Last week the US securit chiefs stated that is was bolstering its network defences following a report which claimed that China had established "information warfare units". A cyber war is on the cards. Well I wonder who is winning the war and are the Chinese the real enemies?
The US Defence Department has been forced to shut down parts of its network after a cyber attack
Taken from The Times, UK, June 22, 2007
By Holden Frith
Hackers have forced the Pentagon to shut down a large number of computers by penetrating parts of the security system.
Reports suggested that 1,500 computers were taken offline, but the US Department of Defence said it could not confirm how many computers were affected.
Navy Lieutenant Commander Chito Peppler, a Pentagon spokesman, said that some computers were still out of action after the attack, which happened on Wednesday. He said that they would be back to normal soon.
Robert Gates, the US Defence Secretary, said that the computers were shut down when a breach of the system was detected. He said the cause was being investigated.
Few details about the attack were released, but Donal Casey, a security consultant at Morse, said that the action taken by the Pentagon suggested that the breach was serious.
“The most frequent form of attack is denial of service attacks [in which hackers swamp a website by directing thousands of computers to access it simultaneously], but they can usually be handled without taking systems down,” Mr Morse said. “In this case it seems that there was an actual breach and someone was on the system.”
Lieutenant Commander Peppler said that Defence Department systems are probed every day by a wide variety of attacks.
“The nature of the threat is large and diverse, and includes recreational hackers, self-styled cyber-vigilantes, various groups with nationalistic or ideological agendas, transnational actors and nation-states,” he said.
Mr Gates said that Pentagon operations were not affected, but acknowledged that there would be “some administrative disruptions and personal inconveniences.” When asked whether he was personally affected he said: “I don’t do e-mail. I’m a very low-tech person.”
Although security for Pentagon networks is among the tightest in the world, the threat could not be completely eliminated, Mr Casey said. “By the nature of websites and e-mail systems that are public-facing, they’re always exposed,” he said.
Saturday, June 23, 2007
Hackers Breach Security At The Pentagon
Sunday, April 22, 2007
Chinese Couple Sue Yahoo! In US Over Torture Case
Taken from The Independent, UK, 20 April 2007
By Clifford Coonan
In a brave legal action against the great firewall of China, a jailed political prisoner and his wife have sued Yahoo! in a US court, accusing the internet firm of contributing to torture by helping authorities identify dissidents who were later beaten and imprisoned.
Wang Xiaoningwas imprisoned in September 2003 for 10 years for the crime of "incitement to subvert state power" after he emailed electronic journals calling for democratic reform and an end to single-party rule in a Yahoo! group in 2000 and 2001.
He was arrested by Chinese police in September 2002 and claims he was kicked and beaten during his detention.
Mr Wang and his wife Yu Ling claim the Hong Kong unit of Yahoo! provided mainland police with information linking Mr Wang to the postings, a claim that Yahoo! denies.
An engineer by profession, Mr Wang hails from Shenyang in China's industrial north-east, and he once famously described the Communist Party as "outwardly democratic but inwardly despotic" in one of his essays. Ms Yu, who lives in China still, is putting herself at risk by putting her name to the lawsuit.
The couple made their claim under US laws, which allow lawsuits from abroad to protect people against torture, and it is the first time anyone has used the legislation against an internet company for its activities in China.
The lawsuit was filed with help from the Washington-based World Organisation for Human Rights USA. In a vivid illustration of how internet censorship in China works with complicity from the big international web companies, I was unable to open the organisation's website using Google as it is blocked by the authorities.
The plaintiffs are seeking damages and an injunction to stop Yahoo! identifying political dissidents to Chinese police.
"While in custody, plaintiffs were subjected to torture and cruel, inhuman or degrading treatment, including arbitrary, prolonged and indefinite detention, for expressing their free speech rights and for using the internet to communicate about democracy and human rights matters," ran the text of their law case, filed with a district court in northern California.
This lawsuit names Yahoo!, its Hong Kong subsidiary and Alibaba.com, China's largest e-commerce firm, as defendants. The California-based Yahoo! bought a 40 per cent stake in Alibaba in a £500m deal in 2005.
China has 134 million internet users and is the world's second largest market, making it extremely attractive to the major web companies.
Google famously bowed down to the demands of the Chinese net nanny by allowing political censorship of its search engine.
Domestic internet giants such as Sohu and Baidu, along with China sites operated by Yahoo! and Microsoft, all routinely block searches on politically sensitive terms.
Blogs are regularly shut down, there are tens of thousands of net police monitoring the internet and searches are routinely blocked.
In 2005, Yahoo! was accused of supplying data that was used to jail for 10 years Shi Tao, a business journalist in Hunan province, for leaking state secrets to an overseas pro-democracy site apparently by using his Yahoo! email account.
Yahoo! sticks to its line that anyone doing business in China is forced to obey Chinese law, but human rights groups link it to a number of cases, including the case of Shi Tao, and the negative publicity has not helped Yahoo!'s image.
The human rights group Amnesty accuses Yahoo!, as well as Microsoft and Google, of facilitating or colluding in China's censorship of the net. Amnesty rejects the argument that the companies are "bringing the internet to China" , saying they are merely interested in getting into the market.
Tuesday, April 03, 2007
British Nasa Hacker Loses Extradition Fight
Taken from The Telegraph, UK, 03/04/2007
By staff and agencies
A British computer hacker accused of committing one of the largest ever cyber-attacks on the US government has lost his High Court challenge to avoid extradition to America.
Gary McKinnon, a 41-year-old former computer systems administrator known online as "Solo", had challenged a decision by John Reid to send him to the US to face trial for illegally accessing military and NASA computer systems.
A judge ruled last May that McKinnon, indicted in New Jersey and northern Virginia, should face trial in the United States and Mr Reid signed off on the request.
McKinnon, who was arrested in 2002, is accused of hacking into around 100 US government computers between February 2001 and March 2002, causing around $700,000 (£354,400) damage.
One attack, which occurred immediately after Sept 11 targeted the Earle Naval Weapons Station in New Jersey and shut down its computer system for a week.
McKinnon was caught after some of the software used in the attacks was traced back to his girlfriend's e-mail account.
The Briton had claimed he could face prosecution under US anti-terror laws and told a British court he accessed systems because he was looking for evidence that America was concealing the existence of UFOs.
But Judge Nicholas Evans said at an earlier court hearing that McKinnon had left notes on computer systems criticizing American foreign policy.
"US foreign policy is akin to government-sponsored terrorism," Judge Evans quoted one such note as saying.
Lord Justice Maurice Kay and Justice Goldring, at the High Court, said McKinnon had no grounds to appeal his extradition, but also expressed their disquiet at an alleged American threat to deny him the right to serve out part of his sentence in Britain.
McKinnon's refusal to plead guilty in the United States had earned him the ire of the American authorities, who were preparing to prosecute him as cyber-terrorist and bar him from serving out part of his sentence in Britain, his lawyers said in a statement.
"His punishment could not be more severe," the statement said. "It amounts to a life sentence in a foreign country."
McKinnon is applying to have his case heard in the House of Lords, Britain's highest court of appeal.
--------------------------------------------------------------------------
So how did he do it? The Guardian (April 3, 2007) explained everything...
With national security a primary concern after September 11, you would assume puncturing the protective layers around military computers would be of Herculean difficulty. So how did Gary McKinnon become a "master hacker"? Very easily, it turns out.
From a house in north London, Mr McKinnon - a self-confessed "bumbling computer nerd" - spent hours laboriously testing different ways of accessing US computers in his quest, he claims, to prove that UFOs exist.
After discovering the addresses of some computers at the fringes of the military system - in departments such as logistics and support - he found it easy to break in. With a management tool usually used by IT staff, Mr McKinnon was then able to work his way into networks at Nasa and the Pentagon.
The biggest loopholes had been created by users who failed to follow basic security measures - such as changing their password from the default "password".
With such glaring errors leaving the backdoor wide open to intruders, Mr McKinnon said it was a simple task to control computers remotely, from the other side of the world.
Deliberately working at times when American staff would be asleep, he would hop on to more secure systems that were impenetrable to outsiders but wide open to "trusted" users.
By time he was caught, Mr McKinnon was even leaving messages on the desktops of the computers he had hacked into.
He has admitted his efforts were more like those of the Keystone Cops than a masterful thriller. "It got a bit silly," he told the Guardian last year. "I suppose it means I'm not a secretive, sophisticated, checking-myself-every-step-of-the-way type of hacker."
Israel Tops The World In Rate Of Malicious Internet Activity
Taken from The Jerusalem Post, Mar. 31, 2007
By JOSHUA FREEMAN
Web-savvy criminals have turned Israel into the world's highest ranking source of malicious Internet activity per user, security experts have told The Jerusalem Post.
From July through December 2006, 9 percent of all such activity could be traced back to Israel. Taiwan came next with 8%, while Poland and the US tied at 6%, according to a report issued in March by security software giant Symantec, based in Cupertino, California.
For overall numbers, the US still has the most malicious activity at 31 percent. China was second with 10 percent.
"It is hard to say exactly how many people may be involved" in making money over the Internet via activities that increasingly involve the theft of sensitive personal information, said Ricardo Reznik, vice president for Marketing at Rosh Ha'ayin-based TrekIT.
"It [malicious Internet activity] is definitely being carried out mostly by organized crime groups looking for new streams of revenue rather than [by] individuals," said Reznik, whose company represents Internet security firms.
Most of the activity, according to the report, is criminal in nature and is executed by organized groups that sometimes target massive networks of users at the same time.
The sophistication of Israel's Internet users and its developed hi-tech sector have contributed to the high level of malicious Web activity, said Arie Danon, Symantec manager for the Mediterranean region.
"Some people will use their knowledge to do good and some people will use their knowledge for bad purposes," he said.
This is the first time that Symantec has included a per capita ranking for countries in its semiannual Internet Security Threat Report.
The new Symantec figure does not mean that a high proportion of Israel's 3.7 million Internet users engage in "malicious activities," cautioned Reznik.
Although Israel tops the ranking in per capita Internet abuse, in absolute terms it does not even place in the top 10, lagging far behind the top-ranked USA, the world's largest Web market, which accounts for 31% of the malicious activity.
According to Symantec, the organized malicious activity often involves propagation of viruses, "trojan horses" and other programs designed to take over target computers. Such programs may be delivered via e-mail and take over control of a victim's computer without his knowledge and/or steal sensitive information.
"It's not like 10 years ago when people were sending out viruses just to play pranks," said Amir Lev, president of Commtouch Software LPD in Netanya, a messaging and security company.
Criminal groups use viruses and trojans to set up networks of infected computers, he said. An e-mail may be used to deliver a virus that then installs a robot program, or "bot," on the user's computer. This bot program hides itself and then makes contact with a server to obtain further instructions. These servers are run by "botmasters" working for criminal groups who run "bot networks" of infected computers.
Once a botmaster has established control over a network, money can be made by using those computers to send spam advertisements for everything from pornography to cheap viagra.
Reznik chalked the high amount of criminal Internet activity here up to the fact that Israel, according to a study his company performed in February, is a large exporters of spam, accounting for approximately 2% of world junk mail in 2006.
"The figures clearly show that spammers are operating intensively in Israel on an international level" said Yaniv Barzilai, TrekIT deputy managing director of sales, referring to the TrekIT report.
Although spam is not itself considered malicious by the researchers and is not necessarily illegal, the Symantec report found that it is increasingly intertwined with malicious criminal activities.
The Knesset passed a anti-spam law in 2005 requiring that recipients "opt-in" for marketers to be able to send them spam. Regulators, however, are still largely powerless to stop international spamming networks.
"We accept that there is a big problem with spam and other [Internet] activities in Israel," said a source at the Communications Ministry. "We're looking at options in the Knesset, examining both European and American models of spam legislation to decide what's best for Israel."
He admitted, however, that he was "not sure" whether new legislation would target the worst offenders - Israelis who send illegal spam to computers all over the world as well as those who send spam solely within Israel.
According to Barzilai, the state needs to act to get such activity under control.
"Ultimately, Israel will have to contend with the problem of junk mail emanating from here, as a result of international pressure by countries or pressure from companies such as Microsoft, which has already taken action against Israeli spammers," he said.
Sunday, March 25, 2007
The Con Remains The Same (Nigerian Email Scams)
I have just received my first Nigerian email scam so I thought I'd publish this interetsing article...
Taken from The Sydney Morning Herald, Australia, February 19, 2007
By Nick Galvin
In among the offers of cheap drugs, hot share market tips and penis enlargement schemes jostling daily for attention in your inbox, you will almost certainly have received "Nigerian scam" emails.
The Nigerian scam, also know as 419 fraud after the section of the Nigerian criminal code it violates, has many variants but the basis of the con remains the same.
The victim is promised millions of dollars in exchange for helping with a scheme that in itself is quasi-legal. Once hooked, the victim is persuaded to part with increasing amounts of cash to cover "administrative" fees. In the end, the fraudster disappears with the money.
Usually these "scambaiting" emails are easily recognisable and most people do the right thing, binning them immediately. However, incredibly, the scam continues to net hundreds of millions of dollars worldwide.
This brings us to a cautionary tale from a reader, Michael (not his real name). What separates his experience from the run-of-the mill 419 scams is that the fraudsters took the extra step of finding out a lot of his personal details before contacting him.
The scam started with an email addressed personally to Michael - both his first and second name. Infuriated by this intrusion into his privacy, he did what he would normally never do and emailed back to tell "Rev F. R. James" where to stick his promise of a multi-million-dollar bequest.
"It was a stupid response," Michael says. "But I get 30 to 40 junk mails every day that I have to wade through. It was the end of a long day and I had had enough."
Another personally addressed email arrived the next day - and then the phone calls started in the early hours. "It sounded like a call centre on the other end - no one spoke - so I just slammed down the phone," he says. "It was 4am."
This was then followed up by the same calls on his mobile phone, which got the same treatment. Then, while Michael was at work, his wife received a series of calls.
"She picked up the phone and there was some person saying that they desperately wanted to speak to me," he says. "They were being really insistent and demanding. It was really scary. My wife was in tears. She was really frightened because she didn't know whether these people were down the road or overseas."
By now, Michael was seriously concerned and he took the drastic step of barring all incoming overseas calls - which is a serious inconvenience but, he says, worth it to stop the frightening messages.
Russell Smith, principal criminologist at the Australian Institute of Criminology, says personally addressed 419 emails were unusual but not unheard of.
"Most advanced-fee fraud attempts are not addressed personally but there [are many] data bases of personal information circulating among fraudsters," he says.
Michael's name could have come from such a hacked or stolen database. Smith said the other possibility was that the scammers were local and targeting people by collecting personal details online and from other sources. Michael runs a small business and its website has his contact details.
Smith's advice to anyone receiving 419-type emails is to delete them immediately. "Bin it, delete it and ignore it but certainly do not enter into any correspondence with these people," he says.
You've been warned.
-------------------------------------------------------------
Despite massive counterfeiting of U.S. currency and checks in Nigeria, the American law enforcement agency with principal jurisdiction, the Secret Service, has closed its office in Lagos, Nigeria. Nigerian officials said the decision has hurt efforts to crack down on criminal rings that produce the counterfeit currency and cheat thousands of Americans with online scams.
One of the most famous people to be duped is Ed Mezvinsky, a former Democratic Congressman from Iowa, who is serving a seven-year sentence for fraud after getting caught up in a series of Nigerian e-mail scams. Prosecutors say Mezvinsky used his connections to the Clintons and his son's social relationship with Chelsea to persuade people to give him money to participate in the scams. Mezvinsky traveled to Nigeria numerous times and ultimately lost more than $3 million as a victim of the scammers. Prosecutors say Mezvinsky fell particularly hard for what is known as the "black money" scam. Victims are told millions of dollars have been coated with black ink so the money could be smuggled out of Nigeria. Prosecutors say Mezvinsky fell for at least three separate "black money" schemes that he thought would bring him millions.
There are groups of people that are hitting back at these Nigerian scams. One of them is 419 Eater. Check out their website. It is really funny.
Here are some "must see" investigative video reports from ABC News
Confessions of a Scam Artist
Master vs. Mugu: Nigerian e-mail scams rip off millions of gullible Americans
Saturday, February 10, 2007
The Chatroom Language That Spells Danger For Your Child
With the recent discovery of a vast international child pornography ring in Austria, i have found this useful piece in the Daily Mail on secret codes Paedophiles could be using to contact our children in web chatrooms. Of course the best way to ensure our children are safe is to speak to them and tell them of the dangers. Anyway have a read...
Taken from The Daily Mail, UK, 07 Feb 2007
By LAURA CLARK
The secret language children use in online chatrooms was unveiled yesterday to help parents trap paedophiles.
Youngsters use the codes and acronyms - including MOS (Mum Over Shoulder) - when conversing about sensitive subjects with friends online.
But paedophiles have been known to deploy the same shorthand language to try to groom unsuspecting children and teenagers.
The phrases, often derived from text message slang, include NIFOC (Naked In Front Of Computer) and others which are even more direct.
The list of phrases was compiled by anti-grooming software company In Loco Parentis to mark Safer Internet Day yesterday.
Police believe that up to 50,000 sexual predators are surfing the net at any time while studies have suggested that as many as one in five youngsters has been solicited for sex online.
In Loco Parentis software designer Paul Duckett said the firm had drawn on findings from its own screening programmes to create the list.
He said: 'The words are dangerous because if you don't understand what your child is saying or who they are talking to you don't know what they are doing to do.
'You could see the initials LMIRL (Let's Meet In Real Life) and not understand your child might be planning to meet someone.'
He said that paedophiles often use questions such as 'Are your parents around?' or 'Have you got brothers and sisters?'
He added: 'They seem like low-key phrases but parents shouldn't expect to see something obvious. These are not something you can learn quickly and there are many variations.
Paedophiles try to get down to the same level as young people and try to get them to trust them to mould them to whatever they want to do.'
He warned that youngsters could be easily led into divulging personal information such as phone numbers.
Mr Duckett added: 'With a little bit of information, in a matter of minutes a paedophile could have found out their whole background, for example by tracing phone numbers.
'They can convince a child they know them and suddenly they feel comfortable and safe.'
The initiative coincided with the jailing of three paedophiles who used Internet chatrooms to plot the rape of two schoolgirls.
Two of the men discussed modelling their crimes on the Soham murdersof Holly Wells and Jessica Chapman. However they left a trail of computer 'conversation' which formed part of the case against them.
Safer Internet Day aims to raise awareness of illegal and inappropriate activity online and help safeguard children from online child abuse and cyber-bullying.
The In Loco Parentis software shuts down the computer or emails parents when a codeword from a banned list is used.
It also allows parents to monitor and screen the e-mail addresses of 'friends' their children chat to online.
The product is backed by child safety campaigner Sara Payne, whose eight-year- old daughter Sarah was murdered in 2000 by sex offender Roy Whiting.
She said: 'No parent wants to hold their children back, or stop them learning and enjoying what the Internet has to offer. But their safety should remain our number one concern.'
Millions of youngsters are registered with sites which allow users to create mini-homepages with pictures and personal profiles, such as MySpace and Bebo. Friends are also increasingly using webcams to see each other as they chat.
As a result, ministers are urging schools to teach 'safe e-etiquette' and ensure pupils are aware of their right to personal privacy.
------------------------------------------------------------
Further Reading:
Daily Mail: Online safety guide for kids