[+] Wayc0de's Blog[+]

Tampilkan postingan dengan label FBI. Tampilkan semua postingan
Tampilkan postingan dengan label FBI. Tampilkan semua postingan

27/09/11

Second LulzSec hacker 'Neuron' could be tracked down via UK VPN

Following the arrest last week of alleged LulzSec member 'Recursion', the Guardian has found that another member of the hacking crew used the HideMyAss service for their connection



LulzSec
 
LulzSec: members allegedly used the HideMyAss proxy service to disguise their IP addresses
 
At least one more member of the hacking group LulzSec, known online as "Neuron", may be arrested if traced by their use of a British anonymous VPN (virtual private network) proxy service, following a similar arrest last week.

Hackers have expressed already dismay after it emerged that that Cody Kretsinger, who was arrested by the FBI last Thursday for allegedly hacking into the Sony Pictures website, had been identified via his use of HideMyAss's proxy service to disguise his IP (internet protocol) address when connecting to the Sony Pictures site.

Kretsinger allegedly went by the online handle "Recursion" – which crops up in chatlogs from the group posted on the Pastebin site. "Recursion" boated of hacking into the Sony Pictures site.

However the Pastebin logs also show that another LulzSec member, using the handle "Neuron", also claimed to use the HideMyAss service. Neuron and Recursion are not the same people: the LulzSec chatlog records posted by the Guardian covering a period from 31 May show the two in the same chatroom at the same time, and on one occasion addressing each other directly. "Recursion" quit the group after it attacked an FBI-related site early in June, but "Neuron" remained.

HideMyAss, posted a lengthy defence of its actions on its blog after the news emerged, insisting that it had to retain logs:
Being able to locate abusive users is imperative for the survival of operating a VPN service, if you can not take action to prevent abuse you risk losing server contracts with the underlying upstream providers that empower your network. Common abuse can be anything from spam to fraud, and more serious cases involve terrorism and child porn.

The main type of logging is session logging – this is simply logging when a customer connects and disconnects from the server, this identifies who was connected to X IP address at X time, this is what we do and all we do. Some providers choose not to do session logging and instead try to locate the abusive customer by using the intelligence from the complaint, for example if someone hacks XYZ.com they may monitor traffic to XYZ.com and log which customers have a connection to this website. Ask yourself this: if a provider claims not to do any form of logging, but is able to locate abusive customers, how are they able to do this without any form of logging?
The company added that it would only hand over logs if they were the subject of a valid UK court order: "if a request for information is sent to us from overseas, we will not accept this request unless it is sent through the appropriate UK channels and a UK judge warrants a court order or a court summons that forces us to provide this information. We are not intimidated by the US government as some are claiming. We are simply complying with our countries legal system to avoid being potentially shut down and prosecuted ourselves."

Some questioned whether HideMyAss – which says that it helped people in Egypt to evade crackdowns during the Arab spring protests – would hand over details of individuals to repressive regimes such as Syria. The company says in the blogpost that it would not because "[in] UK law, there isn't a law that prohibits the use of Egyptians gaining access to blocked websites such as Twitter, even if there is one in Egypt."

The revelation that the service retains some log details has caused outrage amid parts of the hacking community, with a number vowing never to use HideMyAss's service again. A rival service, AirVPN, put out a statement saying that it does not keep logs in the way that HideMyAss does: "we would like to reassure our users and our customers that nothing like that [handover of logs] may happen with AirVPN, for a series of legislative (we are based in the EU, not in the USA, and we don't recognize USA jurisdiction, obviously) and above all technical reasons." It says it will accept payments in BitCoin, the cryptocurrency, which can be made via the Tor network, for security.

Four people have been arrested in the UK relating to LulzSec's activities, with three charged so far.

nb : guardian Read More...

26/09/11

Homeless hacker 'Commander X' pleads not guilty [VIDEO]

Commander XThe FBI believes that the homeless man they arrested on Thursday was "Commander X", a member of the People's Liberation Front (PLF) associated with Anonymous hacktivism.

47-year-old Christopher Doyon has entered a not guilty plea to charges of "conspiracy to cause intentional damage to a protected computer, causing intentional damage to a protected computer, and aiding and abetting".

According to an indictment filed against Christopher Doyon and another man, Joshua John Covelli, the charges specifically relate to a denial-of-service attack against the servers of Santa Cruz County in December 2010, after the city put in place a law prohibiting camping inside the city.

Indictment against Christopher Doyon and Joshua John Covelli
The indictment gives Doyon the aliases "PLF", "Commander Adama" (clearly a Battlestar Galactica fan) and "Commander X". Covelli meanwhile is alleged to use the pseudonyms "Absolem" and "Toxic". 26-year-old Covelli was previously named in connection with internet attacks on PayPal.

Someone calling themselves "Commander X" gave an interview to CBS News earlier this year, claiming responsibility for denial-of-service attacks by Anonymous.


According to a CBS News report, "Commander X" told their reporter that he had no fear about being caught:
"We're not going to turn ourselves in. They can come and get us is what I say. Bring it on. Until then, we run... We will remain free and at liberty and at large for as long as we can, and when the time comes that each and every one of us eventually will be brought to justice, we will hold our head high in any court of law and we will defend our actions."
Doyon is scheduled to appear on September 29th for a bail hearing.

nb : nakedsecurity.sophos
Read More...

24/09/11

FBI Snags Lulzsec Member Involved in Sony Hack

LulzsecThe FBI continued its pursuit of members of the hacking group LulzSec on Thursday, arresting a 23 year old Phoenix, Arizona man believed to be part of an online hacking crew that attacked systems belonging to Sony Pictures, the Bureau said in a statement Thursday.

The arrest, conducted by agents from the FBI's Los Angeles office arrested Cody Kretsinger of Phoenix Arizona on Thursday. Kretsinger was named in a September 2 federal grand jury indictment and charged with conspiracy and unauthorized impairment of a protected computer for his role in attacks in May and June against computer systems belonging to Sony Pictures Entertainment, according to the statement. Published reports indicate that other arrests took place in Ohio, San Francisco, California, Montana, Minnesota and New Jersey.

Kretsinger, who used the online handle "recursion" is alleged to have carried out SQL injection attacks on Sony's application servers, connecting through a proxy server to mask his Internet Protocol (IP) address.

After compromising Sony's networks, Kertsinger is alleged to have distributed information stolen from Sony and to have publicized the attack on LulzSec's Web site and through its Twitter account.

Sony's network became a target in April, after Lulzsec targeted the company for its legal pursuit of PS3 hacker George Holtz (aka "GeoHot"). The hackers broke into the company's online gaming network, PSN Network. The company's Sony Online Entertainment and Station.com networks were also breached, with data on around 100 million users exposed, all told.

Kretsinger is just the latest in a string of arrests and searches of both high- and low level members of LulzSec and Anonymous. In June, a 19 year old man, Ryan Cleary of Essex, England, was arrested and charged with five counts of violating that country's Computer Misuse Act and Criminal Law Act. Subsequent raids and arrests of members of LulzSec and Anonymous claim to have targeted high ranking members of both LulzSec and Anonymous, including the member known as "Topiary" (allegedly 18 year old Jake Davis of the remote Shetland Islands in the UK) and, more recently, individuals believed to be linked to the online identity "Kayla," a key player in many of LulzSec's most notable hacks.

nb : threatpost Read More...

23/09/11

Alleged LulzSec Sony hacker arrested

The 23-year-old Phoenix student is accused of using SQL injection to break into Sony Pictures' database

The U.S. Federal Bureau of Investigation has arrested a Phoenix student, claiming that he is one of the LulzSec hackers responsible for a database attack on Sony Pictures computers that claimed more than 1 million victims.

Cody Kretsinger, 23, was arrested Thursday morning on hacking and conspiracy charges. Prosecutors say he was "Recursion," an LulzSec hacker who used a database attack technique called SQL injection to break into Sony Pictures systems. Kretsinger allegedly provided data that was used in a mammoth June 2, 2011, data dump by LulzSec that included coupon codes along with email addresses and passwords belonging to Sony customers.

[ Get your websites up to speed with HTML5 today using the techniques in InfoWorld's HTML5 Deep Dive PDF how-to report. | Learn how to secure your Web browsers in InfoWorld's "Web Browser Security Deep Dive" PDF guide. ]

At the time that LulzSec posted its data, Sony was already recovering from a devastating break-in to its PlayStation Network. That intrusion knocked the service offline for more than two months and cost the company an estimated ¥14 billion ($183 million) to clean up.

"The extent of damage caused by the compromise at Sony Pictures is under investigation," the FBI said Thursday in a statement.

Sony's heavy-handed response to the release of "jailbreak" code for its PS3 console, which could be used to run unauthorized software on the device, had made the company the enemy of hackers everywhere, and the LulzSec hackers were not the only ones to go after the company's computer systems.

LulzSec had a brief run of Internet mayhem earlier this year, breaking into websites belonging to corporations and law enforcement agencies and then posting the data publicly with gleeful disregard to any consequences.

Since then, the group seems to have been largely rounded up by law enforcement in a series of arrests in the U.S. and U.K.

Kretsinger allegedly covered his tracks by using the Hidemyass.com proxy service and wiping his computer hard drive after the attack. He faces 15 years in prison if convicted.

Separately, the FBI also announced the arrest of two alleged members of the Peoples Liberation Front, a group that claimed credit for a 30-minute long 2010 distributed denial of service attack against Santa Cruz County, California. Like LulzSec, Peoples Liberation has affiliated itself with the Anonymous hacking movement.

Christopher Doyon and Joshua Covelli are both facing hacking charges in the case. Covelli had previously been charged in connection with an Anonymous-sponsored December 2010 attack on Paypal.com.

nb : infoworld Read More...

Microsoft passes Rustock botnet info to FBI

The company's take-down and command disruption has reduced the size of the botnet by 74 percent since March

Microsoft on Thursday wrapped up its civil case against the still-unnamed controllers of the Rustock botnet and handed off the information gleaned during its investigation to the FBI.

But the move doesn't end the company's six-month operation: Last week, a federal judge granted Microsoft and others the right to lock up tens of thousands of Internet protocol (IP) addresses for the next two years.

[ Learn how to greatly reduce the threat of malicious attacks with InfoWorld's Insider Threat Deep Dive PDF special report. ]

The IP addresses were ones that the Rustock controllers could use to issue commands to the malware that still exists on infected PCs.

Richard Boscovich, a senior attorney in the Microsoft Digital Crimes Unit, was confident that authorities would find, arrest and prosecute those involved with Rustock.

"We went as far as we could on the civil side, [but] we were able to develop some very good leads that we think will lead to the identities of some of those responsible," said Boscovich in an interview yesterday. "We decided to give our findings to law enforcement, so they could use their expertise. It was a natural progression for the case."

Later during the interview, Boscovich said he "felt pretty good" about the chance that authorities will eventually make arrests.

In March, Microsoft lawyers and U.S. Marshals seized Rustock command-and-control (C&C) servers at five Web hosting providers in seven U.S. cities, crippling the botnet. At the time, Rustock was hiding on an estimated 1.6 million Windows PCs worldwide, and was being used to send massive quantities of spam -- up to 30 billion messages daily -- much of it pitches for fake pharmaceuticals.
The take-down and subsequent suppression efforts have prevented Rustock from reviving, according to Microsoft.

In a blog post Thursday, Boscovich said that as of September, Microsoft had identified about 422,000 Rustock-infected PCs, a 74% reduction since March. The September numbers were an improvement over June, when Microsoft said that more than 700,000 PCs harbored the Rustock malware.

The take-down didn't remove the Windows PCs from Rustock control. Instead, the server seizures and the blocking of domains Rustock was to use for fallback communications kept the botnet from updating itself.

That, in turn, gave antivirus vendors the time they needed to issue signatures for the existing Rustock malware, and for Internet service providers (ISPs) to notify users that their machines had been compromised.

But for all its work -- including offering a $250,000 reward for information that leads to an arrest -- Microsoft has not been able to conclusively identify those who controlled the botnet.

In an earlier filing with a Seattle federal court, Microsoft said it had traced payments for the hosting of some of Rustock's C&C servers to a specific Webmoney account, and after asking the Russian online payment service for help, identified the owner of that account as one Vladimir Alexandrovich Shergin of Khimki, a city 14 miles northwest of Moscow.

However, Microsoft had cautioned the court that Shergin might not be the actual purchaser of Rustock's C&C hosting services.

The $250,000 reward, which Microsoft posted in July, brought in scores of tips, including some high-quality leads, said Boscovich.

"Some of the information we received seemed to be coming from other individuals in the 'industry,'" said Boscovich, referring to the botnet cybercrime business. He said Microsoft was able to gauge the legitimacy of the incoming tips by using information it had already collected.

"We were getting some very good discovery," Boscovich said, talking about the civil case's investigative phase. "We wanted to supplement that by offering the reward."

Microsoft has not withdrawn the reward, but has asked that tips now be submitted to an FBI email address.

Some of what Microsoft learned during its Rustock digging revealed other cybercrimes, information that the company and others can use.

"It's like when you're walking down an alley looking for one crime, on the way you see several others," Boscovich said. "[The investigation] led to a lot of good leads, not just about Rustock, but about the industry itself."

nb : infoworld Read More...

FBI arrests Sony LulzSec hacking suspect

Sony executives Shiro Kambe, Kazuo Hirai  and Shinji Hasejima
 
At a May press conference in Tokyo, Sony executives bow to apologise for thefts of personal data from Sony's computer networks. An alleged member of LulzSec has been arrested in Arizona by the FBI. Photograph: Toru Yamanaka/AFP/Getty
A suspected member of the clandestine hacking group LulzSec has been arrested in Arizona by the FBI on charges of taking part in an extensive breach of the Sony Pictures computer system.

A federal grand jury indictment charges Cody Kretsinger, 23, with conspiracy and the unauthorised impairment of a protected computer in connection with the attack in May and June.

Kretsinger is alleged to have used the online name, or handle, of "recursion" as part of the hacking crew.

LulzSec, an underground group also known as Lulz Security, at the time published the names, birth dates, addresses, emails, phone numbers and passwords of thousands of people who had entered contests promoted by Sony.

"From a single injection we accessed EVERYTHING," the hacking group said in a statement at the time. "Why do you put such faith in a company that allows itself to become open to these simple attacks?"
Hackers previously had accessed personal information on 77m PlayStation Network and Qriocity accounts, 90% of which belonged to users in North America and Europe, in what was then the biggest such security breach in history.
The nine-page indictment said Kretsinger and co-conspirators obtained confidential information from Sony Pictures' computer systems using an "SQL injection" attack against its website, a technique commonly used by hackers to exploit vulnerabilities and steal information.

The indictment said that Kretsinger, as "recursion", helped post information he and his co-conspirators stole from Sony on LulzSec's website and announced the intrusion via the hacking group's Twitter account.

The extent of damage caused by the breach of the studio's computer network remained under investigation, the FBI said.

Chat logs obtained by the Guardian reveal that two members of LulzSec, "recursion" and "devrandom", decided to leave the group after 3 June after it attacked an FBI-affiliated site.

There have been four arrests in the UK of people alleged to be associated with LulzSec. Trials of three of them are expected to begin in 2012.

LulzSec, an underground group also known as Lulz Security, at the time published the names, birth dates, addresses, emails, phone numbers and passwords of thousands of people who had entered contests promoted by Sony.

"From a single injection we accessed EVERYTHING," the hacking group said in a statement at the time. "Why do you put such faith in a company that allows itself to become open to these simple attacks."

Hackers previously had accessed personal information on 77m PlayStation Network and Qriocity accounts, 90% of which belonged to users in North America and Europe, in what was then the biggest such security breach in history.
Other high-profile companies targeted by cyber attacks included Lockheed Martin and Google.

Sony officials did not comment on Thursday's arrest.

LulzSec is reputed to be affiliated with the international hackers collective called Anonymous, which has claimed responsibility for cyber attacks on government and private institutions around the world.

Kretsinger faces a maximum sentence of 15 years in prison if convicted. The government is trying to extradite him to Los Angeles, where Sony Pictures' computer system is located and where the case against him has been filed.

nb : guardian
Read More...

Homeless hacker arrested by FBI in LulzSec/Anonymous investigation

Homeless manAccording to media reports, the FBI has arrested two alleged hackers in San Francisco and Phoenix, believed to be associated with the LulzSec and Anonymous hacktivist groups.

And one of them is homeless.

FoxNews reports that search warrants have also been executed in the states of Minnesota, Montana and New Jersey as part of a wider FBI investigation into the groups who have launched attacks against government websites as well as corporations such as Sony.

23-year-old Cody Kretsinger, from Phoenix, Arizona, has been charged with computer offences, and is alleged to be the LulzSec member known as "Recursion". Kretsinger is accused of being involved in an SQL injection attack that stole information from Sony Pictures in June, exposing users email addresses and passwords.

According to the indictment against Kretsinger, he is accused of using the hidemyass.com proxy service to cloak probes he made of Sony Pictures' computer systems in May 2011, hunting for vulnerabilities.

Sony passwords leakedApproximately 150,000 confidential records were subsequently published online by LulzSec who criticised Sony's weak security.

Authorities allege that Kretsinger wiped the hard drives used to carry out the attack on Sony in an attempt to hide forensic evidence.

"Recursion" is one of many handles used by members of the LulzSec hacking gang, and features in internet chat logs that have previously published of the group having what they believed to be private conversations.

Chat log between LulzSec members Topiary and Recursion
Meanwhile, the FBI arrested an alleged Anonymous member in San Francisco. The man, who is reported to be homeless, is said to have been involved in internet attacks against Santa Cruz County government websites.

Just because a man is homeless, of course, doesn't mean that he can't get an internet connection. Coffee houses, cafes, libraries, etc can all offer cheap or free internet access - and because the computer being used can be a shared device, it may be harder to identify who might have been responsible for an attack compared to a PC at a home.

At the same time, public places are often watched with CCTV cameras which means that if the authorities were able to identify a time and place, they may also be able to gather evidence as to who was at the location when an attack was begun from a particular computer.

Both LulzSec and the larger Anonymous hacktivist collective have had a tough time of late, with a series of arrests in the USA, UK and elsewhere around the globe.

Wannabe hackers might be wise to read the FBI's press release about the Kretsinger arrest, which points out that if convicted of the hacking offences he could face up to 15 years in prison.

nb : nakedsecurity.sophos
Read More...

18/09/11

Fake FBI Anonymous psychological profile: a lesson to all internet users

The faceless power of Anonymous rages on.
Like headless horsemen, they gallop across the internet, intent on causing massive headaches and embarrassment for some, while keeping their fans and the media informed via social media.

Sounds even too good for a Hollywood movie plot. You couldn't make it up.

But it turns out that someone did make up the recently disclosed FBI document 'Psychological Profile of the Anonymous Key Personalities' [PDF].

And the story was covered by several reputable media outlets, though admittedly some voiced skepticism.

On September 8, Anonymous used Twitter and Tumblr to distribute the fake document.



The question is why did anyone ever think it was real?
  • Why would Anonymous leak a document that would put their esteemed leaders at risk?
  • Why would the FBI actually use Wikipedia as their sole information source for Anonymous's background?
  • The codename for the field informant is Marotte (which means prop stick, dummy head or fad)
  • Looking at the copious typos and grammar glitches in the document, would the FBI have a profiler without a basic grasp of written communication?
Fake FBI profile of Anonymous
So all this made us at Naked Security a bit suspicious at the time. So no surprise that this so-called FBI document turns out that it is a fake.

The thing is though, it does make for interesting lunchtime reading. I absolutely love some of the profiles in this faux document.

It defines "Kayla" as a violent, amoral bisexual with an inferiority complex, and "Topiary" as a youthful, obsessive idealist, possibly afflicted with Aspergers.

Forgive the quasi-psychology here - couldn't a fake document, if indeed it is written by the Anonymous leaders, be used to help the FBI and other authorities better understand the collective? What seems like nonsense to its authors could accidentally reveal some interesting insights for those that analyse and pigeon-hole personalities.

That said, some of you might remember that great article by Malcolm Gladwell where he concludes that criminal profiling isn't all that helpful to the capture of wanted criminals.

So what is the upshot? Whoever is involved in writing this didn't waste the FBI's time with this forgery, because they must have been aware from the get-go that this did not originate from their internal team.

Those responsible for the document did however manage to get the internet, media and bloggers yacking about it. Yes, even me. Anonymous have notoriety because many people have written about it. And if Anonymous did indeed pull this together, they have just lied to their online followers. tsk tsk.

Please, can we all make sure we take this collective's word with a grain of salt next time?

nb : nakedsecurity.sophos
Read More...

16/09/11

FBI: Psychological Profile of Anonymous Leadership is a Fake

It looks as if Anonymous's latest prank is a damning psychological profile of its own members, allegedly assembled by the FBI.

A spokesperson for the federal law enforcement agency said the document that was published online is a forgery, confirming speculation that it was a fake. The denial points a finger at Anonymous, itself, as the source of the document, in what appears to be an elaborate prank or an effort to sow disinformation.

The fake profile includes assessments of known Anonymous leaders, as identified by their Web-pseudonyms. It includes psychological sketches of Sabu, his described second-in-command, Kayla, the already-arrested and former spokesperson, Topiary, and the so-called autonomous members, JoePie91 and Tflow.

Many of the document's allegations are damning. It characterizes Sabu as a self-perceived martyr and narcissistic American male in his early thirties with a nihilistic world-view, likely an information security professional operating within the business community without alerting his peers to his other online activities. Kayla, characterized as the second-in-command, is profiled as a middle-American male in his early to mid-twenties whose stunted emotional age and inferiority complex may be the result of childhood trauma, perhaps an abusive parent, and who seeks attention as a result of a childhood desire for parental approval. Hmmm.... Very, very interesting.

Links to the document appeared on a Tumblr site and Twitter account affiliated with the group, media outlets ran with the story, even as they cast doubts about its authenticity.  Indeed, from the very first, casual readers and Anonymous sympathizers suspected it was a fake. The tone of the document is sensational and its content is rife with broad and thinly-sourced generalizations about the group and its members. (Wikipedia is cited for its description of the group.) It contains numerous spelling  and grammar errors and, perhaps the biggest red flag, casts aspersions on the FBI's own enforcement actions. In just one example, Topiary, a core member was arrested in the UK, is described as an ego-driven and idealistic youth with "Aspergers syndrome" (sp) who was used as cannon fodder for law enforcement.

It is unclear what the purpose of the document is. Despite its outsize reputation, Anonymous's core leadership is believed to be quite young. Many of those arrested so far in connection with distributed denial of service (DDoS) attacks and other actions are in their teens to early 20s. The profiles document may be a ham-fisted effort to throw investigators off the group's scent, or merely a practical joke from one Anonymous member to another.

nb : threatpost Read More...

13/09/11

Ghost in the Wires: The Kevin Mitnick Interview

Summary: The world’s most famous hacker discusses his new book, his exploits, his imprisonment and his success. Meet the Ghost in the Wires, Kevin Mitnick.

I can count on one hand the number of people who’ve significantly influenced a generation of IT professionals: Bill Gates, Linus Torvalds, Steve Jobs, Richard Stallman and Kevin Mitnick. I’ve had the unique privilege of interviewing two of the people in this list (Stallman and Mitnick). Each of the men in this list has his own unique approach to shaping the world in which he lives but they all have one thing in common: Passion for what they do.

But, it’s not a normal passion, it’s an all-consuming passion that seeps from every pore of their being. It’s rare and it’s what sets them apart from everyone else. There is a special pace to their speech–a cadence of thought–and a childlike thrill in their hearts for what they do.

This is a summary of my interview with Kevin Mitnick, the world’s most famous and most passionate hacker.

Kevin Mitnick was the first famous hacker that I remember. He had a face and a name. He looked like a regular guy to me. He certainly didn’t fit into the Ectomorphic Cerebrotonic somatotype that I expected. He didn’t look like an evildoer and he didn’t sound like an evildoer. But, to law enforcement, including the FBI, he was just that. To them, he was a name and a face on a Wanted poster and they wanted him under arrest. The world’s largest and most influential telephone and technical companies just wanted him out of their wires.

He was unstoppable like a ghost that could walk through walls.

His new book, Ghost in the Wires, chronicles his exploits into phone systems, into computer systems, into FBI operations and into prison.

Little, Brown and Company; (August 15, 2011) 115 Amazon.com Customer Reviews: 5 Stars.

Curiosity, Mr. Decker. Insatiable curiosity.

KH: What was your motivation for hacking into phone systems and computer systems?

KM: Pranskterism. It was fun. I was curious. I wanted to know how things worked, especially operating systems. I read the source code. I didn’t sell it or distribute it.

You’d think that someone who hacks into a major company would actually steal something, even if to expose it to the world. Not so with Kevin. He just wanted to read the code and understand how it worked. Apparently, the FBI placed a value on that learning exercise that was higher than his freedom.

“No company that I ever hacked into reported any damages, which they were required to do for significant losses. Sun didn’t stop using Solaris and DEC didn’t stop using VMS.”

Instead, the FBI estimated Kevin’s hacks and code reading into the $300 million range, which accounted not only for any break-in mitigation but also for the entire cost of operating system research and development. It was extreme and unfair but it was to send a message to Kevin and others like him that such actions would not be tolerated.

The punishment became more about the message rather than any actual damages. No one, not even Kevin himself, is saying that what he did was OK but the punishment should fit the crime.

“What I did was illegal and I should have been punished. But, the punishment should have been for any real damages that I caused.”

KH: What is the purpose of Ghost in the Wires? What do you hope to accomplish with it?

KM: Its my story. And, I want to get my story out. I want people to know the true story. There’s a lot of myth and false information about me out there.

FREE KEVIN

KH: Was the Free Kevin campaign to help you with attorney’s fees?

KM: No, it was to educate people about the unfair treatment I was receiving: solitary confinement, exaggerated claims, poor representation and outlandish damage estimates.

KH: How did you pay for your attorney’s fees? The cost must have been overwhelming.

KM: I had a court-appointed attorney. And, the court didn’t want to spend a lot of money defending me, so I sat in prison for more than four years without a trial. About one year of that was in solitary confinement.

Ass Burgers

KH: I’ve heard that a lot of hackers, including you, have been diagnosed with Asperger’s Syndrome. What do you think of that?

KM: I was diagnosed with it but I think it was my attorney’s effort to help my defense. It was never used in the case. I don’t think I have it. I’ve heard that Adrian Lamo, Gary McKinnon and John Draper have it. I might believe that Draper has it. I don’t know about the others or the Lulz guys.

Thank you for calling Cheyenne Mountain, how may I direct your call?

KH: Can you really whistle the launch codes to our nuclear arsenal?

KM: No, that is a gross exaggeration and part of what got me placed in solitary confinement. They wouldn’t allow me to have access to a telephone because of accusations like that.

Welcome to McDonald’s, may I take your order?

KH: Do you have a favorite hack?

KM: Hacking into the communications at McDonald’s. That was a lot of fun.
How it works: Customers pull up to the drive-through box to place an order and instead of hearing the employee inside, they hear your greeting. The employees can also hear you and the reactions of the customers. Hackers who do this use some form of modified CB radio or telephonic device to tune into the frequency used by the wireless sets in fast food restaurants.

“One guy was so frustrated that he went out and looked into the drive-through box to see if he could find something in it. Of course, I was across the street watching it all.”

Danger, Will Robinson!

KH: What kind of threats are big right now. It seems that full frontal attacks are down.

KM: Successful attacks these days are hybrid. Attackers use a combination of Social Engineering and Spear Phishing to compromise systems and networks.
One example of this hybrid technique is that a “vendor representative” will call an unsuspecting person in a company and ask which software versions they’re using. They would ask for an email address along with that information. The hacker will then send an email with malicious code attached to deliver a payload that gets the hacker inside the company’s network.

Close enough for government work?

KH: From our conversation, it seems that there’s no way to fully protect ourselves from hacks. Is that true.

KM: It is. You can never protect yourself 100%. What you do is protect yourself as much as possible and mitigate risk to an acceptable degree. You can never remove all risk. For example, if you accept email attachments as part of your business, you’re introducing risk. But, if your customers need to send attachments, you have to accept that risk.

Got Security?

KH: What do you do now?

KM: I’m still a hacker. I get paid for it now. I never received any monetary gain from the hacking I did before. The main difference in what I do now compared to what I did then is that I now do it with authorization.

The Good Hacking Seal of Approval?

KH: Which operating system do you use?

KM: I use Mac. Not because it’s more secure than everything else. Because it is actually less secure than Windows but I use it because it is still under the radar. People who write malicious code want the greatest return on their investment, so they target Windows systems. I still work with Windows in virtual machines.

KH: Do you use Linux?


KM: Yes, I use Ubuntu and Gentoo.

Just the VAX ma’am, just the VAX

KH: What is your favorite OS?

KM: VMS. I’ve always liked it.

None shall pass

KH: What’s the most secure OS? Is there one that you can recommend?

KM: I don’t know of any secure OS. In the past eight years, I’ve had 100% success at penetration testing on all of them. Wait, ChromeOS, ChromeOS is the most secure because of its very limited attack vector–there’s just nothing to exploit.

Eep Op Ork Ah Ah

KH: What else can you tell me about Ghost in the Wires, are there any secrets that you haven’t revealed?

KM: Yes, at the beginning of each chapter, I’ve placed cryptograms there for readers to solve. If you solve all of them, then I’m going to draw names of the winners and give a piece of evidence from my case in the actual FBI bags. It would be a cool piece of memorabilia for people interested in the case or hacking. You can answer the questions by reading the book. I’m currently setting up the website now for this.

Deep vengeance is the daughter of deep silence

KH: Do you have any recourse or do you want any vengeance against anyone for the wrongs that were done to you?

KM: No. None. The best vengeance for me is that my book is number eight on the best seller list right now, my business is successful and I have my family.

To Kevin: It’s better that you feel that way. Unfortunately, I am neither so wise nor so forgiving. I’m glad you’re on our side and using your powers for good.

Personal Notes: I interviewed Kevin just a few days after his appearance on The Colbert Report and we had a good time trading hacking stories, discussing his new book and talking about security issues facing individuals and companies. I believe that he was treated unfairly by the courts, the FBI and the media (at the time). Accusations against him were ridiculous and exaggerated because he made fools of law enforcement. They took it personally. I also don’t believe that he has Asperger’s. That is nonsense and am glad that it never came up in his proceedings. I want him to have his vengeance through the success of his business, his books and his life. Godspeed, Kevin. Read More...

07/09/11

Anonymous Goes To Hollywood, Targets Jenny Garth, Miley Cyrus, Kreayshawn, Others

 A new faction of hacktivist collective Anonymous appears to be setting its crosshairs not on NATO or government contractors but on a much fatter (or is it fatuous?) target: celebrities.

The splinter group dubbed "Hollywood Leaks" has begun to make waves in the entertainment industry over the last week, leaking celebrities’ phone numbers, unreleased movie scripts and nude photos.According to a report on CSO’s Australian site, the offshoot group has been distributing its leaks via the Twitter account HWLeaks. Anonymous’ motto, “We do not forgive, we do not forget, expect us,” rounds out the profile.

When pressed in an interview for an explanation of the group’s intents by the media/gossip blog Gawker, one member of Hollywood Leaks claimed “We're simply here to facilitate the free flow of information from a place which was previously over looked, Hollywood."


Among the first targets was an actor in Tom Cruise’s upcoming musical Rock of Ages had his e-mail cracked which lead to the script eventually being posted to bittorrent site Pirate’s Bay in late August, well in advance of its 2012 release.

Early last week, rapper Kreayshawn found her nude pictures spread across the Internet after they were tweeted from her hijacked Twitter account. Actress Jenny Garth and musicians Miley Cyrus and DJ Drama have seen their phone numbers leaked over the past few weeks while actor Gerard Butler and rappers Lloyd Banks and Waka Flocka Flame were also targeted and had their e-mail addresses released to the public.

The celebrities’ sensitive information was posted to Pastebin, a file sharing site that has seen increased usage by hackers to show off their exploits as of late. The same site was used to distribute critical information belonging to IRC Federal and the Federal Bureau of Investigation following breaches earlier this year.

nb : threatpost Read More...

03/09/11

LulzSec and Anonymous police and FBI investigation sees two more arrested

The LulzSec logo
LulzSec, which uses this logo, and Anonymous are being investigated by UK police and the FBI over claims the online groups hacked websites.
 
Two men have been arrested in connection with online attacks by hacking gangs Anonymous and LulzSec, Scotland Yard said.

The men, aged 24 and 20, were arrested on Thursday in Mexborough, near Doncaster, South Yorkshire, and Warminster, Wiltshire, for conspiring to commit offences under the Computer Misuse Act 1990.

Scotland Yard said the arrests were part of a continuing investigation in collaboration with the FBI, South Yorkshire Police and other law enforcement bodies, into activities of Anonymous and LulzSec, especially in connection with suspected offences under the cover of online identity "Kayla".

A spokesman said the men were arrested separately. He said the Doncaster address was searched by police and computer equipment was removed for forensic examination.

Detective Inspector Mark Raymond from the Metropolitan Police's Central e-Crime Unit (PCeU), said: "The arrests relate to our inquiries into a series of serious computer intrusions and online denial-of-service attacks recently suffered by a number of multi-national companies, public institutions and gPressovernment and law enforcement agencies in Great Britain and the US.

"We are working to detect and bring before the courts those responsible for these offences, to disrupt such groups, and to deter others thinking of participating in this type of criminal activity."

In a separate investigation two men were charged on Thursday over online attacks by Anonymous, Scotland Yard said.

Christopher Weatherhead, 20, from Northampton, and Ashley Rhodes, 26, from Kennington, south London, have been charged with conspiracy to carry out an unauthorised act in relation to a computer.

Police had already charged a youth from Chester aged 17 and student Peter David Gibson, 22, from Hartlepool, in relation to the same offences.

All four will appear on bail at City of Westminster Magistrates Court on September 7.
Read More...

26/08/11

FBI fights back against cybercrime


Still from film War Games
Rose-tinted view of hacking? Matthew Broderick and Ally Sheedy in the film War Games.
An attractive brunette in a business suit is making her online pitch. "Are you tired of searching for legit CVV shops?" her animated form asks from the corner of the website. "Search no more," she promises. This site has "handpicked cards" with "high balances". "What are you waiting for? Register now."

It looks like a legitimate business website, one for small business financing perhaps. But I'm being shown this site — and asked not to identify it — by FBI special agent Keith Mularski in the offices of the National Cyber-Forensics & Training Alliance, a Pittsburgh-based alliance between international law enforcement agencies, business and academia that has been charged with tackling the growing menace of cybercrime. This is a site at the cutting edge of crime.

CVV stands for card verification value. This site, and its equally professional rivals, are selling stolen credit card information to criminals who snap them up like songs on iTunes. A dollar buys enough information to use someone else's card online, $30 buys a "dump," all the information you need to copy a card and set off on your own real-world shopping spree with somebody else's plastic.

There are millions of stolen accounts available, hacked from banks and online sellers, or swiped at cash machines. The FBI recently reclaimed 1.5m numbers from one seller alone. You can sort by type, MasterCard, Visa, or American Express, by geography, or just stick to business cards for their higher balances. There's no need to fear getting ripped off. Criminals peer-review each other's sites. It's eBay for crooks.

Mularski knows a thing or two about cybercrime. For two years he ran one of the biggest underworld crime sites in the world. Using the pseudonym Master Splynter (a nod to the cartoon Teenage Mutant Ninja Turtles) Mularski masqueraded as a spammer, winning the confidence of online crooks and eventually taking over as host of Dark Market, at the time the largest online forum for cybercriminals. The sting was a big victory for the US authorities, which, along with other governments, have struggled to keep up with the rapidly spreading threat.

Police officers from the UK, Germany, Netherlands, Australia and other countries work alongside the FBI at the NCFTA. The organisation also has about 500 business partners, from the big banks to technology companies and links with academics at local universities Carnegie Mellon and Pittsburgh.

The scale of the problem they are tackling is dizzying. According to a recent study by the British government, cybercrime is endemic and costs UK businesses an estimated £27bn a year. The criminals who buy this information operate a vast, international enterprise that employs teams of "mules" to buy goods either in person or online and yet more mules to launder their cash. They pay each other via digital currencies. "Would you take a credit card if you were one of these guys?" asks Mularski. These are multimillion-dollar businesses with serious costs. "This is serious money," says Mularski.

Serious skills

And it is serious criminals who are doing it. Mularski says he hates the term "hacker". "It's so generic," he says. "Traditionally we have thought of this cybercriminal as a geek. When I first started in cybercrime, the impression I got was [of] the movie War Games, Matthew Broderick sitting in his parents' basement. That's not the case any more. These are serious businessmen with serious skills."

One man arrested as part of a recent FBI investigation had contracts with a factory in China to mass produce fake credit card readers that could steal people's details. There's violence. Rivals have been kidnapped and tortured, and one spammer tried to take out a hit on a witness. "Very traditional organised crime is moving into the cyber realm," Mularski says.

Traditional organised crime activities such as racketeering or prostitution are not going away, he says, but the new generation of criminals is as excited about online growth as their legitimate business rivals. But there are major differences. "This isn't the Sopranos, or gangs," he says. "You don't have the same physical interaction. Here you do your transactions with the push of button, click of a mouse."

Internet crime also attracts people who would never get involved in a bank robbery. "When you are behind a keyboard, you're anonymous, you have more bravado. You need a lot of chutzpah to go into a bank and rob it. You do things online that you may not do in ordinary life. People don't start out thinking they will be a cybercriminal. They start out exploring. And before you know it, the line is crossed from curiosity to crime," says Mularski.

Mularski's high profile makes him a target for hackers. His office has also been working on tackling Anonymous, the hacker collective that has humiliated US government departments and big business on numerous occasions. He won't comment on them except to say: "Hacking into a company, whether it's to put information on the web for everyone to see or if you're going to make money, is still hacking, it's still a crime."
So does he feel vulnerable? "I was worried for a bit, I'll be honest," he says knocking on wood. "I'm very careful now. But the best protection of all is to turn your computer off."

nb : guardian
Read More...