A 26-year-old has pleaded guilty to hacking websites of major institutions including the National Health Service, Sony and News International.
Ryan Ackroyd, from Mexborough, South Yorkshire, was due to stand trial charged with taking part in a string of cyber attacks, but pleaded guilty to one charge of carrying out an unauthorised act to impair the operation of a computer, contrary to the Criminal Law Act 1977.
Southwark Crown Court heard he admitted being a member of hacking group LulzSec, acting as a "hacker" to access websites for Sony, 20th Century Fox, the NHS, Nintendo, the Arizona State Police, and News International, between February and September 2011.
Prosecutor Sandip Patel told the court: "He was the hacker, so to speak, they turned to him for his expertise as a hacker", and said Ackroyd admitted using the persona of a 16-year-old girl Kayla on the site.
He will be sentenced on May 14 and the court heard prosecutors are not planning to pursue other charges against the 26-year-old.
Earlier, Southwark Crown Court heard that fellow hackers Mustafa Al-Bassam, 18, from Peckham, south London, and Jake Davis, 20, from Lerwick, Shetland, have also now pleaded guilty to hacking and launching cyber attacks on a range of organisations, including the CIA and the Serious Organised Crime Agency.
Ryan Cleary, 21, of Wickford Essex, has pleaded guilty to the same two charges as well as four separate charges including hacking into US air force agency computers at the Pentagon.
The men are said to have carried out distributed denial of service (DDoS) attacks on the institutions with other unidentified hackers belonging to online groups such as LulzSec, Anonymous and Internet Feds.
The DDoS attacks they carried out flood websites with traffic, making them crash and rendering them unavailable to users. To do it, they used a remotely controlled network of "zombie" computers, known as a "botnet", capable of being programmed to perform the attack.
LulzSec is a spin-off of the loosely organised hacking collective Anonymous. Lulz is internet slang that can be interpreted as "laughs", "humour" or "amusement", and Sec refers to "security".
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
A security researcher and trained commercial pilot combined his interests and cooked up an exploit framework and Android app that can be used, at least theoretically, to hack a plane.
That includes potentially gaining information about an aircraft's onboard computer, changing the intended destination, flashing interior lights, delivering spoofed malicious messages that affect the behavior of the plane, and, just maybe, if pilots don't manage to turn off autopilot and/or have difficulty with manual flight operation, crashing the plane.
These are theoretical exploits demonstrated by Hugo Teso, a security consultant at n.runs AG in Germany, who gave a talk about his research at the Hack in the Box conference in Amsterdam on Wednesday.
Of course, Teso hasn't tried any of this out on real planes, given that there aren't many planes lying around waiting for people/plane/landscape annihilation, which would, at any rate, be illegal and amoral.
Rather, he conducted his research on aircraft hardware and software he acquired from various places.
That includes equipment from vendors offering simulation tools that use actual aircraft code and from eBay, where he found a flight management system (FMS) manufactured by Honeywell and a Teledyne Aircraft Communications Addressing and Reporting System (ACARS) aircraft management unit, according to Network World.
According to Help Net Security's Zeljka Zorz and Berislav Kucan, Teso's demonstration shed light on "the sorry state of security of aviation computer systems and communication protocols."
Teso created these two tools to exploit vulnerabilities in new aircraft management and communication technologies:
An exploit framework named SIMON, andAn Android app named, appropriately enough, PlaneSploit, which delivers attack messages to the airplanes' FMSes.
The two vulnerable technologies Teso exploited with these tools:
The Automatic Dependent Surveillance-Broadcast (ADS-B) (this surveillance technology, used for tracking aircraft, will be required by the majority of aircraft operating in US airspace by Jan. 1, 2020), and The Aircraft Communications Addressing and Reporting System (ACARS), a protocol for exchange of short, relatively simple messages between aircraft and ground stations via radio or satellite that also automatically delivers information about each flight phase to air traffic controllers.
According to Help Net Security, Teso abused these "massively insecure" technologies, using the ADS-B to select targets.
He used ACARS to siphon data about the onboard computer and to exploit its weaknesses by delivering spoofed messages that tweak the plane's behavior.
Using the Flightradar24 flight tracker - a publicly available tool that shows air traffic in real time - Teso's PlaneSploit Android app allows the user to tap on any plane found within range - range that would be limited, outside of a virtual testing environment, to antenna use, among other things.
The application has four functions: discovery, information gathering, exploitation and post exploitation.
According to Help Net Security, these are some of the functions Teso showed to the conference audience:
Please go here: Allows user to change the targeted plane's course by tapping locations on the map.Define area: Set detailed filters related to the airplane, such as activating something when a plane is in the area of X kilometers or when it starts flying on a predefined altitude.Visit ground: Crash.Kiss off: Remove plane from the system.Be puckish: Trigger flashing lights and buzzing alarms to alert the pilots that something is seriously wrong.
Teso has, thankfully, responsibly, refrained from disclosing details about the attack tools, given that the vulnerabilities have yet to be fixed.
In fact, he told his listeners that he's been pleasantly surprised by the receptivity he's received by the industry, with companies vowing to aid his research.
Given Teso's belief in responsible disclosure, the industry can take steps to patch the security holes before someone with more malicious intent has an opportunity to exploit them.
From the sound of things, this researcher has garnered plenty of media attention but still values aircraft and passenger safety well over fame and glory.
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
American singer Victoria Justice is not happy that someone (she blames a hacker) has leaked swimsuit photos of her onto the internet.
I've never heard of Victoria Justice, which may mean that the 20-year-old singer isn't targeting my particular demographic, but she's clearly famous enough to make headlines when she claims that the photos published of her were stolen by a hacker.
Media who covered the story described the leaked photos as "semi-racy... but nothing of the R-rated variety, showing Victoria fully clothed but in a bathing suit".
Clearly, however, Justice - who has her own show on Nickelodeon called "Victorious" - was not amused and is seeking, err, justice.
Hacking & stealing is NOT COOL. #RespectPeoplesPersonalProperty #Karma— Victoria Justice (@VictoriaJustice) April 12, 2013
Hacking & stealing is NOT COOL. #RespectPeoplesPersonalProperty #Karma
And she's right, of course, hacking into someone's private accounts and stealing photos is *not* cool. And it's even less cool for websites to take the stolen images and to publish them on the net.
And yet it seems to keep on happening, and the websites appear to get away with it Scott free.
For instance, we've seen "news" websites publishing intimate snaps of Scarlett Johansson, Mila Kunis, Christina Aguilera, and many other celebrities in the past without any apparent consequences.
Although hackers can receive harsh penalties for accessing celebrity accounts and stealing photos, we don't hear anything about the gossip websites that willingly went public with the stolen material.
. @oceanup I would never post a picture of myself like that. I'm not taking this lightly & I will find out who stole my private property.— Victoria Justice (@VictoriaJustice) April 12, 2013
So I was at least pleased to see Victoria Justice take the magazine that published the snaps of her in her swimsuit to task via Twitter, and was pleased to hear that the magazine subsequently removed the pics from their site.
Follow @gcluley
Image of Victoria Justice courtesy of jake.auzzie/Flickr (Creative Commons)
Seoul, April 10 (IANS) The South Korean government Wednesday confirmed that North Korea was behind the March 20 cyber attack that paralyzed computer networks at banks and broadcasters.
"The series of cyber attacks last month resembled North Korea's past hacking patterns," the Ministry of Science, ICT & Future Planning said at a press briefing.
"Evidences (showed) that North Korea's reconnaissance general bureau did the act."
On March 20, computer networks at three banks and three broadcasters suffered the cyber attack, crippling about 48,700 PCs and servers, reported Xinhua.
On March 25, there was an attempt to hack PCs of the ordinary people, while computer files at the broadcaster YTN's 58 PCs were destroyed and data at anti-North Korean organizations' homepage were deleted the following day.
Based on 76 malicious codes used for the hacking and Internet access records collected, the March cyber attack was planned at least eight months ago by indirectly planting malware in advance, according to the probe results by the government-led investigation team.
The investigation team found that six PCs in North Korea directly or indirectly accessed the infected computers some 1,590 times, among which Internet Protocol (IP) address linked directly to North Korea was spotted 13 times.
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
If you have a web service that supports remote users, you will know that malevolent login attempts are an everyday occurrence.
Even on my own home-hosted SSH server, listening unassumingly on an IP number on a DSL line, I've seen thousands of login attempts from dozens of different IP numbers in the course of a single day.
But hosting providers worldwide are reporting that they've been seeing systematic attempts, over the last 48 hours or so, to breach blogs and content management systems (CMSes) at well above average levels.
The primary target seems to be WordPress, with Joomla users also reportedly getting a bit of a hammering.
Word from the anti-DDoS world is that a botnet is responsible, with estimates of "up to 90,000," "more than tens of thousands," and "up to 100,000" infected computers (all those figures can be true at the same time, of course) orchestrating the felonious login attempts.
Since it would take too long to try every possible username and password on every known WordPress or Joomla server, this onslaught is using what is known as a dictionary attack.
That's where a crook settles on a list of the most likely usernames and passwords, and tries those in quick succession.
The idea is simple: automate the password guessing, speed up the attack, and don't spend too long on any individual site.
Look for the low-hanging fruit, and harvest it as quickly as you can; if you can't get in within a few hundred or thousand attempts, move on to the next potential victim.
It's doorknob rattling, but on an industrial and international scale.
Tireless cybercrime and underweb reporter Brian Krebs has published a list of sample WordPress usernames and passwords used in this attack, courtesy of security breach cleanup company Sucuri.
The top thirteen generically-chosen dictionary entries for username and password are as follows:
It's worth a look at the list (click on the image above), if only to reassure yourself that you haven't taken chances with any of your own passwords.
Notice also that the attackers are focusing on the username admin, used in 90% of the login attempts, because it's the default WordPress administrative username.
A username shouldn't be considered a secret (that's what the password is for), but you can avoid unwanted attention from low-hanging-fruit attacks by choosing something other than the default, as WordPress founder Matt Mullenweg himself advises.
Matt's suggestions are pithy and clearly put, so I'll repeat them here; they make up good advice for any web service product, whether you're blogging, file sharing, or running a CMS:
Almost 3 years ago we released a version of WordPress (3.0) that allowed you to pick a custom username on installation, which largely ended people using "admin" as their default username. Right now there’s a botnet going around all of the WordPresses it can find trying to login with the "admin" username and a bunch of common passwords, and it has turned into a news story (especially from companies that sell "solutions" to the problem).
Here’s what I would recommend: If you still use "admin" as a username on your blog, change it, use a strong password, if you’re on WP.com turn on two-factor authentication, and of course make sure you're up-to-date on the latest version of WordPress. Do this and you'll be ahead of 99% of sites out there and probably never have a problem. Most other advice isn't great — supposedly this botnet has over 90,000 IP addresses, so an IP limiting or login throttling plugin isn't going to be great (they could try from a different IP a second for 24 hours).
There you have it.
Not being the low-hanging fruit isn't a generic solution to this problem, as it's a bit like outrunning your buddy when you are chased by a hungry lion: it saves you, but leaves someone else to take the hit.
But that is no reason not to move your fruit to higher branches.
Remember that if someone breaks into your server, that's bad for you, but it is also bad for everyone else.
It gives the crooks a free ride for hosting malware, launching further attacks, publishing phishing pages, disseminating fake updates or bogus information, and much more.
All with your imprimatur, and, in the end, with your services blocklisted by anyone who's security conscious.
Remember, password-guessing attacks of this sort happen all the time.
The attack volume in this case has been sufficient to attract global attention, which is a good thing, but it's currently thought to be only about three times the usual level.
In other words, even when "normal service" is resumed, we'll all still be firmly in the sights of the cybercriminals, so take this as a spur to action!
Follow @duckblog
Image of Dictionary with magnifying glass courtesy of Shutterstock.
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
Google has launched a new tool that lets users plan what will happen to their private data after they die.
Announced on Google's blog by Product Manager Andreas Tuerk on Thursday, the tool is called Inactive Account Manager.
(You have to love the humility: "Not a great name, we know," Tuerk writes. The Googlers could have had a field day with the name, but discretion, obviously, won the day. One commenter's suggested name: "My Will." Better, and still classy!)
The Inactive Account Manager is located on the Google Account settings page, under the "Account Management" choice in the "Account" tab.
I had to hunt around to find it: you have to click on the option that says "Control what happens to your account when you stop using Google. Learn more and go to setup."
There, you can tell Google what to do with your Gmail messages and data from other Google services if your account becomes inactive for any reason.
One choice is to have your data deleted after periods of three, six, nine or 12 months of inactivity.
Another option is to pass on data from some or all of these services to your designated beneficiaries:
+1sBloggerContacts and CirclesDriveGmailGoogle+ ProfilesPages and StreamsPicasa Web AlbumsGoogle Voice YouTube
Before Google pulls the plug on your data, it will first warn you by sending a text message to your cellphone and email to the secondary address you’ve provided.
Says Tuerk:
We hope that this new feature will enable you to plan your digital afterlife - in a way that protects your privacy and security - and make life easier for your loved ones after you’re gone.
Now you can die in peace, with your beneficiaries safely assured of receiving the contents of your Google Drive and Picasa albums... Then again, you can choose to make it all go poof like a pile of ashes blown onto a virtual ocean or buried with a virtual fruit tree.
This is a good move, and we can only hope that other holders of our online assets follow suit.
After all, just think of all the online portals outside of the Google universe through which your assets flow:
Buyer/seller accounts on eBay, Amazon, PayPal, Yahoo! Stores, etc. Credits in stores such as iTunes or PartyPoker.comPhotos on Flickr, Photobucket, Snapfish, Kodak GalleryBusiness invoices and intellectual property shared through services such as Dropbox, ShareFile, Syncplicity, Huddle et al. Online bank accountsEmail accounts
Surely none of us wants any of that personal, valuable material to be plundered or to have its privacy compromised when we're no longer around.
Don't wait around for every keeper of your in-the-cloud valuables to come up with a plan for deleting your data, though.
To avoid having data fall into the wrong hands, or not getting to your heirs, draw up a digital will along with your regular will.
Leave instructions for how to get to your digital assets and what you want your heirs to do with them.
WASHINGTON (AP) — The U.S. has taken its first real swipe at China following accusations that the Beijing government is behind a widespread and systemic hacking campaign targeting U.S. businesses.
Buried in a spending bill signed by President Barack Obama on Tuesday is a provision that effectively bars much of the federal government from buying information technology made by companies linked to the Chinese government.
It's unclear what impact the legislation will have, or whether it will turn out to be a symbolic gesture. The provision only affects certain non-defense government agency budgets between now and Sept. 30, when the fiscal year ends. It also allows for exceptions if an agency head determines that buying the technology is "in the national interest of the United States."
Still, the rule could upset U.S. allies whose businesses rely on Chinese manufacturers for parts and pave the way for broader, more permanent changes in how the U.S. government buys technology.
"This is a change of direction," said Stewart Baker, a former senior official at the Homeland Security Department now with the legal firm Steptoe and Johnson in Washington. "My guess is we're going to keep going in this direction for a while."
Rep. Dutch Ruppersberger of Maryland, the top Democrat on the House Intelligence Committee, said he supports the restriction and doesn't think it would be too cumbersome for federal agencies. The Defense and Energy departments already are mindful of how its networks are built.
"Anything we can do to call awareness to the fact that we're continuing to be cyberattacked, we're continuing to lose jobs, and that billions of dollars in American money is being stolen," Ruppersberger said in an interview Wednesday.
In March, the U.S. computer security firm Mandiant released details on what it said was an aggressive hacking campaign on American businesses by a Chinese military unit. Since then, Treasury Secretary Jacob Lew has used high-level meetings with Beijing officials to press the matter. Beijing has denied the allegations.
Congressional leaders have promised to push comprehensive legislation that would make it easier for industry to share threat data with the government. But those efforts have been bogged down amid concerns that too much of U.S. citizens' private information could end up in the hands of the federal government.
As Congress and privacy advocates debate a way ahead, lawmakers tucked "section 516" into the latest budget resolution, which enables the government to pay for day-to day operations for the rest of the fiscal year. The provision specifically prohibits the Commerce and Justice departments, NASA and the National Science Foundation from buying an information technology system that is "produced, manufactured or assembled" by any entity that is "owned, operated or subsidized" by the People's Republic of China.
The agencies can only acquire the technology if, in consulting with the FBI, they determine that there is no risk of "cyberespionage or sabotage associated with the acquisition of the system," according to the legislation.
The move might sound like a no-brainer. If U.S. industry and intelligence officials are right, and China is stealing America's corporate secrets at a breathtaking pace, why reward Beijing with lucrative U.S. contracts? Furthermore, why install technical equipment that could potentially give China a secret backdoor into federal systems?
Last fall, Ruppersberger and House Intelligence Committee Chairman Mike Rogers, R-Mich., released a report urging U.S. companies and government agencies to drop any business with Chinese telecommunications companies Huawei Technologies Ltd. and ZTE Corp. because of the security risks they pose.
"Any bug, beacon or backdoor put into our critical systems could allow for a catastrophic and devastating domino effect of failures throughout our networks," Rogers said in a statement accompanying the report.
But a blanket prohibition on technology linked to the Chinese government may be easier said than done. Information systems are often a complicated assembly of parts manufactured by different companies around the globe. And investigating where each part came from, and if that part is made by a company that could have ties to the Chinese government could be difficult.
Huawei, the third-largest maker of smartphones, says it is owned by its employees and rejects claims that it is controlled by the communist government or China's military.
Depending on how the Obama administration interprets the law, Baker said it also could cause problems for the U.S. with the World Trade Organization, whose members include U.S. allies like Germany and Britain that might rely on Chinese technology to build computers or handsets.
But in the end, Baker says it could make the U.S. government safer and wiser.
"We do have to worry about buying equipment from companies that may not have our best interests at heart," he said.
___
Follow Anne Flaherty on Twitter at https://twitter.com/AnneKFlaherty.