Showing posts with label hackers. Show all posts
Showing posts with label hackers. Show all posts

10/23/12

How To Access Fortune 500 Company Servers For $4 And Other Cyber Secrets





A Russian company called "dedicated express" is selling access to private company servers for as little as $4, according to a recent report.
Security investigative journalist Brian Krebs said in a post on his website krebsonsecurity.com Oct. 22, "The service I examined for this post currently is renting access to nearly 17,000 computers worldwide, although almost 300,000 compromised systems have passed through this service since its inception in early 2010."
Krebs says the problem stems from corporations use of 'remote access' networks, which allow workers to access their corporate desktops from home. The service is called Remote Desktop Protocol, and it's built into Microsoft Windows "to give users graphical access to the host's PC desktop."
Experts in the research community as well as in cyber security fields have raised increasingly dire warnings about U.S. cyber security. Two particularly thin skinned areas they mentioned most were infrastructure, as well as outdated networks open to employees for remote access.


Jarno Limnell, a cyber security expert, recently told Business Insider, ""Cyberwarfare is like Wild West right now, there’s a huge lack of norms and rules."

This lack of norms couldn't be exemplified any better than by this Russian website, which gleefully markets illegal access to American servers and even promises customer support if any problems occur.
They are not the only guilty party though, the U.S. is anything but a hard target. It only took getting to the letter C on an alphabetical list before Krebs found a Fortune 500 website on the "dedicated express" site. It was Cisco. Their username? "Cisco". Password? You guessed it: "Cisco."
"A contact at Cisco’s security team confirmed that the hacked RDP server was inside of Cisco’s network; the source said that it was a “bad lab machine,” but declined to offer more details," wrote Krebs.
The company can hardly blame "hackers" for stumbling on to such an obvious username and password scheme. A more complete guide for protecting usernames and passwords can be found here.
The service, according to the report, doesn't sell any hacks to Russian companies "probably because its proprietors are from that country and do not wish to antagonize Russian law enforcement officials."

10/17/12

Major Chinese Cybercriminal Gang Dismantled by Authorities, 58 Arrested





Chinese authorities have arrested a total of 58 individuals believed to be connected to what’s called the largest cybercriminal scheme that China has seen so far. The fraudsters are suspected of stealing around 300 million Yuan ($47,953,200 or 36,600,000 EUR) from their victims.
The cybercrooks used a piece of malware in order to steal online payment details. Then, they would use the stolen credentials to purchase online game credits which they sold to players.

Their targets – many of them shop owners – would be contacted via QQ messenger and presented with a hard-to-refuse offer. By tricking the users into clicking on malicious links, they could push the information-stealing virus onto their computers, Sina informs.

The Trojan they used to steal their victim’s online banking details was cleverly designed to avoid being detected by antivirus solutions. 

As a result of the police investigation, 112 computers and 456 payment cards have been seized.

8/9/11

Hacker launches volunteer program for security professionals



Renowned hacker Johnny Long drums up support for his Hackers for Charity nonprofit and announces a new InfoSec without Borders program at DefCon.
(Credit: Seth Rosenblatt/CNET)
LAS VEGAS--Johnny Long used to be known for Google hacking--finding vulnerable servers on the Internet using specific search terms. Now he's helping humanitarian groups, street kids, and police in Uganda learn how to use computers and keep malicious hackers out of their systems, as well as matching other information security professionals to charities that need help.
Long, who started the Hackers for Charity nonprofit in 2008, launched a new program at the DefCon hacker conference here this weekend that he's calling InfoSec without Borders and which is modeled after the Doctors Without Borders program.
"The volunteers are professionals in the industry now and they have a corporate responsibility" and want to help communities in need, he said. "We want to help guide that by feeding in charities that we screen."
Long's nonprofit provides free computer training to anyone who wants it, fixes computers, provides technical support to nongovernmental organizations (NGOs), and has fed thousands of families through its "food for work" program.
"We've trained street kids, the Ugandan police, government officials, Red Cross workers. We're trying to raise the level of technical ability to provide not only a service, but jobs," he said in an interview yesterday. "We have given computer training to lots of people who had absolutely no background in it. Now they have jobs and are doing things like word processing, office reception...and that kind of work is very well paid because the pool of resources there is so small."
Hackers for Charity has 30 employees and thousands of volunteers all over the world. "We've been fully embraced by the hacker community," he said, adding that the majority of the group's funding comes from hackers.
For many people, the word "hacker" conjures up images of underground criminals who break into databases and steal credit card data or the Anonymous and LulzSec groups that are really online activists described by veteran hackers as "script kiddies" who use automated tools and other less sophisticated techniques to find and exploit holes in software. But a true hacker is driven by intellectual curiosity and a challenge and has a desire to master technology and find new uses for it.
In Uganda, there's a new definition as a result of Long's work.
"The definition of 'hacker' in areas we work in Uganda has changed to 'aid worker,'" Long said. "They don't have the idea that hackers are criminals. They see us as computer wizard aid workers. That's one of the underlying things I wanted to accomplish with Hackers for Charity, to change the perception. We had been labeled as a criminal community and it's not fair."
In the 1990s, Long worked at Computer Sciences Corporation and created its Strike Force vulnerability assessment team. While there he specialized in using Google to find servers that are vulnerable to attack, sites exposing sensitive data like Social Security numbers and passwords and other things companies wouldn't want accessible via a search engine query.
After his wife went on a mission (they are both Christians) to Uganda in 2006 and shared what she had seen, Long went there and did volunteer computer repair work for an NGO whose virus-laden computer system was "a mess" and was hindering the organization's ability to keep track of contributions and be productive.
"The impact was immediate. The NGO was on the ground and up and running in two weeks, and feeding children the day we left. The last thing they said to us was 'you saved lives,'" he said. "That absolutely struck me and when I got back to the real world it was all I could think about. I wanted to use that platform to get people plugged in to that feeling of doing something positive, and to offer a positive path for hackers."
"It's hactivism by definition," Long said. "It's using technology to create social change, but it's the first example of positive hactivism I've seen."
Asked if people participating in online activism organized by the Anonymous group were hactivists, Long said: "It depends on the results of what they're doing. With Sony's site going down, you can see the immediate effect of their actions. But as to the social change, the political influence that they have, how do you measure that? A successful hactivist will be able to measure both. Personally, I have trouble seeing that impact."
Hackers for Charity is based in Jinja, which is a "stone's throw from the source of the Nile" and the second largest town in Uganda. Long's family runs a restaurant catering to Western tastes of tourists who might want a change from the typical fare of goat milk and rice. Visitors "will have a milkshake and cheeseburger and they'll drop off their laptop for a $20 repair," he said.
A lot of people are poor and turn to crime to survive. Long's family--including his three children ranging in age from nine to 15--live in a gated compound with barbed wire and an armed guard. "We have bars on every window and gates on every door," he said.
Most of the crime in Uganda is theft, he said. Computer security is practically non-existent, and that combined with the poverty is driving criminals online, according to Long, who is helping educate the Ugandan police on how to investigate everything from financial and bank fraud to credit card skimming and online scams.
"Criminals see this as a sand box to play in," he said. In addition to the work Hackers for Charity does, Long also works teaching the police about information security and connecting them to experts in the U.S. "It's basic training with the police there that can lead to training in things like forensics, he said. "We can work on cases, but we're also bringing up a generation of cyber cops in a place that has almost no infrastructure. It's unique."
Long is worried that Uganda could become another Nigeria, which is known in the online world as the birthplace of the Nigerian scam or "advance fee fraud," which features e-mails from a "barrister" who claims to be unable to access a large sum of unclaimed money without access to a bank account in a western country and offers a percentage of the money for help. By offering free computer training and other help Long hopes to help break the cycle of poverty without people having to become online thieves.
"If something doesn't change Uganda will become another Nigeria in the sense that criminals will take advantage of the technology first," he said. "We're trying to head that off as best we can."

8/7/11

AntiSec hackers post stolen police data as revenge for arrests


AntiSec released data on U.S. law enforcement officers in retaliation for arrests related to hacking attacks.
(Credit: AntiSec)
LAS VEGAS--In retaliation for arrests, the AntiSec hackers say they've released their "largest cache yet" of data stolen from law enforcement agencies in the U.S., including personal information, private e-mails, passwords, training files, data from informants, Social Security Numbers, and stolen credit card information from an online sheriff's store.
The news of the latest attacks comes on the second day of the DefCon hacker conference here, where attendees have been playing a digital hacker version of "Where's Waldo" to try to spot one of the more notorious hackers associated with the group, who goes by the handle "Sabu." Using the Twitter profile @AnonymouSabu, the hacker has been taunting others who are trying to unmask him and teasing about showing up at the conference.
The data dump, dubbed "Shooting Sheriffs Saturday Release," was done to "embarrass, discredit and incriminate police officers across the U.S.," the group said in a statement on Pastebin that estimated that there was more than 10GB of data. A sampling of the domains listed as defaced or otherwise attacked were inaccessible this morning.
A Twitter profile belonging to the hackers also said that the Web site of Italy's largest police association had been attacked. The hackers said the U.S. attack was done in response to the arrest 10 days ago of one of their associates, whose hacker handle is "Topiary."
"We are doing this in solidarity with Topiary and the Anonymous PayPal LOIC defendants as well as all other political prisoners who are facing the gun of the crooked court system...," the hackers said in the statement. "You may bust a few of us, but we greatly outnumber you, and you can never stop us from continuing to destroy your systems and leak your data."
Government and law enforcement agencies have been prime targets for the hackers. "We hope that not only will dropping this info demonstrate the inherently corrupt nature of law enforcement using their own words, as well as result in possibly humiliation, firings, and possible charges against several officers, but that it will also disrupt and sabotage their ability to communicate and terrorize communities," the statement said.
"We have no sympathy for any of the officers or informants who may be endangered by the release of their personal information," the hackers said. "For too long they have been using and abusing our personal information, spying on us, arresting us, beating us, and thinking that they can get away with oppressing us in secrecy."
The initial compromise was done about two weeks ago on Mountain Home, Arkansas-based Brooks-Jeffrey Marketing, which hosts sheriff association sites. Someone who answered the phone for Brooks-Jeffrey this morning said he would ask a representative for comment.
The hackers say they were easily able to get back into the compromised servers after they were taken offline and then put back online by the law enforcement agencies.
"It took less than 24 hours to root BJM's server and copy all their data to our private servers. Soon after, their servers were taken down and a news article came out suggesting they received advance FBI 'credible threat' notice of a 'hacking plot,'" the statement says.
"We were surprised and delighted to see that not only did they relaunch a few sites less than a week later, but that their 'bigger, faster server that offers more security' carried over our backdoors from their original box. This time we were not going to hesitate to pull the trigger: in less than an hour we rooted their new server and defaced all 70+ domains while their root user was still logged in and active."
The hackers used the stolen credit card details to make donations to the ACLU, the Electronic Frontier Foundation, and the Bradley Manning Support Network, according to the statement. The hackers are strong supporters of whistle-blower site WikiLeaks and Manning, the Army soldier arrested last year for leaking classified data to the site.
Some of the data stolen during the attack, involving Missouri sheriffs, was released a few days ago.
The hackers have been on a rampage for months (see list of recent attacks), and arrests of suspected members of their operations haven't stopped their activities. Ten days ago Scotland Yard arrested a 19-year-old who it identified as Topiary, a key member of the LulzSec hacking group. That arrest came on the heels of arrests of 16 people in the U.S., four in the Netherlands, and a 16-year-old in London as part of a global investigation into denial-of-service attacks on PayPal late last year in support of WikiLeaks, and other attacks.

Related Posts Plugin for WordPress, Blogger...