Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

Friday, 14 May 2010

Thieves Flood Victim’s Phone With Calls to Loot Bank Accounts

Bank thieves have rolled out a new weapon in their arsenal of tactics — telephony denial-of-service attacks that flood a victim’s phone with diversionary calls while the thieves drain the victim’s account of money.

A Florida dentist lost $400,000 from his retirement account last year in this manner, and the FBI said the attacks are growing.

A spokeswoman for the Communication Fraud Control Association — a telecom industry organization — told Threat Level that although fraudulent transfers have been halted in a number of cases, the losses are increasing.

“I know it’s in the millions,” said Roberta Aranoff, executive director of the CFCA. “It has exceeded a million dollars easily.”

Last November, Robert Thousand Jr., a semi-retired dentist in Florida, received a flood of calls to several phones. When he answered them, he heard a 30-second recording for a sex hotline, according to the St. Augustine Record.

In December, he discovered that $399,000 had been drained from his Ameritrade retirement account shortly after he’d received the calls. About $18,000 was transferred from his account on Nov. 23, with a $82,000-transfer following two days later. Five days after that, another $99,000 was drained, followed by two transfers of $100,000 each on Dec. 2 and 4. The thieves withdrew the money in New York.

Thousand’s son, who shares his name, received similar harassing calls, though his financial accounts were not touched. Thousand did not respond to a request from Threat Level for comment.

The FBI says the calls were a diversionary tactic, meant to tie up Thousand’s line so that Ameritrade couldn’t reach him to authenticate the money transfer requests. FBI spokesman Bryan Travers said AT&T, Thousand’s phone carrier, contacted the agency’s New Jersey office to help investigate the matter. The agency has since seen at least 16 similar cases since November, most of them occurring in the last few weeks.

In some cases, the victims simply heard dead air when they answered their phone or heard a brief advertisement or other recorded message. Some victims had to change their phone numbers to halt the harassing calls.

The perpetrator who targeted Thousand created a number of VoIP accounts, which were used with automated dialing tools to flood the dentist’s home, business and cellphone with calls.

Generally in these cases, Travers said, the thief obtains the victim’s account information through some other means — perhaps through a phishing attack or other method — and then contacts the financial institution to change the victim’s contact information. In this way, the institution will call the thief instead of the victim to verify a money transfer request.

Many banks, however, now contact customers at their previous phone number when contact information on their account has changed.

But with these attacks, the institution’s calls are prevented from reaching the victim, whose phone is tied up with a flood of diversionary calls.

AT&T spokesman Marty Richter told Threat Level that the perpetrators then generally contact the financial institution posing as the victim to complain that a requested money transfer hasn’t gone through. When the institution discloses that it tried unsuccessfully to contact the victim to authenticate the transfer, the perpetrator says he’s been having phone troubles and verifies that the transfer should proceed.

Richter says that other telecommunication companies have been alerted to the problem and are warning customers when they call to complain about harassing calls that the issue may be related to their financial accounts. The victims are warned to place fraud alerts on their financial and credit bureau accounts and block any electronic fraudulent money transfers that may be in the works.

“This may appear to some people that they’re just having a connect issue with their phone carrier,” he said, “and we want to alert them that this may not be the case.”

Travers said that in most cases so far, the victims have acted quickly enough to prevent money from being drained from their accounts, but he says there may be many other cases that haven’t yet been reported to the FBI. He urged consumers who may have been victims to contact the FBI.

Read More http://www.wired.com/threatlevel/2010/05/telephony-dos/#ixzz0nt0tgdrn
By Kim Zetter

Friday, 30 April 2010

PDF Exploits Explode, Continue Climb in 2010

Exploits of Adobe's PDF format jumped dramatically last year, and continue to climb during 2010, a McAfee security researcher said Wednesday.

Microsoft , meanwhile, recently said that more than 46% of the browser -based exploits during the second half of 2009 were aimed at vulnerabilities in Adobe's free Reader PDF viewer.

According to Toralv Dirro, a security strategist with McAfee Labs, the percentage of exploitative malware targeting PDF vulnerabilities has skyrocketed. In 2007 and 2008, only 2% of all malware that included a vulnerability exploit leveraged an Adobe Reader or Acrobat bug. The number jumped to 17% in 2009, and to 28% during the first quarter of 2010.

"In the last three years, attackers have found PDF vulnerabilities more and more useful, for a couple of reasons," Dirro said. "First of all, it's increasingly difficult for them to find new vulnerabilities with the operating system and within browsers that they can exploit across the different versions of Windows. And second, Reader is one of the most widely deployed applications that allows files to be accessed or opened within the browser."

Other factors for the jump in PDF exploits, argued Dirro, range from user belief that PDFs are safe to open, or at least safer to open than Microsoft Office documents, to the age of Adobe's code. "Quite a lot of PDF code was written years ago, and attackers are finding new security problems that no one thought of then," Dirro said. "That makes it difficult for Adobe to clean it up."

A recent discovery illustrated Dirro's point. Earlier this month, Belgium researcher Didier Stevens demonstrated how malicious PDFs could use a by-designed feature of the PDF specification to run attack code hidden in the file, and how to modify a warning message that Adobe Reader displays to further trick users into opening the document. Although some of what Stevens revealed has been publicly known for at least eight months, the technique has only been picked up by hackers in the last several weeks.

A major malware campaign using Stevens' tactics began Tuesday, with malicious PDFs attached to messages masquerading as instructions from companies' network administrators.

Microsoft also recently reported that PDF exploits remains a potent part of hackers' arsenals. In its newest Security Intelligence Report , Microsoft said that nearly half of all browser-based exploits in the second half of 2009 targeted Adobe's Reader. Three Reader vulnerabilities -- which were patched in May 2008, November 2008 and March 2009 -- accounted for more than 46% of all browser attacks.

McAfee rival Symantec has also tracked an explosion in PDF-based attacks. According to Symantec's latest Internet Security Threat Report , published last week, malicious PDFs were responsible for 49% of all Web-based attacks in all of 2009, compared to just 11% in 2008.

Like McAfee, Symantec also recorded a surge in reported Adobe Reader vulnerabilities. Of all browser plug-in bugs logged last year, 15% were in Reader's add-on for Internet Explorer, Firefox, Chrome and other Windows browsers. That was almost a four-fold increase from the 4% in 2008. And two of 2009's top five exploited vulnerabilities were in Adobe Reader.

Adobe declined to comment specifically about McAfee's and Microsoft's statistics on Reader vulnerabilities. Instead, a spokeswoman forwarded a statement the company has used before. "Given the relative ubiquity and cross-platform reach of many of our products, in particular our clients, Adobe has attracted -- and will likely continue to attract -- increasing attention from attackers," she said in an e-mail. "The majority of attacks we are seeing are exploiting software installations that are not up-to-date on the latest security updates."

The company's latest security move attempts to address the update issue; on April 13, Adobe switched on a service that silently updates customers' copies of Reader and Acrobat.

Adobe may be working on other ways to beef up Reader and Acrobat. According to one security researcher, Adobe will add sandboxing defenses to its PDF software this year. Sandboxing, perhaps best known as a technique used by Google 's Chrome browser, isolates processes from each other and the rest of the machine, preventing or hindering malicious code from escaping an application to wreak havoc or infect the computer with malware.

Adobe has acknowledged it will add sandboxing to Flash -- another of its products that is frequently targeted by exploits -- and has it at the top of its to-do list, according to Paul Betlem, senior director of Flash Player engineering.

Reader may, or may not, get sandboxing as well. When asked about the reports that Reader 10 would include sandboxing defenses, a company spokeswoman said Adobe had no announced plans but was "investigating how to get different features to work in a sandbox."

McAfee's Dirro said adding sandboxing to Adobe Reader would be a smart move. "It's one of the most useful ways to address a lot of different vulnerabilities," he said. "Sandboxing had proven to be fairly efficient at stopping attacks."

by Gregg Keizer
http://www.pcworld.com

Wednesday, 7 April 2010

SHADOWS IN THE CLOUD: Investigating Cyber Espionage 2.0

SHADOWS IN THE CLOUD:  Investigating Cyber Espionage 2.0                                                            

Thursday, 28 January 2010

Pentagon Searches for ‘Digital DNA’ to Identify Hackers


One of the trickiest problems in cyber security is trying to figure who’s really behind an attack. Darpa, the Pentagon agency that created the Internet, is trying to fix that, with a new effort to develop the “cyber equivalent of fingerprints or DNA” that can identify even the best-cloaked hackers.

The recent malware hit on Google and other U.S. tech firms showed once again just how hard it is to pin a network strike on a particular person or group. Engineers are pretty sure the attack came from China, and it sure was sophisticated enough to come from a state military like China’s. But it’s hard to say conclusively that the People’s Liberation Army launched the strike.

It’s the kind of problem Darpa will try to solve with its “Cyber Genome” project. The idea “is to produce revolutionary cyber defense and investigatory technologies for the collection, identification, characterization, and presentation of properties and relationships from collected digital artifacts of software, data, and/or users,” the agency announced late Monday.

These “digital artifacts” will be collected from “traditional computers, personal digital assistants, and/or distributed information systems such as ‘cloud computers’,” as well as “from wired or wireless networks, or collected storage media. The format may include electronic documents or software (to include malicious software - malware).”

Ultimately, Darpa wants to develop the “digital equivalent of genotype, as well as observed and inferred phenotype in order to determine the identity, lineage, and provenance of digital artifacts and users.”

“In other words,” The Register’s Lew Page notes, “any code you write, perhaps even any document you create, might one day be traceable back to you - just as your DNA could be if found at a crime scene, and just as it used to be possible to identify radio operators even on encrypted channels by the distinctive ‘fist’ with which they operated their Morse keys. Or something like that, anyway.”

The Cyber Genome project kicks off this week with a conference in Virginia.

[Photo: NASA]

By Noah Shachtman

Tuesday, 10 November 2009

Pirates get a taste of Microsoft COFEE



Microsoft's Computer Online Forensic Evidence Extractor (COFEE) software, which helps law enforcement officials grab data from password protected or encrypted sources, has leaked.

Microsoft's Computer Online Forensic Evidence Extractor (COFEE) has made it into the hands of pirates, and their virtual ships are distributing it quickly for everyone to get a taste. The COFEE application uses common digital forensics tools to help law enforcement officials at the scene of a crime gather volatile evidence of live computer activity that would otherwise be lost in a traditional offline forensic analysis. In other words, it lets officers grab data from password-protected or encrypted sources. That means you can now break the law twice over: download the software and then use it to steal information from other people's computers.

Chances are you won't have any use for the tool, but pirates get a thrill from having something they shouldn't, and a forensics tool only distributed to police departments around the world is pretty high up on the list of things you shouldn't have on your computer. The forensics tool is approximately 15MB in size and works best with Windows XP. Microsoft is working on a new version of COFEE for next year that fully supports Windows Vista and Windows 7. Here's the official description of COFEE:

With COFEE, law enforcement agencies without on-the-scene computer forensics capabilities can now more easily, reliably, and cost-effectively collect volatile live evidence. An officer with even minimal computer experience can be tutored—in less than 10 minutes—to use a pre-configured COFEE device. This enables the officer to take advantage of the same common digital forensics tools used by experts to gather important volatile evidence, while doing little more than simply inserting a USB device into the computer.

The fully customizable tool allows your on-the-scene agents to run more than 150 commands on a live computer system. It also provides reports in a simple format for later interpretation by experts or as supportive evidence for subsequent investigation and prosecution. And the COFEE framework can be tailored to effectively meet the needs of your particular investigation.

Microsoft first revealed the tool back in April 2008, so we have to say that the software giant did quite a good job keeping it away from pirates for over two years (that has to be some kind of record for Redmond). In April 2009, Microsoft announced that it will aid global law enforcement in fighting cybercrime by providing its COFEE tool free of charge to International Criminal Police Organization's (Interpol) Global Security Initiative (GSI), a project that addresses international security challenges, and the participating 187 countries. Now though, the valuable tool is available to more than just government crime fighting bodies, and we can't say we're comfortable with the possible implications.

Saturday, 19 September 2009

Why virus writers are turning to open source


Malware developers are going open source in an effort to make their malicious software more useful to fraudsters.

By giving criminal coders free access to malware that steals financial and personal details, the malicious software developers are hoping to expand the capabilities of old Trojans.

According to Candid W?est, threat researcher with security firm Symantec, around 10 percent of the Trojan market is now open source.

The move to an open source business model is allowing criminals to add extra features to their malware.

"The advantages are that you have more people involved in developing it, so someone who is into cryptography could add a cryptographic plug-in or somebody who does video streaming could add remote streaming of the desktop," W?est said.

Releasing Trojans as open source dates back to 1999, when the Cult of the Dead Cow group released the source code for its Trojan called Back Orifice.

More recently, the developers of the Limbo Trojan published its source code in an effort to boost take-up following a slump in its use by fraudsters.

Following its release in 2007, the Limbo Trojan became the most widely used Trojan in the world but fell from favor in 2008 after the more sophisticated Zeus Trojan was released, according to security company RSA.

There is a big cash incentive to be the dominant Trojan, with infected machines and the financial and personal details they capture worth millions of dollars on the black market. The Limbo Trojan kit was previously sold to fraudsters for $350 per time before it went open source, while the Zeus Trojan today sells for between $1,000 to $3,000.

"It is a move to the same business model as that behind any open source project--to give away a basic version and sell more advanced versions, professional services or customizations."
--Uri Rivner, RSA


However, head of new technologies at RSA, Uri Rivner, said the move to become open source had not reversed Limbo's decline in fortunes.

"It is a move to the same business model as that behind any open source project--to give away a basic version and sell more advanced versions, professional services or customizations.

"At the beginning of it going open source it was big news but people have since stopped investing in it.

"It is not the best Trojan any more but because it's open source you can try it as your first Trojan and it is still used in some places," he said.

Limbo's popularity continues to slump, despite numerous features in the basic version that allow criminals to add extra fields for PIN numbers into fake banking websites and capture the keystrokes and the files saved on an infected computer.

And while open source may not have boosted Limbo's fortunes, it also brings with it separate problems for the fraudsters: open sourcing code also places it in the hands of security professionals.

"If you make (the Trojan) open source, that means that a security company can find the source code and it is easier to make a general heuristic detection for it, as they know what could be in it," Symantec's W?est said.

The majority of Trojan infections occur via drive-by downloads, where the malware is automatically downloaded after browsing an infected website, or messages sent via social networking sites that encourage people to download a Trojan masquerading as a legitimate security update, according to RSA's Rivner.

These infection methods are proving far more effective at getting Trojans onto machines than earlier techniques such as sending an e-mail with a link to an infected file or attachment.

RSA analysts say these new methods have fuelled an exponential growth in the rate of infection, with the security firm detecting 613 Trojan infections in August 2008 compared to 19,102 in August 2009.

Nick Heath of Silicon.com reports from London.

Monday, 25 May 2009

Outlaw Legends: Secrets of Russian Hackers






With cybercrime on the rise worldwide, hackers from Russia and China are called the most dangerous. Though several countries say Russian virtual terrorists threaten their security, they seem impossible to catch.

That mysterious Russian hacker – is he as scary as they say?

RT caught up with a professional hacker who, for obvious reasons, chose to remain anonymous.

“Everything is dependent on computers now,” he said.

“Bank cards, phones – everything functions through a computer, through an operating system. And all of it can be broken into and destroyed.”

The hackers often do it for the cash. But more often than not, the thrill and adrenaline is what drives their curious mind.

In the past few years, the US has often fallen victim to Russian hackers. They’ve broken into the systems of major companies and even the Pentagon. As a leader in computer technology, America is a juicy target for hackers.

“I don't know if Americans are afraid of us, but we’re definitely not afraid of them,” the interviewed hacker told RT.

“Half of our country is made up of hackers, why would we be afraid of the Americans? When we are the ones stealing their products and their software.”

Virtual ‘freedom fighter’


The Russian police’s cybercrime division named 'Department K' has warned many times that Russian hackers are the strongest in the world. And it’s extremely hard to catch a hacker red-handed.

“I was arrested, taken to three prisons in three weeks,” said Dmitry Sklyarov, programmer from Moscow.

“Then I was let out on bail and couldn’t return to Russia for six months because of the American justice system."

Dmitry Sklyarov’s arrest several years ago exploded into a frenzy of outrage among the public, both in the US and abroad.

At a computer conference in America several years ago, Dmitry showed how easy it is to break through the PDF format and was arrested by the FBI. He became a symbol of the fight for programmers’ freedom, and was soon released from an American prison.

Dmitry is now an IT professor at a prestigious Russian computer science university. The pro says he has never carried out any criminal activity using his knowledge.

“Thankfully, no one ever came to me and said ‘help us commit this crime or else,” said Sklyarov.

But Dmitry says, if he had, it would have been impossible to catch him.

Human lives in hackers’ hands

Nikita Sinitsyn, Editor-in-Chief of “Hacker” magazine – a how-to Russian publication – says it’s not true all hackers are criminals. He explained to RT the scale of what a hacker can do.

“The scariest thing about what a hacker can do is not money loss, but human lives,” he said.

“Hypothetically, if a hacker broke into a system of satellite control, made satellites crash into each other and fall to Earth, let’s say, in Los Angeles, that's scary. Systems containg state secrets being broken into by hackers – maybe that’s not such a bad thing. This doesn’t influence individual human lives. That’s something that states and corporations should worry about”.

One of the problems with catching a hacker is that there is no unified international law for Internet crime. Bringing charges against someone based in another country is extremely hard to do. So until there is a strong legal mechanism against them, hackers have lots of time and opportunities to keep up the cyber attacks.

Sunday, 3 May 2009

Israeli hacker to be extradited to US

Canadian media report Ehud Tenenbaum, dubbed 'the analyzer', to be transferred to United States on charges of hacking scheme spanning hundreds of companies

sraeli hacker Ehud Tenenbaum will be extradited to the United States despite his previous requests to be tried in Canada, where he was arrested, Canadian media reported over the weekend.
Case History
Canada: Israeli hacker suspected of involvement in major fraud case / Liron Sinai
Ehud Tenenbaum, who 10 years ago hacked Pentagon computers, detained on fraud charges
Full Story
Tenenbaum, who was dubbed "the analyzer" after it was discovered that he was the mastermind behind the hacking of the Pentagon computer systems in the late 1990s, has been in Canadian custody since August 2008, when he and three Canadian accomplices were arrested for hacking into the computers of Canadian company 'Direct Cash' and stealing CDN$1.8 million.

Ehud's mother, Malka, confirmed the extradition to Ynet and explained that it was "by agreement and there's something to the reports."
Shortly after his arrest, Tenenbaum was scheduled to be released on CDN$30,000 bail. The court later denied bail after the prosecution entered into evidence documentation suggesting he is the leading suspect in a US case investigating the hackings of hundreds of companies around the world, including some in the US, Russia, Turkey, Holland, Sweden and Belgium.

Due to the scope of the fraud and the involvement of US companies and the Pentagon, the United States' Federal Bureau of Investigation (FBI) is involved in the investigation against him.

Previously, Tenenbaum and his associates opposed extradition because the charges levied against them in the United States are much more severe than those in Canada. Now, however, Tenenbaum appears prepared to agree to comply with extradition and even decided to forego a preliminary hearing on the matter.

In the past, Tenenbaum's mother told Ynet she objected to the extradition because it involved charges that had taken place over a decade ago. Regarding the recent decision, she said "I don't want to talk so that I don't ruin anything and you'll understand what I mean when the time comes. Any superfluous talk will harm my son."

by Daniel Edelson
Published: 05.03.09, 10:49 / Israel News