Thursday, February 12, 2009

U.S. And Russian Satellites Collide, 600+ Pieces of Debris

Via CBSNews -

In an unprecedented space collision, a commercial Iridium communications satellite and a defunct Russian satellite ran into each other Tuesday above northern Siberia, creating a cloud of wreckage, officials said today. The international space station does not appear to be threatened by the debris, they said, but it's not yet clear whether it poses a risk to any other military or civilian satellites.

"They collided at an altitude of 790 kilometers (491 miles) over northern Siberia Tuesday about noon Washington time," said Nicholas Johnson, NASA's chief scientist for orbital debris at the Johnson Space Center in Houston. "The U.S. space surveillance network detected a large number of debris from both objects."

Air Force Brig. Gen. Michael Carey, deputy director of global operations with U.S. Strategic Command, the agency responsible for space surveillance, said initial radar tracking detected some 600 pieces of debris. He identified the Russian spacecraft as Cosmos 2251, a communications relay station launched in June 1993, and said the satellite is believed to have been non-operational for the past 10 years or so.

"As of about 12 hours ago, I think the head count was up (to around) 600 pieces," Carey told CBS News late today. "It's going to take about two days before we get a solid picture of what the debris fields look like. But you, I think, can imply that the majority of that should be probably along the same line as the original orbits."

He said U.S. STRATCOM routinely tracks about 18,000 objects in space, including satellites and debris, that are 3.9 inches across or larger. Tracking priority and "conjunction analysis" - identifying which objects may pose a threat to manned spacecraft - is the first priority.

"It's going to take a while" to get an accurate count of the debris fragments, Johnson said. "It's very, very difficult to discriminate all those objects when they're really close together. And so, over the next couple of days, we'll have a much better understanding."

[...]

"Yesterday, Iridium Satellite LLC lost an operational satellite," the company said in a statement. "According to information shared with the company by various U.S. government organizations that monitor satellites and other space objects (such as debris), it appears that the satellite loss is the result of a collision with a non-operational Russian satellite.

[...]

"Nothing to this extent (has happened before)," he said. "We've had three other accidental collisions between what we call catalog objects, but they were all much smaller than this and always a moderate sized objects and a very small object. And these are two relatively big objects. So this is a first, unfortunately."

As for the threat posed by the debris, Johnson said NASA carried out an immediate analysis to determine whether the space station faced any increased risk. The station, carrying three crew members, circles the globe at an altitude of about 220 miles in an orbit tilted 51.6 degrees to the equator.

"There are two issues: the immediate threat and a longer-term threat," he said. "It turns out, when you have a collision like this the debris is thrown very energetically both to higher orbits and to lower orbits. So there are actually debris from this event which we believe are going through the space station's altitude already. Most of it is not, most of it is still clustered up where the event took place. But a small number are going through station's altitude.

"Yesterday, we did an assessment of what the risk might be to station and we found it's going to be very, very small. As time goes on, those debris will (come down) some over months, most over years and decades and as the big ones come down they'll be tracked, we'll see them and the worst-case scenario, we'll just dodge them if we have to. It's the small things you can't see are the ones that can do you harm."

Asked if other satellites might be at risk, Johnson said "technically, yes. What we're doing now is trying to quantify that risk. That's a work in progress. It's only been 24 hours. We put first things first, which is station and preparing for the next shuttle mission."

Most, if not all, of the debris is expected to eventually burn up in Earth's atmosphere.

'Dirty Bomb' Parts Found in Slain Man's Home

Via Bangordailynews.com -

James G. Cummings, who police say was shot to death by his wife two months ago, allegedly had a cache of radioactive materials in his home suitable for building a “dirty bomb.”

According to an FBI field intelligence report from the Washington Regional Threat and Analysis Center posted online by WikiLeaks, an organization that posts leaked documents, an investigation into the case revealed that radioactive materials were removed from Cummings’ home after his shooting death on Dec. 9.

The report posted on the WikiLeaks Web site states that “On 9 December 2008, radiological dispersal device components and literature, and radioactive materials, were discovered at the Maine residence of an identified deceased [person] James Cummings.”

The section referring to Cummings can be read here.

It says that four 1-gallon containers of 35 percent hydrogen peroxide, uranium, thorium, lithium metal, thermite, aluminum powder, beryllium, boron, black iron oxide and magnesium ribbon were found in the home.

Also found was literature on how to build “dirty bombs” and information about cesium-137, strontium-90 and cobalt-60, radioactive materials. The FBI report also stated there was evidence linking James Cummings to white supremacist groups. This would seem to confirm observations by local tradesmen who worked at the Cummings home that he was an ardent admirer of Adolf Hitler and had a collection of Nazi memorabilia around the house, including a prominently displayed flag with swastika. Cummings claimed to have pieces of Hitler’s personal silverware and place settings, painter Mike Robbins said a few days after the shooting.

Backtrack 4 Beta Public Released

Via Backtrack Blog -

Weve gone live with the beta, and the downloads are going crazy. All our mirrors are at 90 mbit, more or less.

You can get the iso here md5sum and sha512sum

And the VMWare image here md5sum and sha512sum

We are trying to get estimates of downloads. If you link to our ISOs, please use:

http://www.remote-exploit.org/cgi-bin/fileget?version=bt4-beta-iso
http://www.remote-exploit.org/cgi-bin/fileget?version=bt4-beta-vm

and do not link them directly.

Release information will shortly be available on the Remote Exploit Web site.

Los Alamos National Lab Missing 67 Computers

Via ComputerWorld -

New Mexico-based Los Alamos National Laboratory (LANL), the nation's leading nuclear weapons lab, once again finds itself the focus of concerns about potentially serious cybersecurity lapses.

The Project on Government Oversight (POGO), a watchdog group, yesterday released a memo from the Department of Energy's National Nuclear Security Administration (NNSA) expressing concern over the theft of three computers from the home of an employee at Los Alamos National Security LLC (LANS) in January.

LANS is a limited liability company comprising the University of California at Oakland, Bechtel National Inc. and two other firms that have been managing LANL since 2006.

The Feb. 3 NNSA letter expressed frustration at LANS's lackadaisical response to the theft and the apparent lack of controls aimed at preventing such incidents in the first place. It noted that follow-up inquiries about the January incident revealed that as many as 67 LANS computers are currently "missing" from the lab, including 13 that are known to have been lost or stolen. It is not clear yet whether any of the computers contained classified or sensitive information.

The memo noted that LANS originally treated the January thefts as a "property management issue." As a result, the DOE did not learn of the missing hardware right away, limiting its ability to respond quickly to the potential loss of sensitive information, the DOE said in its letter. The agency also hit "significant weaknesses in individual controls," configuration management and accountability, and said it is still unsure about the "magnitude of exposure and risk."

Citing an internal memo, POGO last week also disclosed that in a separate incident, a LANL employee had lost an official BlackBerry in a "sensitive" but undisclosed foreign nation.

Ingrid Drake, an investigator for the Washington-based POGO, said the NNSA memo shows that it feels "it has been kept out of the loop" regarding potential security lapses at LANS. It is also significant that there is continuing uncertainty whether the missing computers contained sensitive or classified data, she said.

"They say, at best, there is no sensitive information," Drake said. That suggests that no system is in place for knowing what kind of information is contained on computers used at the laboratory, or if there is one, that it isn't functioning as it should, she said.

A spokesman for the NNSA referred a request for comment on the missing computers to LANS officials, who did not immediately respond to a request for comment.

Wednesday, February 11, 2009

FTC Kills Fraudulent Online Check-Processing Operation

Via NetworkWorld -

The Federal Trade Commission today got a US District Court to permanently stop what it called illegal operations of an Internet-based check creation and delivery service and require the group to give up some $535,000 in ill-gotten gains.

According to the FTC, Qchex.com created and sent checks drawn on any bank account that a Qchex user identified but did not verify whether the user had authority to draw checks on that account. As a result, fraudsters worldwide used the Qchex service to draw thousands of checks on bank accounts that belonged to unwitting third parties. Defendants' practices harmed account holders whose bank accounts were debited without their knowledge or consent, as well as individuals and businesses who received fraudulent Qchex checks as payment for goods and services, the FTC stated.

"The evidence shows that the launch of Qchex.com was a ‘dinner bell' for fraudsters and resulted in a high number of accounts frozen for fraud . . .," said District Court Judge Janis Sammartino. "Defendants' own records show that their failure to employ and maintain adequate verification procedures, over approximately six years, led to substantial losses for consumers that had unauthorized checks drawn on their bank accounts."

The FTC complaint said in many cases scammers used a Qchex check to pay individuals or businesses for goods or services. The unwitting individual or business receiving such a check deposited it, and, because the check initially cleared, provided the goods or services to the scammers. But when the unauthorized check ultimately bounced, the amount of the check was debited from the recipient's account.

Scammers also used Qchex checks in overpayment schemes, in which the scammer overpaid an unsuspecting third party for items or services and asked that third party to wire back the difference between the price of the item or service and the amount of the bogus Qchex check. The checks initially cleared, so these recipients of Qchex checks wired the excess funds as requested. But again, when an unauthorized check ultimately bounced, the amount of the previously deposited Qchex check was debited from the victim's account, the FTC said.

The Judge's order permanently bars the operators, Neovi, from doing business as Neovi Data Corporation and Qchex.com, G7 Productivity Systems from operating a similar site without verifying that customers are authorized to draw checks from the bank accounts they have specified. Further, the court ordered the defendants to give up $535,358 in profits.

Heartland Data Breach Update: Now More Than 150 Institutions Impacted

Via BankInfoSecurity.com -

By the latest count, the number of institutions that have informed their card customers and members that they were hit as a result of the Heartland Payment Systems (HPY) data breach has swelled to 157.

Heartland, the sixth-largest payments processor in the U.S., announced on Jan. 20 that its processing systems were breached in 2008, exposing an undetermined number of consumers to potential fraud. Since then, scores of banks and credit unions from across North America have stepped forward to say their customers are among those whose cards were compromised in the breach.


While Heartland and the credit card companies remain tight-lipped about the total number of institutions and card account numbers involved, Heartland has said that, at the time of the breach, it processed an average of 100 million transactions per month for more than 250,000 different retailers and merchants.

The Independent Community Bankers of America (ICBA) conducted an informal survey of its members after the breach, asking if they had been contacted by Heartland. The survey elicited 512 responses from member banks, and 83 percent of them said they had either credit and/or debit cards affected by the Heartland breach. Only 13 percent of the banks said they didn't know yet if their customers' card accounts were compromised in the breach.

-----------------------------

Click here to see the latest up-to-date list of institutions impacted by the Heartland breach and - where available - the total number of cards compromised.

Tuesday, February 10, 2009

Helix LiveCD Sells Out To Cash In

Via DarkReading -

All good things must come to an end. That's the sentiment I'm seeing on a few forensic mailing lists in regard to the demise of the free version of the Helix incident response and forensic LiveCD.

Well, it's not exactly a demise, but what I'd say is an evolution of a really great free tool into a commercial product complete with three offerings: Helix3 Enterprise, Live Response, and Helix3.

I'm not surprised to see Helix's commercialization, but I am definitely disappointed to that there is no longer a free offering. Looking at the Website shows that e-fense has been very busy putting together a solid-looking product with Helix3 Enterprise. It has features similar to those of AccessData Enterprise, Encase Enterprise, and Mandiant Intelligent Response.

The enterprise features include software agents for endpoints, a centralized console to conduct enterprisewide investigations, and the ability to collect volatile data, including imaging memory, hard drive imaging and detection of anomalous behavior. One of the focuses of the enterprise version that may catch the eye of prospective customers is e-discovery, which has proved to be an expensive and laborious process for large organizations.

The Live Response product is a "live" incident response tool for collecting volatile information from a running Windows system. This is similar to the Microsoft COFEE tool, which raised a stink last year, and the Windows Forensic Toolchest (WFT), which is another free tool that morphed into a commercial offering.

A Helix3 LiveCD is still offered, but it is only available to members of the e-fense Forum, which is currently advertised at $14.95 a month and requires a one-year commitment. In other words, to get the new version of the Helix3 LiveCD due to be released on April 5, it's going to cost you $179.40. As long as you can make as many copies as you want to use within your enterprise on as many hosts as you want, that's a great deal considering the tool's usefulness and power.

I'll reiterate that I'm disappointed to see this change, but I think e-fense deserves a change with its new Helix3 line of products. It has been producing a very popular, well-liked tool for a number of years for free, so I hope that will encourage users to pony up the funds for the commercial version of the LiveCD and even check out the enterprise edition if it sounds like a good fit for their organizations.

I know economic times are tough, but $179.40 is nothing compared to the time that I'm sure many of you out there have saved during incident response while using Helix.

-------------------------------

I would recommend grabbing volatility for all your memory forensics needs before it goes commercial as well.

FAA Says Hackers Broke Into Agency Computers

Via NewsWeek.com -

Hackers broke into the Federal Aviation Administration's computer system last week, accessing the names and Social Security numbers of 45,000 employees and retirees.

The agency said in a statement Monday that two of the 48 files on the breached computer server contained personal information about employees and retires who were on the FAA's rolls as of the first week of February 2006.

The server that was accessed was not connected to the operation of the air traffic control system and there is no indication those systems have been compromised, the statement said.

"The FAA is moving quickly to prevent any similar incidents and has identified immediate steps as well as longer-term measures to further protect personal information," the statement said. The agency said it is providing a toll-free number for employees "who believe they may be affected by the breach."

Tom Waters, president of American Federation of State, County and Municipal Employees Local 3290, said FAA officials told unions representing agency employees at a briefing Monday that the second breached file with personal information contained encrypted medical information.

"These government systems should be the best in the world and apparently they are able to be compromised," said Waters, an FAA contracts attorney. "Our information technology systems people need to take a long hard look at themselves and their capabilities. This is malpractice in their world."

The FAA statement said the data theft has been reported to "law enforcement authorities," who are investigating.

All affected employees will receive letters notifying them of the breach, the statement said.

Waters said FAA officials told union leaders the incident was the first of its kind at the agency. But he said his union complained about three or four years ago about an incident in which employees received anti-union mail that used names and addresses that appeared to be generated from FAA computer files.

He said the union complained to the FAA and the Transportation Department's inspector general but no action was taken.

Monday, February 9, 2009

The Dangers of Our Weak Counterintelligence Efforts

Via CT Blog -

A vitally important description of one of the nation's vulnerabilities-the failure of counterintelligence- was buried in the Washington Post's Outlook section yesterday. It is worth revisiting.

The author, Michelle Van Cleave, headed the Bush administration's first congressionally mandated national counterintelligence executive, a vital mission, she writes that today, "is on life support."

It is a problem that spans the recent administrations, and one the Obama administration should address forcefully as it looks to reshape the intelligence community. The litany of reasons for the current situation, however, are familiar, including:

-lack of centralized thinking and action on the issue
-stovepiping of information
-lack of coherent policy

The lack of attention is borne out by the fact that Van Cleave was the FIRST national head of counterintelligence, appointed only in 2003.

Counterintelligence has to have true national leadership, and is too important to be left to the hodgepodge of agencies that currently carry out bits and pieces of the policy.

Why? As Van Cleave correctly notes, the Chinese have managed to steal EVERY nuclear weapons design the U.S. has, allowing them not only to leapfrog generations and billions of dollars in development, but also to identify every vulnerability in the current systems.

Russia no longer needs to rely solely on KGB thugs to carry out much of its espionage. It simply carries out the best business intelligence gathering operations through front companies, and hires lobbyists to collect other information of interest.

Most tellingly, the Islamist world is heavily invested in the United States through shell corporations and the governments that host and sponsor terrorists, from Hezbollah and al Qaeda. My full blog is here.

TightVNC Authentication Failure Integer Overflow PoC

Andres Lopez Luksenberg's exploit for Authentication Failure scenario in TightVNC.

BID 33569 CVE-2009-0388

http://www.milw0rm.com/exploits/8024

Obama Orders Review of US Cyber Security

Via Google AP -

President Barack Obama on Monday ordered a 60-day review of the nation's cybersecurity to examine how federal agencies use technology to protect secrets and data.

Obama said former Bush administration aide Melissa Hathaway will head the effort to examine all the government plans, programs and activities under way to manage massive amounts of data — everything from passport application to tax records, personal tax returns to national security documents. A failure or attack on that infrastructure could harm the country by, for example, shutting down the nation's airlines or crashing the stock market.

"The national security and economic health of the United States depend on the security, stability and integrity of our nation's cyberspace, both in the public and private sectors," said John Brennan, Obama's top adviser for counterterrorism and homeland security. "The president is confident that we can protect our nation's critical cyber infrastructure while at the same time adhering to the rule of law and safeguarding privacy rights and civil liberties."

Obama — as a candidate — was critical of President George W. Bush's efforts to protect this information. He compared cyber threats to nuclear or biological attacks on the country and pledged a cybersecurity adviser who would report directly to him.

Between his election and inauguration, Obama tasked aides with looking at the proposal. Some advised him to keep his pledge for a czar, while others advocated it go to the Homeland Security Department.

A senior administration official said the president remains committed to cybersecurity, but the official could not say if the cyber czar would be a permanent position after the 60-day review. The official spoke on the condition of anonymity to discuss internal deliberations.

Hathaway will carry the title of acting senior director for cyberspace in both the national security and homeland security councils. She led Bush's Comprehensive National Cybersecurity Initiative, which cost the government about $6 billion this budget year, and has a reputation as a leading expert on cybersecurity issues.

Her review of all government programs to address cybersecurity will include an inventory of what was already being done and recommendations on how it can improve, the official said.

The White House also has briefed members of the House and Senate intelligence committees about the move.

-----------------------------

See more over @ SecurityFocus

Pathetic DDoS vs Metasploit (Round 2)

Via Metaspoit Blog -

It looks like our little DDoS buddy got sent home from school early today -- the flood started up again, this time ignoring the DNS name for the metasploit.com web site and instead targeting both IP addresses configured on the server. While SSL service is still unaffected (including Online Update over SVN), folks who wish to visit the Metasploit web site will need to do so using an alternate port until we roll out the next countermeasure.

http://metasploit.com:8000/

We also host the main web server for Attack Research, which can now be accessed at:

http://www.attackresearch.com:8000/

Thanks for your patience,

-HD

-------------------------------------------

Also, check out this DarkReading article about Metasploit's new up and coming services...
The Metasploit hacking tool soon will come with services-based features aimed at offloading resource-intensive penetration testing tasks, as well as augmenting the popular open-source software.....The goal is to add back-end services, such as an "opcode" database client and a password-cracker to Metasploit, that seamlessly expand the tool's features and resources for its users, says HD Moore, creator of Metasploit.

Pakistani Taliban Beheads Polish Engineer in Released Video

Via FoxNews -

Poland pledges to capture and "punish" the Taliban militants who beheaded a Polish engineer in Pakistan on Friday before delivering a video of the attack to the media, the Times of London reports.

Piotr Stanczak was reportedly kidnapped four months ago while working in the Attock district — a region close to Pakistan's lawless North West Frontier Province.

A video released to media outlets Sunday shows the beheading of Stanczak just minutes after he appears on tape urging the Polish government not to send troops to neighboring Afghanistan.

On Monday, Poland's Foreign Minister Radoslaw Sikorski said the video had been authenticated and pledged to bring the terrorists to justice, according to the Times of London.

"The cassette of the execution, this bestial execution, is authentic and unfortunately it confirms the worst," Sikorski reportedly said in a statement. "Now we can no longer save our compatriot, we are going to try to punish his killers."

Sikorski promised to issue international arrest warrants for the Taliban militants, and officials charged that elements within the Pakistani government shared blame for the killing.

But Pakistan's top diplomat in Poland firmly rejected the accusation that some members of the Islamabad government are sympathetic to Islamic extremists, saying his country is snarled in a bitter fight with terrorist groups that is killing many of its own.

Stanczak's death would appear to be the first killing of a Western hostage in Pakistan since U.S. journalist Daniel Pearl was beheaded in 2002.

Mac Clone Maker Wins Legal Round Against Apple

Via ComputerWorld -

A federal judge last week ruled that Psystar Corp. can continue its countersuit against Apple Inc., giving the Mac clone maker a rare win in its seven-month-old battle with Apple.

He also hinted that if Psystar proves its allegations, others may then be free to sell computers with Mac OS X already installed.

In an order signed on Friday, U.S. District Court Judge William Alsup gave Psystar the go-ahead to amend its lawsuit against Apple. According to Alsup, Psystar may change that countersuit, which originally accused Apple of breaking antitrust laws, to instead ague that Apple has stretched copyright laws by tying the Mac operating system to its hardware.

Computer Virus Shuts Down Houston Municipal Courts

Via Chron.com (Houston) -

Houston shut down part of its municipal court operations Friday, cancelling hearings and suspending arrests for minor offenses after a computer virus infected hundreds of its machines. City officials said they expected the problems to extend at least through Monday.

Court offices will remain open to allow people to pay tickets and fines, but the dockets will have to be reset, a move that will affect thousands of cases, city officials said.

It was unclear Friday how the virus got into the system, but officials promised a thorough investigation. They could not say when they hoped to have the virus removed from the city network.

The disruption cascaded through city departments, leading police to temporarily abandon making some arrests for minor offenses. Officials also briefly disconnected the Houston Emergency Center. Although some emergency communications, such as dispatching, are routed through the center, police experienced no major disruptions, officials said.

By Friday afternoon, officials said the virus appeared to be contained to 475 of the city’s more than 16,000 computers. But the problems it caused grew so severe that city officials made an emergency purchase order for up to $25,000 to bring in Gray Hat Research, a technology security company that began trying to eradicate it through the early morning hours Friday.

“We’re working as hard as we can on it,” said Richard Lewis, the city’s information technology director. “This is a complex matter. We’re not sure what virus has attacked us. It’s going to probably be days.”

The compromise of the city networks dealt another blow to the municipal court computer system, which has been beset by problems almost as soon as it went live in April 2006.

The $10 million effort by Maximus Inc. to bring the court’s activities online was immediately troublesome to judges, clerks and prosecutors and delayed court proceedings in 2006. After threatening litigation, the city reached a $5 million settlement with Maximus and may seek another vendor.

Janis Benton, the city’s deputy director of information technology, said officials suspected the infection was a form of Conficker, the latest super virus that has breached at least 10 million computers worldwide as of late January, including the government health department in New Zealand and defense systems in France.

Conficker, also known as Downadup, infects computers via a flaw in the Microsoft Windows operating system. Microsoft issued an emergency patch back in October, and PCs that have the patch are protected from the worm.

Once on a computer, Conficker disables some of its capabilities, connects to outside servers and can download other malicious programs. It may also gather personal information and upload it to remote servers.

Because individuals and larger operations are often slow to patch their systems, Conficker has spread quickly.

Lewis said the patch almost certainly would have been installed because of protocols in place, but said he is not sure the problem is Conficker.

Kaspersky Lab Confirms SQL Injection Flaw in Site

Via ComputerWorld -

Kaspersky Lab, a Moscow-based security company, admitted today that a database containing customer information had been exposed for almost 11 days and that it only learned of the breach when Romanian hackers told the firm about it last Saturday.

"This is not good for any company, especially for a company dealing with security," said Roel Schouwenberg, a Kaspersky senior antivirus researcher, in a telephone conference call today. "This should not have happened."

According to Schouwenberg, no customer data was accessed. "No real data has been accessed, and no data was revealed," he said.

The hackers, who are presumed to be Romanian, went public early Saturday in a blog post where they claimed that after launching a SQL injection attack on Kaspersky's U.S. support site, they were able to access a customer database that included e-mail addresses and software activation codes.

Schouwenberg confirmed that the database was hacked via a SQL injection attack, but reiterated that only the database's table labels had been accessed by the hackers, not the data itself. "A more advanced hacker could have gotten access to the information," Schouwenberg admitted, "including activation codes for the product and e-mail addresses. But that didn't happen."

A pool of approximately 2,500 users' e-mail addresses, and some 25,000 activation codes were at risk, he said.

Schouwenberg blamed a combination of vulnerable code crafted by an unnamed third-party vendor and poor code review by Kaspersky. "We could have done a bit more to protect ourselves." He also acknowledged that both internal and external monitoring of the company's Web properties had not caught the error. "A piece of the [support] site did not receive the usual scrutiny," said Schouwenberg.

The revamped support site, part of the company's U.S. operations, had been relaunched Jan. 28, leaving the database open to attack from that time until 12:15 a.m. Saturday, when Kaspersky took the new site offline and swapped in the old version.

Kaspersky has hired David Litchfield, of Next Generation Security Software Ltd. and one of the world's experts on SQL injection attacks and database security, to do an independent audit of the company's systems. Schouwenberg said Kaspersky would make public the results of Litchfield's report, which is expected shortly.

"Something went wrong with our internal code reviewing process," said Schouwenberg. "Obviously we are not happy about that." Kaspersky is evaluating that process, he added, and the company "will be making it stricter than it was. We need to do a much better job to prevent this from happening again."

Top Army Biowar Lab Suspends Research After Toxin-Tracking Scare

Via Danger Room (Wired) -

When the Pentagon needs to handle the deadliest biowarfare threats, it turns to the labs of the U.S. Army Medical Research Institute of Infectious Diseases (USAMRIID) in Maryland. It's the only place in the American military complex equipped to handle the worst of the worst diseases -- those that have no cure and can are transmissible by air. Which makes it extremely unnerving, that the place had to suspend biodefense research on Friday, "after discovering apparent problems with the system of accounting for high-risk microbes and biomaterials."

That's the scoop from the new ScienceInsider blog, which notes that "the lab has been under intense scrutiny since August, when the Federal Bureau of Investigation named former USAMRIID researcher Bruce Ivins as the perpetrator of the 2001 anthrax letter attacks."

The concern this time is that the lab may not be accurately tracking the use and storage of all of its biological organisms in an internal government database -- leaving the door open to misplacement, mishandling, or worse. According to an internal memo obtained by ScienceInsider, "any materials found without a corresponding record in the database must be reported to the Vice Chief of Staff of the Army."

"I believe that the probability that there are additional vials of BSAT [biological select agents and toxins] not captured in our … database is high," institute commander Col. John Skvorak wrote.

This is not a good thing. After all the hullabaloo surrounding the Ivins case, it's a little surprising to find Army researchers reluctant to toe the line on biosecurity issues. It's not clear right now whether the issue is new regulations that need to be fine-tuned -- or scientists not worried enough about prudent security regulations. Whatever the case, we ought to expect the Army's premiere Army biodefense research lab to be leading the private and academic institutions in sound security practices. Over the past year or so, the Army has been leading the development of regulations to better safeguard its research facilities. Ironically, now that the regs are completed, it's USAMRIID itself that still needs work on tightening up its shop.

UPDATE: Rutgers University molecular biologist Richard Ebright wonders how many more biodefense labs are having problems tracking and handling deadly agents. In an e-mail to Danger Room, he notes:

  1. There currently are 400 U.S. institutions and 15,000 U.S. individuals authorized to possess bioweapons agents.
  2. Security measures at the overwhelming majority of the 400 U.S. institutions that possess bioweapons agents are inadequate.
  3. Very few of the 400 institutions has comprehensive video monitoring of work areas.
  4. Very few of the 400 institutions has a two-person rule (a rule requiring that at least two persons be present when bioweapons agents are handled).
  5. Very few of the 400 institutions perform psychological screening and psychological monitoring of personnel.

Ebright adds, "There is an urgent need to reduce sharply the number of institutions with access to bioweapons agents and to implement effective security at institutions with access to bioweapons agents."


----------------------------------------------


Shortly after the FBI closed the Amerithrax Investigation, members in Congress started to ask a very important question.
Has the unprecedented boom in biodefense research made the country less secure by multiplying the places and people with access to dangerous germs?
In the last 8 years, we have seen more money and more researchers getting access to these dangerous biological agents all against the county.

I believe everyone will agree that research is required, but without proper security measures for all of these facilities, like those outlined by Mr. Ebright, we are very likely increasing our overall risk.....

Sunday, February 8, 2009

Virtual Networking Improving Collaborative Terrorism Analysis

Via NY News Daily -

When a cell of 10 Islamic militants stole into the Indian port city of Mumbai in November and began to unleash a fusillade of hell on two hotels, a train depot in rush hour and a Jewish center, US spooks scrambled to make sense of it all. About 20 analysts from across the globe immediately convened - not in the same room, but on two classified Web sites called Intellipedia and A-space.

Think of it as Wikipedia and Facebook for spies.

The first Mumbai entry was posted by a watch officer at the National Counterterrorism Center at the onset of the attacks, officials told The Mouth. Soon, analysts from across America’s 16 spy agencies familiar with extremists in India and Pakistan logged on to A-space - a discussion site accessible to only a few thousand US intelligence analysts with the highest security clearances - to weigh who the attackers might be.

Analysts posted realtime satellite imagery and video depicting the carnage outside the Taj Mahal Hotel, which showed a sluggish response by Indian security forces. They also uploaded the first news photos of one young terrorist in Mumbai’s rail station who was later nabbed alive - noting how professionally he carried his weapons, and how he was dressed as blandly Western as the 9/11 hijackers 7 1/2 years ago.

The ad hoc group of analysts, who did not all know each other - including at least one in a Far East military outpost - quickly agreed that a claim of responsibility by the unheard of “Deccan Mujahadeen” was malarkey. It was really the handiwork of Pakistan’s Al Qaeda-affiliated Lashkar-e-Taiba.

“The analysts concluded it was LeT hours before that was made public,” said one senior US intelligence official.

The Mumbai strikes were the first big test of the new system of collaboration using social networking tools put in place last fall by Directorate of National Intelligence chief technology czar Michael Wertheimer and his crew of savvy young spooks from the Myspace Generation. There are also Top Secret elements modeled on YouTube and Flicker.

One participant in the A-space Mumbai discussion even posted an ominous message titled, “Next Mumbai: Indian Mujahadeen.” That terror group, typed the analyst a few days after the massacre of about 200 Indians, Americans and westerners, “has now threatened to carry out attacks on Mumbai, Agencies reported.”

While about 20 analysts were active in assembling, discussing and dissecting incoming intelligence and news reports on the mayhem which unfolded over three days, other simply watched and read. The sites logged more than 7,000 page views.

To avoid a repeat of politically-tainted intel on Iraq prior to the 2003 US invasion, policymakers and politicos are strictly banned from getting access to Intellipedia and A-space. About half of the roughly 9,000 intel analysts with high enough clearances have signed up to use it, officials said.

“There’s a lot of expertise and accumulated knowledge that doesn’t fit easily on a piece of paper,” Wertheimer told The Mouth in a recent interview at the DNI’s Liberty Crossing complex in Virginia.

Besides tossing around theories with other analysts, the users - who cannot post anonymously - plunge into secret databases previously off-limits to other spy agencies, though intel from the most sensitive human assets is verboten, he said. “What used to take months is taking days. What used to take hours is taking minutes,” Wertheimer added.

Analysts now compare notes from across the continent - or oceans - about targets such as Chinese submarines and North Korean and Iranian nuclear facilities. But the biggest and most heavily-trafficked A-space page is devoted to the Afghanistan-Pakistan border, where the US is battling the Taliban and hunting Al Qaeda leadership, one source said. Another page set up to collect intel on potential threats to President Obama’s Inauguration events also attracted interest, when assets such as GoogleEarth imagery and other information feeds were added.

“The last time there was an Inauguration (in 2004), you couldn’t look at realtime traffic cams,” marveled one official involved in the new program.

Pathetic DDoS vs Security Sites

Via Metasploit Blog -

On Friday, starting around 9:00pm CST, the main metasploit.com was hit with a highly-annoying, if pretty useless distributed denial of service. The attack consisted of a botnet-sourced connection flood against port 80 for the metasploit.com host name. This flood consisted of about 80,000 connections per second, all from real hosts trying to send a simple HTTP request. At the same time, Packet Storm and Milw0rm were being hit as well. About 95% of the bots would intermittently resolve metasploit.com and follow the target address with the connection flood. The other 5% continued to bang on the main metasploit.com IP address and port even after the host record was changed.

Solving this involved parking the metasploit.com host record at 127.0.0.1 and moving the other host names and services to a spare IP address. This allows for www.metasploit.com and most of our other domains and services to work properly. The only drawback is that until the flooding stops, we can't use the metasploit.com A record, which happens to be the default for updating the Metasploit Framework installation. A fun side effect is that they handed us full control of the DDoS stream: we can point the metasploit.com record anywhere we like and the connection flood will follow it.

We will continue to find other ways to mitigate the flood; but until we can safely use the metasploit.com name again, our standard online update mechanism is going to fail. If you are trying to check out a fresh copy of Metasploit from subversion, use the https://www.metasploit.com/svn/framework3/ URL for now.

As of 9:30am CST, the
Immunity web site is being hit as well. If anyone has information on the folks involved, we would love to hear from you :-)

Somali Pirates Freed Ukraine Weapons Ship for 3.2 Million

Via AllAfrica.com (2/5/09) -

Somali pirates who seized a Ukrainian vessel with controversial cargo in September have released the ship after cashing in a ransom payment, three days after a pirate kingpin was killed in Puntland, Radio Garowe reports.

The MV Faina was being held hostage off the coast of central Somalia for more than four months, making it the longest period of time a ship has been held hostage by the pirates.

A source close the ship's owners said a US$3.2 million ransom payment was given to the pirates, who had previously demanded a whopping US$25 million ransom payment when they first seized the ship.

A pirate source in the coastal town of Harardhere, central Somalia, told Radio Garowe that most armed men have gotten off the MV Faina and that the remaining few pirates would get off later Wednesday.

The MV Faina's cargo, which includes 33 Soviet-era tanks, has been the source of diplomatic and media speculation after Kenyan authorities announced that the ship was destined for the Kenyan port of Mombassa.

But other reports said the ship was ultimately destined for South Sudan, a semi-independent territory preparing for independence from Khartoum.

--------------------------------

The US Navy watched the whole thing go down....and decided not to act, on the fear of endangering 147 other seamen still held hostage on other hijacked ships.

House Intel Committee Member Reveals Secret Iraq Trip on Twitter

Via The Raw Story -

Forget anonymous leaks -- official Twitter feeds are now a source of classified government information.

Rep. Peter Hoekstra, R-Mich., helped the increasingly popular micro-blogging outlet reach a new milestone Friday, when he reported on a congressional trip to Iraq on his Twitter feed -- a trip that was supposed to be a secret.

"Heading to Iraq and Afghanistan weds night.I'll update on twitter and web pg as links are available.I'll ne back in touch mid next week," the House Intelligence Committee member wrote Tuesday.

And then, one day later, the Republican wrote: "Just landed in Baghdad. I believe it may be first time I've had bb service in Iraq. 11 th trip here."

Both of those "tweets," along with others, went against what Hoekstra had been told before leaving Washington D.C.: to keep the trip a secret. Various media outlets, including Congressional Quarterly and the Watertown Daily Times, had agreed not to disclose the trip until the the congressional delegation left Iraq.

But Hoekstra broke the story himself, so the Agence France Press noticed the representative's public-record tweets and reported on the trip.

After averaging 2-3 tweets per day earlier in the week, Hoekstra hasn't posted since Friday afternoon. Perhaps the former chairman of the House's intelligence panel -- who is routinely entrusted with some of the nation’s most closely guarded secrets -- was embarrassed.

But the delegation's trip appeared to be an educational one, according to Hoekstra's last tweet:

"Iraq! Issues! lLong term impact on containing Iran.. Need a coherent detainee strategy. Amb Crocker leaving after very successful tenure."

Computer Model Says Iran Won't Build Nuclear Bombs

Via physorg.com -

A veteran consultant to US spy agencies predicted on Saturday that Iran won't build nuclear bombs and that the power of its president Mahmoud Ahmadinejad will quickly fade. The projections are based on a gaming and computer model built by political scientist Bruce Bueno de Mesquita, an advisor to the Central Intelligence Agency and the Department of Defense.

By the start of next year, Iran will stabilize its nuclear program at a point where it makes enough weapons-grade fuel to build national pride by showing it can, but not enough to actually produce a bomb, the model predicts.

Bueno de Mesquita's computer model has reportedly been found by CIA officials to be right 90 percent of the time.

The influence of religious leaders is projected to slide while that of "moneyed interests" such as bankers and oil producers rises.

"Ahmadinejad is on the way down," Bueno de Mesquita told a Technology, Entertainment, Design Conference audience while describing how the outcomes of complex negotiations are predictable. "His clout is dropping."

Bueno de Mesquita's computer model factors in who has stakes in issues, what they say they want, and how much they could sway outcomes.

"Everything is not predictable, but most complicated negotiations are," Bueno de Mesquita said.

"It's important not just because you want to hedge funds but because what you can predict you can engineer. You can change the world."

The annual TED conference ending Saturday in California is known as a place where technology titans, political leaders, celebrities and other accomplished people collaborate to battle global ills.

Personal Info of 29,500 Kaiser Employees Stolen

Via cbs13.com -

Thousands of northern California Kaiser employees are being notified that their personal information including social security numbers was stolen from the company.

Kaiser has set-up a Employee Security Support Line for the 29,500 employees whose information was stolen to handle the situation. A recorded message on the line says that the stolen information was found in the possession of a criminal who has since been arrested. The information included employee names, social security numbers and birthdates. And that so far, only a 'few employees had been impacted'.

Kaiser says it is working with law enforcement to discover how their computer system was breached. But it does not say when the information was actually stolen or recovered.

In a statement released to CBS13, Kaiser said no patient information or health files were involved. "The file appears to contain information typically considered to be Human Resources type data. There was no Kaiser Permanente member information or personal health information involved. We regret that this unfortunate incident occurred," said Gay Westfall, Senior Vice President Human Resources, Kaiser Foundation Health Plan/Hospitals, Northern California.

Kaiser says it is notifying affected employees in three ways: by automated phone call, by letter to their home and by email at their work email address if they have one. Kaiser is also offering to pay for a year of credit monitoring for the employees.

Saturday, February 7, 2009

Kaspersky USA Site Hacked, Database Dumped

http://hackersblog.org/2009/02/07/usakasperskycom-hacked-full-database-acces-sql-injection/

Kaspersky is one of the leading companies in the security and antivirus market. It seems as though they are not able to secure their own data bases.

Seems incredible but unfortunately, its true.

Alter one of the parameters and you have access to EVERYTHING: users, activation codes, lists of bugs, admins, shop, etc.

First, lets see the version, user and name of the database.

User host & password for mysql.user

----------------------

Hat-tip to Billy Rios (XSSniper).

CIA Warns of British-Based Terrorist Threat

Via The Telegraphy UK -

American spy chiefs have told the President that the CIA has launched a vast spying operation in the UK to prevent a repeat of the 9/11 attacks being launched from Britain.

They believe that a British-born Pakistani extremist entering the US under the visa waiver programme is the most likely source of another terrorist spectacular on American soil.

Intelligence briefings for Mr Obama have detailed a dramatic escalation in American espionage in Britain, where the CIA has recruited record numbers of informants in the Pakistani community to monitor the 2,000 terrorist suspects identified by MI5, the British security service.

A British intelligence source revealed that a staggering four out of 10 CIA operations designed to thwart direct attacks on the US are now conducted against targets in Britain.

And a former CIA officer who has advised Mr Obama told The Sunday Telegraph that the CIA has stepped up its efforts in the last month after the Mumbai massacre laid bare the threat from Lashkar-e-Taiba, the militant group behind the attacks, which has an extensive web of supporters in the UK.

The CIA has already spent 18 months developing a network of agents in Britain to combat al-Qaeda, unprecedented in size within the borders of such a close ally, according to intelligence sources in both London and Washington.

Bruce Riedel, a former CIA officer who has advised Mr Obama, told The Sunday Telegraph: "The British Pakistani community is recognised as probably al-Qaeda's best mechanism for launching an attack against North America.

"The American security establishment believes that danger continues and there's very intimate cooperation between our security services to monitor that." Mr Riedel, who served three presidents as a Middle East expert on the White House National Security Council, added: "President Obama's national security team are well aware that this is a serious threat."

The British official said: "The Americans run their own assets in the Pakistani community; they get their own intelligence. There's close cooperation with MI5 but they don't tell us the names of all their sources.

"Around 40 per cent of CIA activity on homeland threats is now in the UK. This is quite unprecedented."

Explaining the increase in CIA activity over the past month, Mr Riedel added: "In the aftermath of the Mumbai attack the US and the UK intelligence services now have to regard Lashkar-e-Taiba as just as serious a threat to both of our countries as al-Qaeda. They have a much more extensive base among Pakistani Diaspora communities in the UK than al–Qaeda."

Information gleaned by CIA spies in Britain has already helped thwart several terrorist attacks in the UK and was instrumental in locating Rashid Rauf, a British-born al-Qaeda operative implicated in a plot to explode airliners over the Atlantic, who was tracked down and killed in a US missile strike in November.

----------------------------

What about Canada?

CERN Aims for "Late 2009" LHC Start-up

Via Scientific American Blog -

Here we go again. Giving doomsayers yet more time to predict the end of the Earth, the perpetually delayed restart of the Large Hadron Collider (LHC) has once again been pushed back. CERN, the European lab for particle physics that manages the mega particle accelerator, has nudged the start-up from this summer to some point later in the year at the earliest. The lab is still dealing with repercussions from a September electrical malfunction that put the kibosh on the collider's operation shortly after its initial start-up.

According to CERN, some of the magnets in the LHC's 17-mile-long tunnel will not be ready for testing until September; the lab had previously said it planned to have the collider operating by the end of June. CERN's top brass are set to meet Monday to decide on an advisory panel's recommendations for a repair-and-restart timeline that would have the LHC running by the end of the year.

Assuming the LHC is brought online by the end of the year as proposed, it will not be going full throttle. As previously planned, the collider will ease into operation with a period of reduced-energy running. Under the panel's recommendations, the LHC would run at an energy of five trillion electron-volts (5 TeV) per beam, down from its design energy of 7 TeV, until fall 2010.

"CERN’s priority for 2009 is to get collision data for the experiments, but with caution as the guiding principle," Steve Myers, the lab's director for accelerators who chaired the advisory workshop, said in a statement. "The recommendations made to the CERN management are cautious, while achieving the goal of running this year."

Warning Over the 'Surveillance State'

Via BBC -

Electronic surveillance and collection of personal data are "pervasive" in British society and threaten to undermine democracy, peers have warned.

CCTV cameras and the DNA database were two examples of threats to privacy, the Lords constitution committee said.

It called for compensation for people subject to illegal surveillance.

The government said CCTV and DNA were "essential" to fight crime but campaign group Liberty said abuses of power mean "even the innocent have a lot to fear".

Civil liberties campaigners have warned about the risks of a "surveillance society" in which the state acquires ever-greater powers to track people's movements and retain personal data.

Controversial government plans for a database to store details of people's phone calls and e-mails were put on hold late last year after they were branded "Orwellian".

Ministers are consulting on the plan, which would involve the details but not the content of calls and internet traffic being logged, saying it is essential to fighting terrorism.

The Department for Communities and Local Government said it had written to local councils to ask them to ensure surveillance powers were used "proportionately" and not for tackling minor offences such as dog fouling.

A spokesman said: "It is right and important that councils have these powers of surveillance - they are an effective means of tackling real problems that can blight communities, such as rogue traders, fly tippers and loan sharks.

"But the public must have confidence in who has these powers and that they are used in a proportionate and proper way which is why we are working closely with the home office and local government to develop training and guidance."

In its report, the Lords constitution committee said growth in surveillance by both the state and the private sector risked threatening people's right to privacy, which it said was "an essential pre-requisite to the exercise of individual freedom".

People were often unaware of the scale of personal information held and exchanged by public bodies, it said.

"There can be no justification for this gradual but incessant creep towards every detail about us being recorded and pored over by the state," committee chairman and Tory peer Lord Goodlad said.

Among areas of most concern were the growth of CCTV cameras, of which there are now an estimated four million in the UK.

The UK is said by privacy campaigners to have the most cameras per head of population in the world, but no definitive figures are available.

According to a 2004 European Commission report, Britain has the highest density of CCTV cameras in Europe. It found 40,000 cameras monitored public areas in 500 British towns and cities, compared to fewer than 100 cameras in 15 German cities and no open street CCTV at all in Denmark.

In its report, the Lords committee said the use of cameras should be regulated on a statutory basis in the UK, with a legally binding code of practice governing their use.

There was evidence of abuse of surveillance powers by some councils, with cameras wrongly being "used to spy on the public over issues such as littering".

The UK's DNA database is the "largest in the world", the report concluded, with more than 7% of the population having their samples stored, compared with 0.5% in the US.

Police in England, Wales and Northern Ireland can take DNA and fingerprints from anybody arrested on suspicion of a recordable offence and the samples can be held indefinitely whether people are charged or not.

Campaigners say anyone not convicted of a crime should have their DNA removed, a position endorsed by the European Court of Human Rights in a recent ruling in the case of two British men.

Ministers should comply with this ruling quickly, peers said, and legislate for a new regulatory framework for the database.

Other recommendations include a requirement for any new data scheme to be preceded by a public assessment of its impact on privacy and for the information commissioner to be given powers to carry out inspections on private companies.

"The huge rise in surveillance and data collection by the state and other organisations risks undermining the long-standing tradition of privacy and individual freedom which are vital for democracy," Lord Goodlad added.

"If the public are to trust that information about them is not being improperly used, there should be much more openness about what data is collected, by whom and how it is used."

---------------------------------

Of couse, it isn't just citizens in the UK that need to stop and think...this is a global issue - Japan, India, Australia, the whole EU, US and of course, the Middle East.

The surveillance state isn't coming folks...its here. It remains hidden with the help of ubiquitous technology and will continue to grow while staying just out of sight.

Thursday, February 5, 2009

TightVNC / UltraVNC Multiple Integer Overflow Vulnerabilities

The errors were found in UltraVNC 1.0.2 and 1.0.5 and TightVNC 1.3.9 and it is probable that previous versions are also vulnerable. The holes are fixed in UltraVNC 1.0.5.4 and TightVNC 1.3.10. While the new version of UltraVNC is already available, TightVNC users will have to wait till February 10th for the release of the fixed version. Users who compile TightVNC from source will find the errors already fixed in the TightVNC repository.

----------------------

Exploit Code = http://www.milw0rm.com/exploits/7990

Eleven Former Gitmo Inmates on Saudi Wanted List

Via Yahoo! News (AP) -

Saudi Arabia said Wednesday that 11 men released from the U.S. prison at Guantanamo Bay are now on the kingdom's most-wanted list despite having attended its touted extremist rehabilitation program.

President Barack Obama has signed an executive order closing the detention center at the naval base in Cuba, leaving countries scrambling over what to do with released detainees.

Saudi Arabia and terror experts defended the program for terror suspects, saying it is largely effective. The Pentagon has said it's unlikely to change its policy on prisoner transfers to the kingdom.

Saudi Arabia, the birthplace of al-Qaida leader Osama bin Laden and home to 15 of the 19 Sept. 11 hijackers, has pursued an aggressive campaign against militants but also sought to rehabilitate those it believes can abandon their violent extremist beliefs and reintegrate into society.

These rehab programs — and the kingdom's assurances that they are effective — have been a major reason why most of the Saudis have been released from Guantanamo. Only 13 of the 133 Saudis detained there remain, said Saudi Interior Ministry spokesman, Gen. Mansour al-Turki.

"Besides the 11 people (on the wanted list) who came from Guantanamo, there are still 106 people who have gone through this rehabilitation program and are doing OK," al-Turki told the Associated Press by phone. Three others committed suicide in Guantanamo.

The 11 were on a list of 83 Saudis and two Yemenis wanted for their connections to al-Qaida issued Monday by the Saudi government. The government knows where the rest of the 106 former detainees are.

Among the 11 were two Saudis who have emerged as the new leaders of Yemen's branch of al-Qaida. The two appeared in a militant video last month calling for attacks against Arab governments and Western interests.

"Imprisonment only increased our persistence in our principles for which we went out, did jihad for, and were imprisoned for," Said Ali al-Shihri said during the video. Al-Shihri was jailed for six years in Guantanamo after his capture in Pakistan, and said he resurfaced as the branch's leader after completing the Saudi rehab program.

The Saudi rehab program placed former Guantanamo detainees in secure compounds with facilities such as gyms and swimming pools. Imams gave them lessons on moderate Islam, and they met with psychologists and sociologists.

Georgetown University terror expert Bruce Hoffman stressed that the vast majority of those going through the program have not rejoined extremist groups.

"I think it would be a mistake to view the program as a failure. Instead of looking at the 11, concentrate on the (others) who have not gone back to terror. ... I think the success has been remarkable," he said.

The Pentagon also has said it is unlikely to stop prisoner transfers to Saudi Arabia. After the video of al-Shihri was released on extremist Web sites in January, Pentagon spokesman Navy Cmdr. Jeffrey Gordon said the U.S. sees the Saudi rehab program as admirable.

"The best you can do is work with partner nations in the international community to ensure that they take the steps to mitigate the threat ex-detainees pose," Gordon said.

Wednesday, February 4, 2009

Global ATM Caper Nets Hackers $9 Million in One Day

Via Wired.com -

A carefully coordinated global ATM heist last November resulted in a one-day haul of $9 million in cash, after a hacker penetrated a server at payment processor RBS WorldPay, New York's Fox 5 reports.

RBS WorldPay announced on December 23 that they'd been hacked, and personal information on approximately 1.5 million payroll-card and gift-card customers had been stolen. (Payroll cards are debit cards issued and recharged by employers as an alternative to paychecks and direct-deposit.) Now we know that account numbers and other mag-stripe data needed to clone the debit cards were also compromised in the breach.

At the time, the company said it identified fraudulent activity on only 100 cards, making it sound like small beans. But it turns out the hacker managed to lift the withdrawal limits on those 100 cards, before dispatching an global army of cashers to drain them with repeated rapid-fire withdrawals. More than 130 ATMs in 49 cities from Moscow to Atlanta were hit simultaneously just after midnight Eastern Time on November 8.

A class action lawsuit has been filed against RBS WorldPay on behalf of consumers.

A nearly identical cybercrime feeding frenzy targeted payment card company iWire in late 2007. From September 30 to October 1 of that year -- just two days -- four iWire payroll cards were hit with more than 9,000 actual and attempted withdrawals from ATM machines around the world, resulting in losses of $5 million.

A similar MO was employed against Citibank account holders last year, after a processing server that handles withdrawals from Citibank-branded ATMs at 7-Eleven convenience stores was breached. In that case, cashers converged on New York and withdrew at least $2 million from Citibank accounts, sending 70 percent of the take back to a mysterious hacker kingpin in Russia.

Could all three breaches be the work of a single wealthy cybercrook sitting on piles of cash somewhere in Moscow? Some of the cashers in the iWire and Citibank caper are cooperating with the FBI, so we may eventually find out.

What's clear is that this is a great time to be a hacker. In just over one year we've seen these kinds of breaches go from virtually unheard of into a multimillion dollar industry.

In September, Canadian police announced the arrest of Israeli hacker Ehud Tenenbaum for allegedly penetrating the Calgary-based financial services company Direct Cash Management and increasing the cash limits on prepaid debit cards he and his co-conspirators legitimately purchased. The caper allegedly netted the crooks the equivalent of $1.7 million U.S.

Despite much-ballyhooed payment card security standards, the industry responsible for protecting our money appears to be as leaky as a sieve. But, as always, consumers aren't responsible for fraudulent withdrawals that they find and promptly report to their card issuer.

SRA International Warns of Possible Data Breach

Via FCW.com -

SRA International’s computer network was infected by a virus, which may have jeopardized some federal employees’ personal information, a company spokeswoman confirmed today.

The company warned the Maryland Attorney General’s office on Jan. 20 about the incident, as SRA estimated that nearly 1,400 Maryland residents' information may be affected because of the virus.

The breached information could include names, addresses, dates of birth, health information and Social Security numbers. Personal company computers with data from questionnaires related to employees’ security positions may have been exposed to unauthorized access too, according to SRA’s notification letter.

“At this time, we have not determined that any employee, customer or project data has been compromised, but we believe it is appropriate to notify them that data may have been subject to unauthorized access,” Sheila Blackwell, vice president of communications and public affairs at SRA International, said in a statement.

Along with all current and former employees, SRA decided to warn its customers, which include federal agencies in Maryland, Nicole Betancourt, the senior corporate paralegal at SRA, wrote to Maryland authorities.

The company also said the security issue may affect more than only SRA.

There is no indication that an employee caused the problem, but SRA is continuing to investigate the incident with its in-house information technology security team and its cybersecurity experts, according to the letter.

“SRA takes the security of personal data very seriously and is committed to minimizing the risks associated with the exposure of personal information,” Betancourt wrote.

SRA received $865 million in federal contracts in fiscal 2008, and $65 million worth of its federal business was conducted in Maryland that year. The National Institutes of Health was SRA’s largest customer in Maryland in 2008. SRA provided mainly program management support services to NIH for nearly half of the $65 million, according to USASpending.gov.

CIA Guide to Analysis of Insurgency, and Other Resources

Via FAS Secrecy News -

A Central Intelligence Agency publication on the analysis of insurgencies that has often been cited but not widely circulated was recently released by CIA under the Freedom of Information Act.

“This pamphlet contains key definitions and analytic guides applicable to any insurgency…. Among other things, this guide is designed to assist in conducting a net assessment of the overall status or progress of a specific conflict,” the document (pdf) states. The CIA “Guide to the Analysis of Insurgency” is undated, but may have been written in the 1980s.

U.S. military intelligence agencies should follow the lead of Federal Express and other corporations and use “operations research” tools to guide their investment decisions and resource allocations, according to a new study by the Defense Science Board. See “Operations Research Applications for Intelligence, Surveillance and Reconnaissance” (pdf), January 2009.

The Air Force Intelligence, Surveillance and Reconnaissance Agency (AF ISR Agency) is a little-known successor of the former Air Intelligence Agency, and its mission is described in this January 27, 2009 Air Force directive (pdf).

Bill Gates Just Unleashed a Swarm Of Live Mosquitoes On A Room Full of Geniuses

Via Gizmodo.com -

In what is probably the coolest conference-talk attention grab I've ever heard of, Bill Gates apparently just released a swarm of mosquitoes into the crowd at TED, the geniuses-only mind meld. Holy shit.

"Not only poor people should experience this," the Tweetosphere has Gates saying as he released the swarm into the audience. Malaria is a cause that Bill and Melinda have been hitting hard with their philanthropy, and this is certainly a way to drive that point home.

No word yet on the size of said swarm, or confirmation that they weren't actually infected with malaria for that matter, but as far as stunts go, this is prit-tay fucking awesome. We would know.

Bravo Bill—your sense of humor does geeks proud.

----------------------------

How awesome is this?

Freaking awesome is what it is...Genius indeed. lol

Tuesday, February 3, 2009

Drive-By 'War Cloning' Attack Hacks Electronic Passports, Driver's Licenses

Via DarkReading -

With a $250 used RFID scanner he purchased on eBay and a low-profile antenna tucked away in his car, a security researcher recently cruised the streets along Fisherman's Wharf in San Francisco, where he captured -- and cloned -- a half-dozen electronic passports within an hour.

Chris Paget, who will demonstrate the privacy risks with these IDs at the Shmoocon hacker confab later this week in Washington, D.C., coined this newest RFID attack "war cloning" given its similarity to war-driving, or wireless sniffing. "War cloning -- it's the new hacker sport," he says.

The security weaknesses of the EPC Gen 2 RFID tags, which lack encryption and true authentication, have been well-known and of concern to privacy advocates for some time. These tags are being used in the new wallet-sized passport cards that the U.S. Department of Homeland Security offers under the new Western Hemisphere Travel Initiative for travel to and from Western Hemisphere countries. The e-cards are aimed at simplifying and speeding up the border-crossing process, providing U.S. Customs and border agents with information on the individual as he or she queues up to inspection booths at the border.

Until now, security researchers for the most part have shied way from hacking away at the new e-passports and e-driver's licenses to illustrate the potential privacy problems because the necessary scanners are expensive -- nearly $3,000 new -- and tough to get. "I found a way to procure equipment on the cheap and repair it and make it do exactly what I wanted it to do," Paget says.

Unlike previous RFID hacks that have been conducted within inches of the targeted ID, Paget's hack can scan RFID tags from 20 feet away. "This is a vicinity versus proximity read," he says. "The passport card is a real radio broadcast, so there's no real limit to the read range. It's conceivable that these things can be tracked from 100 meters -- a couple of miles."

Paget says he was able to drive his car at 30 miles per hour and capture an RFID tag in a matter of seconds. "The software for [copying them] lets you just choose the tag you want to copy, wave a blank tag in front of it, and it writes it out," he says.

The only protections these RFID tags include is one code that makes the tag read-only, and another that makes it self-destruct. But there are multiple ways to recover those codes, so they are basically ineffective, he says.

"This is just simply the wrong technology," says Paget, who conducted the RFID research independently. "My goal is to inform people about the risks with these things and how much impact it could have on your personal privacy and security if you don't keep [these IDs] in a protective wallet or if you carry it on your person."

Paget says the RFID chip technology found in traditional passport books, however, is better because it has encryption and authentication features. He suggests the federal government replace the e-passport RFID chips with the RFID chips used in the passport books.

For his Shmoocon presentation, Paget will borrow his boss' e-passport and clone it on-stage. "If anyone else has one they want copied, I can absolutely do that as well," says Paget, who is the technical lead for research and testing in information security at eBay. He also plans to borrow a friend's car and do a little war-driving in the nation's capital.

Monday, February 2, 2009

Monumental Video Projection: 3D Mapping Against Real World Objects

What do you get when you mix light projection holograms with real-world objects?

Something bad ass....

http://www.easyweb.fr/slideshow.html

---------------------

It reminds of me of the work done by G.R.L in the Interactive Architecture project...

http://graffitiresearchlab.com/?page_id=32#video

In Japan, Your Blood Type is Kind of a Big Deal

Via Yahoo! News (AP) -

In Japan, "What's your type?" is much more than small talk; it can be a paramount question in everything from matchmaking to getting a job.

By type, the Japanese mean blood type, and no amount of scientific debunking can kill a widely held notion that blood tells all.

In the year just ended, four of Japan's top 10 best-sellers were about how blood type determines personality, according to Japan's largest book distributor, Tohan Co. The books' publisher, Bungeisha, says the series — one each for types B, O, A, and AB — has combined sales of well over 5 million copies.

Taku Kabeya, chief editor at Bungeisha, thinks the appeal comes from having one's self-image confirmed; readers discover the definition of their blood type and "It's like 'Yes, that's me!'"

As defined by the books, type As are sensitive perfectionists but overanxious; Type Bs are cheerful but eccentric and selfish; Os are curious, generous but stubborn; and ABs are arty but mysterious and unpredictable.

All that may sound like a horoscope, but the public doesn't seem to care.

Even Prime Minister Taro Aso seems to consider it important enough to reveal in his official profile on the Web. He's an A. His rival, opposition leader Ichiro Ozawa, is a B.

Nowadays blood type features in a Nintendo DS game and on "lucky bags" of women's accessories tailored to blood type and sold at Tokyo's Printemps department store. A TV network is set to broadcast a comedy about women seeking husbands according to blood type.

It doesn't stop there.

Matchmaking agencies provide blood-type compatibility tests, and some companies make decisions about assignments based on employees' blood types.

Children at some kindergartens are divided up by blood type, and the women's softball team that won gold at the Beijing Olympics used the theory to customize each player's training.

Not all see the craze as harmless fun, and the Japanese now have a term, "bura-hara," meaning blood-type harassment.

And, despite repeated warnings, many employers continue to ask blood types at job interviews, said Junichi Wadayama, an official at the Health, Welfare and Labor Ministry.

"It's so widespread that most people, even company officials, are not aware that asking blood types could lead to discrimination," Wadayama said.

Blood types, determined by the proteins in the blood, have nothing to do with personality, said Satoru Kikuchi, associate professor of psychology at Shinshu University.

"It's simply sham science," he said. "The idea encourages people to judge others by the blood types, without trying to understand them as human beings. It's like racism."

Sunday, February 1, 2009

Blue Light Destroys Antibiotic-Resistant Staph Infection

Via ScienceDaily.com -

Two common strains of methicillin-resistant Staphylococcus aureus, commonly known as MRSA, were virtually eradicated in the laboratory by exposing them to a wavelength of blue light, in a process called photo-irradiation.

Antibiotic-resistant bacterial infections represent an important and increasing public health threat. At present, fewer than 5% of staphylococcal strains are susceptible to penicillin, while approximately 40%-50% of Staph aureus isolated have developed resistance to newer semisynthetic antibiotics such as methicillin as well.

Chukuka S. Enwemeka, Deborah Williams, Sombiri K. Enwemeka, Steve Hollosi, and David Yens from the New York Institute of Technology (Old Westbury, NY) had previously demonstrated that photo-irradiation using 405-nm light destroys MRSA strains grown in culture. In the current study, "Blue 470-nm Light Kills Methicillin-Resistant Staphylococcus aureus (MRSA) in Vitro," the authors exposed bacterial colonies of MRSA to various doses of 470-nm light, which emits no UV radiation.

The two MRSA populations studied—the US-300 strain of CA-MRSA and the IS-853 strain of HA-MRSA—represent prominent community-acquired and hospital-acquired strains, respectively.

The authors report that the higher the dose of 470-nm blue light, the more bacteria were killed. High-dose photo-irradiation was able to destroy 90.4% of the US-300 colonies and the IS-853 colonies. The effectiveness of blue light in vitro suggests that it should also be effective in human cases of MRSA infection, and particularly in cutaneous and subcutaneous infections.

"It is inspiring that an inexpensive naturally visible wavelength of light can eradicate two common strains of MRSA. Developing strategies that are capable of destroying MRSA, using mechanisms that would not lead to further antibiotic resistance, is timely and important for us and our patients," says Chukuka S. Enwemeka, PhD, FACSM, Co-Editor-in-Chief of the Journal and first author of the study.

The article will appear in the April 2009 issue (Volume 27, Number 2) of the peer-reviewed journal Photomedicine and Laser Surgery.