Follow us on RSS or Twitter for the latest updates.

December 29, 2012

Hackers Steals 36,000 Individual Details from US Army Database


Earlier this month, unknown hackers managed to gain illegal access to the details of around 36,000 individuals who were somehow connected to the US Army command center formerly located at Fort Monmouth.

According to APP, the details of Communications-Electronics Command (CECOM) and Command, Control, Communications, Computers, Intelligence, Surveillance and Reconnaissance (C4ISR) personnel were accessed by the hackers.

Nongovernmental personnel and Fort Monmouth visitors are also affected by the breach.

The hack, discovered on December 6, exposed names, dates of birth, social security numbers and salaries, Army representatives said. After the incident, the targeted databases have been taken offline.

CECOM and C4ISR were relocated from Fort Monmouth to Aberdeen Proving Ground back in September 2011.

The affected individuals are being offered one year of free credit monitoring services.

Author: dfgdfg,

July 21, 2012

Hacker Arrested for 2008 DDoS Attacks on Amazon.com


amazon-ddos-attack
A 25-year-old Russian hacker has been arrested for allegedly orchestrating two DDoS (Denial-of-Service) attacks on Amazon.com and eBay in 2008.

"Cyber bandit" Dmitry Olegovich Zubakha was indicted in 2011, but he was just arrested in Cyprus on Wednesday. Zubakha was arrested on an international warrant and is currently in custody pending extradition to the United States.

According to the indictment, which was unsealed on Thursday, Zubakha, with the help of another Russian hacker, planned and executed DDoS attacks against Amazon.com, eBay, and Priceline in June 2008. Zubakha and his co-conspirator launched the attack by programming botnet computers to request "large and resource intensive web pages." According to a press release by the U.S. Department of Justice (DOJ), the attacks made it "difficult for Amazon customers to complete their business on line."

Zubakha and his friend claimed credit for the attacks on online hacker forums, and law enforcement traced 28,000 stolen credit card numbers to the pair in 2009. For that reason, Zubakha and his partner are also charged with aggravated identity theft for illegally using the credit card of at least one person.

"These cyber bandits do serious harm to our businesses and their customers," said U.S. Attorney Jenny Durkan in a statement. "But the old adage is true: the arm of the law is long. This defendant could not hide in cyberspace, and I congratulate the international law enforcement agencies who tracked him down and made this arrest."

At present, the charges in the indictment -- conspiracy, intentionally causing damage toa protected computer resulting in a loss of more than $5000, possession of more than 15 unauthorized access devices (credit card numbers), and aggravated identity theft -- are just allegations. Zubakha faces up to five years in prison for conspiracy, up to teh years in prison and a $250,000 fine for intentionally causing damage to a protected computer, up to ten years in prison and a $250,000 fine for possessing unauthorized access devices, and an additional two years in prison (on top of any other sentence) for aggravated identity theft.

Author: dfgdfg,

Categories: , ,

November 1, 2011

THC SSL DoS/DDoS Tool Released For Download


A German group of Hackers known as Hackers Choice have released a program they assert will allow a single computer to take down a Web server using a secure connection

THC-SSL-DOS is a tool to verify the performance of SSL.Establishing a secure SSL connection requires 15x more processing power on the server than on the client. THC-SSL-DOS exploits this asymmetric property by overloading the server and knocking it off the Internet.

This problem affects all SSL implementations today. The vendors are aware of this problem since 2003 and the topic has been widely discussed. This attack further exploits the SSL secure Renegotiation feature to trigger thousands of renegotiations via single TCP connection.

Usage:
./thc-ssl-dos 127.3.133.7 443
Handshakes 0 [0.00 h/s], 0 Conn, 0 Err
Secure Renegotiation support: yes
Handshakes 0 [0.00 h/s], 97 Conn, 0 Err
Handshakes 68 [67.39 h/s], 97 Conn, 0 Err
Handshakes 148 [79.91 h/s], 97 Conn, 0 Err
Handshakes 228 [80.32 h/s], 100 Conn, 0 Err
Handshakes 308 [80.62 h/s], 100 Conn, 0 Err
Handshakes 390 [81.10 h/s], 100 Conn, 0 Err
Handshakes 470 [80.24 h/s], 100 Conn, 0 Err

Comparing flood DDoS vs. SSL-Exhaustion attack:

A traditional flood DDoS attack cannot be mounted from a single DSL connection. This is because the bandwidth of a server is far superior to the bandwidth of a DSL connection: A DSL connection is not an equal opponent to challenge the bandwidth of a server.

This is turned upside down for THC-SSL-DOS: The processing capacity for SSL handshakes is far superior at the client side: A laptop on a DSL connection can challenge a server on a 30Gbit link.

Traditional DDoS attacks based on flooding are sub optimal: Servers are prepared to handle large amount of traffic and clients are constantly sending requests to the server even when not under attack.

The SSL-handshake is only done at the beginning of a secure session and only if security is required. Servers are _not_ prepared to handle large amount of SSL Handshakes.

The worst attack scenario is an SSL-Exhaustion attack mounted from thousands of clients (SSL-DDoS).

Tips & Tricks for whitehats

  1. The average server can do 300 handshakes per second. This would require 10-25% of your laptops CPU.
  2. Use multiple hosts (SSL-DOS) if an SSL Accelerator is used.
  3. Be smart in target acquisition: The HTTPS Port (443) is not always the best choice. Other SSL enabled ports are more unlikely to use an SSL Accelerator (like the POP3S, SMTPS, ... or the secure database port).
Counter measurements:

No real solutions exists. The following steps can mitigate (but not solve) the problem:
  1. Disable SSL-Renegotiation
  2. Invest into SSL Accelerator
Either of these countermeasures can be circumventing by modifying THC-SSL-DOS. A better solution is desireable. Somebody should fix this.

You can download THC-SSL-DOS here:

Windows: thc-ssl-dos-1.4-win-bin.zip
Linux: thc-ssl-dos-1.4.tar.gz

Author: dfgdfg,

October 26, 2011

Anonymous Plans to Hit Fox News on November 5


The hactivist group Anonymous plans to take down the Fox News Web site on November 5, according to a new video released recently by the group.

The group said it targeted the network for what it called biased news coverage of the Occupy Wall Street protests occurring in cities across the country.

The network's "continued right-wing, conservative propaganda against the occupations" is the group's catalyst for its intention of "destroying the Fox News Web site," a digitally generated voice on the video explains. "Since they will not stop belittling the occupiers, we will simply shut them down."

The group had earlier vowed to take down Facebook on November 5 as well, although there was some question about the credibility of that threat within the hacktivist group.

The date--November 5--is commonly referred to as Guy Fawkes day in honor of the Brit who tried to blow up parliament in the Gunpowder Plot of 1604. Fawkes was immortalized in "V For Vendetta," a 2006 movie about a freedom fighter who uses terrorist tactics against a totalitarian society, and the mask that Fawkes wears has become a symbol for Anonymous.

Author: dfgdfg,

September 1, 2011

Hackers has obtain Google certificate, could hijack Gmail accounts


gmail-hacked.jpg
Hackers have obtained a digital certificate good for any Google website from a Dutch certificate provider, a security researcher said.

Criminals could use the certificate to conduct "man-in-the-middle" attacks targeting users of Gmail, Google's search engine or any other service operated by the Mountain View, Calif. company.

"This is a wildcard for any of the Google domains," said Roel Schouwenberg, senior malware researcher with Kaspersky Lab, in an email interview Monday.

"[Attackers] could poison DNS, present their site with the fake cert and bingo, they have the user's credentials," said Andrew Storms, director of security operations at nCircle Security.

Man-in-the-middle attacks could also be launched via spam messages with links leading to a site posing as, say, the real Gmail. If recipients surfed to that link, their account login username and password could be hijacked.

Details of the certificate were posted on Pastebin.com last Saturday. Pastebin.com is a public site where developers -- including hackers -- often post source code samples.

According to Schouwenberg, the SSL (secure socket layer) certificate is valid, and was issued by DigiNotar, a Dutch certificate authority, or CA. DigiNotar was acquired earlier this year by Chicago-based Vasco, which bills itself on its site as "a world leader in strong authentication."

Vasco did not reply to a request for comment.

Security researcher and Tor developer Jacob Applebaum confirmed that the certificate was valid in an email answer to Computerworld questions, as did noted SSL researcher Moxie Marlinspike on Twitter. "Yep, just verified the signature, that pastebin *.google.com certificate is real," said Marlinspike.

Because the certificate is valid, a browser would not display a warning message if its user went to a website signed with the certificate.

It's unclear whether the certificate was obtained because of a lack of oversight by DigiNotar or through a breach of the company's certificate issuing website.

Schouwenberg urged the company to provide more information as soon as possible.

"Given their ties to the government and financial sectors it's extremely important we find out the scope of the breach as quickly as possible," Schouwenberg said. The situation was reminiscent of a breach last March, when a hacker obtained certificates for some of the Web's biggest sites, including Google and Gmail, Microsoft, Skype and Yahoo.

Then, Comodo said that nine certificates had been fraudulently issued after attackers used an account assigned to a company partner in southern Europe.

Initially, Comodo argued that Iran's government may have been involved in the theft. Days later, however, a solo Iranian hacker claimed responsibility for stealing the SSL certificates.

Kaspersky's Schouwenberg said "nation-state involvement is the most plausible explanation" for the acquisition of the DigiNotar-issued certificate.

"For one [thing], there's the type of information being looked for -- from Google users," said Schouwenberg. "This hints towards an intelligence operation rather than anything else. Secondly, this type of attack only works when the attacker has some control over the network, but not over the actual machine."

Others were more skeptical because of the claim that a single hacker pulled off the Comodo heist.

"I think it might still be a stretch to attribute this to the Iranian government," said Marlinspike on Twitter shortly before 4 p.m. ET. "We all know how that went last time."

The google.com certificate has not yet been revoked by DigiNotar -- the first step to blocking its use -- even though it was issued July 10.

Last March, browser makers, including Google, Microsoft and Mozilla, rushed out updates that added the stolen Comodo certificates to their applications' blacklists.

Storms said he expected Google to quickly update Chrome, and that Microsoft, Mozilla and other would do the same some time later. "I suspect that if asked [Microsoft and Mozilla] will also issue updates, as there is already a precedent," said Storms.

Author: dfgdfg,

August 8, 2011

DefCon: The World’s Largest Hackers Conference


r-DEFCON-HACKER-CONFERENCE-large570
Hackers compete in a digital capture the flag game at the DefCon conference

There are so many ways to get hacked at the world’s largest hacker conference.

A hacker could bump against your pocket with a card reader that steals your credit card information. Or a hacker might eavesdrop on your Internet traffic through an unsecured Wi-Fi network. Or a hacker might compromise your cell phone while you charge it in the hotel’s public phone-charging kiosk.

The Internet connection here has been dubbed "the world’s most hostile network." You might want to avoid the A.T.M.'s, too.

Welcome to DefCon, where thousands of the world's best code crackers gather each year to discuss the latest hacking techniques -- then occasionally try them out on each other.

More than 10,000 hackers and security experts have descended upon the Rio Hotel and Casino in Las Vegas this weekend for three days of lectures and contests.

Admission to DefCon, now in its 19th year, is $150, far less than Black Hat, a cybersecurity conference held earlier this week at nearby Caesar’s Palace that cost around $1,500.

At both conferences, hackers can make a name for themselves by demonstrating how they found security flaws in technology that most observers would consider well-protected or harmless.

At DefCon this year, there are presentations on how to hack office printers, wireless water meters, smart phones, laptop batteries and the network used at correctional facilities to open and close prison doors.

For the paranoid, there is a presentation on how to destroy data if you're "convinced that the black helicopters are incoming and ruthless feds are determined to steal your plans for world domination," according to the conference program.

The conference also offers more than 50 games and contests to challenge hackers. In one room, techno music thumps over loud speakers as teams of hackers hunched over laptops try to steal files from each other in a game called "Capture the Flag."

Another game gives contestants five minutes to hack into a voting machine. Yet another contest, called "Crack Me If You Can," challenges teams to crack as many passwords as possible in 48 hours; the winner gets $600.

Some DefCon attendees complained Friday on Twitter that A.T.M.'s inside the convention hotel were out of service. To some, this was no surprise. After all, hacker Barnaby Jack demonstrated at Black Hat last year how to hack into an A.T.M. Two years ago, a malicious A.T.M. was placed at DefCon and stole data from conference attendees before it was detected.

Some companies see the hacker conference as a place to scout for new talent. In June, Facebook hired George Hotz, the young hacker who gained notoriety in 2007 for "jailbreaking" Apple's iPhone, getting around the phone's software controls.

Companies exposed for weak security are not the only ones being embarrassed at DefCon. If a conference attendee logs on to her email account, for example, using an unsecured wireless network, her username and password are posted on an electronic board known as the "Wall of Sheep."

Brian Markus, chief executive of Aries Security, said his company runs the "Wall of Sheep" to teach a lesson on Internet security. He compared using unsecured networks to the free-love ethic of the 1960s and 1970s when many people had unprotected sex.

"Today, everybody is connected and they need to go out and get protection because the environment has changed," Markus said.

Most DefCon attendees are particularly cautious about security, going so far as to use only their online nicknames at the conference. Many attendees are young, wear dark clothes and sport a wide range of hairstyles -- including mohawks -- with enough hair colors represented to match a Crayola box.

Not everyone here is a hacker, though. Employees of federal agencies also attend, giving panel discussions and inspiring a traditional game among hackers at DefCon called “Spot the Fed.”

Friday's program included a beer-chilling contest, where contestants competed to cool beer that had been sitting in the hot desert sun. Two participants, Chris McMinn and Chris Lopez, built an 11-foot-long contraption from aluminum and steel pipes that they said cools beer from 90 degrees to 40 degrees in four seconds.

They did not win the contest, but they didn't seem to care.

"We did it more for the glory," Lopez said. "All of our science teachers would be very proud."

McMinn added: "Where else would you chill beer for sport?"

Author: dfgdfg,

June 10, 2011

FBI site hacked; NATO challenged


The same group, "LulzSec," that attacked Sony Corp's film site also went to destroy an FBI-affiliated Web site in Atlanta in retribution to the NATO alliance's "act of war" against hackers.

LulzSec on June 6 said in its Web site http://lulzsecurity.com that in response to NATO's and U.S. President Barrack Obama's decision to up the stakes with regard to hacking and now treat hacking as "an act of war", the group just hacked an FBI affiliated Web site, Infragard, specifically the Atlanta chapter.

The hackers said they leaked the user base, including the 180 accounts.  "Most of them reuse their passwords in other places, which is heavily frowned upon in the FBI/Infragard handbook and generally everywhere else too," the group said.

LulzSec's identified one of its victims, Karim Hijazi, who allegedly used his Infragard password for his personal Gmail, and the Gmail of the company he owns.  "Unveillance, a whitehat company that specializes in data breaches and botnets, was compromised because of Karim's incompetence.  We stole all of his personal emails and his company emails.  We also briefly took over, among other things, their servers and their botnet control panel," the hackers said.

LulzSec said that after informing Karim, he offered to pay the group to eliminate his competitors through illegal hacking means in return for the group's silence.

NATO vs Hackers

A report by NATO, a powerful military alliance of countries from North America and Europe, noted that the Internet has made state and society much more vulnerable to attacks such as computer intrusions, scrambling software programs, undetected insiders within computer firewalls, or cyber terrorists.

NATO Parliamentary Assembly General Rapporteur Lord Jopling said in his report that Anonymous, a prominent group of on-line hackers, poses a hazard that needs to be taken seriously.

Anonymous has led a campaign against companies stopped providing services for WikiLeaks, which released the US diplomatic cables and other sensitive information.  The U.S. government received the most serious blow when the "anti-secrecy" organization WikiLeaks published, among other things, Pentagon documents on the Afghan war and the Iraq War and 250,000 confidential US diplomatic cables on diplomats' candid assessments of terrorist threats and the behaviour of world leaders.

According to the NATO report, the US authorities suspect that the material was leaked by Private Bradley Manning stationed in the Persian Gulf who passed these files on to the "whistleblower" organization.

Anonymous earlier launched a campaign against Iran, Australia and the Church of Scientology. In its on-line seven-point manifesto, Anonymous announced its engagement in "the first infowar ever fought" and named PayPal as its enemy.  Anonymous has also been linked to the first cyber attacks against Sony.

Jopling warned that Anonymous could potentially hack into sensitive government, military, and corporate files.

He suggested, among many things, that on the global level, NATO should support initiatives to negotiate at least some international legal ground rules for the cyber domain.  He added that NATO should consider applying common funding procedures for procurement of some critical cyber defence capabilities for its member states.

Jopling stated, "As sources of cyber attacks are usually impossible to trace, it cannot be said with certainty who has, so far, dominated "the cyber world".  Nevertheless, when it comes to the involvement of states in cyber attacks, Russia and China are said to be the usual suspects.  From what we know today, terrorist groups such as al Qaeda do not yet have the capability to carry out such attacks.  In the future, however, organized crime and hacker groups could sell their services to terrorist groups."

"We accept your threats, NATO.  Game on, losers," LulzSec said, in a press release announcing its hacking of the FBI affiliated site.

Author: dfgdfg,

Categories: , , , ,