hacking news

Report: China Likely Hacked US Satellites

Hackers who hit two US satellites four times in 2007 and 2008 may have been tied to the Chinese military, reports Bloomberg. “Such interference poses numerous potential threats, particularly if achieved against satellites with more sensitive functions,” says a draft of the annual report by the US-China Economic and Security Review Commission. The report, which says one attack "achieved all steps required to command the satellite,” stops short of directly accusing China of making the attacks, but says they were "consistent" with Chinese military policy. The report does not give many details about the hacking, but says that China “conducted and supported a range of malicious cyber activities” over the past year. China strongly denies the assertions. China “never does anything that endangers other countries’ security interests," says a spokesman from the Chinese embassy in Washington, accusing the commission of “collecting unproved stories to serve its purpose of vilifying China’s international image over the years."

Hacking Hackers and the Hacks they Hack

Wow, it’s true. If you type a word often enough, it starts to lose its meaning. But before I start to use the word hack as a koan in a meditation session, I thought it would be a good idea to do a quick news roundup of some hacking stories. Not all hacks are created equal the use of the words hack, hackers and hacking can sometimes be misleading.
First, there’s the turmoil in the United Kingdom over scandals at News Corp. The story centers on phone hacking — but what does that actually mean? In my opinion, calling it hacking is misleading. What happened was that reporters or private investigators working for reporters illegally accessed voicemails belonging to other people. Those people may have included politicians, celebrities, athletes and crime victims, among others. It’s actually pretty simple — to access your voicemail from a remote phone, you need to enter a PIN. In the past, most carriers would assign a generic PIN to customers. Since customers usually access voicemail on their own phones, they never needed to use or change the PIN. That meant anyone else could access the voicemail remotely and just use the default PIN to get in.
It’s illegal to access someone else’s voicemail that way in the UK but it’s not really hacking. If someone walked up to your computer and accessed it because you hadn’t changed the default password — or you had disabled passwords entirely — you wouldn’t call it hacking. But the word does serve as useful shorthand. The best way to protect yourself against a similar attack is to change any default PINs to something unique.
There’s also news about News Corp. reporters allegedly bribing police to get cell phone tracking data in order to locate and follow people. Again, that’s not actually hacking, though it might fall under the category of social engineering. It’s definitely bad news. The scandal at News Corp. is ongoing and we’re not really sure how much fallout there will be.
Meanwhile, Reddit co-founder Aaron Swartz was arrested in Boston under charges that he stole around four million documents from MIT and JSTOR. Massachusetts District Attorney Carmen M. Ortiz has filed the charges, which could see Swartz slapped with a million-dollar fine and up to 35 years in prison. According to Ortiz, Swartz broke into a secured area of MIT and accessed the documents from a wiring closet. This is definitely closer to my idea of hacking than the News Corp. story, though usually I imagine hackers trying to access secret corporate documents or military files, not scientific journals.
Across the United States, law enforcement officers have arrested 14 people the FBI claims are connected to the group Anonymous. The arrests follow raids on the suspects’ homes. It looks like these suspects aren’t directly connected to LulzSec, the anti-security hacker group that seemed to split off — and later rejoin — Anonymous. Instead, these members may have used their computers to participate in direct denial of service (DDoS) attacks against targets like credit card companies during various Anonymous operations.
Speaking of LulzSec, the group recently claimed responsibility for a hack of British tabloid The Sun’s web site. Readers visiting the site were redirected to a fake article that said Rupert Murdoch, founder of News Corp., had died. The attack appears to be in response to the scandal over at Murdoch’s company. I think a web site redirect falls into hacking territory. And the story really brings us full circle, which as a writer I appreciate.

Storm worm: More powerful than Blue Gene?

Criminals behind the Storm worm have created a botnet containing millions of PCs, which have a combined computing power greater than the most powerful supercomputer in existence. The Storm worm botnet has been estimated to control between one million and five million computers, which one researcher says makes it more powerful than IBM’s Blue Gene/L supercomputer. Peter Guttman, a computer sciences security researcher, wrote in an email posted on insecure.org’s website: “This may be the first time that a top 10 supercomputer has been controlled not by a government or mega-corporation but by criminals. The question remains, now that they have the world’s most powerful supercomputer system at their disposal, what are they going to do with it?”

At the lowest estimate of one million computers, Guttman roughly calculated that using an army of 2.8GHz P4s, the group behind the Storm worm would have at least one petabyte of RAM, compared with Blue Gene/L’s “paltry 32 terabytes”.
Guttman listed 10 supercomputers, comparing the total number of PCs required to achieve equivalent RAM. He estimated 128,000 PCs would be required to match Blue Gene/L while, at the lower end, 10,000 PCs would be needed to match MareNostrum.
Is it comparable?
However, debate rages as to whether a million-strong cluster of computers is the same as a supercomputer.
IBRS security analyst James Turner said that comparing a botnet and a supercomputer is like comparing an army of snipers with a nuclear weapon.
“It takes more than a pile of CPUs and RAM to make a super computer‌ Any supercomputer like Blue Gene has millions of dollars of R&D, tweaked I/O and an optimised operating system. In all, it’s a system with substantial differences to a botnet,” he said.
However, Turner said that should the Storm owners want to start breaking encryption codes, they could do it in a similar fashion to the Search for Extraterrestrial Intelligence project, or SETI@home.
SETI@home uses a distributed network of computers to decipher signals from an array of radio telescopes, which listen for signals from outer space.
The SETI@home network, at the time of writing, consists of 158,000 active users, utilizing 1.5 million active hosts in over 200 countries.
Bradley Anstis, director of product management at security firm Marshal, believes the botnet at the Storm gang’s disposal is likely to be closer to five million strong.
“The SETI@home network is quite different because the owner has full knowledge of any use of their computer. When you start using your computer, its network will back off. This worm, however, seems to be working in the background so it doesn’t take all resources, so the average computer user does not notice,” said Antsis.
“It has a very high number of distributed nodes, so it can scale faster and a lot larger than any supercomputer. It’s certainly a lot of faster than for Cray to bring out its latest supercomputer,” he said.
Paul Ducklin, head of technology at Sophos said a supercomputer differs drastically due to how CPU nodes are interconnected and the speed at which data can be pushed from one node to another.
“They [the Storm gang] don’t need a ‘supercomputer’,” said Ducklin. “They just need a wide range of different computers to do their dirty work. It’s not so much about CPU, and RAM, and disk space. It’s about being able to operate from a widely distributed and ever-moving target. Slim down the target and it becomes much easier to hit.”
Besides CPU and RAM, Marshal’s Anstis said: “The more worrying thing is bandwidth. Just calculate four million times a standard ADSL connection. That’s a lot of bandwidth. It’s quite worrying. Having resources like that at their disposal — distributed around the world with a high presence and in a lot of countries — means they can deliver very effective distributed attacks against hosts.”

Russian US Consulate hacked

IT security and control firm Sophos has reported on its blog that webpages of the US Consulate General in St.Petersburg, Russia, were attacked by hackers earlier this week. The infected pages have since been cleaned up. The attack was part of a larger campaign by cybercriminals in which vulnerable web servers were targeted. This resulted in more than 400 webpages around the world being infected over the last week, with the majority of the compromised pages hosted in Russia.

“Unfortunately, while high profile sites such as the US Consulate can be cleaned up quickly, we are seeing a dangerous number of companies that are failing to act responsibly to retain the sanctity of their sites,” said Fraser Howard, principal virus researcher at Sophos.

Year-old QuickTime bug Exploits Firefox

A year-old bug in QuickTime that, when paired with Firefox, allows hackers to hijack PCs and Macs now has Mozilla Corp. scrambling for a fix, the company’s chief security officer said yesterday.According to Petko Petkov, a U.K.-based Web application penetration tester, the current version of QuickTime contains a flaw in its Media Link (.qtl file formats) function. Any file with a QuickTime-supported extension — there are more than 60 — will be parsed by Apple Inc.’s media player. However, because it fails to sanitize the XML content, an attack can sneak links to malicious JavaScript into the file and get QuickTime to run it.

“In practice, I can do anything with the browser — like installing browser back doors — and the operating system if the victim is running with administrative privileges,” Petkov said in the write-up he posted Wednesday. He said he first disclosed the vulnerability, as well as a second one in QuickTime, in September 2006. When he didn’t hear from Apple, he did so again in December.
Although some security companies, including eEye Digital Security Inc., called out the open-source Firefox browser as a requirement for a successful exploit, Petkov noted that the bug is in QuickTime and affects users of other browsers, including Microsoft Corp.’s Internet Explorer. “It is not Firefox-specific,” he wrote on his blog. “It works for IE as well, although the impact is less critical. This is due to the tightened security policies IE implements for local zone scripts.”
Others who left comments on Petkov’s post, however, made a wide range of claims. Some, for instance, reported that the proof-of-concept samples that Petkov offered up failed on Windows XP SP2 when running Opera, while others said Firefox on Mac OS X is also invulnerable to the hacks.
Mozilla’s security chief, Window Snyder, said her team is on the case. “Mozilla is working with Apple to keep our users safe, and we are also investigating ways to mitigate this more broadly in Firefox,” she said yesterday on the company’s security blog.
She did not downplay the danger, calling it a “very serious issue,” and warned users that Petkov’s proof code “may be easily converted into an exploit.”

Apple warns iPhone hackers

Apple sent out a thinly veiled threat on Monday evening, warning iPhone owners that have hacked their devices to expect them to turn into fancy bricks. Earlier this month, a number of hacker groups unleashed their wares upon the iPhone fan base, selling, and in some cases giving away, tools to unlock the device from its designated carrier.

Naturally, Apple set the lawyers on the hackers but so far we’ve heard of nothing more than a few threatening letters being sent out. Meanwhile, eBay has been doing a roaring trade in iPhones, as consumers around the world snap up devices released in the US and then unlock them to use on their local network.
But Monday’s warning had a sinister tone to it. “Apple has discovered that many of the unauthorised iPhone unlocking programs available on the internet cause irreparable damage to the iPhone’s software, which will likely result in the modified iPhone becoming permanently inoperable when a future Apple-supplied iPhone software update is installed,” the statement read.
The hackers have yet to respond but there is some scepticism over Apple’s statement. The majority of the unlocking tools simply modify the device firmware to ignore the SIM lock, allowing the phone to operate as intended. But it sounds like Apple is saying a future software update will check to see if the firmware has been modified and kill the phone if it has.
“Apple plans to release the next iPhone software update, containing many new features including the iTunes Wi-Fi Music Store, later this week,” the company said.

Online scam crackdown nets worldwide arrests

An international crackdown on internet financial scams this year has yielded more than $2.1bn (ÂŁ1bn) in seized fake cheques and 77 arrests in the Netherlands, Nigeria and Canada, US and other authorities said on Wednesday. The scammers use ploys such as “spam” email offering to pay recipients “processing fees” for depositing cheques, which later turn out to be fake, and sending the ostensible proceeds to the scammer, authorities said.

In the US, the ruses are aided by financial practices that quickly credit a bank customer for deposits even though it can take far longer to discover a fake cheque and reclaim the money from the customer. The victims find themselves out the money they forward when the cheques prove to be fake.
“Most Americans don’t realise they are financially liable when they fall for these scams,” Susan Grant, vice president of the National Consumers League, said at a news conference to publicise the arrests and promote awareness of the frauds.
The crackdown led to16 arrests in Nigeria, 60 in the Netherlands and one in Canada, said Greg Campbell, US Postal Inspection Service inspector in charge of global security.
“We shut down internet cafes, we arrested scammers, and significantly disrupted the flow of fake cheques into the US,” Campbell said.
Law enforcement in England also took part. Nigeria is a recognised hotbed for the financial frauds and the other countries have significant West African populations that include fraud operators, authorities said.
Three suspects from the Netherlands and Nigeria were extradited to New York and are awaiting trial, said US assistant attorney general Alice Fischer. The US is seeking to extradite five others.
The US is a major draw for the scammers. But other English-speaking countries are also targeted, in part because of the widespread use of English on the internet and because of Nigeria’s large English-speaking population, Campbell said.
Nigeria has brought to court 290 cases of suspected fraud, and the prosecutions have been successful in 115 of the cases so far, said Ibrahim Lamorde, head of Nigeria’s Economic and Financial Crimes Commission.
He said Nigeria is doing its best to stamp out the fake cheque operations. It has seized counterfeiting equipment and convened meetings of anti-fraud officials from across Africa. But he acknowledged Nigeria has an image problem.
“The first country that comes to mind is Nigeria,” Lamorde said.
Two-thirds of Americans said they received at least one potential scam contact per week, and 18 percent said they or a family member had fallen for one, in a survey conducted for an alliance of banks, consumer groups and the US Postal Service.
Grant said complaints to her group about fake cheques have risen 60 percent this year, and the average victim loses about $3,000 (ÂŁ1,500) to $4,000.
Some US banks have changed their practices, for example, by training tellers to better inform depositors about risks, Grant said. She called for regulations mandating that bank customers be given clearer information.
Offers can also come in direct mail. Fisher showed handwritten envelopes directed to her at a Justice Department address.
Inside were $850 cheques with a Wal-Mart logo, with letters offering her a 10 percent cut if she would cash the cheques and send the money back. “After you laugh and think how silly it is… this shows [the problem] is just completely rampant,” she said.

Apple patches QuickTime for Windows flaw

Apple released a security update for its QuickTime media player on Wednesday, patching a flaw that allows remote users to execute arbitrary code onto Windows PCs. Security Update for QuickTime 7.2 for Windows patches the flaw on PCs running Vista and XP operating systems. An attacker can take advantage of the flaw on unpatched machines by enticing the user to view a specially crafted QTL file, which can lead to arbitrary code execution.

The vulnerability exists in QuickTime’s handling of URLs in the qtnext field of QTL files. The issue, which does not affect computers running Apple’s Mac OS X operating system, is fixed through improved handling of URLs, according to Apple’s advisory.
In September, Mozilla patched a QuickTime flaw in Firefox that had been disclosed by researcher Petko Petkov earlier that month.
Petkov explained that such files can contain malicious code, executable on remote machines.
“To sum up, QTL files can contain malicious JavaScript code that can take over some important network device when executed,” he said.
Amol Sarwate, director of the vulnerability research lab at Qualys, said that attacks via media files are becoming more common.
“QuickTime and many of the media players today are embedded in many websites, so if you visit, they have animations, clips and music. So it affects not just home users, but corporate users as well,” he said. “This is part of the trend of new media type of attacks, meaning vulnerabilities or attacks that come via videos or music files. These new attacks make use of social engineering or social networking websites.”

Israel suspected of ‘hacking’ Syrian air defences

Questions are mounting over how Israeli planes were able to sneak past Syria’s defences and bomb a “strategic target” in the country last month. Israeli F-15s and F-16s bombed a military construction site on 6 September. Earlier reports of the attack were confirmed this week when Israeli Army radio said Israeli planes had attacked a military target “deep inside Syria”, quoting the military censor.

Syrian President Bashar al-Assad said it reserved the right to retaliate when he took the unusual step of offering interviews to Western media.
Syria and Israel have remained formally at war since the Arab-Israeli war of 1967, during which Israeli forces seized the Golan Heights.
The motives for the strike, much less what was hit and what damage was caused, remain unclear. One theory is that a fledgling nuclear research centre, the fruits of alleged collaboration between Syria and North Korea, may have been hit. Others speculate that a store of arms shipments bound for the Lebanese militant group Hezbollah might have been targeted. A test against Syria’s air defences has also being suggested in some quarters. None of these theories appear to be much better than educated guesswork.
Bombers carrying out the raid are believed to have entered Syrian airspace from the Mediterranean Sea. Unmarked fuel drop tanks were later found on Turkish soil near the Syrian border, providing evidence of a possible escape route. Witnesses said the Israeli jets were engaged by Syrian air defences in Tall al-Abyad, near the border with Turkey.
This location is deep within Turkey, prompting questions about how the fighters avoided detection until so long into their mission. Neither F-15s nor F-16s used by the Israeli air force in the raids are fitted with stealth technology.
Flying under the radar is a dangerous tactic, no longer favoured since a number of British fighters went down during the first Gulf War over the liberation of Kuwait. That leaves the possibility that jamming techniques, or some even more sophisticated electronic warfare tactic, was brought into play.
Aviation Week reckons the success of the attack might be down to use of the “Suter” airborne network attack system. The technology, was developed by BAE Systems and integrated into US unmanned aircraft by L-3 Communications, according to unnamed US aerospace industry and retired military officials questioned by Aviation Week.
Instead of jamming radar signals, Suter uses a more sophisticated approach of “hacking” into enemy defences.
“The technology allows users to invade communications networks, see what enemy sensors see, and even take over as systems administrator so sensors can be manipulated into positions so that approaching aircraft can’t be seen,” Aviation Week explains. “The process involves locating enemy emitters with great precision and then directing data streams into them that can include false targets and misleading message algorithms.”
Suter is said to have being “tested operationally” in Iraq and Afghanistan over the last year, according to Aviation Week. Syria reportedly recently bought two state-of-the art radar systems from Russia, reckoned to be Tor-M1 launchers that carry a payload of eight missiles, as well as two Pachora-2A systems. Iran recently bought 29 of these Tor launchers from Russia for $750m in order to defend its nuclear sites.
The apparent failure of these systems in detecting and responding to the Israeli raid therefore poses questions for arms manufacturers and armies all the way from Damascus to Moscow and over to Tehran.

Spammers hit YouTube’s email servers

Spammers are using YouTube’s servers to send massive quantities of unsolicited email, according to security firm Marshal.

The company has warned email users to be wary of messages carrying YouTube invites which appear to derive from the video-sharing site’s ‘Invite Your Friends’ feature, claiming the compromised servers are sending out spam messages from the service@youtube.com address.
“YouTube users have a facility where they can invite their friends to view videos that they are looking at or have posted. This effectively allows them to email to any address from their YouTube account. This is the functionality that the spammers are exploiting,” said Bradley Anstis, Marshal’s director of product management.
Marshal said the emails have the same appearance as a legitimate YouTube invite, except they include typical spam content and links to spam websites.
“Spammers are doing this to defeat spam filters and to lower the recipient’s guard by making it look as though the messages are coming from a perfectly innocuous email address. YouTube’s own Help Centre suggests that you exclude the service@youtube.com email address from spam filtering. The spammers are keenly aware of this.”

Hackers Could Shut Down Car Engines!

Some people just have no idea what they are doing. Here we go again – this is another case of overzealous security that can seriously end up in hurting the ones who should be protected!
General Motors is going to come up with a system to make car thefts history‌ at least in their opinion! The technology is called Stolen Vehicle Slowdown and it’s used, as you might have imagined, to slow down cars. So, basically, should the Police be chasing a stolen vehicle, or a speeding one, they could call GM and ask for them to remotely shut down the engine. Now, surely this would help the Police a lot, but let’s think what else could happen.

Over the time, we’ve learned that hackers can do just about anything if they have the right skills and the right tools. So, if they bypass GM security systems and gain access to the control panel for this technology, things could end up in a disaster! Also, malicious insiders could wreak havoc on the streets, by abusing this system.

And imagine what could happen if a hacker accesses the system and, instead of slowing down the engine, would actually reverse the process and increase velocity – now that would cause a lot of problems, probably death! Also, these systems are going to be controlled remotely, fact which means jamming stations could be put in place to avoid control. I don’t even want to think what could happen if a terrorist gained access to this system!

These are just a few possible things, and when GM releases this new technology, they need to think things through and be pay even more attention to aspects of security! But do not worry, this system isn’t something compulsory. You have to choose if you want it or not; furthermore, it’s not out yet – it’s going to be available in 2009. I hope that by then, they will have the time to improve security too. And I certainly hope that nothing of what I have predicted in this article is going to come true!

iPod touch now running Mail, Google Maps, and more

We’re not looking at general availability yet, but those happy hacking cats unravelling the iPod touch have decrypted the ramdisk and are now busy installing applications. Already, Mail, Maps, and other 3rd party apps are up and running on their jailbreaked touches. The race is on between the cat and the mouse to see who will release their wares first. Maps screenshot after the break.

Hackers zero in on wireless hotspots

YOU’VE got ten minutes until you need to leave for the airport, but you just have to send out that e-mail containing this month’s sales figures. Dashing up the street in search of a taxi, you spot the magic words “wireless hotspot” in a cafĂŠ window. The figures are sensitive, but the cafĂŠ is almost empty. You sit down, facing your laptop screen away from the few others in the room and log on.

Safe as houses. Or not? Richard Rushing, chief security officer for US firm AirDefense, says people are leaving themselves open to fraudsters every day through insecure public wireless networks, which have transformed working practices.

Rushing, in Edinburgh to speak to Scottish business leaders about how to secure company data, believes groups of “bad guys” are targeting areas they know business people are likely to frequent, such as airports, or a cafĂŠ near financial institution headquarters.

He says most open networks, such as those offered for free in many public places, such as airports, coffee houses and even telephone booths, are insecure – and anyone with access to the same network could steal information just by logging on.

A former consultant for the CIA and the FBI, Rushing knows how important it is for companies – and individuals – to keep their data protected. “With more and more companies going to wireless now, it is a growing problem,” he says.

“If they supply laptops to their employees, they are at risk.

The people who are doing this are looking for company data, they’re looking for anything that is valuable, credit card details, even just knowing that people are there.”

Rushing’s firm, based in Georgia but with an operation in Basingstoke, can advise on how firms can make their computers more secure – by supplying software to encrypt data sent over the internet and also a package that can alert a PC user to someone trying to access information.

“A cafĂŠ owner doesn’t know what the situation is with his Wi-Fi – it’s not his responsibility,” says Rushing.

“He doesn’t think about the wireless network unless a customer tells him it doesn’t work, then he unplugs it, plugs it back in and asks ‘Does it work now?’ That’s it. A lot of them, especially those which are cheap to use, or even free, are unlikely to have encrypting technology.”

With plans for Edinburgh to become a city-wide Wi-Fi hotspot underway and many Scottish cities already covered by BT’s service, businesses were keen to listen to his message, with representatives from Standard Life, ScottishPower and Royal Bank of Scotland signing up to Rushing’s seminar.

Rushing, who has worked as a computer security adviser for the likes of Siemens and General Electric, and most recently held the role of chief technical officer of VeriSign’s network security services division, adds: “People get excited by wireless networks, at home as well. They say ‘great – I can log on to my next door neighbour’s wireless!’ But that means their neighbour could possibly log on to theirs too – and potentially see all of their personal information.”

Hackers do not need special software to check on what their network co-users are up to. “It’s not like they can see your screen shot for shot,” says Rushing. “But they can see any data that is sent via the internet, on an e-mail, over a website form and so on.

“You wouldn’t put your bank details on a postcard and send it through the mail for everyone to see, so why would you send them through an insecure network?”

In addition to protecting sensitive business information, Rushing is also keen to educate workers on keeping personal data close to their chests.

“If you’re out, you have your laptop and find you’re in a Wi-Fi zone, it is fine to use the internet to do certain things like check the football scores,” he says. “But if you’re not sure the network is safe, leave checking your internet bank, or using your credit card for when you are somewhere where you know no-one can access what you are doing.”

Anna Steven, senior press officer at BT, says wireless security was a hot issue for both broadband providers and companies.

The firm, which already uses AirDefense’s systems for wireless intrusion detection in around a dozen BT buildings UK-wide, recently launched a high-security way of sharing wireless broadband with other people – by providing separate channels for different users.

Steven said: “Users need to assess what is at risk and then implement the appropriate technology to protect it.”

Storm: The malware that won’t die

We like to imagine that hackers are smart, but it is their collective incompetence that has allowed the IT industry to survive their attacks as long as they have. Viruses may be unleashed, worms may spread, but usually the McAfees and Symantecs of the world are quick enough to help isolate and deal with such malware in a manner of weeks, if not days. This was the case with Sasser, Nimda, and even Code Red. Rare is the malware that acts with the consistent, determined approach of a stealth marketing campaign. This, however, has been the hallmark of Storm, a quietly professional example of online organised crime at its best. And scariest.

You know something’s different when Storm starts cropping up in the pages of mainstream newspapers, as it did in the Toronto Star here in Canada last week. In a story which described Storm as the “syphilis of computers”, the Star explained in very basic, accessible terms what the threat is and how it is growing. It’s the kind of story you would have expected to find written about head lice in elementary schools or, before SARS hit Toronto, the nature of pandemics. A problem historically of concern to specialists such as doctors (or in Storm’s case, IT managers) is translated for a mass audience, because the specialists are proving incapable of stopping the worst of its effects.

The most recent reports about Storm, particularly a blog post from Secure Works researcher Joe Stewart, suggest that the hackers behind it are splitting up access to the compromised computers for sale to spammers. It doesn’t matter whether you believe there are millions of such zombie machines or, as some experts say, a quarter of a million. We’re potentially talking about an army of infected machines the size of several corporate enterprises. Selling them to those who send unsolicited commercial email is the least of the dangers such a “market” of botnets poses.

We’ve become so used to the identify-contain-forget cycle of security that Storm may require a completely different mind set, both for IT managers and their users. Storm has already hung on for the better part of a year. There’s little to indicate it will be on the wane anytime soon. Instead of seeing such malware as a short-term event which we combat and vanquish, we may have to think of coping strategies that extend to several years. This would, of course, have major implications for enterprise IT security policies, which typically focus on user behaviour in exceptional circumstances (illegal downloads, connecting an unknown device to the network) rather than guidelines for ongoing vigilance.

Storm got its name because of an email message that warned of a disastrous weather event that was taking place in Europe, but the metaphor may not really apply anymore. When a real storm ends, people can usually walk around the way they did before. With the Storm malware, the rain might keep falling. IT managers will have to decide whether to permanently carry an umbrella, or get used to being wet.

Cracker sales target pegged at Rs.1 crore

TIRUCHI: The Chinthamani Cooperative Supermarket at Puthur here has fixed a cracker sales target of Rs. 1 crore for Deepavali festival. The authorities have planned to establish 10 special sales outlets in the Chinthamani branches at Puthur and Teppakulam in the city and Manapparai and Kulithalai towns to sell popular brands of fireworks.

Transport Minister K.N. Nehru inaugurated the sale at a function held at the Chinthamani supermarket on Sunday.

The cracker outlets will function from 9 a.m. to 9 p.m. on all days till Deepavali and adequate stock of crackers have already been procured.

A sales target of Rs. 35 crore has been fixed for the supermarket during the current financial year through its six branches at Kailasapuram, Subramaniapuram, Puthur and Teppakulam in the city and Mapparai and Kulithalai towns. The business done during the half-year stood at Rs. 19 crore.

Special arrangements have been made for the sale of essential commodities such as sugar, dhal, rava, maida, dalda and edible oil at the supermarket in connection with Deepavali. The supermarket’s annual turnover through the sale of controlled and non-controlled commodities was Rs. 45 crore, according to its Special Officer

A. Palanivel. MLAs Anbil Periasamy and K. N. Sekaran, Deputy Mayor M. Anbalagan, deputy registrar of Public Distribution System Sirajudeen were present.

Hacker uses public APIs to breach eBay

eBay has begun an audit of its IT systems after a hacker managed to access and disable user accounts. The company said last week that the hacker exploited public application programming interfaces (APIs) that enable merchants to build e-commerce sites on top of eBay. “This fraudster found very old administrative interfaces into the eBay system that had not been deactivated when we changed the security of our internal systems several years ago,” a member of the company’s trust and safety division said in a posting on an eBay blog.

Germany accuses China of digital espionage

The Chinese state is behind almost daily internet espionage attacks on German companies and government bodies, a top German intelligence official said on Monday. “In our view, state Chinese interests stand behind these digital attacks,” said Hans Elmar Remberg, vice president of the Federal Office for the Protection of the Constitution, the country’s domestic intelligence agency.

“Supporting this view is the intensity, structure and scope of the attacks, and above all the targets, which include [German] authorities and companies,” Remberg told a conference on industrial espionage in Berlin.

In August, German media reported that computer hackers believed to be linked to the Chinese army had infected German government ministries with spying programs. Beijing denied the allegation and said all “hacking” behaviour was prohibited.

“Some people call this the Chinese cyberwar,” Remberg said, adding that a new concept for protection against such cyberattacks was needed.

Remberg added it was important to differentiate between legitimate attempts to gather information on competitors by Chinese companies and state-led industrial espionage.

Driving China’s interest in industrial and government secrets is its desire to become a top global economic power, Remberg said. To catch up with the West, China needed “a massive transfer of high technology”.

“Across the world the People’s Republic of China is intensively gathering political, military, corporate-strategic and scientific information in order to bridge their technological gaps as quickly as possible,” Remberg said.

The attacks often rely on “Trojan horse” email programs or the hacking of websites, Remberg said.

“Astonishing intensity”
The attacks on German ministries and authorities had an “astonishing intensity” and the perpetrators appeared unconcerned that the attacks were being discovered.

“Every one or two days new attacks are detected,” Remberg said.

China is also using classic espionage methods.

“The diplomatic representative offices and Chinese media agencies in Germany enable the hidden deployment of intelligence agents,” Remberg said.

Firms in joint ventures with Chinese firms were also at risk, Remberg added.

China is not the only country engaged in such espionage, according to Remberg.

“Russian intelligence agencies are making great efforts in Germany to get important information in the military fields, politics, economy and science, using both open and conspiratorial methods,” Remberg said.

Remberg added that other countries had sent intelligence agents to Germany to procure “dual-use” machinery and know-how for illegal weapons technology, including nuclear technology.

Remberg named Iran, North Korea, Pakistan and Syria as countries seeking to procure technology with dual civilian and military uses.

System failures rated number one concern for IT

UK IT professionals are more concerned about internal system failures than hacker attacks, according to new research. The study by training company Firebrand Training asked 601 UK IT workers to rank their greatest concerns. System failure ranked the highest with 63 per cent of those questioned more concerned about interrupted IT services than the 24 per cent who ranked external threats as their key worry.

Technology issues rate far higher than human error or breaches in security from employees.

Almost half of those questioned said they did not worry about security threats from their company’s staff.

The research indicates a trend towards external security issues taking a back seat to day-to-day operational concerns, said Firebrand Training chief executive Robert Chapman.

“The fact that IT staff are pushing protection against external threats to the bottom of the pile is concerning,” he said.

“Security must be higher up the priority list for IT because a security breach, whether by a hacker or a disgruntled employee could be far more damaging in the long run than a few hours’ downtime.”

Hacker bust for virtual theft

Hacker bust for virtual theft. Dutch police arrested a 17-year-old who stole ÂŁ2 500 worth of virtual furniture from an online hotel. The teenager was arrested after playing Habbo Hotel, an international online community with an estimated seven million members and an annual turnover of ÂŁ3 million, states The Times. The game allows players to create virtual characters, or Habbos. These characters can take their own rooms in the hotel, which they can then decorate with their own furniture. The furniture is purchased with special Habbo credits, but the credits are paid for with real money.

The teenager hacked into the accounts of other Habbo community members, took their furniture and put it in his own room. The 17-year-old has been charged with hacking and burglary.

Dell unveils all-in-one PC

Dell has introduced an all-in-one computer that combines the monitor and CPU in one box, says PC World.

The XPS One will be available as a system with only a widescreen display, a mouse and keyboard. Processing capabilities and other components will be fixed inside the display.

The systems will be available in four designs with the monikers indicating the target audience: the Essential One, the Music One, the Performance One and the Entertainment One.

eBay bot hops to other sites

Yet another sophisticated Web-based attack against eBay and its users is being investigated by a Tel Aviv-based security vendor that discovered a similar attack two months ago involving a custom-made bot designed to steal accounts, states Network World.

Ofer Elzam, Aladdin Knowledge Systems’ director of product management, says his firm has determined in the last few days that at least two Web sites, Save Our Planet and Nova Radio, appear to have been compromised with malicious code that combines to launch an attack against a site visitor.

The goal of the attack is to combine code to break in through the browser to the victim’s desktop and install a Trojan to collect eBay user account information, if it’s found, and connect to eBay to use that account information to commit fraud.

Germany accuses China of digital espionage

The Chinese state is behind almost daily internet espionage attacks on German companies and government bodies, a top German intelligence official said on Monday. “In our view, state Chinese interests stand behind these digital attacks,” said Hans Elmar Remberg, vice president of the Federal Office for the Protection of the Constitution, the country’s domestic intelligence agency.

“Supporting this view is the intensity, structure and scope of the attacks, and above all the targets, which include [German] authorities and companies,” Remberg told a conference on industrial espionage in Berlin.
In August, German media reported that computer hackers believed to be linked to the Chinese army had infected German government ministries with spying programs. Beijing denied the allegation and said all “hacking” behaviour was prohibited.
“Some people call this the Chinese cyberwar,” Remberg said, adding that a new concept for protection against such cyberattacks was needed.
Remberg added it was important to differentiate between legitimate attempts to gather information on competitors by Chinese companies and state-led industrial espionage.
Driving China’s interest in industrial and government secrets is its desire to become a top global economic power, Remberg said. To catch up with the West, China needed “a massive transfer of high technology”.
“Across the world the People’s Republic of China is intensively gathering political, military, corporate-strategic and scientific information in order to bridge their technological gaps as quickly as possible,” Remberg said.
The attacks often rely on “Trojan horse” email programs or the hacking of websites, Remberg said.
“Astonishing intensity”
The attacks on German ministries and authorities had an “astonishing intensity” and the perpetrators appeared unconcerned that the attacks were being discovered.
“Every one or two days new attacks are detected,” Remberg said.
China is also using classic espionage methods.
“The diplomatic representative offices and Chinese media agencies in Germany enable the hidden deployment of intelligence agents,” Remberg said.
Firms in joint ventures with Chinese firms were also at risk, Remberg added.
China is not the only country engaged in such espionage, according to Remberg.
“Russian intelligence agencies are making great efforts in Germany to get important information in the military fields, politics, economy and science, using both open and conspiratorial methods,” Remberg said.
Remberg added that other countries had sent intelligence agents to Germany to procure “dual-use” machinery and know-how for illegal weapons technology, including nuclear technology.
Remberg named Iran, North Korea, Pakistan and Syria as countries seeking to procure technology with dual civilian and military uses.

Back to Top