Google Search

Showing posts with label sentenced. Show all posts
Showing posts with label sentenced. Show all posts

Monday, November 12, 2012

TinKode sentenced after hacking Oracle, NASA and others to expose weak security

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

TinKodeThe infamous hacker known as TinKode has been sentenced by a Romanian court, according to media reports.

Cernaianu Manole Razvan was arrested in January 2012, after a series of high profile hacks of government and military websites, exposing their poor security and often publishing passwords and screenshots as evidence.

Past victims have included website belonging to the British Royal Navy, MySQL.com (which ironically fell foul of a SQL injection attack) and NASA servers.

Royal Navy website

To the relief of many, TinKode appeared to be inspired more by the desire to embarrass organisations into improving web security - rather than making money.

In an interview with Network World in 2011, TinKode compared his activities to a free security audit:

Until now, no. I don't do bad things. I only find and make public the info. Afterwards I send an email to them to fix the holes. It's like an security audit, but for free.

Nevertheless, his actions were illegal and led to his arrest by Romanian authorities earlier this year. Last month a Romanian court ordered Razvan to pay 93,000 Euros (approximately $120,000) to cover the costs suffered by his breached victims, and gave him a two year suspended prison sentence.

That's a lesson that others would be wise to learn from if engaged in similar activities.

Free TinKode petition

An online petition, started by TinKode's sympathisers, failed to receive significant support (a hoped-for 5000 signatures has only reached 187 at the time of writing). It remains to be seen whether they will help the young Romanian pay his substantial fine.

It's no excuse for TinKode's criminal hacks, but if the websites had been properly secured in the first place they would have never found themselves embarrassed by the Romanian hacker.

If you haven't already done so, check out our free technical paper about "Securing websites", which discusses common ways web servers are attacked and the various ways that they can be protected.

Follow @gcluley

View the original article here

Sunday, July 29, 2012

Cybercrime trio sentenced for $3m hacking spree via WiFi and malware

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

The Seattle Times has reported on the final nail in the coffin of a Pacific North West hacking trio, with the third and final member of the group being sentenced by the court.

The three men, Joshuah Allen Witt, 35, John Earl Griffin, 36, and Brad Eugene Lowe, 39, have all now been given stiff prison terms. Lowe picked up the lightest sentence, with six-and-a-half years, whilst Witt and Griffin were sent down for nearly eight years each.

They attacked companies both externally - by wardriving and looking for poorly-protected corporate WiFi connections - and internally - by breaking in and installing keyloggers on company computers. (It's much easier to infect a PC if you do it deliberately!)

There are two lessons to be learned here.

The first lesson is to make sure you get your WiFi security right - at work and at home. We've written up some simple guidelines before to help you do the right thing.

To summarise, here are three things which do not provide WiFi security. Two of them provide a touch of safety against inadvertent connections, but none of these protect you against wardrivers:

WEP encryption. The security system in WEP (Wired Equivalent Privacy) is flawed and can easily and automatically be cracked. A wardriver will bypass WEP in 60 seconds - and that includes the time taken to park outside your office and boot up his laptop. Use WPA instead.

MAC address filtering. MAC (Media Access Control) addresses aren't secret. WiFi networks broadcast the MAC addresses of all currently-connected devices, so a wardriver already has a list of addresses he can use.

SSID hiding. The SSID (Service Set identifier) is your network name. Hiding it merely means your network doesn't openly advertise itself for use. But it isn't a secret - the SSID appears in other network traffic anyway, so the wardriver knows what it is.

The second lesson is to be doubly vigilant after a physical break-in. Don't just look for what's missing, but what might have been left behind.

(That's the same sort of lesson as we should all learn from the recent DNS Changer excitement.)

Cybercrooks who have physical access to your network can install malware on your computers, connect hardware keylogging devices to your keyboards, and even stash rogue wireless access points behind the furniture.

Just what the crooks were after in this case is clear: money.

They're said to have netted $3 million, raiding company bank accounts and even, it seems, modifying database records to steal directly from the payroll.

The crooks will now have years to regret their actions. Sadly, so too will the companies whose finances were plundered.

Follow @duckblog
-

The images of imprisoned hands, the little red "X for Noooo!", and the stylised WiFi antenna on the main page are courtesy of Shutterstock.

Tags: conviction, Cybercrime, griffin, IT, lowe, Malware, north west, prison, seattle, wardriving, wifi, witt


View the original article here