked him out.

When he learned of the hacker's ultimate success in defacing the Los Angeles Times page, Keys allegedly responded, "nice."

It's a long and twisty story, involving famed (and subsequently busted) former Anonymous top dog Sabu having outed Keys back in March 2011.

Buzzfeed has done a great job of pulling together all the intricacies of Keys's story, including an image of the defaced Los Angeles Times new story, a blog post from Keys about losing his job at the local FOX Affiliate in Sacramento, California, and more, including this statement from Keys's current employer, Thomson Reuters:

"We are aware of the charges brought by the Department of Justice against Matthew Keys, an employee of our news organization... Thomson Reuters is committed to obeying the rules and regulations in every jurisdiction in which it operates. Any legal violations, or failures to comply with the company's own strict set of principles and standards, can result in disciplinary action. We would also observe the indictment alleges the conduct occurred in December 2010; Mr. Keys joined Reuters in 2012, and while investigations continue we will have no further comment."

Will Keys get fired from Reuters? Should he?

Reuters logoBuzzfeed checked in with a Reuters employee who said that yes, if Keys is found guilty of divulging login credentials while at Reuters, he will have violated the company's Trust Principles, which is grounds for immediate dismissal.

What if Keys is found guilty of working with Anonymous only before Reuters hired him?

It's hard to imagine any reputable news venue countenancing the type of betrayal alleged in these charges.

If I were a Reuters editor or lawyer, I'd be finding ways to ensure Keys didn't come back from his suspension in the eventuality of a guilty verdict.

This case may look a little muddy given that journalists working undercover can act as double agents, but the fact is, Keys wasn't working for the news outlet at the time of the breach he allegedly helped to bring about.

As far as what non-journalists can take away from this, the lesson is this: priority No. 1 should be to shut down accounts for terminated employees.

Shuttering accounts should be a priority, but it often isn't.

You can't assume that a disgruntled former employee won't open up your systems to spammers, plant malware, or replace the CEO's presentation with porn.

If found guilty, Keys is looking at a maximum of 10 years in prison and a fine of up to $250,000.

Follow @LisaVaas
Follow @NakedSecurity


View the original article here

Tuesday, April 23, 2013

Microsoft admits it was also hit by hackers, malware infects their Mac business unit

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Late on Friday, Microsoft published a statement on its security blog revealing that it was joining the growing list of well-known companies who had suffered at the hands of hackers.

Microsoft says that a "small number of computers", including some in the company's Mac business unit, were infected by malware.

microsoft-statement

As reported by Facebook and Apple, Microsoft can confirm that we also recently experienced a similar security intrusion.

Consistent with our security response practices, we chose not to make a statement during the initial information gathering process. During our investigation, we found a small number of computers, including some in our Mac business unit, that were infected by malicious software using techniques similar to those documented by other organizations. We have no evidence of customer data being affected and our investigation is ongoing.

This type of cyberattack is no surprise to Microsoft and other companies that must grapple with determined and persistent adversaries (see our prior analysis of emerging threat trends). We continually re-evaluate our security posture and deploy additional people, processes, and technologies as necessary to help prevent future unauthorized access to our networks.

If Microsoft is right, and the attack is similar to those which impacted the likes of Facebook and Apple, then a key part of the attack was the exploitation of a Java browser plug-in vulnerability.

Simply visiting an infected webpage with a browser which had Java enabled would be enough to silently infect computers via a drive-by download.

If we have to say it once, twice or a thousand times - we'll keep on saying it:

Because if you don't, yours might be the next company having to make any uncomfortable announcement about a security breach.

Like Facebook before it, Microsoft chose to release the news on a Friday afternoon, west coast time.

microsoft-170Although some might view the timing of the disclosure cynically, and speculate that the bad news was released just before the weekend to limit its pick-up by the press, the good news is that Microsoft says it has found no evidence that any customer data was compromised as a consequence of the attack.

Let's not forget who the real villains are in this story - it's the criminal gangs who infected legitimate websites, and spread malware designed to steal information from unsuspecting computer users.

Knowing Microsoft, I am confident that they will be sharing information with the authorities and doing everything they can to ensure that the culprits are brough to justice.

If you haven't already done so, patch your computers and consider running anti-virus software on your Macs as well as your PCs. Clearly some of the bad guys are targeting Mac OS X, knowing that many "cool" developers prefer to write their software on shiny Apple hardware as well as dull beige PCs.

Sophos has a free Mac anti-virus for home users if you want to give it a whirl.

Follow @gcluley

Microsoft image from Shutterstock.


View the original article here

Saturday, January 26, 2013

Samsung Smart TV security hole allows hackers to watch you, change channels or plug in malware

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Samsung remote controlDid your Samsung Smart TV just switch channel?

Don't blame the dog for stepping on the remote control - there's a remote possibility it could be hackers who've hijacked your smart TV.

Researchers with Malta-based security consultancy and bug seller ReVuln have found a vulnerability in an unspecified model of a Samsung LED 3D TV that they exploited to get root access to the TV and any attached USB drives.

In a video titled "The TV is Watching You", ReVuln shows a Samsung TV screen with which the researchers systematically fiddle.

Here's what the researchers found they could access:

TV settings and channel listsSecureStorage accounts Widgets and their configurationsHistory of USB moviesIDFirmwareWhole partitionsUSB drives attached to the TV

By exploiting the vulnerability, ReVuln also found that they could retrieve the drive image, mount it locally, and check for sensitive documents or material that should remain private, such as usernames, passwords, financial documents, or any other type of material typically kept on USB drives.

If the victim uses a remote controller, ReVuln also found that they could get its configuration and thereby control the TV remotely.

Samsung Smart Hub

ReVuln also found they could install malware remotely to gain complete root access to the TV, co-founder Luigi Auriemma told IDG News Service:

"If the attacker has full control of the TV...then he can do everything like stealing accounts to the worst scenario of using the integrated webcam and microphone to 'watch' the victim."

The vulnerability extends beyond one specific model tested in the firm's lab, he said:

"The vulnerability affects multiple models and generations of the devices produced by this vendor, so not just a specific model as tested in our lab at ReVuln."

ReVuln is a recent entrant into the market for buying and selling bug and vulnerability information and mostly focuses on vulnerabilities in SCADA and ICS software that run utilities, industrial systems and the like.

Auriemma has played around with TVs before. In April, he stumbled on a vulnerability in all current versions of Samsung TVs and Blu-Ray systems that would allow an attacker to gain remote access.

At the time, he said that the vulnerabilities could be found in all Samsung devices with support for remote controllers.

One hopes that the researchers have acted responsibly and informed Samsung of the vulnerabilities in their consumer devices, and that an over-the-internet firmware update to plug the security holes will be forthcoming.

Follow @LisaVaas
Follow @NakedSecurity


View the original article here

Thursday, January 10, 2013

Romanian hackers busted with half a MILLION credit cards from Australia - how could THAT have happened?

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

The Australian Federal Police (AFP) are cock-a-hoop this week, announcing the bust of a gang of Romanian credit card hackers.

According to reports, 200 Romanian cops pounced on 36 locations, detained 16 people and ultimately arrested seven of them.

The carding crew had allegedly made off with half a million Aussie credit card numbers, racking up charges averaging more than $1000 each on 30,000 of them.

At this point, I'm sure you're thinking what I am. "Half a MILLION cards from Australia. And the crooks didn't even need to leave Romania. How could THAT have happened?"

The answer, according to the Australian cops, is RDP.

Remote Desktop Protocol - or Routine Darkside Probe, as we dubbed it in a recent article advising you on how to secure it - is Microsoft's solution for remote administration of your computers.

RDP effectively mirrors the screen and keyboard of a remote system on your local device.

Move the mouse in the RDP client, and it moves on the remote system. Pop up a software dialog on the remote system and the screen updates are mirrored on your local desktop. It's almost as good as being right there.

Leaving RDP open to the internet is therefore a little bit like giving a visitor a seat in the corner of your server room and saying, "I'll just leave you here while I go for lunch. Don't touch anything, will you?"

In this case, a bunch of small Aussie retailers were targeted. It's not clear whether the hacking took place via IT infrastructure they all shared (a so-called cloud), so that the crooks were able to penetrate everyone in one shot, or if each retailer was probed and hacked individually.

Once you've got an RDP connection to the inside of a network, you can run pretty much any software you like, even GUI-only applications that weren't built with remote control in mind.

It seems that's what the crooks did, running up the retailers' Point of Sale (PoS) software and retrieving credit card numbers already collected by the retailers' own payment devices.

We've written about skimming a couple of times recently.

That's where you add a covert credit card reader in front of a real one.

Any card swiped or inserted gets read in twice: once by your data-siphon and once by the genuine device. Loosely speaking, you steal the card data individually from each card.

In this hack, the hackers didn't even need a skimmer. They let the official card reading devices handle that job, and stole the credit card data in bulk - straight from the horse's stomach, if you don't mind mixing your mixed metaphors.

The problem with this sort of hack is that there is very little consumers can do to protect themselves.

All the advice you'll hear about choosing decent passwords, wiggling the card slot to look for tampering, and avoiding phishing emails that invite you to initiate an on-line transaction? Those won't help here.

You can do everything right, but if your retailer - or your retailer's IT provider - does the wrong thing, invisibly to you somewhere in the back of the network, you may never know until it's too late.

(That, my friends, is why we need mandatory breach disclosure laws: so you can keep current with what's happened to your personally identifiable information.)

The take-aways from this story?

• If you're a cybercrook, the fact that you're sitting far away in a different jurisdiction makes it tougher for the cops to nab you. But not impossible!

• Don't leave RDP open across the internet. It ends in tears, for you and your customers.

Follow @duckblog

Fancy using the free Sophos UTM Home Edition?

You get web and email filtering, web application security, IPS, VPN and more for up to 50 IP addresses.

Yes, it can help you do RDP safely. so turn that spare PC into a full-on network security appliance!

(Note: registration required.)


View the original article here

Monday, December 3, 2012

National Weather Service website hacked by Kosova Hacker's Security

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Hackers have breached servers belonging to the US National Weather Service by exploiting a vulnerability in the weather.gov website, releasing sensitive data from the government systems.

A post on pastebin.com by a group identifying itself as "Kosova Hacker's Security" took credit for the hack and posted lists of files allegedly copied from the servers as proof.

KHS Pastebin posting

The group exploited a local file inclusion vulnerability on the weather.gov servers, according to information in the Pastebin document, which said the attack was in retaliation for American aggression against Muslim nations, including cyber attacks.

The leaked information includes a listing of administrative account names, which could open the hacked servers to subsequent brute force attacks against the accounts.

Kosovo Hacker's Security

According to media reports, the hacking group cited the release of the Flame and Stuxnet malware as instigation for the attack.

"They hack our nuclear plants using STUXNET and FLAME like malwares , they are bombing us 27*7, we can't sit silent - hack to payback them," The Hacker News (THN) reported the hackers as saying.

The local file inclusion vulnerability was patched and the weather.gov site remained up Thursday. However, at least one other vulnerability, a cross site scripting hole, was subsequently identified on the site.

Little is know about the group claiming responsibility for the attack. However, they allege that the weather.gov hack was just one of many US government hacks the group had carried out and that more releases are pending.

Attacks against government systems and banks are raising alarms in the U.S. and elsewhere.

US Secretary of Defense Leon Panetta invoked the image of a "digital Pearl Harbor" in a speech last week, warning that the country is as unprepared for a large scale cyber attack, as it was for the 9/11 terrorist attacks.

Follow @paulfroberts
Follow @NakedSecurity


View the original article here

Sunday, November 25, 2012

Hackers pwn the sun - Exploit code released for software used to manage solar energy plants

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Department of Homeland SecurityBlack hat hackers can now take over photovoltaic solar arrays and harness their combined energy to create vaporizing solar death beams.

Well, that may be an exaggeration, but only a slight one.

The US Department of Homeland Security is warning about vulnerabilities in a common SCADA (supervisory control and data acquisition) package that is used to remotely monitor and manage solar energy-generating power plants.

The DHS’s ICS-CERT issued an advisory on Wednesday that exploit code was circulating on the internet for security holes affecting the Italian vendor Sinapsi’s eSolar Light Photovoltaic System Monitor.

The eSolar Light Photovoltaic System Monitor is a SCADA product that allows solar power stations to simultaneously monitor different components of photovoltaic arrays, such as photovoltaic inverters, energy meters, gauges and so on.

According to information released by the researchers Robert Paleari and Ivan Speziale, the Sinapsi eSolar product contains a number of critical security vulnerabilities that make the devices easily exploitable by remote attackers, who could gain administrative privileges and run arbitrary commands and code on vulnerable eSolar devices.

Those security holes include a slew of SQL injection vulnerabilities in webpages included with the device firmware. Among other things, the researchers found they could exploit SQL injection holes in the web based management interface to access the underlying MySQL database, gaining access to usernames and passwords for the device.

Solar panel, courtesy of ShutterstockPasswords, the researchers noted, were stored in plaintext.

And, in a pattern that has become distressingly common in the SCADA world, the researchers discovered hard coded administrative accounts for the Sinapsi devices.

The login.php page would accept a small number (two or three) of universal passwords that would grant access to the device regardless of what user login they were paired with.

ICS-CERT said in its advisory that the vulnerabilities, if successfully exploited, could allow attackers to remotely connect to the management server, "executing remote code, possibly affecting the availability and integrity of the device."

The researchers disclosed the holes to Sinapsi in August, 2012 and released details of their findings on October 9, after failing to get a response, they said.

The impact of the security holes could be widespread. The Sinapsi eSolar management product is bundled with photovoltaic SCADA products from other vendors, as well. They include the Enerpoint eSolar Light, Astrid Green Power Guardian and Schneider Electric Ezylog Photovoltaic Management Server, according to ICS-CERT.

Follow @paulfroberts
Follow @NakedSecurity

Solar panel and sunlight images courtesy of Shutterstock


View the original article here

Sunday, November 4, 2012

Chinese hackers linked to breach of control systems used in electric grids

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

electricity_170Attackers breached Telvent's network, the company has informed its customers in a letter. Telvent is the maker of an industrial control system that remotely controls smart grid networks used in portions of the electric grid.

Telvent told its customers that on Sept. 10, it learned that hackers had breached its internal firewall and security systems, implanted malicious software, and stolen project files.

According to
Chinese Hackers Blamed for Intrusion at Energy Industry Giant Telvent" href="http://krebsonsecurity.com/2012/09/chinese-hackers-blamed-for-intrusion-at-energy-industry-giant-telvent/" rel="nofollow">KrebsOnSecurity, which first reported the breach, the project files concerned Telvent's
Standardized, centralized SCADA solutions from Telvent" href="http://www.telvent.com/en/business_areas/smart_grid/solutions_overview/smart_grid/smart_operations/oasys-scada.cfm" rel="nofollow">OASyS SCADA product, which offers energy firms a bridge between older technology and advanced smart grid technologies.

Telvent, which is owned by Schneider Electric, told customers that the attack spans operations in the US, Canada and Spain.

Experts detected digital fingerprints implicating a Chinese hacking group that has been tied to cyber-espionage campaigns against Western interests.

Telvent_logo

KrebsOnSecurity cited Joe Stewart, director of malware research at Dell SecureWorks, who said that website and malware names mentioned in a more recent letter from Telvent can be traced to a Chinese hacking team known as the "Comment Group."

That group, often referred to as the Comment group, has been under investigation by US intelligence for years.

Researchers told Bloomberg that during two months of monitoring last year, targeted companies spanned a vast scale as data "bled from one victim to the next":

...from oilfield services leader Halliburton Co. (HAL) to Washington law firm Wiley Rein LLP; from a Canadian magistrate involved in a sensitive China extradition case to Kolkata-based tobacco and technology conglomerate ITC Ltd. (ITC)

A loose-knit group of some 30 North American private security researchers tracking the group have called the Comment Group one of the biggest and busiest hacking groups in China.

Bloomberg quoted Shawn Henry, former executive assistant director of the FBI in charge of the agency’s cyber division, who said that typical cybersecurity headlines about data breaches scarcely hint at the scope of the group's activities:

What the general public hears about — stolen credit card numbers, somebody hacked LinkedIn (LNKD) — that’s the tip of the iceberg, the unclassified stuff. … I’ve been circling the iceberg in a submarine. This is the biggest vacuuming up of U.S. proprietary data that we’ve ever seen. It’s a machine.

Evidence indicates that at least 20 organizations have been harvested for data, many of whose secrets could give China a leg up on its path to becoming the world’s largest economy.

Bloomberg cited unnamed security experts who said that the breaches have sprung data leaks in major oil companies, who've lost seismic maps charting oil reserves, while patent law firms have been squeezed for clients' trade secrets and investment banks have been targeted for market analysis regarding global ventures of state-owned companies.

Telvent said that investigations are still under way, but it's taken the precaution of severing data links between clients and the affected portions of its internal networks.

The company also said that it hasn't yet found evidence that the attackers had been able to compromise customers' systems:

Although we do not have any reason to believe that the intruder(s) acquired any information that would enable them to gain access to a customer system or that any of the compromised computers have been connected to a customer system, as a further precautionary measure, we indefinitely terminated any customer system access by Telvent.

Telvent gave me this statement:

Telvent is aware of a security breach of its corporate network that has affected some customer files. Customers have been informed and are taking recommended actions, with the support of Telvent teams. Telvent is actively working with law enforcement, security specialists and its affected customers to ensure the breach has been contained.

Meanwhile, the Obama adminstration and Congress have grown increasingly vocal about Chinese and Russian cyber espionage and attacks, with the White House close to completing the first draft of a cybersecurity executive order designed to bring about stronger cyber security around the nation's water, electrical and transportation systems.

It's a reasonable thing to call for stronger protection around vital infrastructure.

But as Reuters pointed out in a recent report on what one top US cybersecurity official called "reckless" cyber behavior from nation states, the US's right to complain about other nations' cyber warfare might be questionable, given what is by now a widespread belief that the US and Israel were behind Stuxnet.

Follow @LisaVaas
Follow @nakedsecurity

electricity images courtesy of Shutterstock


View the original article here

Monday, October 29, 2012

Adobe revokes certificate after hackers compromise server, sign malware

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

AdobeAdobe security chief Brad Arkin has warned that hackers have managed to create malicious files with Adobe's digital code-signing signature.

According to a blog post published on Thursday, the issue appears to have been the result of hackers compromising a vulnerable build server.

Malware seen using the digital signature includes pwdump7 v 7.1 (a utility that scoops up password hashes, and is sometimes used as a single file that statically links the OpenSSL library libeay32.dll.)

According to Adobe, the second malicious utility is myGeeksmail.dll, a malicious ISAPI filter.

Adobe blog

Adobe plans next week to revoke the certificate for all code signed after July 10, 2012, according to an advisory from the company:

The certificate revocation will affect the following certificate:

sha1RSA certificateIssued to Adobe Systems IncorporatedIssued by VeriSign Class 3 Code Signing 2010 CASerial Number: 15 e5 ac 0a 48 70 63 71 8e 39 da 52 30 1a 04 88sha1 Thumbprint: fd f0 1d d3 f3 7c 66 ac 4c 77 9d 92 62 3c 77 81 4a 07 fe 4cValid from December 14, 2010 5:00 PM PST (GMT -8:00) to December 14, 2012 4:59:59 PM PST (GMT -8:00)

However, even when a CA (Certificate Authority) revokes a certificate for an abused private key, any digital signature made before the revocation date will remain valid.

This very topic was covered in a paper presented by my SophosLabs colleague Mike Wood at the Virus Bulletin conference in Vancouver two years ago, "Want My Autograph? The use and abuse of digital signatures by malware".

For that reason, Adobe will be publishing updates for those existing Adobe software products which are signed using the compromised certificate.

SophosLabs has released detection for the malicious files that Adobe references in its advisory, identifying them as Troj/HkCert-A.

SophosLabs researchers are also actively exploring whether there are other threats that may have misused the same certificate.

Further information can be found in Adobe's security advisory (APSA12-01).

Since Mike Wood discussed the abuse of digital signatures in Vancouver two years ago, there have been several stories about certificate abuse in attacks.

It is probably just an odd coincidence that news of this latest instance of certificate abuse has come to light while the world's leading anti-virus experts are once again meeting at the Virus Bulletin conference, this time in Dallas.

Follow @SophosLabs

View the original article here

Thursday, August 30, 2012

Hackers get into AMD and steal over 30,000 - wait for it - BYTES!

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

A hacker calling himself r00tbeer, supposedly representing a four-strong hacker group calling itself r00tbeersec, has announced on Twitter a hack of chip vendor and Intel rival AMD.

After bragging just over a day ago that "our next target will be a large company, stay tuned for the upcoming database dump," the mighty hackers lived up to their promise. Earlier today they leaked a complete SQL database dump totalling nearly thirty-two KB.

(Yes. You read that correctly. It's just under 32 kilobytes in the new measuring system, and just over 30 kibibytes, as today's youth - who wouldn't know a power of two if it chopped them in half - like to call the old units.)

It's a SQL database of 189 usernames and and what look like PHPass-hashed passwords, apparently retrieved by foul means from AMD's WordPress-driven blog site.

185 of the usernames are accompanied by email addresses, of which 174 are from AMD and most of the rest from two PR companies, edelman.com and bitecommunications.com. A reminder to the PR guys: if you work on the AMD account and you've been using the same password on other sites, stop doing that!

A few of the records also include an intriguing - but unexplained - field called user_activation_key. Whatever those are, it would be a good idea for AMD to deactivate them and issue new ones.

All in all, a small deal in the history of security breaches. More of a hackette than a hack, and no AMD customers need to panic, which is good news.

But every hack is, at its heart, bad news.

If only we were collectively more conscientious about patching against criminals, and if only those criminals were more likely to be caught!

Of course - since, where hacking is concerned, an injury to one is an injury to all - the vast majority of Internet Good Guys amongst us can help make both those things come true.

Patch early. Patch often. Keep logs. Report breaches.

Here's some frank talk to tell you why:

(Duration 15'25", size 11MBytes)

Follow @duckblog
-


View the original article here

Tuesday, August 7, 2012

Facebook hackers pwn baseball team pages, claim NY Yankees captain is having sex change

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

A host of Facebook accounts belonging to US baseball teams were hacked yesterday, and defaced with messages in dubious taste, including one which claimed that New York Yankees captain Derek Jeter was undergoing a sex change.

Message posted on New York Yankees Facebook page

"We regret to inform our fans that Derek Jeter will miss the rest of the season with sexual reassignment surgery. He promises to come back stronger than ever in 2013 as Minnie Mantlez"

Other clubs affected included the Miami Marlins, San Diego Padres, Chicago White Sox, Washington Nationals, Chicago Cubs and San Francisco Giants.

Here is a selection of the messages that were posted:

Messages posted on Facebook pages belonging to Miami Marlins and San Diego Padres

Message posted on Chicago White Sox Facebook page

Clearly an unauthorised party had managed to gain admin access to the Facebook pages in order to post the messages - and the first thought is that it would be a very strange coincidence to have the Facebook pages of so many clubs compromised at the same time.

However, it turns out that the clubs run the Facebook pages in conjunction with MLB Advanced Media.

One possible scenario is that an MLB Advanced Media employee was sloppy with their password (maybe they weren't using a hard-to-guess password, or maybe they were using a password that they had also been using elsewhere on the net), allowing a hacker to gain access and post the inappropriate content.

A spokesperson for the baseball league told the Wall Street Journal that they were working with Facebook and law enforcement to see if they could identify what had happened, and who might have been responsible:

"For a brief moment today, a few MLB Club Facebook accounts were hacked and inappropriate material was briefly on display from those Clubs' pages on Facebook. MLB Advanced Media oversees these Facebook pages on behalf of the Clubs and regrets this occurrence. We are working with Facebook, Major League Baseball Security and, where appropriate, legal authorities to determine the circumstances surrounding this situation."

Baseball player. Image from ShutterstockI guess everyone should be grateful that the hacker didn't exploit their access to the baseball clubs' Facebook pages by posting something more malicious - such as links to malware-infected pages - that could have impacted thousands of sports fans.

This isn't, of course, the first time that Facebook fan pages have been hacked and unauthorised posts made. There have been a wide variety of victims in the past, ranging from Viagra manufacturer Pfizer, Nicolas Sarkozy, and last year the rapper Soulja Boy who blamed a hacker for a series of racist and homophobic rants.

Perhaps the most embarrassing incident of this nature was when Facebook's own CEO, Mark Zuckerberg, had his official fan page hacked via an API bug.

Make sure that you keep informed about the latest security and privacy issues on Facebook. Join the Sophos page on Facebook, where over 190,000 people regularly share information on threats and discuss the latest security news.

Follow @gcluley

Baseball player image from Shutterstock.

Tags: baseball, Chicago Cubs, Chicago White Sox, Derek Jeter, Facebook, hacking, Miami Marlins, MLB, New York Yankees, San Diego Padres, San Francisco Giants, Washington Nationals


View the original article here