hacking articles

Sniper Spy Remote Software for hacking

Sniper spy is the industry leading Remote password hacking softwarecombined with the Remote Install and Remote Viewing feature.
Once installed on the remote PC(s) you wish, you only need to login to your own personal SniperSpy account to view activity logs of the remote PC’s!  This means that you can view logs of the remote PC’s from anywhere in the world as long as you have internet access!
Do you want to Spy on a Remote PC? Expose the truth behind the lies! Unlike the rest, SniperSpy allows you to remotely spy any PC like a television! Watch what happens on the screen LIVE! The only remote PC spy software with a SECURE control panel!
This Remote PC Spy software also saves screenshots along with text logs of chats, websites, keystrokes in any language and more. Remotely view everything your child, employee or anyone does while they use your distant PC. Includes LIVE admin and control commands!

Read More. . .

Backdoor in Linksys and Netgear routers - Hacking

router

This news could hurt the reputation of both companies. A passionate (and obviously very competent) reverse-engineer from France, Eloi Vanderbeken forgot the admin interface password of his router and so he just wanted to have fun accessing the administration side and that’s when he discovered a backdoor in his Linksys WAG200G router. After publishing this discovery on Github, other users have confirmed its existence in at least three other routers:
  • Netgear DM111Pv2
  • Linksys WAG320N
  • Linksys WAG54G2
Other routers are suspected of providing equal opportunity to obtain the administrator password through the 32764 port, but it has not yet been confirmed:
  • Netgear DG934
  • Netgear DG834
  • Netgear WPNT834
  • Netgear DG834G
  • Netgear WG602
  • Netgear WGR614
  • Netgear DGN2000
  • Linksys WAG120N
  • Linksys WAG160N
  • Linksys WRVS4400N

    Read more. . .

Hacking in Computer and Predators

How are computer hackers and predators a threat to computer security?

People, not computers, create computer threats. Computer predators victimize others for their own gain. Give a predator access to the Internet — and to your PC — and the threat they pose to your security increases exponentially. Computer hackers are unauthorized users who break into computer systems in order to steal, change or destroy information, often by installing dangerous malware without your knowledge or consent. Their clever tactics and detailed technical knowledge help them access information you really don’t want them to have.

How do computer hackers and predators find me?

Anyone who uses a computer connected to the Internet is susceptible to the threats that computer hackers and predators pose. These online villains typically use phishing scams, spam email or instant messages and bogus Web sites to deliver dangerous malware to your computer and compromise your computer security. Computer hackers can also try to access your computer and private information directly if you are not protected with a firewall. They may also monitor your chat room conversations or peruse your personal Web page. Usually disguised with a bogus identity, predators can lure you into revealing sensitive personal and financial information, or much worse.

What can computer hackers and predators do to me?

While your computer is connected to the Internet, the malware a hacker has installed on your PC quietly transmits your personal and financial information without your knowledge or consent. Or, a computer predator may pounce on the private information you unwittingly revealed. In either case, they may:
  • Hijack your usernames and passwords
  • Steal your money and open credit card and bank accounts in your name
  • Ruin your credit
  • Request new account Personal Identification Numbers (PINs) or additional credit cards
  • Make purchases
  • Add themselves or an alias that they control as an authorized user so it’s easier to use your credit
  • Obtain cash advances
  • Use and abuse your Social Security number
  • Sell your information to other parties who will use it for illicit or illegal purposes
Predators can pose a serious physical threat. Use extreme caution when agreeing to meet an online “friend” or acquaintance in person.

How will I know?

Check the accuracy of your personal accounts, credit cards and documents. Are there unexplained transactions? Questionable or unauthorized changes? If so, dangerous malware installed by predators or hackers may already be lurking.

What can I do about computer hackers and predators?

When you arm yourself with information and resources, you’re wiser about computer security threats and less vulnerable to threat tactics. Hackers and predators pose equally serious and but very different threats.

To protect your computer from hackers and predators:

  • Continually check the accuracy of personal accounts and deal with any discrepancies right away
  • Use extreme caution when entering chat rooms or posting personal Web pages
  • Limit the personal information you post on a personal Web pages
  • Carefully monitor requests by online “friends” or acquaintances for predatory behavior
  • Keep personal and financial information out of online conversations
  • Use extreme caution when agreeing to meet an online “friend” or acquaintance in person

Computer hacking using EFS Easy Chat Server Buffer Overflow in LAN

This module exploits a stack buffer overflow in EFS Software Easy Chat Server. By sending a overly long authentication request, an attacker may be able to execute arbitrary code. NOTE: The offset to SEH is influenced by the installation path of the program. The path, which defaults to “C:Program FilesEasy Chat Server”, is concatentated with “users” and the string passed as the username HTTP parameter.
Exploit Targets
Easy Chat Server 2.5
Requirement
Attacker: Backtrack 5
Victim PC: Windows XP
Open backtrack terminal type msfconsole

Read more. . .

Hacking attack on KickStarter Username and password is stolen

KickStarter hacking attack

Online Crowdfunding website KickStarter is to be the latest high-profile website reporting security breach.  KickStarter became aware of the breach, after receiving a notification from Law enforcement.
Hackers breached their website( kickstarter.com) and gained access to the user's information including usernames, encrypted passwords, email IDs and phone numbers.  The company says there is No Credit card data compromised in this breach.  

Even though the password is encrypted one,  we aware the fact that attackers with enough computing power can easily crack those passwords.

The company informs that two accounts have been accessed by hackers so far.  All users are recommended to change their password immediately for the KickStarter website.

If you are using the same password in any other websites(most of us do), you are also advised to reset the password there also.

"We’re incredibly sorry that this happened. We set a very high bar for how we serve our community, and this incident is frustrating and upsetting." the company apologizes in their blog post.

See more at: http://www.ehackingnews.com/2014/02/kickstarter-website-hacked.html#sthash.St3MIcdW.dpuf

Ten tips of Ethical hacking

Here are 10 tips for Ethical hacking which will surly help you alot

  1. Get it in writing.
    You've heard it a thousand times, but believe it or not I've seen security professionals perform -- and security managers allow -- ethical hacking on critical business systems without putting anything in writing ahead of time. You've absolutely got to cover your assets and not only get a basic sign-off by all parties involved, but also consider and document who's responsible (or not) when something goes awry during the testing. Bad things can happen during ethical hacking -- servers can crash and data can get lost. Think about this from a business perspective. You'll make your lawyer and insurance underwriter proud!
  2. You've got to have goals.
    Just like with any successful business venture, you've got to determine exactly what you want to get out of ethical hacking. What outcomes are you looking for? Is this to prove you need to migrate to a Novell or Unix platform? Are you trying to get more money to spend on security? Are you trying to comply with federal regulations or meet security standards? Also, ask yourself what information you're trying to protect and which systems need to be tested.
  3. Don't try to test everything at once.
    This doesn't necessarily apply to small networks, but who really has a small network any more? Prioritize the systems that need to be tested, and test the most critical ones first. This is most likely Web, e-mail or database servers, and even perimeter devices such as routers and firewalls. Look for single points of failure and systems your business can do without. Many security professionals focus only on publicly accessible hosts. Remember that hacking can occur from inside the network, so don't forget about the insider threat and the systems that could be affected by it.
  4. Don't forget to test the "unimportant" systems.
    OK, so this conflicts with lesson number three. Well, not exactly. You don't have to test all of your systems, but it does help to think through how attacks can occur and affect other, less important systems. Workstations that don't have confidential data on them, the telecommuter's home PC or that Web server that only provides basic e-mail access are often the systems that are used as stepping stones to attack other, more critical systems. Never rule out the rogue "little guy."
  5. It sounds clichÉ, but thinking like the enemy really does help.
    On the heels of lesson number four comes the tried and true "know your enemy." It's old-fashioned, but true. If systems are tested using only the latest automated tools without thinking through all the other various ways manual hacks that can be carried out, the complete picture won't be seen. There's no way to test for every possible hack from every possible angle. The key is making sure the research has been done and hacker motives and methods are understood and made part of your ethical hacking program.
  6. Use the right tools.
    This is something I'm reminded of every time I perform ethical hacking tests. I don't know what I'd do without the tools (both freeware and commercial) I've gathered over the years. It's just like any successful homebuilder will tell you; you've got to have the right tool for the task at hand. Otherwise, it will likely be an exercise in futility with bad results. As a security manager, make sure your team or the third-party ethical hackers you've hired have the right tools. Many are not simple to use and many are not inexpensive, but they sure are worth it.
  7. It's all in the timing.
    Ever hear of someone pounding on a system with a million packets per minute to see if the TCP/IP stack is stable? This kind of testing might be OK, but as my mother always told me, there's a time and a place for everything. Make sure that the ethical hacking tests are not carried out during peak network or host usage. You don't want the network to run slow or have a system crash. There are a lot of security tools that can do just that if the system is unstable or overloaded with other requests at the time the testing is being carried out. Come up with a timeline. And put it in writing!
  8. Don't think that no penetration means you're secure.
    A very common misconception is that if no penetration was possible that the systems must be secure. Nope! It could be that the right tools weren't used or the right systems weren't tested. It could also be that a vulnerability has not yet been discovered for the system you're testing. Ethical hacking is a snapshot in time of a few specific systems. There could be a rogue router (or user) presenting a security problem on the other side of the world that was overlooked or not part of the original scope. You just never saw it.
  9. Keep up the good work.
    Lesson number eight is what makes number nine critical. I know you hear about testing your systems over and over again. It's true; things change. New threats and vulnerabilities crop up. Make sure your systems are being tested periodically for new issues and to catch vulnerabilities that were missed in the past. Repetition is key.
  10. Focus on the important and urgent vulnerabilities
    I've seen a lot of security managers feel obligated to fix every vulnerability discovered during the ethical hacking process. It realistically can't be done. It's not reasonable or fair to put pressure on yourself or your team to secure everything. Take the route that time management experts recommend when prioritizing daily tasks: go for vulnerabilities that are both important (high impact if exploited) and urgent (high likelihood of being exploited). The other vulnerabilities can then be addressed as time, resources and money allows.
If you can incorporate into your ethical hacking efforts even just a few of these 10 lessons I've learned over the years, I know they'll make your job as a security manager a little easier; after all, every little bit counts.

Read more at: http://searchsecurity.techtarget.com/tip/Ethical-hacking-Ten-crucial-lessons

PSN Hacking – The law-suit is closed, Sony paid the charges

The lawsuit that was filed against Sony for the famous hacker attacks suffered by the NDP in 2011, or at least one of those organized in the United States, has been closed by Judge Anthony Battaglia, Sony released all the charges. The reason being that none of the plaintiffs in the law-suit signed up for any premium subscription on Playstation network, and used the services for free.

PSN Logo1 PSN Hacking   The law suit is closed, Sony paid the charges
In addition to receiving the free service, there is another point that free Sony accusations: the same formulation of the cause is hereby given that the service has been suspended for an illegal attack brought from outside intrusion into the Network which Sony is not responsible for. Addition to the agreement signed by the use of PSN users it is reported that if the system is not perfect and that errors and problems can emerge, then the person signing the agreement does so at his own risk with regard to any failure.

A Beginner’s Guide to Ethical Hacking

A Beginners Guide to Ethical Hacking1 A Beginners Guide to Ethical Hacking [E Book]

Learn What It Takes to Become a Master Hacker

A Beginner’s Guide to Ethical Hacking is a complete path for newbie hackers who  are curious to Learn Ethical Hacking Techniques. The Information given in this book will make you a Master in Hacking.
How will the information in the book affect you?
  • You will learn All Ethical hacking techniques and also you will learn to apply them in real world situation.
  • You will start to think like Hackers.
  • Secure your computer from trojans, worms,  adwares etc.
  • Amaze your friends with your newly learned tricks.
  • You will be able to protect your self from future hack attacks.

Bonus 1

bonus1.jpg 249x300 A Beginners Guide to Ethical Hacking [E Book]

1000 Hacking Tutorials

For a limited time only , with the purchase of “A Beginner’s Guide to Ethical Hacking” you will receive the following bonus package! 1000 Hacking Tutorials contains 1000 of the best hacking tutorials of 2010 leaked on the internet!

Bonus 2


Set of Phishers With the purchase of “A Beginner’s Guide to Ethical Hacking” you will also get a set of 30+ Phishers(Fake Login Pages) already created by the Author!

Its Decision Time!

Now you have heard it all so what are you waiting for.
This book does not demand any prior knowledge about Hacking. So if you are a newbie to the concept of hacking and want to master it from the basics, then this book is for you.
The information given in this underground handbook will put you into a hacker’s mindset and teach you all of the hacker’s secret.So what are you waiting for? Grab “A Beginner’s Guide to Ethical hacking” and start your Hacking Journey.

Will the iPhone be a Security Nightmare?

So here it is, iPhone month. At last. It’s been on the mind of many a gadget geek ever since Steve Jobs announced it in January. That’s a long time to make us wait, by the way, Steve. But will it be worthy of our expectations? Of course I’m referring here to our security expectations. We’ve all heard more than enough about the iPhone’s features, revolutionary user interface, and so on, right? Perhaps my optical grep isn’t what it used to be, but I sure don’t recall even seeing the word security in that myriad of coverage about this new must-have gadget. Are we all being drawn into the functional specification trap that so many software developers fall for also? Are we paying too much attention to what this thing does and not enough about what can go wrong? Seems likely to me.

I’ve been an IT junkie for years, ever since building my first Heathkit computer back in college. Like so many of us, I’m irresistibly drawn to new stuff as it hits the markets. In all these years, I can’t remember one single product announcement that has had the same level of buzz as the iPhone does now. That’s likely to be a great thing for Apple’s shareholders, but there’s a side effect to it as well. Along with buzz comes a veritable “kick me” sticker on the iPhone’s back.
Oh yes, make no mistake about it. The moment the first iPhone ships off the assembly line, there’ll be a line of people who are going to want to be the first to break it.
But we shouldn’t be concerned, right? After all, the iPhone is built on Apple’s formidable OS X (and thus UNIX) operating system, which is pretty rock solid over all. Isn’t it?
I’m a big believer in UNIX in general, but even I want a solid mechanism for quickly and easily installing security patches and updates as they’re made available. Has there been any mention of an “iPhone Update” icon in all the functional discussions we’ve heard about in the iPhone? I must have missed that discussion.
I do hope, though, that there’s a quick and easy way of installing software updates in the device. Given Apple’s track record, I do expect that to be the case. But will it be opt-in or opt-out? Will it automatically run every night and keep my iPhone up to date with security patches or will I have to connect to some Apple website and download the latest firmware and install it – long the status quo among smart phones from other vendors.
If the latter is the case, how will the users find out about the security patches? From an email sent out by Apple? (I sure hope they digitally sign that email!) From a press release? And then, what percentage of the iPhone users do you think will actually read that email/release and go out and grab the patch? If history serves as an accurate predictor of the future, that percentage won’t be very high.
And then there’s the security configuration of the base operating system. In the desktop version of OS X, the user can turn on and off firewalling, for example. What’s the default configuration on the iPhone, and will the user have any ability to change it? Again, I’m hoping for an opt-out configuration that defaults to secure and requires the user to override if she chooses to.
After all, the iPhone speaks Wi-Fi and runs UNIX – it is an Internet-connected host just like any other when connected to a network at your favorite coffee shop or airport lounge. Many of the same issues regarding safely configuring a UNIX server on the Internet are entirely relevant to configuring this little hand-held device, but we know precious little so far about it.
By all accounts, the iPhone sure looks like it’s going to be an incredible device. Indeed, if it were available on my mobile provider, I’d be getting one myself. My concern, however, is that there are so many security unknowns here that there could be trouble ahead.
I should point out that, up until about a month ago, I was using a Linux-based smart phone for my own mobile needs. It seemed to me to be quite secure from a network standpoint, but lacked any consumer-level mechanism for installing security updates. That was one of the primary reasons why I moved to a different device. But in popularity terms, that phone paled in comparison to what the iPhone is likely to hit in its first week in the market.
I, for one, hope our security expectations are in line with our functional expectations. I also hope that the smart folks at Apple have thought these issues through thoroughly and they’re ready to knock our socks off on all fronts. It’ll be an important lesson for the entire mobile device community to learn from.

The enforcer

IT SHOULD have been the entertainment industry’s best-kept secret. However, in February a hacker known only as Arnezami found a key to the encryption system protecting the latest high-definition DVDs against pirates and published it online just three months or so after the new players went on sale. Attempts to have the key removed from websites backfired and it quickly spread, even appearing in artwork and songs and on T-shirts. To make matters worse, other hackers soon discovered that, in some DVD players, by disconnecting a chip inside the machines they could circumvent their encryption system entirely.

Yet such setbacks aren’t deterring the industry from trying to make copy protection work. Worried by the fresh opportunities that digital broadcasting creates for pirates to copy and swap films and videos on the internet, the industry along with a conglomeration of TV studios, broadcasters and consumer electronics manufacturers is quietly pressing ahead with plans that could transform the way we watch TV.
Their idea is to add a hidden label to every digital TV broadcast. This will be read by a secure chip in the TV receiver in your living room and place restrictions on what you can do with a programme whether it can be copied, say, or even recorded in the first place. The studios or broadcasters will control these restrictions.
If the technology works as planned, it should help prevent pirates from making illegal copies of movies or TV shows and distributing them on the web. Innocent viewers will be affected too, however, according to US-based campaign group the Electronic Frontier Foundation (EFF). The system could prevent you recording your favourite soap or pausing live TV, or stop you watching a recorded movie because you’ve already seen it once. “Worse, the restrictions can be changed at the whim of the rights holder,” says Ren Bucholz, EFF policy coordinator. “It may be that today you can record a programme and transfer it to DVD for long-term storage but next week you could be prevented from doing the same thing.”
In 2005 the courts blocked the introduction of a similar copy-protection system in the US. Yet the entertainment industry is determined to see the new technology operating in Europe, Australia, New Zealand and Asia. The final specifications are due for release by the end of 2007 and the system could be adopted soon after. If that happens, experts warn, the technology could be resurrected in the US.
It is hardly surprising that the major broadcasters and movie studios feel threatened. The internet has already made it simple to copy and share music tracks. Now, with high-speed broadband connections and powerful data-compression software, people can distribute video clips, films and TV programmes just as easily . This should become even simpler as TV broadcasters go digital before switching off analogue transmissions.
Just as record companies developed copy-protection software in an attempt to smash music piracy, the film and TV industry has long wanted a system that will thwart video pirates. In 2001, US-based Fox Broadcasting part of Rupert Murdoch’s News Corporation came up with technology it believed could do it. Prior to broadcast, each programme would be labelled with a digital code called a broadcast flag. If the flag was set “on”, digital TV receivers would encrypt the programme when it was received. The only way viewers could then watch it would be with an industry-authorised TV or computer which would prevent them making unlimited copies or uploading clips to the internet. Unauthorised devices, such as DVD burners that could be used to create unencrypted copies of a film, would not be able to read it.
The broadcast flag was backed by the Motion Picture Association of America (MPAA), which speaks for the Hollywood studios, as well as the US Federal Communications Commission and the “5C” group of electronics companies Panasonic, Sony, Intel, Toshiba and Hitachi. The scheme ran into trouble, however, largely due to opposition from campaign groups. The final blow came in May 2005 when the US Court of Appeals ruled that the Federal Communications Commission did not have the authority to force broadcast flag technology on consumers.
The MPAA was more successful in Europe. In 2003 a version of the broadcast flag system was adopted by the Swiss-based Digital Video Broadcasting Project (DVB), an industry-led consortium of over 250 broadcasters, manufacturers, network operators, software developers and regulatory bodies that was developing new digital TV standards for over 35 countries from Europe to Australia. The result is the Content Protection and Copy Management system (CPCM).
Until recently, very little was known about CPCM. The system has been developed in a series of international meetings held behind closed doors. The only non-industry participant was the EFF, which had to pay several hundred thousand dollars and sign a non-disclosure agreement to attend. Only in March, when the outline technical specification for CPCM was submitted to European regulators, did the EFF feel able to blow the whistle and publicise in plain English what CPCM would mean to viewers.
Ultimate controlCPCM is more sophisticated than the failed US broadcast flag. Each programme will contain a CPCM code that is read by a secure chip in the digital receiver. Rather than the simple “on” or “off” of the US version, however, CPCM allows broadcasters to impose a range of restrictions. If the programme is marked “not for recording”, say, any attempt to transfer it to a hard disc recorder or DVD burner will be blocked. Alternatively, the CPCM code might allow you to create a single copy, or allow you to record and view a programme for a limited time. It could prevent you storing a programme temporarily on a computer disc, which would disable the live-action pause facility on many digital recorders. CPCM can also stop video clips being uploaded onto the internet.
To work as intended, CPCM must establish a “secure” connection between receivers, TVs, recorders and computers in other words, a connection that can’t be hacked into to divert the content flowing through it and make an illicit copy. So the DVB project plans to use technology that is already built into many devices the high-density multimedia interface. This uses encryption to protect high-definition TV programmes and can even check if the connections between a digital receiver and TV screen are secure; if not, pictures will be blocked or deliberately degraded.
The restrictions that CPCM can create should make life difficult for video pirates. Innocent users will be affected too, though, warns Bucholz. “The system goes to some pretty dark places for consumers,” he says. “You won’t even know ahead of time whether and how you will be able to record and make use of particular programmes or devices.” Restrictions can be changed at will by the broadcasters, and without secure digital connections, TVs, digital or DVD recorders could turn into “oversized paperweights”, he says. If you take your equipment in for repair, the service engineer will tell you there is nothing wrong with it.
In contrast, Peter MacAvock, executive director of DVB, argues that CPCM will actually make things easier for consumers because it will harmonise video copy protection across different technologies, including TVs, computers, mobile phones and other hand-held devices. “Our aim remains to facilitate access to content in a converging digital television landscape,” he says. Information released by the DVB suggests that restrictions will be made clear to viewers, but does not say how and puts the burden of responsibility on the programme providers. Most likely viewers will get an error message on screen when they try to do something illegal. DVB also says there will only be a few types of broadcasts such as on-demand movies that viewers will not be able to record. If the EFF feels CPCM is flawed, says MacAvock, it should have addressed its concerns “using the DVB’s processes”.
Phil Laven, director of the technical department at the European Broadcasting Union (EBU), based in Geneva, Switzerland, believes that the protection offered by CPCM is important. “The threat of unauthorised redistribution over the internet is a real problem, both for pay TV and free-to-air broadcasters. If popular programmes are made available on the internet as they are being broadcast live, viewers elsewhere might opt to watch the illicit version thus reducing TV audiences and advertising revenue.”
Nevertheless, the EBU was unhappy with some aspects of CPCM, says Laven. For example, people in many European countries have a legal right to make a copy of broadcasts for personal use. Blocking this with CPCM could trigger lawsuits. What’s more, while Laven acknowledges that pay-TV broadcasters need to protect valuable content such as new movies, he believes there’s little point worrying about many programmes on free-to-air TV: “No commercial pirate is going to wait for free-to-air TV broadcasts of movies that have long been available on DVD. Although Hollywood might like us to take extraordinary measures to protect such movies against piracy, there really is no point.”
Will it even work? Copy protection on music downloads has caused so many headaches that some companies, including EMI and Linn Records, have removed protection from their tracks, arguing that it is simply not worth the bother. Copy protection on movie DVDs has also had a rough ride. A couple of years after the first DVDs appeared in 1997, their protection was unravelled by hackers a feat now repeated with the Advanced Access Content System (AACS) on new high-definition DVDs (New Scientist, 11 March 2006, p 42).
According to Ed Felten, a computer security expert at Princeton University, even if the entertainment industry changes the encryption keys, hackers will crack the fresh batch within weeks. Should CPCM prove more resilient than AACS, pirates could still make use of unrestricted analogue connections on digital recorders, or even simply film the screen with a digital video camera. “CPCM is happening just as the music industry is questioning the value of copy protection and hackers are proving just how ineffective it is,” says Bucholz.
This doesn’t seem to be putting DVB off. Its engineers are already building a “proof of concept” system to show that CPCM works, and the technology should be ready for ratification by the European Telecommunications Standards Institute later this year or early in 2008 and could be in operation soon after.
Is there an alternative? The EFF argues that rather than relying on protection that is easily defeated, the entertainment industry needs to move to a new kind of business model. “We do recognise that copyright infringement is a bad thing,” says Bucholz, “but there are other ways in which artists could be compensated without crippling new technologies or harming consumers.” Rather than adding copy protection to music tracks, for instance, the EFF advocates a voluntary collective licence in which consumers pay a small monthly fee that entitles them to unlimited downloads. A similar licence system has long worked for the radio industry, he says.
Ted Shapiro, a lawyer representing the MPAA says that this sort of licence is no alternative to CPCM. “The music sector producers and authors do not find the proposal workable either.” The EBU agrees.
Now Hollywood and the TV industry have come up with another strategy. In what it describes as a “bold new approach”, the Industry Trust for IP Awareness an alliance of 22 film and TV companies will spend 3m over the next year on TV and cinema adverts which try to stop illegal copying by making those who download pirated videos feel guilty. “We want to create a social stigma,” says Liz Bales, director general of the Industry Trust. “It has been done before,” says Johnny Fewings, joint managing director of Universal Pictures. “With drinking and driving, not smoking at football matches and picking up dog mess. We want to make people feel grubby.”
Streaming videoBarry Fox New businesses are springing up to make use of digital TV, video clips and movies. Some, including Joost, convert live TV pictures into digital data packets and stream them across the internet so they can be watched on computers anywhere in the world. Since many TV broadcasts are now digital rather than analogue, this is relatively simple.
Two popular consumer gadgets, Sony’s LocationFree and Sling Media’s Slingbox, even let you stream pictures from your home TV to a private website that you can access from anywhere in the world. Students living away from their parents for the first time use this technology to watch satellite or cable TV programmes from home, and lonely oil rig workers watch TV news sent direct from their home towns.
Is this legal? Like the situation with home copying of music, the laws differ from country to country and are nearly impossible to enforce using conventional techniques.
However the movie industry has pursued and shut down several websites that were hosting pirated movies, and in February, the media entertainment company Viacom began legal action against Google which owns video-hosting website YouTube claiming that some clips on YouTube are copyrighted. Others, including English football’s Premier League have followed suit, and both MySpace and YouTube say they will now remove copyrighted material on request.

Security fears raised at conference

Concerns over the latest hi-tech security vulnerabilities have been highlighted at a conference in Kuala Lumpur, Malaysia. There seems to be an unspoken understanding among hackers that dressing in black is cool. Hack in the Box, Asia’s leading hacking and security gathering, is full of geeks in black. And their cloak and dagger looks add a certain frisson to the occasion.

However though some may dress in black they are not ‘black hats’ as malicious hackers are known. Most put their hacking skills at the service of industry closing down security loopholes.
There are presentations about weaknesses in Vista, Microsoft’s new operating system due out early next year; ‘blue pill’ attacks that can create a virtual computer within your own without you knowing anything about it.
There are talks on the use of technology to track our every move and record our every written or even spoken thought and there are lectures about technical issues so dense just reading their titles makes my brain ache.
However if there’s a discernable thread running though many of this year’s presentations in Kuala Lumpur it’s the vulnerability of communications software and technology.
The term ‘phishing’ has entered the English lexicon, defined as an attempt to gain access to an individual’s bank or other sensitive personal details by using fraudulent e-mails or by diverting him or her to bogus websites.
Check your inbox and if it is like mine you’ll find dozens of security alerts purporting to be from banks.
This morning I had e-mails purporting to be from Barclays and Volksbanken Raiffeisenbanken. Both contained Trojans designed to phish for information.
You might think that your phone was secure but if you or the institution you are ringing uses Voip (internet telephony) you might have to think again.
Telecoms security specialists like “The Grugq”, who kept his school nickname as a cover for his hacking activities, are highly sceptical.
“Basically Voip is going to make telephony as secure as the internet,” he says. That’s about as damning as a hacker can be.
“What I expect we’re going to be seeing in a few months, and what’s already technically possible, is for an attacker to gain access to a call centre.”
The Grugq outlines a scenario in which “the customer does everything right,” rings his bank’s legitimate number, is put through to a call centre whether in the US, UK or even India and has their call hijacked.
“An attacker would be able to [hack] into the call centre. He could then set up a server that would monitor all of the traffic and during the hold music it would be possible for an attacker to inject content such as ‘In order for us to better serve you please enter your account number and PIN code’.”
If that were to happen, you have just handed over your bank details to someone who wants to empty out your accounts. And the Grugq has bad news for companies looking to save money through Voip.
“They need to make sure that everyone who has a Voip system that’s connected to the internet is secure otherwise the entire system falls apart. It’s basically a house of cards.”
And if internet usage and mobile Voip telephony takes off with the next generation of mobile phones (3.5 / 4G), experts say its coding, known as IPv6, will be open to the same sort of “man in the middle attacks” that The Grugq describes.
“The vulnerabilities that we have in our current internet protocol they still have similar vulnerabilities in the upcoming IP version 6,” says Van Hauser, a member of The Hacker’s Choice, a group of international network and system security experts.
“There are ways to secure it if implemented correctly, set up correctly, administered correctly which will be a big challenge but at least there is a chance and a hope.”
Triple Play, the term used for bundled internet telephony, data and TV services, is also open to hacking, says Yen-Ming Chen, who works for the Foundstone division of the McAfee security software company.
“Right now we see vulnerabilities in different components in this whole architecture so we categorise them into home networks, delivery and management network and also the back end and content source.
“What that could mean in practice is that rather than storming the local TV station political hackers could take control from the comfort of their own bedrooms.
“In this case the goal of the attackers would be taking control of a lot of home users set top boxes or just computers,” says Chen, “and then to broadcast whatever content they want to. That’s the worst scenario, for whatever political motivation or anything like that.”
But perhaps the most intriguing possibility is that of hackers hijacking satellites.
Jim Geovedi, a Jakarta based information security consultant with Bellua Asia Pacific doesn’t look like a Bond villain. But he possesses secrets that some of them might kill for.
“There’s a theory that if somebody can control one satellite they can cross to the next satellite and create a chain of destruction because everything is around the equator. If everything is destroyed so you don’t have any communication, any TV any data transfer’.”
It is just a theory, but can someone actually do it?
“Hacking satellites is not as easy as hacking kids’ toys,” he says.
“It’s very difficult. Every manufacturer has their own kind of technology. You have to understand everything.
“But, hacking a commercial satellite that’s been up there more than 10 years is very easy for some people, if you have the right equipment.”
“In my experience telecoms companies and lots of other companies only do what is absolutely necessary and hope that the rest will not fall apart,” says Van Hauser.
It is a view echoed by The Grugq: “When they [banks] really start losing money on it they’ll have the motivation to come up with some way of fixing it.”

Mobile Keyloggers and Your Credit Card Information

I’ve touched on the topic of mobile keyloggers in the past, but as they are quickly growing in popularity I find it important to raise the issue again. Mobile keyloggers for anyone unfamiliar with the topic is cell phone software that records every keystroke one types into their mobile keypad. Much like its computer related predecessor, mobile keyloggers are used as a tracking/recording device.

Why does the average cell phone owner care about mobile keyloggers? The recent global consolidation of landline/mobile service providers is a good indicator of how many people are ditching their landline in favor of only having wireless service. For years now, I’ve personally only had a mobile phone without a second thought of a landline. The issue then becomes the information that we so willingly punch into our mobile phones. Consider that last call you made to your credit card company, chances are (if your experiences are anything like mine) you had to navigate through the seemingly endless queue where you were required to provide everything sacred from your card number to the blood type of your first-born before reaching a live representative. This act of providing your information could be one of the greatest mobile threats we face as a mobile community.
Every credit card type is identifiable by the first four digits making your credit card number the easiest data for mobile keyloggers to target. I don’t need to go into the havoc that having your credit card number in the wrong hands can cause as we’re all familiar with the world’s horror stories. If you are a skeptic that thinks this is an isolated thing that won’t get your phone, consider that a simple Google search I just did of “mobile keylogger” which yielded over 2.2 million results. Mobile keyloggers are readily available around the world and are already tracking millions of unsuspecting mobile users. I encourage you to start considering a mobile security solution such as MyMobiSafeŽ so that you can keep your mobile information private. The mobile environment is changing with the heavy migration of financial information for cell phones. Start protecting your phone and your information today. Keep following my blog for the latest mobile security developments/tips.
By: Eric Everson, Founder – MyMobiSafe.com

Mitigating the effects of a DDoS attack

There’s a great variety of attacks and hacks that black hats can perpetrate on your network. Fortunately, you can prevent most of them using an assortment of security measures.
However, a distributed denial-of-service attack (DDoS) is an entirely different story. You can’t thwart a DDoS attack — they attack an IP address or service that’s available to the internet.

If you can’t prevent such an attack, what can you do to protect your organisation? You can better understand the threat by learning the three phases of a DDoS attack and learning how to quickly mitigate the attack’s effects.
Understand the attack
A DDoS attack usually entails three different phases. Target acquisition is the first phase: a black hat scouts or recons a network and picks a target IP address. The target can be a web server, DNS server, internet gateway, and so on. The reason for selection could be financial (someone is paying the attacker), or it could be just for malicious fun.
The next phase is the groundwork phase. During this phase, the attacker compromises a large number of unsecured machines — typically home user machines with DSL or cable connections. The attacker then installs software on each machine that will later be used to target your network.
The final phase is the actual attack. The attacker sends a command to each of the compromised hosts, or zombies, and commands them to flood the target with packets, overwhelming the service or choking the bandwidth to a crawl.
A really smart black hat will also command the zombies to forge the source address of their attack packets and insert the target’s IP address as the source — known as a reflector attack. Servers and routers that see these packets will forward, or reflect, replies directly to the source address of the packet — that is, straight to the target.
Again, you can’t prevent a DDoS attack, but understanding it better will help you mitigate the effects once one begins.
Mitigate the effects
“Ingress filtering” is a simple strategy that all networks — we hope ISPs are listening — should employ. At the border of your network — that is, every router that directly connects to an outside network — there should be a routing statement that directs all inbound traffic with a source IP address owned by that network to null. While ingress filtering won’t prevent a DDoS attack, it can prevent a DDoS reflector attack from overwhelming a machine or network.
However, large ISPs seem to be reluctant to implement ingress filtering for some reason. Because of that, you’ll need an alternative to help mitigate DDoS attacks. The current best strategy is the “backscatter traceback” method.
The first step to this strategy is to recognise that the problem is an external DDoS attack — not an internal network or routing problem. Next, configure all of the external interfaces on your routers to reject all traffic with a destination of the target for the DDoS attack.
In addition, you should already have configured your external router interface to route to null all inbound packets with an unallocated source address. For example:
|> 10.0.0.0 – 10.255.255.255
|> 172.16.0.0 – 172.31.255.255
|> 192.168.0.0 – 192.168.255.255
Each router configured to reject the packets will send an internet control message protocol (ICMP) “destination unreachable” error message packet back to the source IP address contained in the rejected packet.
Next, start sampling your router logs to determine which of your external routers is routing the most DDoS traffic. You also want to identify which IP blocks are your biggest offenders. On those routers, adjust the routing statements to “black hole” the IP blocks, and adjust the network masks to isolate only the offending IP addresses.
Look up who owns that network block. Contact your ISP and the owner’s ISP to inform them of what’s going on and ask for assistance. They might help or they might not, but it only costs a phone call.
Network service should be available but congested for legitimate traffic. You can remove all of your router reject statements except the ones on the border routers facing the attacking networks. If your ISP and the upstream ISP from the attacking network put up any network blocks, your inbound traffic should normalise quickly.
Final thoughts
DDoS attacks may be nasty and unpreventable, but you can diminish their effects. You just need to act quickly and methodically to find the offending traffic and send it to the bit bucket.

IPhone Flaw Lets Hackers Take Over, Security Firm Says

A team of computer security consultants say they have found a flaw in Apple’s wildly popular iPhone that allows them to take control of the device. The researchers, working for Independent Security Evaluators, a company that tests its clients’ computer security by hacking it, said that they could take control of iPhones through a WiFi connection or by tricking users into going to a Web site that contains malicious code. The hack, the first reported, allowed them to tap the wealth of personal information the phones contain.

Although Apple built considerable security measures into its device, said Charles A. Miller, the principal security analyst for the firm, “Once you did manage to find a hole, you were in complete control.” The firm, based in Baltimore, alerted Apple about the vulnerability this week and recommended a software patch that could solve the problem.
A spokeswoman for Apple, Lynn Fox, said, “Apple takes security very seriously and has a great track record of addressing potential vulnerabilities before they can affect users.”
“We’re looking into the report submitted by I.S.E. and always welcome feedback on how to improve our security,” she said.
There is no evidence that this flaw had been exploited or that users had been affected.
Dr. Miller, a former employee of the National Security Agency who has a doctorate in computer science, demonstrated the hack to a reporter by using his iPhone’s Web browser to visit a Web site of his own design.
Once he was there, the site injected a bit of code into the iPhone that then took over the phone. The phone promptly followed instructions to transmit a set of files to the attacking computer that included recent text messages — including one that had been sent to the reporter’s cellphone moments before — as well as telephone contacts and e-mail addresses.
“We can get any file we want,” he said. Potentially, he added, the attack could be used to program the phone to make calls, running up large bills or even turning it into a portable bugging device.
Steven M. Bellovin, a professor of computer science at Columbia University, said, “This looks like a very genuine hack.” Mr. Bellovin, who was for many years a computer security expert at AT&T Labs Research, said the vulnerability of the iPhone was an inevitable result of the long-anticipated convergence of computing and telephony.
“We’ve been hearing for a few years now that viruses and worms were going to be a problem on cellphones as they became a little more powerful, and we’re there,” he said. The iPhone is a full-fledged computer, he noted, “and sure enough, it’s got computer-grade problems.”
He said he suspected that phones based on the Windows mobile operating system would be similarly “attackable,” though he had not yet heard of any attacks.
“It’s not the end of the world; it’s not the end of the iPhone,” he said, any more than the regular revelations of vulnerabilities in computer browser software have killed off computing. “It is a sign that you cannot let down your guard. It is a sign that we need to build software and systems better.”
Details on the vulnerability, but not a step-by-step guide to hacking the phone, can be found at www.exploitingiphone.com, which the researchers said would be unveiled today.
Hackers around the world have been trying to unveil the secrets of the iPhone since its release last month; most have focused their efforts on unlocking the phone from its sole wireless provider, AT&T, and getting unauthorized programs to run on it. The iPhone is a closed system that cannot accept outside programs and can be used only with the AT&T wireless network.
Some of those hackers have posted bulletins of their progress on the Web. A posting went up on Friday that a hacker going by the name of “Nightwatch” had created and started an independent program on the phone.
The Independent Security Evaluators researchers were able to crack the phone’s software in a week, said Aviel D. Rubin, the firm’s founder and the technical director of the Information Security Institute at Johns Hopkins University. Mr. Rubin, who bought an iPhone the day after the cellphone was released, said in an interview that he had approached three colleagues, Dr. Miller, Joshua Mason and Jake Honoroff, and offered them an enticing prize if they would try to crack the iPhone. “I told the guys I would buy them iPhones.”
Dr. Miller had already been exploring weaknesses in the computer versions of Safari, Apple’s Web browser, and was planning to reveal that vulnerability, a relatively common kind of flaw known as a buffer overflow, at the Black Hat computer security conference next month. Dr. Miller instantly thought to see whether the phone, which uses a version of Safari, would be as vulnerable.
Mr. Rubin said the research was not intended to show that the iPhone was necessarily more vulnerable to hacking than other phones, or that Apple products were less secure than those from other companies. “Anything as complex as a computer — which is what this phone is — is going to have vulnerabilities,” he said.
There are far more viruses, worms and other malicious software affecting Windows systems than Apple systems. But Mr. Rubin said that Apple products have drawn fewer attacks because the computers have fewer users, and hackers reach for the greatest impact.
“Windows gets hacked all the time not because it is more insecure than Apple, but because 95 percent of computer users are on Windows,” he said. “The other 5 percent have enjoyed a honeymoon that will eventually come to an end.”
The iPhone is becoming a victim of its own success, he said. “The irony is that the more popular something is, the more insecure it becomes, because popularity paints a large target on its back.”
Mr. Rubin said his goal was to discover vulnerabilities and warn of them so that companies would strengthen their products and consumers would not be lulled into thinking that the technology they use was completely secure.
Mr. Rubin said, “I will think twice before getting on a random public WiFi network now,” but his overall opinion of the phone has not changed.
“You’d have to pry it out of my cold, dead hands to get it away from me,” he said.

As Apple Asserts iPhone Control, Hackers Fight Back

Perhaps more important than the bricking of unlocked iPhones is the fact that the firmware update blocked third-party application development. Apple has refused to open the iPhone platform to third-party developers, saying programmers should write Ajax-based applications that users can access through the Safari Web browser.

Appearing at a London Apple store for the UK launch of the iPod, Steve Jobs was asked about the rash of solutions for “unlocking” the iPhone, software and procedures that allow customers to use the device with a carrier other than AT&T.
“It’s a cat-and-mouse game,” he said. “We try to stay ahead. People will try to break in, and it’s our job to stop them breaking in.” Jobs brought down the hammer last week with firmware update 1.1.1, which turned cracked iPhones into very handsome bricks. More importantly, the upgrade disabled hundreds of third-party applications that users had downloaded.
Now the cat-and-mouse game is in full swing, as a team of hackers has posted several methods for downgrading the firmware back to version 1.0.2. The downgrade turns a bricked iPhone back into a useful device — essentially an iPod touch with iPod and Wi-Fi capabilities — but so far hackers have not figured out how to downgrade the phone’s “baseband” chip Relevant Products/Services, which controls the telephony Relevant Products/Services aspects of the device.
Update Blocked Third-Party Apps

One site posted three alternative methods of downgrading the firmware. The simplest is a four-step process of deleting iTunes 7.4, reinstalling iTunes 7.3 and restoring to firmware version 1.0.2. However, this, like all other methods, does not downgrade the baseband chip, the site said.
Apple spokesperson Jennifer Bowcock was quoted by the New York Times on Friday as saying, “If the damage was due to use of an unauthorized software application, voiding their warranty, they should purchase a new iPhone.”
Perhaps more important than the bricking of unlocked iPhones is the fact that the firmware blocked third-party application development. Apple has refused to open the iPhone platform to third-party developers, saying programmers should write Ajax-based applications that users can access through the Safari Web browser. (Ajax, which stands for asynchronous JavaScript and XML, has become a popular method for developing interactive, Web-based applications.)
But with application installers such as AppTap, users have been able to install and uninstall third-party programs on the iPhone. Clearly, with the latest firmware update, Apple means to control its platform.
“So long as Apple controls the platform, they can negotiate who gets their specialized applications native to the device,” Andrew Storms, director of security Relevant Products/Services operations, for nCircle, said in an e-mail. “One has to imagine that Apple has some of the brightest and dedicated programmers working on the iPhone. The downside is that most of them are probably right now working on further ways to keep control of the device in Apple’s hands.”
Still, over the past few months, Apple got a good look at the kinds of apps that users responded to. “I’ll place a wager that the iPhone product-management team is actively looking at those custom apps and making plans to integrate some of that creative inspiration in future iPhone updates,” he said.
‘We’re Just Heartbroken’
That’s little solace to folks like Damien Stolarz, author of the upcoming book “iPhone Hacks” and a software developer. Downloading applications on the iPhone was a “fully polished, Apple-like experience,” he said in a telephone interview. “This isn’t hacking; this is double-click installer app and download.” Over the EDGE network, he said, applications downloaded almost instantly.
“When they said the iPhone ran OS X, they weren’t kidding,” he added. “If you know how to write for OS X you know how to write for iPhone. This is the most flexible development environment I’ve ever owned.” That makes it all the more galling that Apple just shut off third-party programs, he said. “We’re just heartbroken,” he added.
As for developing apps through Ajax, Stolarz said, “that’s really BS.” Apple doesn’t provide the hooks into the phone to allow online apps to create compelling experiences, he added. Ultimately, this cat-and-mouse game is a giant waste of brainpower, Stolarz suggested.
“If you just let them work on the platform,” he speculated, “what amazing things would the platform do? Some of these brilliant hackers are the ones who could write the next killer app.”

Hackers zero in on wireless hotspots

YOU’VE got ten minutes until you need to leave for the airport, but you just have to send out that e-mail containing this month’s sales figures. Dashing up the street in search of a taxi, you spot the magic words “wireless hotspot” in a cafĂŠ window. The figures are sensitive, but the cafĂŠ is almost empty. You sit down, facing your laptop screen away from the few others in the room and log on.

Safe as houses. Or not? Richard Rushing, chief security officer for US firm AirDefense, says people are leaving themselves open to fraudsters every day through insecure public wireless networks, which have transformed working practices.
Rushing, in Edinburgh to speak to Scottish business leaders about how to secure company data, believes groups of “bad guys” are targeting areas they know business people are likely to frequent, such as airports, or a cafĂŠ near financial institution headquarters.
He says most open networks, such as those offered for free in many public places, such as airports, coffee houses and even telephone booths, are insecure – and anyone with access to the same network could steal information just by logging on.
A former consultant for the CIA and the FBI, Rushing knows how important it is for companies – and individuals – to keep their data protected. “With more and more companies going to wireless now, it is a growing problem,” he says.
“If they supply laptops to their employees, they are at risk.
The people who are doing this are looking for company data, they’re looking for anything that is valuable, credit card details, even just knowing that people are there.”
Rushing’s firm, based in Georgia but with an operation in Basingstoke, can advise on how firms can make their computers more secure – by supplying software to encrypt data sent over the internet and also a package that can alert a PC user to someone trying to access information.
“A cafĂŠ owner doesn’t know what the situation is with his Wi-Fi – it’s not his responsibility,” says Rushing.
“He doesn’t think about the wireless network unless a customer tells him it doesn’t work, then he unplugs it, plugs it back in and asks ‘Does it work now?’ That’s it. A lot of them, especially those which are cheap to use, or even free, are unlikely to have encrypting technology.”
With plans for Edinburgh to become a city-wide Wi-Fi hotspot underway and many Scottish cities already covered by BT’s service, businesses were keen to listen to his message, with representatives from Standard Life, ScottishPower and Royal Bank of Scotland signing up to Rushing’s seminar.
Rushing, who has worked as a computer security adviser for the likes of Siemens and General Electric, and most recently held the role of chief technical officer of VeriSign’s network security services division, adds: “People get excited by wireless networks, at home as well. They say ‘great – I can log on to my next door neighbour’s wireless!’ But that means their neighbour could possibly log on to theirs too – and potentially see all of their personal information.”
Hackers do not need special software to check on what their network co-users are up to. “It’s not like they can see your screen shot for shot,” says Rushing. “But they can see any data that is sent via the internet, on an e-mail, over a website form and so on.
“You wouldn’t put your bank details on a postcard and send it through the mail for everyone to see, so why would you send them through an insecure network?”
In addition to protecting sensitive business information, Rushing is also keen to educate workers on keeping personal data close to their chests.
“If you’re out, you have your laptop and find you’re in a Wi-Fi zone, it is fine to use the internet to do certain things like check the football scores,” he says. “But if you’re not sure the network is safe, leave checking your internet bank, or using your credit card for when you are somewhere where you know no-one can access what you are doing.”
Anna Steven, senior press officer at BT, says wireless security was a hot issue for both broadband providers and companies.
The firm, which already uses AirDefense’s systems for wireless intrusion detection in around a dozen BT buildings UK-wide, recently launched a high-security way of sharing wireless broadband with other people – by providing separate channels for different users.
Steven said: “Users need to assess what is at risk and then implement the appropriate technology to protect it.”

Russian PDF attacks surge; Microsoft takes blame

Microsoft updated a security advisory that addressed a broad flaw in Windows and said it is working around the clock to fix the bug. But it may be too late for many. Security researchers said hackers had amped up attacks using malicious PDF files that exploit the vulnerability.. Finland-based F-Secure called the surge in spam carrying the rigged PDF documents “massive” and said the run is ongoing. Ken Dunham, director of response at iSight Partners, confirmed that the number of messages hitting mailboxes with rogue PDFs soared just before the weekend. “PDF exploits are ramping up just in time for the weekend,” he said in.

The attacks, which began last week, exploit bugs in the Windows versions of Adobe Systems’ Reader and Acrobat software; Adobe patched the newest editions of those programs, but has not yet updated older variants.
According to Dunham and other researchers, the infamous Russian Business Network (RBN), a collective of cybercriminals, is behind the PDF assault. When recipients open an attack PDF, a combination of Trojan Horses, downloaders and rootkits strike, knocking out the Windows firewall and installing code that captures all information entered into any SSL-secured form on a Web page. That information is then transmitted back to RBN.
Microsoft updated its security advisory because it detected what it called “fairly limited” attacks using PDFs, said Bill Sisk, a member of the Microsoft security response team.
“This week we became aware of publicly disclosed exploit code being used in limited attacks on customers,” said Sisk in a posting to a Microsoft company blog. “This change in the threat landscape has triggered our Software Security Incident Response Plan.” Microsoft’s SSIRP coordinates its investigations with researchers from other vendors. Sisk said Microsoft had developers around the world “working around the clock” to devise a fix.
The reason Microsoft is involved is that while the current attacks are based on malformed PDFs, the real vulnerability lies in Windows XP and Windows Server 2003 code, not in Adobe’s, Sisk acknowledged. “The vulnerability mentioned in this advisory is in the Microsoft Windows ShellExecute function,” he said. “These third-party updates [such as Adobe's fix] do not resolve the vulnerability, they just close an attack vector.”
His admission is the clearest yet from Microsoft that the updates produced by Adobe and similar fixes issued by Mozilla for Firefox and Skype for its flagship VoIP software would have been unnecessary if Windows had been patched against problems in URI protocol handlers, which let browsers run other programs via commands in a URL.
This northern summer, researchers argued over who was responsible for URI protocol handler vulnerabilities that were beginning to surface. Microsoft strenuously denied that its software was at fault until earlier this month, when it issued the advisory Sisk referenced, and said it would create a patch.
“This may be Microsoft’s first public acceptance that this bug is in fact a Microsoft vulnerability,” said Andrew Storms, director of security operations at nCircle Network Security. Although Microsoft has not set a timeline for rolling out a patch to plug the hole currently used by RBN’s PDFs, Storms bet it would be next month. “It’s safe to assume Microsoft will attempt to release a patch in time for the November regular patch cycle,” he said.
The next scheduled patch day for Microsoft is November 13, more than two weeks away.
The newest PDF-based exploits, said researchers, are using different subject headings in the spam that delivers the files, and new filenames for the PDF documents. According to F-Secure, the spam messages’ subjects now include “Your credit report,” “Your Credit File” and “Personal Finance Statement.”
Another researcher, Don Jackson of SecureWorks, said that the malware eventually planted on PCs by the RBN attacks is a new variant of Gozi, a Trojan he pegged in February as responsible for the theft of at least US$2 million from bank and credit card accounts.
Gozi then and now works much the same way, Jackson said. Any information entered into a Web page form secured by SSL is nabbed, then sent to the RBM hackers. Virtually every log-on for accessing online bank or brokerage accounts and every major e-tailer order form are secured with SSL, and thus in danger of being stolen by Gozi.
Unlike in February, when RBN carelessly exposed a server containing the stolen data — which Jackson discovered — the current attack results are unknown. “They’ve gotten smarter about where they store their data.”
If Jackson is right about the RBN hackers’ technical skills, the amount they’ll steal this time should prod Microsoft to push out a patch sooner rather than later.
“These guys are good,” said Jackson. “They’re right up there with the Windows kernel developers as far as programming goes. They’re very, very talented. And once they have a foot in the door, they can use that [talent] to force their way in.”

Back to Top