I was scanning the news today, and nothing much was going on. There were some half-arsed stories about Anonymous and LulzSec – but nothing really worth writing about. And then, and then I spotted this, which quite frankly scares the shit out of me.
As much as it may well have a use in law enforcement, I’m sorry but I don’t want any single organization, corporation or entity to have the power to take out domains.
It’s just plain wrong, and well the UK has already started tabling something like this back in September.
VeriSign, which manages the database of all .com internet addresses, wants powers to shut down “non-legitimate” domain names when asked to by law enforcement.
The company said today it wants to be able to enforce the “denial, cancellation or transfer of any registration” in any of a laundry list of scenarios where a domain is deemed to be “abusive”. VeriSign should be able to shut down a .com or .net domain, and therefore its associated website and email, “to comply with any applicable court orders, laws, government rules or requirements, requests of law enforcement or other governmental or quasi-governmental agency, or any dispute resolution process”, according to a document it filed today with domain name industry overseer ICANN.
The company has already helped law enforcement agencies in the US, such as the Immigration and Customs Enforcement agency, seize domains that were allegedly being used to sell counterfeit goods or facilitate online piracy, when the agency first obtained a court order.
That seizure process has come under fire because, in at least one fringe case, a seized .com domain’s website had already been ruled legal by a court in its native Spain.
Senior ICE agents are on record saying that they believe all .com addresses fall under US jurisdiction.
But the new powers would be international and, according to VeriSign’s filing, could enable it to shut down a domain also when it receives “requests from law enforcement”, without a court order.
Yes VeriSign do manage all the .com and .net domains, but they aren’t technically ruled under the US jurisdiction – there are plenty of .com domains that are hosted outside of the US, including the DNS infrastructure.
What I’m especially interested in, is how they plan to handle the fact that lots of things are illegal in some countries and perfectly legal in others. The part that scares me is they will be able to take down a domain without a court order, just on ‘request’ from a law enforcement agency.
To me, that opens it up to abuse – if you are going to do something like this, at least institute a due process to manage it properly.
“Various law enforcement personnel, around the globe, have asked us to mitigate domain name abuse, and have validated our approach to rapid suspension of malicious domain names,” VeriSign told ICANN, describing its system as “an integrated response to criminal activities that utilize Verisign-managed [top-level domains] and DNS infrastructure”.
The company said it has already cooperated with US law enforcement, including the FBI, to craft the suspension policies, and that it intends to also work with police in Europe and elsewhere.
It’s not yet clear how VeriSign would handle a request to suspend a .com domain that was hosting content legal in the US and Europe but illegal in, for example, Saudi Arabia or Uganda.
VeriSign made the request in a Registry Services Evaluation Process (RSEP) document filed today with ICANN. The RSEP is currently the primary mechanism that registries employ when they want to make significant changes to their contracts with ICANN.
The request also separately asks for permission to launch a “malware scanning service”, not dissimilar to the one recently introduced by ICM Registry, manager of the new .xxx extension.
That service would enable VeriSign to scan all .com websites once per quarter for malware and then provide a free “informational only” security report to the registrar responsible for the domain, which would then be able to take re-mediation action. It would be a voluntary service.
Scary thoughts really. However the malware scanning service sounds like something that would help the Internet clean up all the nasty stuff, but then again – do the registrars really care, and would they respond?
Either way, I don’t like the fact that these draconian control laws may be placed on the Internet as we know – that basically allow US law enforcement agencies to take down domains as they please.
What I’m guessing, if this is implemented, it may well become a major target for Social Engineering efforts. What’s more effective than a traditional DDoS attack? Having the domain completely killed by VeriSign – that’s what.
Read More...
-=WELCOME IN MY BLOG=-
13/10/11
VeriSign Demands The Power To Take Down Websites/Domains
06/10/11
NSS Labs offers reward money for fresh exploits
The company has set aside $4,400 for rewards for working exploits for 12 vulnerabilities
NSS Labs is sweetening the pot for its ExploitHub marketplace by offering rewards to security gurus who can write working exploits for a dozen "high-value" vulnerabilities.The company, which has set aside $4,400 in reward money, plans to give $100 to $500 to the first people to submit a working exploit for the vulnerabilities. Ten of the vulnerabilities concern Microsoft's Internet Explorer browser, and two were found in Adobe's Flash multimedia program.
[ The Web browser is your portal to the world -- as well as the conduit that lets in many security threats. InfoWorld's expert contributors show you how to secure your Web browsers in this "Web Browser Security Deep Dive" PDF guide. ]
The exploits must be client-side remote exploits that can result in code execution. Proof-of-concept code and denial-of-service conditions do not qualify. NSS Labs will pay the developer with American Express gift cards. Residents from countries that the U.S. has a standing embargo against are not allowed to participate.
NSS Labs said that those who win can then sell their exploits on ExploitHub, a marketplace the company set up for penetration testers to acquire exploits to test against their infrastructure. ExploitHub was set up to help with the development of penetration testing tools and to assist computer security researchers.
Those who write the winning exploits may then sell their code on ExploitHub, with NSS Labs taking a 30 percent commission. Penetration testers can also make requests via the marketplace for exploits for specific vulnerabilities. Those who want to buy exploits are vetted by NSS Labs to ensure the marketplace is not abused.
ExploitHub also only sells exploits for vulnerabilities that have been patched and does not host ones for zero-day vulnerabilities. The vulnerabilities that NSS Labs is offering the reward for are:
- CVE-2011-1256: Microsoft Internet Explorer CElement Memory Corruption
- CVE-2011-1266: Microsoft Internet Explorer VML vgx.dll Use After Free
- CVE-2011-1261: Microsoft Internet Explorer selection.empty Use After Free
- CVE-2011-1262: Microsoft Internet Explorer Redirect Memory Corruption
- CVE-2011-1963: Microsoft Internet Explorer XSLT Memory Corruption
- CVE-2011-1964: Microsoft Internet Explorer Style Object Memory Corruption
- CVE-2011-0094: Microsoft Internet Explorer CSS Use After Free Memory Corruption
- CVE-2011-0038: Microsoft Internet Explorer 8 IESHIMS.DLL Insecure Library Loading
- CVE-2011-0035: Microsoft Internet Explorer Deleted Data Source Object Memory Corruption
- CVE-2010-3346: Microsoft Internet Explorer HTML Time Element Memory Corruption
- CVE-2011-2110: Adobe Flash Player ActionScript Function Variable Arguments Information
- CVE-2011-0628: Adobe Flash Player Remote Integer Overflow Code Execution
05/10/11
Google shells out $10,000 to fix 10 high-risk Chrome browser flaws
Google has shipped another Chrome browser update with fixes for several “high-risk” security vulnerabilities that expose Windows, Mac OS X and Linux users to malicious hacker attacks.The new Google Chrome version 14.0.835.202 also contains Adobe Flash Player 11, a software update that includes several security and privacy goodies.
As part of its bug bounty program, Google spent about $10,000 to buy the rights to the vulnerability information from security researchers.
Details on the vulnerabilities:
- [$1000] High CVE-2011-2876: Use-after-free in text line box handling. Credit to miaubiz.
- [$1000] High CVE-2011-2877: Stale font in SVG text handling. Credit to miaubiz.
- [$2000] High CVE-2011-2878: Inappropriate cross-origin access to the window prototype. Credit to Sergey Glazunov.
- [96150] High CVE-2011-2879: Lifetime and threading issues in audio node handling. Credit to Google Chrome Security Team (Inferno).
- [$4500] High CVE-2011-2880: Use-after-free in the v8 bindings. Credit to Sergey Glazunov.
- [$1500] High CVE-2011-2881: Memory corruption with v8 hidden objects. Credit to Sergey Glazunov.
- [98089] Critical CVE-2011-3873: Memory corruption in shader translator. Credit to Zhenyao Mo of the Chromium development community.
Mozilla advises Firefox users to disable McAfee plugin
McAfee ScriptScan could cause stability or security problems and is responsible for browser crashes, according to Mozilla
It's the last thing McAfee would want users to hear about one of its products, but the Firefox browser is advising users to disable McAfee's ScriptScan software, saying that it could cause "stability or security problems."SriptScan ships with McAfee's VirusScan antivirus program. It's designed to keep Web surfers safe by scanning for any malicious scripting code that might be running in the browser. But according to Mozilla it has an unintended side-effect: It can cause Firefox to crash... a lot.
[ Get your websites up to speed with HTML5 today using the techniques in InfoWorld's HTML5 Deep Dive PDF how-to report. | Learn how to secure your Web browsers in InfoWorld's "Web Browser Security Deep Dive" PDF guide. ]
In a note posted to its website, Mozilla said that the add-on "causes a high volume of crashes," and is "strongly encouraging" users to disable the software. The warning applies to all users of version 14.4.0 and below of the plugin, Mozilla said.
The Firefox browser started popping up warning messages Monday, advising that users disable the software
In McAfee user forums, there is a smattering of complaints about the Firefox problem.
The problem affects Firefox 7 users, according to Francie Coulter, a McAfee spokeswoman. "McAfee has identified the cause and is working actively with the Firefox team to resolve this issue and expects to roll out an update shortly," she said in an email message.
Read More...
30/09/11
Cisco Patches Slew of IOS Bugs
Cisco has patched a string of serious vulnerabilities in its IOS networking software, including some that could be used for remote code execution, and also fixed flaws in some of its other products. In all, Cisco released 10 advisories, nine of which concerned IOS vulnerabilities.
The most serious of the flaws in IOS, the company's ubiquitous network operating system, is a bug in the way that the Smart Install application works on some Cisco Catalyst switches. The problem can allow an attacker to run arbitrary code on the switch.
"A vulnerability exists in the Smart Install feature of Cisco Catalyst Switches running Cisco IOS Software that could allow an unauthenticated, remote attacker to perform remote code execution on the affected device. Smart Install uses TCP port 4786 for communication. An established TCP connection with a completed TCP three-way handshake is needed to be able to trigger this vulnerability," Cisco said in its advisory.
Several of the other vulnerabilities that Cisco patched in IOS are denial-of-service flaws. IN addition to those problems, there also is a serious issue in the Identity Services Engine, which has a default set of credentials for its underlying database.
"The Cisco ISE contains a set of default credentials for its underlying database. A remote attacker could use those credentials to modify the device configuration and settings or gain complete administrative control of the device," the advisory says.
The full list of Cisco advisories is available on the Cisco security support site.
Read More...
27/09/11
Second LulzSec hacker 'Neuron' could be tracked down via UK VPN
Following the arrest last week of alleged LulzSec member 'Recursion', the Guardian has found that another member of the hacking crew used the HideMyAss service for their connection
Hackers have expressed already dismay after it emerged that that Cody Kretsinger, who was arrested by the FBI last Thursday for allegedly hacking into the Sony Pictures website, had been identified via his use of HideMyAss's proxy service to disguise his IP (internet protocol) address when connecting to the Sony Pictures site.
Kretsinger allegedly went by the online handle "Recursion" – which crops up in chatlogs from the group posted on the Pastebin site. "Recursion" boated of hacking into the Sony Pictures site.
However the Pastebin logs also show that another LulzSec member, using the handle "Neuron", also claimed to use the HideMyAss service. Neuron and Recursion are not the same people: the LulzSec chatlog records posted by the Guardian covering a period from 31 May show the two in the same chatroom at the same time, and on one occasion addressing each other directly. "Recursion" quit the group after it attacked an FBI-related site early in June, but "Neuron" remained.
HideMyAss, posted a lengthy defence of its actions on its blog after the news emerged, insisting that it had to retain logs:
Being able to locate abusive users is imperative for the survival of operating a VPN service, if you can not take action to prevent abuse you risk losing server contracts with the underlying upstream providers that empower your network. Common abuse can be anything from spam to fraud, and more serious cases involve terrorism and child porn.
The main type of logging is session logging – this is simply logging when a customer connects and disconnects from the server, this identifies who was connected to X IP address at X time, this is what we do and all we do. Some providers choose not to do session logging and instead try to locate the abusive customer by using the intelligence from the complaint, for example if someone hacks XYZ.com they may monitor traffic to XYZ.com and log which customers have a connection to this website. Ask yourself this: if a provider claims not to do any form of logging, but is able to locate abusive customers, how are they able to do this without any form of logging?The company added that it would only hand over logs if they were the subject of a valid UK court order: "if a request for information is sent to us from overseas, we will not accept this request unless it is sent through the appropriate UK channels and a UK judge warrants a court order or a court summons that forces us to provide this information. We are not intimidated by the US government as some are claiming. We are simply complying with our countries legal system to avoid being potentially shut down and prosecuted ourselves."
Some questioned whether HideMyAss – which says that it helped people in Egypt to evade crackdowns during the Arab spring protests – would hand over details of individuals to repressive regimes such as Syria. The company says in the blogpost that it would not because "[in] UK law, there isn't a law that prohibits the use of Egyptians gaining access to blocked websites such as Twitter, even if there is one in Egypt."
The revelation that the service retains some log details has caused outrage amid parts of the hacking community, with a number vowing never to use HideMyAss's service again. A rival service, AirVPN, put out a statement saying that it does not keep logs in the way that HideMyAss does: "we would like to reassure our users and our customers that nothing like that [handover of logs] may happen with AirVPN, for a series of legislative (we are based in the EU, not in the USA, and we don't recognize USA jurisdiction, obviously) and above all technical reasons." It says it will accept payments in BitCoin, the cryptocurrency, which can be made via the Tor network, for security.
Four people have been arrested in the UK relating to LulzSec's activities, with three charged so far.
nb : guardian Read More...
Underground Radar: Possible Compromise of MySQL.com and its Subdomains
We recently found an interesting post in a Russian underground forum in the course of our research. People exchange information about their illegal activities in these kinds of forums. We found a user in the forum with the handle ‘sourcec0de’ and ICQ number ’291149′ who is currently offering root access to some of the cluster servers of mysql.com and its subdomains.
![]() |
The screenshot above shows that the seller appears to have a shell console window with root access to these servers. The price for each access starts at $3,000 USD, with the exchange of money/access being provided by the well known garant/escrow system, whereby a trusted third party verifies both sides of the transaction.
In our previous underground research, we have also seen the user ‘sourcec0de’ selling stolen PayPal accounts and discussing the management of botnet command and control servers.
We contacted MySQL.com about this issue last week. We are making this public to stress the fact that hackers do not only profit from selling stolen data or by inserting bad links into spammed or phishing messages, websites and other possible infection vectors . In this case, whether sourcec0de’s claim is true or not, it shows how cybercriminals are so brazen as to sell admin access to specific systems, which could be negatively impacted by their break-ins.
nb : trendmicro Read More...
26/09/11
Secure web browsing cracked by BEAST
The researchers used this week's Ekoparty security conference in Buenos Aires to unveil a new tool that attacks TLS and SSL, the cryptographic protocols used to establish secure web connections.
The ability to crack encrypted web traffic removes the safety net that protects you when you're doing sensitive online tasks like banking or using credit cards.
The tool, known as BEAST (Browser Exploit Against SSL/TLS), compromises TLS by exploiting a vulnerability that has been known about for years but which has been treated as a theoretical problem until now.
However, although researchers Thai Duong and Juliano Rizzo have significantly raised the stakes it's probably too early to start hoarding tins of beans and donning our tin foil hats.Right now the attack can take up to half an hour to execute. Although the researchers have hinted that this can be significantly reduced the fact is that if you have the malicious nature, time and access required to execute this attack then there are probably easier ways to exercise your criminal ambitions.
Even when governments attack weapons manufacturers, they don't need to get any more high-tech then basic con tricks like spear-phishing.
The danger of BEASTly attacks against TLS has moved a little closer but we probably have enough time to react before it becomes practical.
A good start would be for browser and server vendors to pull their collective fingers out and start supporting versions 1.1 and 1.2 of TLS. Both of them have specific defences against this kind of attack but unfortunately support for them is poor.
Duong and Rizzo tipped off the major browser vendors about their findings months ago but so far the only response appears to have come from the folks at Chrome. A fix for the attack is currently under test in the development version of their browser.
If you run a web server and you're concerned you may want to take a look at switching them so that they prefer the rc4-sha cipher. It's widely supported and isn't vulnerable to this kind of attack.
Although the BEAST attack is targeted at browsers there are plenty of other applications that rely on TLS, not least mail servers. Although BEAST isn't targeted at them I'm sure it will have raised eyebrows and their vendors will be taking a keen interest. Keep an eye out for updates and advisories.
If you want to know more about how the attack actually works then I recommend you take a look at nickm's excellent and accessible write-up over at the Tor project.
nb : nakedsecurity.sophos
24/09/11
FBI Snags Lulzsec Member Involved in Sony Hack
The FBI continued its pursuit of members of the hacking group LulzSec on Thursday, arresting a 23 year old Phoenix, Arizona man believed to be part of an online hacking crew that attacked systems belonging to Sony Pictures, the Bureau said in a statement Thursday.The arrest, conducted by agents from the FBI's Los Angeles office arrested Cody Kretsinger of Phoenix Arizona on Thursday. Kretsinger was named in a September 2 federal grand jury indictment and charged with conspiracy and unauthorized impairment of a protected computer for his role in attacks in May and June against computer systems belonging to Sony Pictures Entertainment, according to the statement. Published reports indicate that other arrests took place in Ohio, San Francisco, California, Montana, Minnesota and New Jersey.
Kretsinger, who used the online handle "recursion" is alleged to have carried out SQL injection attacks on Sony's application servers, connecting through a proxy server to mask his Internet Protocol (IP) address.
After compromising Sony's networks, Kertsinger is alleged to have distributed information stolen from Sony and to have publicized the attack on LulzSec's Web site and through its Twitter account.
Sony's network became a target in April, after Lulzsec targeted the company for its legal pursuit of PS3 hacker George Holtz (aka "GeoHot"). The hackers broke into the company's online gaming network, PSN Network. The company's Sony Online Entertainment and Station.com networks were also breached, with data on around 100 million users exposed, all told.
Kretsinger is just the latest in a string of arrests and searches of both high- and low level members of LulzSec and Anonymous. In June, a 19 year old man, Ryan Cleary of Essex, England, was arrested and charged with five counts of violating that country's Computer Misuse Act and Criminal Law Act. Subsequent raids and arrests of members of LulzSec and Anonymous claim to have targeted high ranking members of both LulzSec and Anonymous, including the member known as "Topiary" (allegedly 18 year old Jake Davis of the remote Shetland Islands in the UK) and, more recently, individuals believed to be linked to the online identity "Kayla," a key player in many of LulzSec's most notable hacks.
nb : threatpost Read More...
Arrested LulzSec Supsect Pined for Job at DoD
A 23-year-old Arizona man arrested on Thursday in connection with the hack of Sony Pictures Entertainment last May was a model student who saw himself one day defending networks at the Department of Defense and the National Security Agency.
Wired.com’s Threat Level, the Associated Press, and other news outlets are reporting that Tempe, Ariz. based Cody Andrew Kretsinger is believed to be a member of the LulzSec group, an offshoot of the griefer collective Anonymous. According to the indictment against Kretsinger, he was involved executing and later promoting the high-profile and costly attack on Sony’s networks. Sony estimates that the breaches would cost it more than $170 million this year.
Where do you want to work after graduation?
“I hope that I’ll be able to work for the Department of Defense. From what I hear, they’re pretty good at what I want to do.“
Where do you see yourself in 5 years?
“Traveling, doing Network Security as a profession with the Department of Defense. While I wouldn’t mind being a penetration tester, I think it’s a lot more fun to try to build and secure a network and its devices from the ground up. I suppose I wouldn’t mind being in management, either.”
What’s the ultimate dream for your life?
“Good secure job, great family, maybe a ’64 GTO or something to that effect. I think a job with the NSA or Department of Defense is my ultimate dream.
I hope that I’ll be able to work for the Department of Defense. From what I hear, they’re pretty good at what I want to do.”
Kretsinger may have a difficult time finding work in the public sector. In June, LulzSec claimed responsibility for hacking into computers at the Arizona Department of Public Safety’s computers and releasing hundreds of law enforcement files. The hacking group also claimed to have breached the websites of the CIA and the U.S. Senate.
nb : krebsonsecurity Read More...
23/09/11
'Lurid' malware hits Russia, CIS countries
Trend Micro says more than 1,400 computers in 61 countries were targeted
The latest espionage-related hacking campaign detailed by security vendor Trend Micro is most notable for the country it does not implicate: China.Researchers from Trend wrote on Thursday that they discovered a series of hacking attacks targeting space-related government agencies, diplomatic missions, research institutions and companies located mostly in Russia but also Vietnam and Commonwealth of Independent States countries. In total, the attacks targeted 1,465 computers in 61 countries.
[ Also on InfoWorld: Security failures could erode public trust in the Internet.| Learn how to greatly reduce the threat of malicious attacks with InfoWorld's Insider Threat Deep Dive PDF special report. ]
The attacks, which Trend dubbed "Lurid," are not particularly unusual compared to other stealthy, long-range hacking campaigns publicized recently, said Rik Ferguson, director of security research and communication for Europe. Targeted e-mails were sent to employees that were engineered to attack unpatched software and sought to steal spreadsheets, Word documents and other information.
Those pilfered documents were then uploaded to Web sites hosted on command-and-control servers in the U.S and the U.K. Ferguson said. The location of the servers in these attacks shows that hackers can choose servers anywhere in the world to collect stolen information, which is not an indication of where the hackers may be located, he said.
China has endured frequent accusations that it is complicit in hacking since many high-profile attacks have originated from infrastructure within the country. But Ferguson said there are many tools ranging from VPNs (Virtual Private Networks) to e-mail spoofing techniques that can mislead hacking investigations.
"What do we do now?" Ferguson asked. "Point the finger at the U.S. and U.K.?"
Trend classified the Lurid attacks as an "advanced persistent threat" or APT, a relatively new term applied to hacking campaigns that endure for long periods of time undetected. Lurid has been active since at least August 2010.
Lurid uses a downloader program known as "Enfal" to steal documents. The downloader has been around since at least 2006, although it is not known to be sold on underground criminal forums, Ferguson said.
The e-mails sent to victims contained an attached file that looked for vulnerabilities in software on the computer. This particular series of attacks often exploited a vulnerability in Adobe Reader that dates back to 2009, Ferguson said. If the companies or organizations have not patched their software, they may be vulnerable: Security experts generally recommend patching as soon as a fix has been released.
Trend found that the hackers also assigned a special code to individual pieces of malware in order to identity their victims. Although the Lurid attacks touched on many organizations, most of the attacks were targeted at just three.
Ferguson said Trend identified 301 different campaign codes, with 115 campaigns focused on just one victim and 64 others hitting just two more organizations.
The information exfiltrated from compromised computers was sent encrypted to the command-and-control servers via HTTP POST requests. Since the stolen information was encrypted and appeared to be normal Web traffic, it can be difficult for organizations to detect that they may have been compromised, he said.
Ferguson said Trend had contacted Computer Emergency Response Teams in the affected countries and is also working with the U.K.'s Serious Organised Crime Agency, which includes hacking as part of its remit.
nb : infoworld Read More...
Alleged LulzSec Sony hacker arrested
The 23-year-old Phoenix student is accused of using SQL injection to break into Sony Pictures' database
The U.S. Federal Bureau of Investigation has arrested a Phoenix student, claiming that he is one of the LulzSec hackers responsible for a database attack on Sony Pictures computers that claimed more than 1 million victims.Cody Kretsinger, 23, was arrested Thursday morning on hacking and conspiracy charges. Prosecutors say he was "Recursion," an LulzSec hacker who used a database attack technique called SQL injection to break into Sony Pictures systems. Kretsinger allegedly provided data that was used in a mammoth June 2, 2011, data dump by LulzSec that included coupon codes along with email addresses and passwords belonging to Sony customers.
[ Get your websites up to speed with HTML5 today using the techniques in InfoWorld's HTML5 Deep Dive PDF how-to report. | Learn how to secure your Web browsers in InfoWorld's "Web Browser Security Deep Dive" PDF guide. ]
At the time that LulzSec posted its data, Sony was already recovering from a devastating break-in to its PlayStation Network. That intrusion knocked the service offline for more than two months and cost the company an estimated ¥14 billion ($183 million) to clean up.
"The extent of damage caused by the compromise at Sony Pictures is under investigation," the FBI said Thursday in a statement.
Sony's heavy-handed response to the release of "jailbreak" code for its PS3 console, which could be used to run unauthorized software on the device, had made the company the enemy of hackers everywhere, and the LulzSec hackers were not the only ones to go after the company's computer systems.
LulzSec had a brief run of Internet mayhem earlier this year, breaking into websites belonging to corporations and law enforcement agencies and then posting the data publicly with gleeful disregard to any consequences.
Since then, the group seems to have been largely rounded up by law enforcement in a series of arrests in the U.S. and U.K.
Kretsinger allegedly covered his tracks by using the Hidemyass.com proxy service and wiping his computer hard drive after the attack. He faces 15 years in prison if convicted.
Separately, the FBI also announced the arrest of two alleged members of the Peoples Liberation Front, a group that claimed credit for a 30-minute long 2010 distributed denial of service attack against Santa Cruz County, California. Like LulzSec, Peoples Liberation has affiliated itself with the Anonymous hacking movement.
Christopher Doyon and Joshua Covelli are both facing hacking charges in the case. Covelli had previously been charged in connection with an Anonymous-sponsored December 2010 attack on Paypal.com.
nb : infoworld Read More...
FBI arrests Sony LulzSec hacking suspect
A federal grand jury indictment charges Cody Kretsinger, 23, with conspiracy and the unauthorised impairment of a protected computer in connection with the attack in May and June.
Kretsinger is alleged to have used the online name, or handle, of "recursion" as part of the hacking crew.
LulzSec, an underground group also known as Lulz Security, at the time published the names, birth dates, addresses, emails, phone numbers and passwords of thousands of people who had entered contests promoted by Sony.
"From a single injection we accessed EVERYTHING," the hacking group said in a statement at the time. "Why do you put such faith in a company that allows itself to become open to these simple attacks?"
Hackers previously had accessed personal information on 77m PlayStation Network and Qriocity accounts, 90% of which belonged to users in North America and Europe, in what was then the biggest such security breach in history.
The nine-page indictment said Kretsinger and co-conspirators obtained confidential information from Sony Pictures' computer systems using an "SQL injection" attack against its website, a technique commonly used by hackers to exploit vulnerabilities and steal information.
The indictment said that Kretsinger, as "recursion", helped post information he and his co-conspirators stole from Sony on LulzSec's website and announced the intrusion via the hacking group's Twitter account.
The extent of damage caused by the breach of the studio's computer network remained under investigation, the FBI said.
Chat logs obtained by the Guardian reveal that two members of LulzSec, "recursion" and "devrandom", decided to leave the group after 3 June after it attacked an FBI-affiliated site.
There have been four arrests in the UK of people alleged to be associated with LulzSec. Trials of three of them are expected to begin in 2012.
LulzSec, an underground group also known as Lulz Security, at the time published the names, birth dates, addresses, emails, phone numbers and passwords of thousands of people who had entered contests promoted by Sony.
"From a single injection we accessed EVERYTHING," the hacking group said in a statement at the time. "Why do you put such faith in a company that allows itself to become open to these simple attacks."
Hackers previously had accessed personal information on 77m PlayStation Network and Qriocity accounts, 90% of which belonged to users in North America and Europe, in what was then the biggest such security breach in history.
Other high-profile companies targeted by cyber attacks included Lockheed Martin and Google.
Sony officials did not comment on Thursday's arrest.
LulzSec is reputed to be affiliated with the international hackers collective called Anonymous, which has claimed responsibility for cyber attacks on government and private institutions around the world.
Kretsinger faces a maximum sentence of 15 years in prison if convicted. The government is trying to extradite him to Los Angeles, where Sony Pictures' computer system is located and where the case against him has been filed.
nb : guardian
Homeless hacker arrested by FBI in LulzSec/Anonymous investigation
According to media reports, the FBI has arrested two alleged hackers in San Francisco and Phoenix, believed to be associated with the LulzSec and Anonymous hacktivist groups.And one of them is homeless.
FoxNews reports that search warrants have also been executed in the states of Minnesota, Montana and New Jersey as part of a wider FBI investigation into the groups who have launched attacks against government websites as well as corporations such as Sony.
23-year-old Cody Kretsinger, from Phoenix, Arizona, has been charged with computer offences, and is alleged to be the LulzSec member known as "Recursion". Kretsinger is accused of being involved in an SQL injection attack that stole information from Sony Pictures in June, exposing users email addresses and passwords.
According to the indictment against Kretsinger, he is accused of using the hidemyass.com proxy service to cloak probes he made of Sony Pictures' computer systems in May 2011, hunting for vulnerabilities.
Approximately 150,000 confidential records were subsequently published online by LulzSec who criticised Sony's weak security.Authorities allege that Kretsinger wiped the hard drives used to carry out the attack on Sony in an attempt to hide forensic evidence.
"Recursion" is one of many handles used by members of the LulzSec hacking gang, and features in internet chat logs that have previously published of the group having what they believed to be private conversations.

Meanwhile, the FBI arrested an alleged Anonymous member in San Francisco. The man, who is reported to be homeless, is said to have been involved in internet attacks against Santa Cruz County government websites.
Just because a man is homeless, of course, doesn't mean that he can't get an internet connection. Coffee houses, cafes, libraries, etc can all offer cheap or free internet access - and because the computer being used can be a shared device, it may be harder to identify who might have been responsible for an attack compared to a PC at a home.
At the same time, public places are often watched with CCTV cameras which means that if the authorities were able to identify a time and place, they may also be able to gather evidence as to who was at the location when an attack was begun from a particular computer.
Both LulzSec and the larger Anonymous hacktivist collective have had a tough time of late, with a series of arrests in the USA, UK and elsewhere around the globe.
Wannabe hackers might be wise to read the FBI's press release about the Kretsinger arrest, which points out that if convicted of the hacking offences he could face up to 15 years in prison.
nb : nakedsecurity.sophos
Gleeonsky - first UK Promoted Tweets exploited by spammers
Surprise surprise. Within minutes of Twitter announcing that UK brands can now target British Twitter users with promoted tweets and trends, spammers are also jumping on the bandwagon.Twitter UK says that Sky is using its entire suite of promoted products to advertise that the TV show "Glee" returns to British TV screens tonight.
To increase awareness, Sky is using the twitter account @gleeonsky and paying for the hashtag #gleeonsky to be promoted to British Twitter users.
Of course, they're not the only ones taking advantage of the hashtag. Spammers are using it too.

I suspect that when Sky paid for the #gleeonsky hashtag to be promoted on Twitter, this isn't the kind of response they were hoping for. They wanted people to watch the TV show on Sky tonight, not to go hunting for hot photographs of Natalie Portman, Jessica Alba, Selena Gomez and others..
These aren't mischievous Twitter users, these are spam accounts set up specifically for the purposes of blurting out a message using a popular hashtag. In this case, #gleeonsky.
The spammers don't care that their accounts get reported and shut down by Twitter security, because they just create another one. And remember, they don't have to do this by hand - the whole process can be automated.
The danger is that unsuspecting users curious about a hot trend like the promoted #gleeonsky might click on one of the dodgy links above.
By the way, if they do click, Twitter users may find that they are taken to a website like this:

Of course, the spammers can choose to redirect you to any webpage they like once you have clicked on the link. It could be a phishing site designed to steal your Twitter credentials, it could be a fake pharmacy, it could be a porn site or it could be a website harbouring malware.
Exploiting trending Twitter hashtags is nothing new. But as the company's business model relies more and more heavily upon convincing companies to pay big money to promote their brands in this way, there will be more pressure on Twitter to police abuse on their site and clean-up offending tweets.
nb : nakedsecurity.sophos
22/09/11
Researchers claim to have broken SSL/TLS encryption
The researchers, Thai Duong and Juliano Rizzo, are due to demonstrate their Browser Exploit Against SSL/TLS (Beast) at the Ekoparty security conference on Friday 23 September.
News of the Beast ahead of the demonstration has created a stir in the security community, according to Help Net Security.
The latest two versions (1.1 and 1.2) of the TLS cryptographic protocol are reportedly invulnerable to the exploit, but the majority of websites, VPNs and instant messaging services in operation use the vulnerable version 1.0 because of its compatibility with the widest range of other web technologies.
Beast consists of JavaScript code that works with a network sniffer to decrypt the cookies that carry user credentials to access accounts.
Unlike most published attacks against https that focus on the authenticity property of SSL, Beast attacks the confidentiality of the protocol, Duong told The Register.
Duong and Rizzo claim that Beast implements the first attack that actually decrypts https requests.
The researchers claim they have been working with browser and SSL suppliers since May, but every fix proposed so far has proved to be incompatible with some existing SSL applications.
Philip Hoyer, director of Strategy Solutions at ActivIdentity, said if the claims are true, authentication should be done as an ever-changing and one-time password, so even if the attacker sees a password, it always changes and hence cannot be guessed for the next authentication.
This can be achieved by many techniques, he said, both using one-time password (OTP) technology and public key infrastructure (PKI) using a challenge response.
"But this won't help to a level that is needed since the attacker can then simply read and hijack your session. So the only true defence from fraudulent transactions is to sign the transaction or part of the transaction data so that the attacker cannot inject bogus material," said Hoyer.
This means effectively using a token with a pin pad to enter transaction details or signing the transaction using a PKI certificate.
"This allows a cryptographic signature that the attacker can't forge and is intrinsically linked to the transaction data that is independent from the transport security and cannot be forged by the spying attacker," he said.
Hoyer believes this is the only way to stay secure until the infrastructure has been upgraded from TLS V1.0.
nb : computerweekly
Should you trust this 'BBC' news report? Work from home scam spammed out
Your friends? Lady Gaga? The media? How about the BBC?
If you read a news story on the BBC website, would you trust what it was saying?
A Naked Security reader forwarded us this interesting email which (fortunately) had been quarantined by his anti-spam defences. What's particularly interesting is the webpage to which it links.

If you were tempted to click on the link are taken to a website which looks like this.

A pretty convincing replica of the BBC website. But, of course, it's not the real BBC News website at www.bbc.co.uk/news, but instead a page that is copying the popular site's graphics and style.
The URL in the address bar might be a giveaway, if you were watching carefully enough.

And see how it refers to a housewife in Abingdon - that's because I was in Abingdon, just outside Oxford, UK, when I visited the webpage. The site has tailored its content to appear more compelling to me by determining where in the world I am.
If I had visited from Bhutan, Botswana or Bognor I would have been told the single mother lived in those places instead.
The purpose of the spam campaign, and the bogus BBC website, is to try to convince you to sign up for a working from home scheme.

As they're using subterfuge to promote their scheme - my advice would be to keep your distance.
nb : nakedsecurity.sophos
21/09/11
Spamvertised 'We are going to sue you' emails lead to malware

Security researchers from WebSense have intercepted a currently active and circulating malicious spam campaign.
The spamvertised emails contain subjects and messages attempting to socially engineer users into thinking that spam is coming from their mailboxes, and that they face legal action:
In this campaign, emails are spoofed to appear as though they are sent from established companies. The emails even formally claims that legal action will be taken because of the spam you have sent. These emails with the fake warning even attach a ZIP file that contains a scanned copy of a document that is supposed evidence of your spam.-Spamvertised subjects include:
- We will be impelled to sue you
- We are going to sue you
- We are suing you
- You are sending add messages
- A message from our security service
Hello. Your email is sending spam messages. If you don’t stop sending spam, we will be impelled to sue you! We’ve attached a scanned copy of the document assembled by our security service to this letter. Please care carefully read through the document and stop sending spam messages. This is the final warning.-Detection rate for the spamvertised malware.
Users are advised not to interact with suspicious emails, or spam emails in general.
nb : zdnet Read More...
Malicious spam campaigns proliferating

With spam continuing to represent the distribution vector of choice for the majority of cybercriminals, it shouldn’t be surprising that the volume of malicious spam campaigns is proliferating.
In a recent blog post, researchers from Commtouch have summarized their observation status on the malicious spam campaigns from last month, namely, UPS/FedEx, Map of love and Hotel charge error and pointed out that someone is actively building crimeware-friendly botnets:
“Pre-outbreak levels varied between a few hundred million emails to around 2 billion per day. The peak outbreak included distribution of nearly 25 billion emails with attached malware in one day.”Malware campaigns have cyclical pattern of distribution, namely, cybercriminals constantly rotate and introduce new topics, once the lifecycle of the previous campaign have reached the maturity stage. Meanwhile, users continue interacting with spam emails, clicking on links, downloading attachments and unsubscribing themselves, prompting the success of spam in general.
Now, that the cybercriminals have set up the foundations for their botnet aggregation practices by spamvertising billions of emails, it’s worth keeping an eye on the actual response rate of the command and control servers used in the campaigns in order to roughly estimate the damage caused by the campaigns.
nb : zdnet
20/09/11
Banker – the other way around
There are many techniques used by malware in the banker family to steal user’s authentication credentials for online banking sites. We came across an interesting sample recently, detected as Trojan:Win32/Banload.A, which uses a remote proxy script in order to target online banking sites and facilitate data theft.
When Trojan:Win32/Banload.A is executed, it opens an Internet browser to a certain animation site to trick the user into thinking that it’s nothing but an animation file:

However, the cute animation masks the main objective of this trojan, which is to modify the web browser settings to use a Proxy Automatic Configuration script… And once set, that’s it! Mission accomplished! This malware’s job is done, for now…

By using a proxy configuration script, the trojan sets the user’s Internet connection to be routed through a proxy server.
Affected users should note that in the case of Trojan:Win32/Banload.A, because it makes changes to the proxy settings, removing the malware will not be enough to fix an affected computer and return it to a pre-compromised state. The configuration settings will need to be fixed manually. Without changing these settings, while the remote script remains available, the affected computer will still be utilizing it. The script effectively moderates the affected user’s Internet use – possibly providing false information and redirecting the user away from sites of their choice to sites of the attacker’s choice – with the affected user being none the wiser.
MMPC downloaded the Proxy Script from the URL (shown in the above graphic) and found it to be malicious; we detect it as TrojanProxy:JS/Banker.B. It contains code that monitors for online banking sites visited by the affected user, and redirects traffic to a proxy server that could result in the theft of authentication credentials or other sensitive information.
In order to change these proxy settings:
1. In Internet Explorer, click the Tools menu, and then click Internet Options.
2. Click the Connections tab, and then click LAN Settings.
3. In the Automatic configuration area, de-select Use automatic configuration script.
4. Click OK.
For more information about using automatic proxy configuration, see the following articles:
- http://technet.microsoft.com/en-us/library/dd361918.aspx
- http://support.microsoft.com/kb/135982
- http://support.microsoft.com/kb/819961
SHA1s:
C3D1E6E68CC5241F92F22C07F120487C0AFB03D4
c93c7823c5ba4fe39a91964c8db08f413262719e
0525cbdce83410586a7707c10aea49e87c3f8a19
nb : technet Read More...
![[+]d'ZheNwaY's Blog[+]](http://feeds.feedburner.com/blogspot/YRtWp.1.gif)



