Behind the Internet Wheels of Steel - Recording Live From Somewhere - Mixing the Fresh Beats of Technology, Intelligence, Science & Security together with the occasional bass-heavy break of Humor.
"There is no security on this earth, there is only opportunity"
- General Douglas MacArthur (1880-1964)
Wednesday, August 26, 2009
Social Networks Leak Personal Information
Online social networking sites leak personal information, a new study has found, raising the possibility that users of such sites can be tracked everywhere they go online.
The study, "On the Leakage of Personally Identifiable Information Via Online Social Networks," was co-authored by Balachander Krishnamurthy, a researcher at AT&T Labs and Craig E. Wills, a professor of computer science at the Worcester Polytechnic Institute in Massachusetts, and presented last week at the Second ACM SIGCOMM Workshop on Online Social Networks in Barcelona, Spain.
The researchers say that social networks leak information through a combination of HTTP header information -- the Referer header and the Request-URI -- and cookies sent to third-party aggregators such as Google (NSDQ: GOOG)'s DoubleClick, Google Analytics, and Omniture, among others.
As a consequence of this leakage, third-party aggregators can potentially link social network identifiers to past and future Web site visits, thereby identifying a person and his or her online activities.
"The ability to link information across traversals on the Internet coupled with the wide range of daily actions performed by hundreds of millions of user on the Internet raises privacy issues, particularly to the extent users may not understand the consequences of having their PII [personally identifiable information] available to aggregators," the study states.
The study notes that while the privacy policies of the third-party aggregators typically declare the sharing of non-indentifying information, they don't make it clear that an identity can often be derived from supposedly non-identifying information.
"What we are clearly trying to establish with this work is that these third party companies are receiving information about us from online social networks," said Wills in a phone interview. "When you or I create an account on an online social network, there's a unique identifier that's always associated with your account. That account number is being passed along to these third party aggregators. And along with the cookies these aggregators are already maintaining, they now can link that cookie to a social network identifier."
The study looked at twelve social networking sites: Bebo, Digg, Facebook, Friendster, Hi5, Imeem, LinkedIn, LiveJournal, MySpace, Orkut, Twitter, and Xanga.
"Not only do they know where I'm visiting, they know who I am," said Wills. "And that's disconcerting."
Many social networking sites provide privacy controls to limit information disclosure, but the report found that between 55% and 90% of users -- Wills suggests it's closer to 70% on the lower end -- of social networking services keep the default privacy settings for allowing strangers to view profile information and 80% to 97% keep the default privacy settings for viewing friends.
The report does not suggest that there's misuse of this information by third party aggregators and notes that contracts between social networking sites and third party aggregators may require aggregators not to use identifying information.
Facebook did not respond to a request for comment.
Opening the First Generation Mul-T-Lock Cliq with Vibration
I have been looking forward to the HAR conference for a long time. After all, it was going to be the moment to publicly talk about our discovery on bypassing the electronic locking part on the first generation Mul-T-Lock Cliq. More then one year ago we discovered the samples we had in some instances could be opened with the so called ‘magnetic ring’ (you still needed to have the correct mechanical key or bypass the mechanical part). An important discovery as the attack would not show up in the electronic logfile in the lock. And the integrity of the logfile is a key issue in these kind of systems. So we immediately informed Mul-T-Lock about this problem. And even though communication did not always go smooth we came to an agreement. We agreed to go into full detail about this at the HAR conference in 2009. And that is what we just did. At the presentation we showed the problem was not magnetism … it was vibration!
Tuesday, August 25, 2009
PCI Council Releases Recommendations For Preventing Card-Skimming Attacks
The PCI Security Standards Council (PCI SSC) today unveiled best practices for retailers to defend themselves against the growing number of credit- and debit-card skimming scams.
Skimming credit- and debit-card data is becoming a popular way for cybercriminals to steal credit and debit card account numbers and execute financial fraud against grocery stores, gas stations, convenience stores, and other retailers and their customers, who are increasingly falling victim to hijacked card readers and ATM machines. Skimming occurs either by a malicious insider at the retail point-of-sale capturing the customer's card data, or more commonly by someone physically rigging a reader with a sniffer-type device to capture the data, which is then transmitted to the bad guys remotely.
"Skimming is becoming a widespread problem. These are guidelines for what retailers should be looking at" with their reader devices, says Bob Russo, general manager of the PCI SSC. "We discuss different techniques for protecting those point-of-sale devices."
But security experts say the council's skimmer protection guidelines are more a symptom of the already-broken system of credit and debit cards. "The concept of a 'credit card' as it exists today is the problem: If credit cards were cryptographic devices rather than just numbers, then none of these threats would be a problem," says Chris Paget, a security researcher. "The technology exists to implement this today and to completely eliminate credit card fraud, but it seems there's too much money being made from fraud for the card issuers to care."
Paget says the PCI guidelines are missing two key elements of this type of fraud: a malicious merchant stealing the data, and equipment tampered with at the factory. "If the person you give your card to at a restaurant has their own card skimmer, you're just as vulnerable," he says.
Legitimate card-reader equipment is also being compromised at the factory, so when merchants receive their new terminal, it could arrive rigged. "[The guidelines] do not address the case of legitimately purchased equipment that was tampered with at the factory, nor the case of a software-only addition to an ATM or card reader," says Paget, who himself fell victim to an ATM scam in Las Vegas during the Defcon17 conference.
[...]
The PCI Council's "Skimming Prevention: Best Practices for Merchants" guidelines, meanwhile, include a risk assessment questionnaire and self-evaluation forms to help retailers gauge their susceptibility to these types of attacks and to determine where they need to shore up their defenses. The guidelines cover how to educate and protect employees who handle the PoS devices from being targeted, as well as ways to prevent and deter compromise of those devices. They also detail how to identify a rigged reader and what to do about it, and how physical location of the devices and stores can raise risk.
The guidelines are geared to be used in conjunction with the PCI's PIN Entry Device Security Requirements, which specifies how to secure PIN devices.
PCI's Russo says the guidelines are for all sizes of retailers, but are especially geared for helping mom-and-pop retailers: "A small merchant that makes pizza isn't going to know much when someone with a terminal shows up with a business card and says he's there to put in a replacement, but is doing something [malicious] with it and leaving it there," PCI's Russo says.
Among some of the information in the guidelines is how to look for signs of physical tampering and how to monitor the device for that. "Write down the serial number on your terminal and look at what the terminal looks like. Does it have seals on it? A label on the back? What color wires go to it?" he says. "Once a quarter, take a look at it and make sure it's intact."
"Most of this stuff is common sense, and that's where most of the fail happens," adds Michael Rothman, senior vice president of strategy at eIQnetworks. "But in reality, skimming defense is really more about process and education. People on the front lines need to know what to look for -- and that is a huge challenge. But it always has [been]."
But skimming is typically more about adding a layer to the existing device that can't be detected, he says, so the guidelines may not be effective in those cases.
Meanwhile, Paget says credit card companies need to wake up. "Credit cards as they exist today are the financial equivalent of a Telnet login session over the Internet. It's about time the dominant payment infrastructure upgraded to SSL [Secure Sockets Layer] and got rid of all of these attacks -- and more -- at once," he says.
Apple Adds Malware Blocker in Snow Leopard
Apple’s commercials may give the impression that Macs are virus-free (.mov) but the company isn’t taking any chances with the newest Mac OS X refresh.
Apple has quietly added a new Snow Leopard feature to scan software downloads for malware, a no-brainer move that coincides with a noticeable spike in malicious files embedded in pirated copies of Mac-specific software.
The malware blocker, first spotted by the folks at Intego, appears to be scanning installation packages for signs of known Mac malware.
[...]
It is not yet clear how Apple is handling the package scans for signs of malicious software.
I have confirmed that Apple is not using the open-source ClamAV engine to handle these scans so it’s likely the company has entered into an agreement with a commercial anti-virus company.
This isn’t the first official acknowledgment from Apple that the Mac operating system may be susceptible to malware. This Web page on Mac OS X security actually recommends the use of third-party anti-virus software to get “additional protection.”
--------------------------------
Apple has confirmed that its new operating system, Mac OS X 10.6 Snow Leopard, will be released on 28 August.
Saturday, August 22, 2009
Relative May Have Helped the CIA Find Baitullah Mehsud
A “paid agent”, possibly a relative, helped signal the whereabouts of Tehreek-e-Taliban Pakistan’s former chief Baitullah Mehsud to the Central Intelligence Agency (CIA), helping it take out the Taliban leader in a drone strike on August 5.
Officials and tribal sources told Daily Times on Saturday that the Taliban were holding Baitullah’s in-laws “hostage”.
The Taliban still deny Baitullah’s death but TTP deputy chief Faqeer Muhammad has named Hakeemullah Mehsud the new Taliban chief. “No new strategy was undertaken while hunting Baitullah. Agents pin-pointed the TTP chief’s position and the CIA took him out through a drone attack,” officials familiar with training agents for tracking down targets told Daily Times. “He (TTP chief) was simply not spotted through the powerful lens fixed on the drone, rather the complete set of procedures laid down for such missions was followed,” the officials said.
A belt wrapped above an agent’s waist carries two electronic chips, the officials said. “The agent pushes the first chip when he finds himself close to the target to intimate the satellite, which transfers the information to the control-room. The second chip is pushed only when the target is present and the agent has moved to a safer place. That is what when the drone is positioned and Hellfire missiles are fired,” officials explained. The Taliban confirmed they had executed a resident of Mardan on charges of spying for the CIA, one week after the August 5 drone attack. The killed man’s family said he had served Baitullah as his driver. The possible involvement of the killed TTP leader’s in-laws in giving away his position was highlighted in a report published by the BBC on Saturday, which said Baitullah’s father-in-law Maulana Ikramuddin, his son Ziauddin, brother Saeedullah and a nephew were in Taliban custody for the last few days.
Photo of the Day - Ramadan 2009

(Photo Credit = AFP)
http://news.bbc.co.uk/2/hi/in_pictures/7149890.stm
Rituals include fasting between dawn and dusk, and offering special prayers during the evening, as here in Jakarta's Istiqlal mosque.
-----------------------------
Ramadan is the ninth month of the Islamic calendar. It is the Islamic month of fasting, in which participating Muslims refrain from eating, drinking, smoking, and indulging in anything that is in excess or ill-natured; from dawn until dusk. Fasting is meant to teach the Muslim patience, modesty and spirituality. Ramaḍān is a time to fast for the sake of Allah, and to offer more prayer than usual. During Ramaḍān, Muslims ask forgiveness for past sins, pray for guidance and help in refraining from everyday evils, and try to purify themselves through self-restraint and good deeds. As compared to solar calendar, the dates of Ramadan vary, moving forward about ten days each year. Ramadhan was the month in which the first verses of the Qur'an were revealed to the Prophet Muhammad.
America's Muslims Celebrate Holy Month of Ramadan
As the Muslim holy month of Ramadan begins on August 22, Muslim Americans are observing it in many ways.
American Muslims of diverse national backgrounds are coming together to worship. They will break their dawn-to-dusk fast -for a whole month - in Islamic centers and in their homes across the country.
Imam Abdulla Khouj is president of the Islamic Center in Washington, DC.
"People from all over the world gather in one place and all do feel one people regardless of the distances and regardless of the geographical areas," he said.
Regardless of national origin, Ramadan is observed with rituals that bridge those differences.
Families shop for foods that have been prepared especially for Ramadan. They prepare Iftar meals that break the daily fast and they pray together.
Nadia Rachid immigrated to the US from Morocco. She misses the big Ramadan gatherings in her home country.
"There is a big difference. Here you do not have extended family, and so instead of having 10 people around the table, there is only the two of us," she said.
Her husband, Mohamed Ibrahim, says it's easy to observe Ramadan in America even though most people around him are not fasting.
"Because it is my duty to fast it does not matter what everybody else is doing," he explained.
Pakistan Taliban Appoints New Chief - Hakimullah Mehsud
Pakistan's Taliban movement has named a new leader, its deputy head Maulvi Faqir Mohammed has told the BBC.
He said Hakimullah Mehsud, a close associate of ex-leader Baitullah Mehsud, had been unanimously appointed at a meeting in northern Pakistan.
Pakistani and US officials believe Baitullah Mehsud was killed in a US drone strike in early August.
However the Taliban continue to insist that he is still alive, despite their decision to appoint a new leader.
Hakimullah Mehsud, who is in his late 20s, is a military chief of the Tehrik-e-Taliban Pakistan (TTP) organisation formed by Beitullah Mehsud in an effort to unite the various factions under one umbrella.
He controls an estimated 2,000 fighters in the Orakzai, Kurram and Khyber regions.
The announcement by Maulvi Faqir Mohammed follows weeks of speculation, and rumours of shootouts and disarray in Taliban ranks.
Mr Mohammed says Baitullah Mehsud has been seriously ill and wanted to see his successor appointed in his lifetime.
But the BBC's Orla Guerin in Islamabad says many will see the naming of a new leader as confirmation that Baitullah Mehsud is dead.
Our correspondent says Hakimullah Mehsud is a young commander in Baitullah's own image, and is reported to be equally ruthless.
Some believe he could be an even bigger threat to Pakistan, and to foreign troops across the border in Afghanistan, she adds.
Friday, August 21, 2009
Metasploit Gets Wyse [Exploits] & Two New Beta Modules
http://pastie.org/588882
This appears to be an exploit for the 'hagent.exe' buffer overflow vulnerability that was making news in July of this year. According to Wyse Security Advisory (WSB09-01), this vulnerability affected WDM Server 4.7.x, Wyse 9x, 5x and 3x series devices.
It will be interesting to see what else KF has up his sleeves....
In other MSF news, digininja recently released two beta Metasploit modules - DHCP Exhaustion and DNS MITM. Feedback is highly welcome....
One-in-four Browser Hackers Run Opera to Ward Off Other Criminals
Hackers using multi-exploit attack "toolkits" take defensive measures of their own against other criminals, a security researcher said today.
"Exploit kit operators do use mainstream browsers, but they're much more likely to use Opera than the average user, because they know that the browser isn't targeted by other hackers," said Paul Royal, a principal security researcher with Atlanta-based Purewire.
While the most generous Web measurements peg Opera, a browser made by Norwegian company Opera Software, at a 2% share of the global market, 26% of the hackers who Purewire identified use the far-from-popular application.
Because of its small market share, few hackers bother to unleash exploits for Opera vulnerabilities, said Royal.
Purewire obtained this insight, and others, by infiltrating hackers' systems using a bug in the analytics software included with a pair of hacker toolkits, notably one dubbed "LuckySploit," said Royal. "We forged a 'refer' field and put in a little JavaScript," he explained, "and that revealed the hackers to us via their IP addresses."
Out of 51 exploit kit-using hackers, Purewire's tactic successfully identified the IP addresses of 15, as well as the browsers they ran. "We essentially did a code audit," said Royal. "Even criminals who attack others cannot architect reliable software," he added, talking about the vulnerabilities in the toolkits.
Most multi-strike attack kits, including LuckySploit, serve up a grab bag of exploits, including code that leverages vulnerabilities in Microsoft's Internet Explorer (IE), in ActiveX controls that IE uses, and in Adobe's Flash Player and Reader.
Criminals also try to hide from law enforcement by distancing themselves from the servers that host their exploit kits, said Royal. Of the 15 hackers Purewire identified, only two -- both with IP addresses traced to Latvia -- resided in the same country that also hosted the system containing their attack kit.
Most had at least one country between where they lived and where their malware-serving machine was located.
"This is a first stab," Royal said when asked what value could be placed on the information Purewire rooted out. "If we can discover the IP addresses of exploit kit operators, we can then turn that over to law enforcement."
World's Most Expensive Bicycle
A Danish designer has created what he claims is the "world's most expensive bicycle".
Coated throughout with 24-carat gold and studded with hundreds of Swarovski crystals, the bike is on sale for 80-thousand euros.
----------------------------------In the video, I love the last young lady's reaction....
"In Denmark, we just steal bikes...we don't pay for them, so to pay that large amount of money...its just silly"It's silly indeed.
More pictures of the bike can be found here.
----------------------------------
This story made me think of a little bike I encountered back in Amsterdam in 2006...

Stolen? Abandoned? Not sure, but definitely not ride-able.
Eight Indicted For $22M Identity Theft Scam Against AT&T, T-Mobile
Eight defendants were arraigned in a Brooklyn court yesterday for allegedly using the stolen identities of AT&T, T-Mobile, and Asurion customers to steal some $22 million worth of wireless equipment and services.
An indictment was unsealed in Brooklyn federal court yesterday morning charging Courtney Beckford, Gabe Beizem, Rawl Davis, Lennox Lambert, Marsha Montayne, Saul Serrano, Ron Shealey, and Rohan Stewart, with conspiracy to commit mail fraud and wire fraud. Beizem, Montayne, and Stewart were also charged with wire fraud and aggravated identity theft.
According to the indictment, between February 2005 and July 2009, Beizem -- an owner of Got Wireless (aka USA Wireless), a former authorized AT&T and T-Mobile dealer that operated in Brooklyn -- obtained dealer access codes for AT&T's and T-Mobile's online customer databases. Stewart, the owner of KP Wireless -- an authorized T-Mobile wireless device dealer operating in West Palm Beach, Florida -- also obtained dealer access codes for T-Mobile's customer database.
Using these access codes, Beizem, Stewart, and Montayne, and others, allegedly obtained existing customer information from the customer databases, including customers' names, addresses, and personal identifying information, the indictment says. Montayne, and others, then fraudulently assumed the identities of existing customers and obtained new wireless devices without payment and without the customers' permission.
[...]
As a result of these fraudulent requests, AT&T and T-Mobile shipped new or replacement wireless devices for express mail delivery by FedEx, DHL or UPS, according to the indictment. The FedEx and DHL shipments from AT&T were generally shipped to addresses along the routes of private express mail drivers whom Beckford, Davis, Lambert, and Stewart, and others, allegedly recruited and paid to divert the packages.
FedEx and DHL drivers, including Serrano and Shealey, then allegedly scanned the packages into their respective carrier's computerized tracking systems as "delivered" to the stated delivery addresses, but actually diverted the packages to Beckford, Davis, Lambert, and Stewart, and others. UPS shipments from T-Mobile were shipped directly to addresses connected to the defendants and their associates.
Beckford, Beizem, Davis, and Montayne, and others, allegedly then sold the fraudulently obtained wireless devices to others. When charges were incurred on these devices, they were billed to existing AT&T and T-Mobile customers' accounts. When the customers reported or confirmed the fraud on their accounts to AT&T and T-Mobile, the companies absorbed the losses, which included the cost of the devices, insurance payments, shipping costs, and wireless service and other calling charges.
New Details, and Lessons, on Heartland Breach
Thanks to an anonymous reader, we may have some additional information on how the Heartland breach occurred. Keep in mind that this isn't fully validated information, but it does correlate with other information we've received, including public statements by Heartland officials.
On Monday we correlated the Heatland breach with a joint FBI/USSS bulletin that contained some in-depth details on the probable attack methodology. In public statements (and private rumors) it's come out that Heartland was likely breached via a regular corporate system, and that hole was then leveraged to cross over to the better-protected transaction network.
According to our source, this is exactly what happened. SQL injection was used to compromise a system outside the transaction processing network segment. They used that toehold to start compromising vulnerable systems, including workstations. One of these internal workstations was connected by VPN to the transaction processing datacenter, which allowed them access to the sensitive information. These details were provided in a private meeting held by Heartland in Florida to discuss the breach with other members of the payment industry.
As with the SQL injection itself, we've seen these kinds of VPN problems before. The first NAC products I ever saw were for remote access -- to help reduce the number of worms/viruses coming in from remote systems.
I'm not going to claim there's an easy fix (okay, there is, patch your friggin' systems), but here are the lessons we can learn from this breach:
- The PCI assessment likely focused on the transaction systems, network, and datacenter. With so many potential remote access paths, we can't rely on external hardening alone to prevent breaches. For the record, I also consider this one of the top SCADA problems.
- Patch and vulnerability management is key -- for the bad guys to exploit the VPN connected system, something had to be vulnerable (note -- the exception being social engineering a system 'owner' into installing the malware manually).
- We can't slack on vulnerability management -- time after time this turns out to be the way the bad guys take control once they've busted through the front door with SQL injection. You need an ongoing, continuous patch and vulnerability management program. This is in every freaking security checklist out there, and is more important than firewalls, application security, or pretty much anything else.
- The bad guys will take the time to map out your network. Once they start owning systems, unless your transaction processing is absolutely isolated, odds are they'll find a way to cross network lines.
- Don't assume non-sensitive systems aren't targets. Especially if they are externally accessible.
Okay -- when you get down to it, all five of those points are practically the same thing.
Here's what I'd recommend:
- Vulnerability scan everything. I mean everything, your entire public and private IP space.
- Focus on security patch management -- seriously, do we need any more evidence that this is the single most important IT security function?
- Minimize sensitive data use and use heavy egress filtering on the transaction network, including some form of DLP. Egress filter any remote access, since that basically blows holes through any perimeter you might think you have.
- Someone will SQL inject any public facing system, and some of the internal ones. You'd better be testing and securing any low-value, public facing system since the bad guys will use that to get inside and go after the high value ones. Vulnerability assessments are more than merely checking patch levels.
Patch management isn't new...and it is so critically important, yet many many companies still don't take it serious.
One of the factors that can greatly affect any patch management process is inventory control.
Inventory control is rarely talked about in the realm of patch management, but they go hand-in-hand.
After all, you can't patch what you don't see...
Thursday, August 20, 2009
Apple + In-Store Recycling + Old Cell Phone = FAIL
As a pretty happy owner of a iPhone 3G, I don't see the use in keeping them around.
I'm not a total hater of the environment, so I figured I would attempt to recycle them at the very least...as opposed to just breaking them with a hammer and throwing them directly into the landfill myself. Recycling sounds good, right?...but where can I do that?
http://www.apple.com/environment/recycling/
Ohhh, sweet! Apple takes old things for recycling...but will they take my old phones??
Lets check the site....

Very cool, the boxes on the right seem to indicate the following facts...
Apple’s free recycling program will take back your iPod or any cell phone — regardless of manufacturer or model.So the first sentence indicates that they will take any old phone for recycling...you just have to print out the mailing form and ship them off. Awesome, sounds easy enough. But wait!
You can bring your old cell phone to any Apple Retail Store for free recycling.
I can bring my old cell phones to ANY Apple Retail Store for free recycling. Extra Awesome!!
Feeling comfortable that my logic was sound, I headed off to the local Apple Store to hand over my old busted phones.
Upon entering the store, I found one of those normally helpful blue/orange shirted employees and started into my story....about how old cell phones kill cute kittens.....and I like cute kittens so I wanted to recycle my phones.
After my short story, the employee kindly told me that they don't take any old phones for recycling...just some older iPhones. Ummmm Esqueeze me?
I explained that the website clearly and logically said otherwise....which he insisted wasn't correct.
So which is it Apple? Do you take off old non-Apple phones at ANY Apple Retail Store or not??
Either the employee was wrong...or your website is misleading. You tell me...
US Indicts Mexican Drug Traffickers From Sinaloa Cartel
U.S. authorities have announced new charges against members of a Mexican drug cartel accused of smuggling vast quantities of cocaine and other narcotics into the United States.
The Justice Department unveiled indictments against 43 leaders, members and associates of the powerful Sinaloa drug cartel, which is blamed for much of the drug-related violence that has claimed thousands of lives along the U.S.-Mexico border in recent years.
"We allege that these defendants shipped multi-ton quantities of narcotics into the United States through various established smuggling corridors and then through a network of affiliated distributors, [and] disbursed these drugs into cities and neighborhoods around the country," said US Attorney General Eric Holder.
Holder said the alleged smuggling spans nearly two decades, and has brought real harm and suffering to both the United States and Mexico.
"These cartels are not abstract organizations operating in far-off places," he said. "They are multi-billion dollar networks funneling drugs onto our streets. What invariably follows these drugs is more crimes and more violence in our communities."
The attorney general paid tribute to Mexico's efforts to battle drug cartels and said the United States must do its part.
"Our friends and partners in Mexico are waging an historic and heroic battle with the cartels as we speak," said the U.S. attorney general. "This is not a fight that we in the United States can afford to watch from the sidelines. The stakes are too high and the consequences are too real for us."
Man Sentenced For Role In Domestic Terror Plot
A man was sentenced to 70 months in prison today for his role in a domestic terrorism plot to wage war on the United States by attacking Jewish synagogues and military bases. Hammad Riaz Samana is the fourth member of Jami’yyat Ul-Islam Is-Shaheeh, or JIS, a prison-founded group that wanted to make a political statement that also had plans to attack the Israeli consulate in Los Angeles and El Al Israel Airlines at the Los Angeles International Airport.
Samana was 21 when he was charged in the case in July 2005, along with the cell’s mastermind, Kevin James, and members Levar Haley Washington and Gregory Patterson.
The group committed armed robberies of 11 gas stations, including two in Fullerton, to buy weapons and gear for the attacks. Authorities said gas stations were chosen as targets because of the symbolism of the oil.
Samana had a smaller role in the plot, and conducted computer research on the terrorism targets, and was the getaway driver for one of the armed robberies, according to U.S. District Judge Cormac Carney at today’s sentencing hearing.
Carney acknowledged he was imposing a substantially lighter sentence on Samana than those given to the other men.
New Chinese Defence Ministry Website
In the last few hours (days?) weeks, China has launched a new website for its Ministry of National Defense. It comes in two flavours, Chinese and English, which only differ in colour scheme, The Dark Visitor tells us (Chinese green, English red). I might be showing my ignorance of international English here, but ‘defense’ with an ’s’ is the American, as opposed to the UK/European, way of spelling it, so perhaps that’s a sign of who it’s aimed at, public diplomacy-wise. Today’s official press release tells us the following:
The website of the Chinese Ministry of National Defense mainly releases authoritative information of China’s national defense and army building. The founding of the website is designed to let the outside world have a better perception of China’s national defense policy, help enhance foreign exchanges and cooperation, display before the world the fine image of the PLA as a mighty, civilized and peaceful force and better promote the national defense and army modernization drive.
Netizens to visit the website will be impressed by its succinct and graceful webpage featuring novel and attractive design with distinctive military characteristics.
Indeed – I particularly like the green, Mandarin version.It continues:
The Chinese version of the website is composed of three parts, i.e. news channels, data and documentary materials, columns and special reports.
The news channels are today’s headlines, high-level development, national defense building, national defense education, national defense technology, military operations, military diplomacy, arms control & disarmament.
The data and documentary materials provided by the website include brief introductions to the leaders of the CMC and the four general headquarters/departments of the PLA, military laws and regulations, weaponry and equipment and military history.
The website also offers columns and special reports such as the collection of national defense videos, military photo gallery and special reports on domestic and international hot spots inside and outside the military circle.
The English version of the website will give more consideration to the concerns of overseas netizens on Chinese national defense information and their reading habits and better accord with the characteristics and rules of foreign publicity.
More from Reuters here.
Update: the London Times ran this story on 1 August 2009. Shows how slow I am. One of the comments on that article says,
You forgot to mention that the website is sponsored by Wulianyue – the PLA generals’ favourate [sic] and the strongest spirit in China (Chinese Whisky)!!!
That’s just not true. More on Chinese whisky here.
Interesting how both the US and China released new defense websites recently...
Wednesday, August 19, 2009
Confidential Informants: A Double-Edged Sword
Police in El Paso, Texas, announced Aug. 11 that they had arrested three suspects in the May 15 shooting death of Jose Daniel Gonzalez Galeana, a Juarez cartel lieutenant who had been acting as a confidential informant (CI) for the U.S. Immigration and Customs Enforcement (ICE) agency. It was an activity that prompted the Juarez cartel to put out a hit on him, and Gonzalez was shot multiple times outside his home in an upscale El Paso neighborhood. A fourth suspect was arrested shortly after the Aug. 11 announcement. Among the suspects is an 18-year-old U.S. Army soldier stationed at nearby Fort Bliss who the other suspects said had been hired by one of the leaders of the Juarez cartel to pull the trigger on Gonzalez. The suspects also include two other teenagers, a 17-year-old and a 16-year-old.
The man who recruited the teenagers, Ruben Rodriguez Dorado — also a lieutenant in the Juarez cartel — has also been arrested, and the emerging details of the case paint him as a most interesting figure. After receiving orders from his superiors in the Juarez cartel to kill Gonzalez, Rodriguez was able to freely enter the United States and conduct an extensive effort to locate Gonzalez — he reportedly even paid Gonzalez’s cell phone bill in an effort to obtain his address. Armed with the address, he then conducted extensive surveillance of Gonzalez and carefully planned the assassination, which was then carried out by the young gunman he had recruited.
The sophistication of Rodriguez’s investigative and surveillance efforts is impressive, and the Gonzalez hit was not the first time he undertook such tasks. According to an affidavit filed in state court, Rodriguez told investigators that he also located and surveilled targets for assassination in Mexico. Perhaps the most intriguing aspect of this case is that the entire time Rodriguez was plotting the Gonzalez assassination he, too, was working as a CI for ICE.
---------------------------------
Yet another great article from Stratfor....make sure to check out the full article. It contains awesome insight into the counterintelligence abilities of Mexican cartels.
Here are a couple of points that I found most interesting....
- Groups like the Beltran Leyva Organization (BLO) have recruited scores of intelligence assets and agents of influence at the local, state and even federal levels of the Mexican government. They even have enjoyed significant success in recruiting agents in elite units such as the anti-organized crime unit of the Mexican attorney general’s office. The BLO even allegedly recruited Mexico’s former drug czar, Noe Ramirez Mandujano, who reportedly was receiving $450,000 per month from the organization.
- According to a report released last week, in a 10-month period, four applicants for U.S. border law enforcement positions were found through background checks and polygraph examinations to be infiltrators from drug-trafficking organizations. It is important to remember that these four were only those who were caught, and not all agencies submit applicants to the same scrutiny, so the scope of the problem is likely much larger. In light of this history of cartel intelligence activity, it is not unreasonable to assume that the cartels possess the sophistication and skills to employ double agents.
- Rodriguez’s use of teenage assassins to kill Gonzalez is also in keeping with a trend we have seen in Laredo and elsewhere, that of the cartels recruiting young street-gang members and training them to be assassins. Young gunmen working for Los Zetas in Laredo, Houston, San Antonio and elsewhere have been given the nickname “Zetitas,” or little Zetas.
Virus Found to Infect Delphi Development Environments
Anti-virus software vendor Kaspersky has discovered a new type of virus which infects and compromises systems running the Delphi development environment. After infection, all Delphi programs compiled using the infected Delphi environment are also infected. Anti-virus laboratory AV-Test has already spotted the first examples in the wild.
The virus affects Delphi versions 4.0, 5.0, 6.0 and 7.0. After making a backup which it names SysConst.bak, it overwrites the Delphi file SysConst.dcu with a self-compiled version. Since the infected file is loaded whenever Delphi programs are compiled, all programs generated after this point will be infected.
The virus does not carry a malicious payload, so does not do any damage to systems which are not running Delphi. It does not therefore represent an actual hazard at present. The programs Any TV Free 2.41 (anytv241_setup.exe) and Tidy Favorites 4.1 (TidyFavorites_Setup_4_1_free.exe), which are included on some current magazine CDs and are also among the top 100 downloads on some download portals, are infected with the virus. Kaspersky, F-Secure and Ikarus anti-virus products report the malware as "Virus.Win32.Induc.a". McAfee reports infected files as "W32/Induc" or "Generic!Artemis". Other anti-virus vendors have been informed of the virus and are working on updates.
The idea of concealing malicious code in a compiler is by no means new. In his very readable acceptance speech for the 1984 Turing Prize, Reflections on Trusting Trust, Unix grandee Ken Thompson discussed the possibility of using the C compiler to inject a back door into the login process. However, it has taken 25 years for reality to catch up with the theory.
Air Force Establishes ‘Reduced’ Cyber-War Command
A year ago, the Air Force suspended its plans to set up a new “cyber command” for network defense and online warfare. The suspension came at a tumultuous time for the air service. Its two top officials had just been canned, botched airplane buys were under close scrutiny and Air Force nuke handlers were reeling from several potentially catastrophic gaffes. “It makes sense for new leadership to want to pause and evaluate,” cyber-security specialist Richard Bejtlich said.
Things are calmer now. The Air Force has new leaders, new and more modest acquisition plans and tighter nuke controls. Amid the calm, and without much fanfare, the Air Force on Tuesday established a new, “greatly reduced” cyber-warfare organization, to borrow Gannett’s description. The 24th Air Force, at Lackland Air Force Base in Texas, “will provide combat-ready forces trained and equipped to conduct sustained cyber operations, fully integrated with air and space operations.”
What does that mean? Setting up and protecting new, instant networks in war zones, for one. Plus defending existing Air Force networks from intrusion. If there’s an offensive component to the 24th, the Air Force isn’t saying.
The 24th will subsume two existing wings, and add one new one, so it mostly amounts to re-packaging old forces. “The largest advantage is focus,” Gen. Robert Kehler, the top officer at Air Force Space Command, told Danger Room. Having a new umbrella organization for cyber-defense helps the Air Force “think differently about requirements and acquisition.”
Plus, the 24th will oversee revamped network training for incoming recruits and officer candidates. That will range from proper use of thumb drives to complex cyber-defense exercises, such as the one held annually at West Point (pictured), according to Maj. Gen. Richard Webber, the new 24th commander. “We’re starting to see evolution,” Webber said.
US Agency Tests Censorship Circumvention Tool
Citizens living in China, Vietnam, Iran, and other countries may soon have another option for bypassing Internet filters, courtesy of a US-based agency. The Broadcasting Board of Governors (BBG) announced on Friday that it was working on a new system that would use e-mail to carry encrypted data to and from the recipient, including information that would otherwise be blocked.
The system, called "feed over e-mail" (FOE), is not yet ready for primetime, but BBG IT head Ken Berman said that it will be tested in China and Iran when it goes into beta. "China is the benchmark, the gold standard, of Internet censorship," Berman told the AFP. "We try things. The idea is to extend freedom of the Internet, freedom of the press, freedom of inquiry to those that want to know more."
Because the BBG would like to avoid tipping off the two governments before the software even gets to be tested, there are few details on how FOE currently works. It does, however, appear to be taking a different approach to filter circumvention by using e-mail instead of the traditional Web proxies used by some of the more prominent systems. Berman said that FOE uses encryption that comes with most e-mail systems, including Gmail, Yahoo Mail, and even Hotmail, to transmit news. One individual who helped develop FOE, Sho Ho, told Reuters that it could easily be tweaked to work with mobile phones, as well.
The announcement about FOE comes just as Internet censorship seems to be all over the news—China and Malaysia recently scaled back their plans to mandate more filtering, while Vietnam added an additional layer. These three are just the beginning, though; Reporters Without Borders also points the finger at Burma, Cuba, North Korea, Egypt, Iran, Saudi Arabia, Syria, Tunisia, Turkmenistan, and Uzbekistan for being "Enemies of the Internet," and numerous others engage in some level of blocking or filtering.
DNA Evidence Can Be Fabricated, Scientists Show
Scientists in Israel have demonstrated that it is possible to fabricate DNA evidence, undermining the credibility of what has been considered the gold standard of proof in criminal cases.
The scientists fabricated blood and saliva samples containing DNA from a person other than the donor of the blood and saliva. They also showed that if they had access to a DNA profile in a database, they could construct a sample of DNA to match that profile without obtaining any tissue from that person.
“You can just engineer a crime scene,” said Dan Frumkin, lead author of the paper, which has been published online by the journal Forensic Science International: Genetics. “Any biology undergraduate could perform this.”
Dr. Frumkin is a founder of Nucleix, a company based in Tel Aviv that has developed a test to distinguish real DNA samples from fake ones that it hopes to sell to forensics laboratories.
The planting of fabricated DNA evidence at a crime scene is only one implication of the findings. A potential invasion of personal privacy is another.
Using some of the same techniques, it may be possible to scavenge anyone’s DNA from a discarded drinking cup or cigarette butt and turn it into a saliva sample that could be submitted to a genetic testing company that measures ancestry or the risk of getting various diseases. Celebrities might have to fear “genetic paparazzi,” said Gail H. Javitt of the Genetics and Public Policy Center at Johns Hopkins University.
Tania Simoncelli, science adviser to the American Civil Liberties Union, said the findings were worrisome.
“DNA is a lot easier to plant at a crime scene than fingerprints,” she said. “We’re creating a criminal justice system that is increasingly relying on this technology.”
John M. Butler, leader of the human identity testing project at the National Institute of Standards and Technology, said he was “impressed at how well they were able to fabricate the fake DNA profiles.” However, he added, “I think your average criminal wouldn’t be able to do something like that.”
The scientists fabricated DNA samples two ways. One required a real, if tiny, DNA sample, perhaps from a strand of hair or drinking cup. They amplified the tiny sample into a large quantity of DNA using a standard technique called whole genome amplification.
Of course, a drinking cup or piece of hair might itself be left at a crime scene to frame someone, but blood or saliva may be more believable.
The authors of the paper took blood from a woman and centrifuged it to remove the white cells, which contain DNA. To the remaining red cells they added DNA that had been amplified from a man’s hair.
Since red cells do not contain DNA, all of the genetic material in the blood sample was from the man. The authors sent it to a leading American forensics laboratory, which analyzed it as if it were a normal sample of a man’s blood.
The other technique relied on DNA profiles, stored in law enforcement databases as a series of numbers and letters corresponding to variations at 13 spots in a person’s genome.
From a pooled sample of many people’s DNA, the scientists cloned tiny DNA snippets representing the common variants at each spot, creating a library of such snippets. To prepare a DNA sample matching any profile, they just mixed the proper snippets together. They said that a library of 425 different DNA snippets would be enough to cover every conceivable profile.
Nucleix’s test to tell if a sample has been fabricated relies on the fact that amplified DNA — which would be used in either deception — is not methylated, meaning it lacks certain molecules that are attached to the DNA at specific points, usually to inactivate genes.
----------------------------------
It was only a matter of time. Biological hacking is just starting and while it might be at the ground floor now, it is on its way up.
Prime example = MIT has a biological engineering department.
Tuesday, August 18, 2009
Cyber-Dissident Zhang Lin Released After Finishing Five Year Sentence
Reporters Without Borders welcomes the release of the well-known blogger and pro-democracy activist Zhang Lin on 12 August on completing a five-year sentence for posting articles online that were deemed to be “contrary to the bases of the constitution” and “a danger to national security.”
“We are glad that Zhang Lin has been able to rejoin his wife and family,” Reporters Without Borders said. “His release is a relief but we cannot forget the other prisoners of opinion held by the Chinese government and we urge the authorities to free all the journalists and bloggers who have been convicted for using their right to free expression under the International Covenant on Civil and Political Rights, which China has signed.”
Arrested illegally on 29 January 2005 in the eastern province of Anhui, where is from, Zhang was initially placed in “administrative detention.” He was then accused of threatening the country’s security by means of the articles he posted online and was given the five-year sentence on 14 October 2005.
Zhang often posted articles on websites linked to the Falun Gong spiritual movement such as Dajiyuan.com and Epochtimes.com, as well as Boxun.com, a website about human rights in China. He was imprisoned from 1989 to 1991, and again from 1995 to 1998, when he was sentenced to hard labour.
He then left for the United States to pursue his political activities, but reentered China clandestinely a few months later and was rearrested a third time, at which point he was sent to a labour camp until 2001. In all, he has spent 13 years in detention.
At least 59 cyber-dissidents and 30 journalists are currently held in China in violation of the right to free expression. The latest bloggers to be detained include Ilham Tohti and Tan Zuoren. Their imprisonment is direct evidence of the censorship practiced by the Chinese government.
Pakistani Taliban's Top Spokesman Captured in Mohmand
Pakistani security forces reportedly detained the chief spokesman for Baitullah Mehsud and his Movement of the Taliban in Pakistan. A senior aide to Baitullah was also captured in Islamabad on Monday.
Maulvi Omar and two aides were captured in the tribal agency of Mohmand as he was traveling through the region. Omar was captured with the help of tribal leaders, Pakistani intelligence officials told Dawn.
Omar has been the face of the Pakistani Taliban for the past several years. He has been in constant contact with the media and has credited the Taliban with conducting some of the largest attacks inside Paksitan.
Most recently, Omar claimed Baitullah Mehsud is still alive after Pakistani and US officials claimed Baitullah was killed in the Aug. 5 airstrike that killed his wife.
Omar's capture may have been facilitated by the controversy surrounding Baitullah's reported death. Taliban spokesmen and leaders have been contacting the media to state that Baitullah is alive. The increased contact may have provided clues on Omar's whereabouts to Pakistani and US intelligence services seeking to dismantle the Taliban in the insurgency-ridden northwest.
The military previously had claimed Omar was killed during fighting against the Taliban in the Bajaur tribal agency in October 2008. Omar later surfaced and resumed his job as the chief Taliban spokesman.
Australian Federal Police Take Down R00t-Y0u.org
An Australian Federal Police boast, on the ABC's Four Corners program, about officers breaking up an underground hacker forum, has backfired after hackers broke into a federal police computer system.
Security consultants say police appear to have been using the computer as a honeypot to collect information on members of the forum but the scheme came undone after the officers forgot to set a password.
Last Wednesday, federal police officers in co-operation with Victoria Police executed a search warrant on premises in Brighton, Melbourne, connected to the administrator of an underground hacking forum, r00t-y0u.org, which had about 5000 members.
[...]
After the raid, the federal police covertly assumed control of the forum and began using it to gather evidence about members.
"We can operate in a covert activity here fairly seamlessly with no harm to our members with continual and actual significant penetration," Neil Gaughan, national manager of the federal police's High Tech Crimes Operation, told Four Corners.
However, what the federal police did not know was that hackers had already cottoned on to their plan.
Police were monitoring the forum by logging into the account of the administrator they had raided, but this aroused suspicion among members who knew the raid had taken place.
A hacker broke into the federal police's computer system and, according to a source close to the investigation, accessed both police evidence and intelligence about federal police systems such as its IP addresses.
A spokeswoman for the federal police confirmed that the hacker broke into a computer system used in its investigation but denied that any evidence was compromised, saying the computer was not connected to other federal police systems.
"The AFP has identified a person whom [sic] has attempted to access the stand-alone computer system and we are currently working with our law enforcement partners regarding this matter," the spokeswoman said.
The hacker appears to have been provoked by a message published on the r00t-y0u.org site by the federal police, warning members they were under surveillance and that "all member IP addresses have been logged", with some arrests having already been made.
In two provocative messages published on anonymous document-sharing site pastebin.com, the hacker slammed the federal police for "making it sound like they can bust 'hackers', when all they have done is busted a COUPLE script kiddies". "Script kiddies" is hacker parlance for novice hackers.
The second of these messages contained several links to screenshots allegedly proving that the writer had access to the federal police's server.
These included shots of files containing fake IDs and stolen credit card numbers, as well as the federal police's server information.
The hacker then defaced the r00t-y0u.org website with the same message it had posted on the anonymous document-sharing site.
The federal police spokeswoman said: "The information posted on the http://pastebin.com website is information contained on a stand-alone [federal police] system designed specifically to be used in investigations such as this.
"The information consists of directory file names of previously compromised credentials. No information or files exist that have, or could have, been compromised."
Pentagon Web Site Redesigned
The Defense Department on Monday unveiled a fresh look for its Web site, focused on increasing two-way communication.
The redesigned site is hosted on the new URL Defense.gov and highlights social networking tools such as Facebook and Twitter. The primary goal of the makeover, Pentagon officials said, is to engage the public, particularly 18 to 24 year olds.
"We need to embrace these technologies," Price Floyd, principal deputy assistant secretary of Defense for public affairs, told the American Forces Press Service, the Defense Department's news service. "We need to use them because that's what the young people use these days. ...If we just stick to the traditional ways of communicating, we leave out a huge portion of society."
Unlike most other Web sites, the former Defense home page, DefenseLINK.mil, attracted more visitors over age 45 than under, according to Floyd. Attracting younger visitors -- while retaining the existing audience -- will be one of the Pentagon's key challenges.
Steve Radick, an associate at consulting firm Booz Allen Hamilton's social media/Government 2.0 practice, said the Pentagon's focus on engaging with 18 to 24 year olds likely is an extension of its recruiting goals.
"They want to tell the story and connect with these people so [young people] hear directly from the Pentagon and troops, rather than just the media or their parents," Radick said.
Steve Ressler, founder of Young Government Leaders and GovLoop, a social networking site for federal employees, said Defense is taking a big step in the right direction by offering visitors choices about how they connect. The new home page prominently displays links to subscribe to the Pentagon's RSS Feeds, podcasts and widgets. It also invites users to "connect with us" via the DoDLive Blog, Facebook, Flickr, Twitter, UStream or YouTube.
Defense public affairs officials, who designed the site, modeled it after WhiteHouse.gov, which has avenues for members of the public to submit policy recommendations.
How 10 Digits Will End Privacy As We Know It
Internet denizens and urban dwellers alike need to recognize that an era of anonymity is ending.
The population of the world stands at about 7 billion. So it takes only 10 digits to label each human being on the planet uniquely.
This simple arithmetic observation offers powerful insight into the limits of privacy. It dictates something we might call the 10-Digit Rule: just 10 digits or so of distinctive personal information are enough to identify you uniquely. They're enough to strip away your anonymity on the Internet or call out your name as you walk down the street. The 10-Digit Rule means that as our electronic gadgets grow chattier, and databases swell, we must accept that in most walks of life, we'll soon be wearing our names on our foreheads.
A study of 1990 U.S. Census data revealed that 87 percent of the people in the United States were uniquely identifiable with just three pieces of information (PDF): five-digit ZIP code, gender, and date of birth. Internet surfers today spew considerably more information than that. Web sites can pinpoint our geographical locations, computer models, and browser types, and they can silently track us using cookies. Banking sites even confirm our identities by verifying that our log-ins take place at consistent times of day.
Database dossiers, too, carry surprising amounts of identifying information, even when specifically anonymized for privacy. Researchers at the University of Texas at Austin last year studied a set of movie-rating profiles from about 500,000 unnamed Netflix subscribers (PDF).
Knowing just a little about a subscriber--say, six to eight movie preferences, the type of thing you might post on a social-networking site--the researchers found that they could pick out your anonymous Netflix profile, if you had one in the set. The Netflix study shows that those 10 deanonymizing digits can hide in surprising places.
[...]Thankfully, despite proliferating sources of those 10 digits that are fatal to anonymity on the Internet and the sidewalk, we can still prevent the world of the film "Minority Report." There are many defensible facets to privacy beyond identity. Even if our names are blazoned forth to all and sundry, we still have the opportunity to safeguard health care and financial data, entertainment preferences, purchase histories, and social interactions.
In this battle, identity theft is a key challenge for technologists and policymakers. The only way to prevent unauthorized access to personal data is to ensure that even when criminals learn the digital constituents of your identity, they can't steal it. Strong authentication will need to fill the gap as the privacy of identities crumbles.
Perhaps the world will be friendlier when in-store advertisements greet you personally, criminals wear "Hello, My Name Is" badges, and the people you meet at parties already have your bio in hand. Facebook, Twitter, and pervasive blogging already augur a society of reflexive exhibitionism and voyeurism. But the technologies that advance us into a world of omniscience will also bring us a step backward.
For years, people aspired to escape small towns for the big city, for the fresh start of an identity without history. The Internet offered similar horizons of freedom. But the society of the small town will soon have us back in its clutches, for good and bad. And on the Internet, everyone will know if you're a dog.
Jihadis Search for Intelligence Penetration on Jihadi Website Forums
Periodically jihadi internet gatherings raise concerns about scrutiny of their forums by security services. Investigations into the identity of forum members and their promotion and initiation of sensitive jihadi issues trigger these concerns. A recent posting entitled “The top seven Arab countries that intrude on or penetrate the Forums” accused some Western security services of monitoring jihadi forums and suggested ways to identify security agents who may be active in the forums (muslm.net, July 29-August 3).
A forum participant, nicknamed al-Taer al-Maymoon, warns that the secret services of seven Arab countries have a permanent presence in jihadi forums in general and in muslm.net in particular. Some of these intelligence agents are prominent members of the forums and specialists in Shari’a. The countries intruding on jihadi forums, alleges al-Maymoon, are Egypt, Jordan, Syria, Morocco, Algeria, Tunisia and the Palestinian National Authority – where the latter is accused of selling the information obtained from the forums to the Zionists. Further, al-Maymoon said various Arab nations monitor jihadi forums either to collect intelligence for preventive purposes or to exchange intelligence with Western countries “waging war on Islam.”
[...]
According to Qotoz, there are two techniques used by security agencies to hunt down jihadis. First is the technical method. This includes stealing an email address and monitoring all incoming and outgoing emails; planting Trojans in the target’s computer; using the target’s nickname in the forums by posting subjects under his name and hacking into the target’s computer.
The second technique for hunting jihadis on the internet is comprised of “human methods”:
• Posting subjects designed to attract the targeted jihadi. Consequently, relations will be established with the subject before luring him into a face to face meeting.
• Expressing opinions diametrically opposed to those found acceptable by Salafi-Jihadis, thus drawing them out as they rebuke or criticize the posting.
• Security agents, having established a connection with the target, will enhance the relationship in the forums by supporting the target’s postings and by sending him private emails.
• Through such relationships, the agents will obtain the names of other jihadis from the target.
• Building trust with the target by pretending to help the cause.
All these methods and more, says Qotoz, are part of a bigger security plan to hunt down jihadi forum members and create dissension among supporters of jihad. Jihadis must be aware of intelligence officers in the forums tasked with distorting the jihadi image. The electronic plan of the intelligence services includes setting up dummy cells in the jihadi forums to disseminate misleading jihadi statements. Qotoz ends his posting by alleging that there is other information he can’t discuss in the forum, an insinuation of the presence of security agents in the forum.
------------------------------------------
Terrorism Monitor - Volume VII, Issue 25 (August 13th, 2009)
http://www.jamestown.org/uploads/media/TM_007_76.pdf
Mexico Cartels Go From Drugs to Full-Scale Mafias
Shopkeepers in this pine-covered mountain region easily recite the list of "protection" fees they pay to La Familia drug cartel to stay in business: 100 pesos a month for a stall in a street market, 30,000 pesos for an auto dealership or construction-supply firm.
First offense for nonpayment: a severe beating. Those who keep ignoring the fees — or try to charge their own — may pay with their lives.
"Every day you can see the people they have beaten up being taken to the IMSS," said auto mechanic Jesus Hernandez, motioning to the government-run hospital a few doors from his repair shop.
Mexican drug cartels have morphed into full-scale mafias, running extortion and protection rackets and trafficking everything from people to pirated DVDs. As once-lucrative cocaine profits have fallen and U.S. and Mexican authorities crack down on all drug trafficking to the U.S., gangs are branching into new ventures — some easier and more profitable than drugs.
[...]
Organized crime is seeping into Mexican society in ways not seen before, making it ever more difficult to combat. Besides controlling businesses, cartels provide jobs and social services where government has failed.
"Today, the traffickers have big companies, education, careers," said Congresswoman Yudit del Rincon of Sinaloa state, which has long been controlled by the cartel of the same name. "They're businessman of the year, they even head up social causes and charitable foundations."
Local officials say they do not have the manpower to investigate cartel rackets and refer such cases to the state, which hands them over to overloaded federal agents because organized crime is a federal offense. A federal police report released in April notes that often no one confronts the cartels, "not the police, because in many cases there is probably corruption, and not the public, because they live in terror."
[...]
"It's almost like Chicago, when Al Capone ruled everything," said a senior U.S. law enforcement official who was not authorized to be quoted by name. "They control everything from the shoeshine boy to the taxi driver."
Mexican cartels gained their dominance in drug trafficking in the mid-1980s, when U.S. drug agents and the Colombian government cracked down on Colombian cartels and drug routes through the Caribbean. The vast majority of cocaine headed to the U.S. started going through Mexico.
In the meantime, trade in pirated and other smuggled goods in Mexico traditionally was carried out by small gangs centered around extended families or neighborhood rings.
In the last five to 10 years, Mexican cartels created domestic drug markets and carved out local territories, using a quasi-corporate structure, firepower and gangs of hit men to control other illicit trades as well. Federal prosecutors now call them "organized crime syndicates" and say their tactics — such as charging a "turf tax" to do business in their territory — mirror the Italian mafia.
[...]
Still, the gangs have created elaborate systems to avoid property seizures and to move money quickly through store-front check-cashing and wire-transfer services, according to federal police. And they have become so omnipresent that they take a cut of almost every transaction in some areas.
Javier, the owner of a small video store in Ciudad Hidalgo, got so fed up with La Familia controlling his town, he decided to sell his house and sent his two daughters to live in another state. His business had withered from the competition of street vendors selling pirated DVDs for La Familia.
But when he put his two-story, 1930s-era home up for sale, he got a phone call from the cartel.
"Putting up a 'for sale' sign is like sending them an invitation," said Javier, who asked that his last name not be used for fear of retaliation. "They call and say, 'How much are you selling for? Give me 20 percent.' "
Burglar Taunts Victim on Facebook
Victoria Richardson, 42, from Hove, East Sussex, was burgled last week, losing an iPhone, a Nintendo DS games console, a handbag containing a purse, cash and debit cards and a black Toshiba laptop.
When she later logged into her Facebook account she found the burglar who had rifled through her belongings had also invaded her Facebook account.
One message left on the site read: "on my new laptop". The next said: "Listening to music on my new phone feels so good."
The callous thief then mocked the fact they had left Victoria's television because it was 'rubbish', adding: "I have the laptop , phones ok but a bit scratched itll do, tv was rubbish so I left it , ds was a bonus, now to the porn shop, thankyou toshiba is my favourite make".
The final post read: "regards your night time burglar".
Ms Richardson said: "I felt very spooked. I have never felt like that before. It felt like they were rubbing my nose in it.
"They have been in your physical space, and then they are in your online space. My friends could all see what they were writing so it was really degrading.
"It is bad enough being robbed in the first place but this invasion of my privacy has made it doubly painful."
A spokeswoman for Sussex Police said: "Being burgled is traumatic enough for any family but for the culprit to apparently use their stolen possessions to publicly gloat over the crime is a sinister twist.
"As with all burglaries we are taking the matter seriously and a thorough investigation is under way to bring this offender to justice."
ATM Skimmer Ring Hits Chicago Suburbs
Reader Kellie reports being the victim of an ATM skimming scam in the Chicago area. Mostly, she was amazed that the thefts weren't reported in the local media, and she asked bank employees why. Here's what they told her.
I live in Park Ridge, a suburb of Chicago, and I was recently the victim of ATM skimming. My ATM/debit card was skimmed at the Charter One branch in Park Ridge during the weekend of July 25-26. Withdrawals totaling $2,000 were made from my checking account on August 5 and 6. Fortunately, the bank reimbursed me for the funds stolen, but this incident caused me a lot of unnecessary hassle and worry.
What I wanted to share with you is some information I got from a bank employee I'm friendly with. She told me that the scammers who did this are an Eastern European gang who have already skimmed numerous other ATMs in the Chicago area. They got over 50 people's card and PIN information from the Park Ridge ATM alone. According to her, the FBI and bank investigators have been chasing this gang for six months. She said that they started out in the city and are now working their way out into the suburbs.
What's amazing to me is that to the best of my knowledge there has been not one single story about this in the local media. Do a Google news search for "ATM skimming Chicago" and you won't find anything. If these guys have been in the area for six months, they must have already scammed hundreds if not thousands of people. You would think that might warrant a story in the Trib or something. It wasn't even mentioned in the police blotter of the local Park Ridge paper.
Very interesting. To prevent something similar from happening to you, familiarize yourself with how to recognize an ATM skimmer, try to stick to a few familiar-looking ATMs when possible, and be generally alert.
Monday, August 17, 2009
Alleged International Hacker Indicted for Massive Attack on U.S. Retail and Banking Networks
Albert Gonzales, 28, of Miami, Fla., was indicted today for conspiring to hack into computer networks supporting major American retail and financial organizations, and stealing data relating to more than 130 million credit and debit cards, announced Assistant Attorney General of the Criminal Division Lanny A. Breuer, Acting U.S. Attorney for the District of New Jersey Ralph J. Marra Jr. and U.S. Secret Service Assistant Director for Investigations Michael Merritt.
In a two-count indictment alleging conspiracy and conspiracy to engage in wire fraud, Gonzales, AKA "segvec," "soupnazi" and "j4guar17," is charged, along with two unnamed co-conspirators, with using a sophisticated hacking technique called an "SQL injection attack," which seeks to exploit computer networks by finding a way around the network’s firewall to steal credit and debit card information. Among the corporate victims named in the indictment are Heartland Payment Systems, a New Jersey-based card payment processor; 7-Eleven Inc., a Texas-based nationwide convenience store chain; and Hannaford Brothers Co. Inc., a Maine-based supermarket chain.
The indictment, which details the largest alleged credit and debit card data breach ever charged in the United States, alleges that beginning in October 2006, Gonzales and his co-conspirators researched the credit and debit card systems used by their victims; devised a sophisticated attack to penetrate their networks and steal credit and debit card data; and then sent that data to computer servers they operated in California, Illinois, Latvia, the Netherlands and Ukraine. The indictment also alleges Gonzales and his co-conspirators also used sophisticated hacker techniques to cover their tracks and to avoid detection by anti-virus software used by their victims.
If convicted, Gonzales faces up to 20 years in prison on the wire fraud conspiracy charge and an additional five years in prison on the conspiracy charge, as well as a fine of $250,000 for each charge.
Gonzales is currently in federal custody. In May 2008, the U.S. Attorney’s Office for the Eastern District of New York charged Gonzales for his alleged role in the hacking of a computer network run by a national restaurant chain. Trial on those charges is scheduled to begin in Long Island, N.Y., in September 2009.
In August of 2008, the Justice Department announced an additional series of indictments against Gonzales and others for a number of retail hacks affecting eight major retailers and involving the theft of data related to 40 million credit cards. Those charges were filed in the District of Massachusetts. Gonzales is scheduled for trial on those charges in 2010.
The charges announced today relate to a different pattern of hacking activity that targeted different corporate victims and involved different co-conspirators.
This case is being prosecuted by Assistant U.S. Attorneys Erez Lieberman and Seth Kosto for the U.S. Attorney’s Office for the District of New Jersey and by Senior Trial Counsel Kimberly Kiefer Peretti of the Criminal Division’s Computer Crime and Intellectual Property Section. The case is being investigated by the U.S. Secret Service.
Sunday, August 16, 2009
Tight Security in Place for Elections Day in Afghanistan
Top government officials responsible for security in Afghanistan say there is no way to ensure the Taliban will not be able to cause civilian casualties before the election or on the day of voting. Afghanistan's military is declaring a one-day unilateral cease-fire for election day Thursday, saying troops will only take defensive positions to prevent Taliban violence against polling stations.
The top government ministers responsible for security are defending their efforts four days before the presidential election and one day after a Taliban suicide car bombing in the capital. The attack outside the front gates of NATO headquarters in the most heavily guarded part of the capital killed seven people and injured nearly 100.
Speaking to reporters, the interior minister, the defense minister and the national security chief gave no promises there will not be another such event this week, but said they are doing their best to protect voters.
[...]
"Such terrorist attacks will not break the resolve of our nation. They [voters] will go to polling stations. They will vote for the person of their choice," said Atmar. "And they will show again and demonstrate their remarkable courage and resilience."
The defense minister, General Abdul Rahim Wardak, noted that even nations with "100-fold" more security resources, mentioning the United States, Britain, Spain, India, Indonesia and Pakistan, have not been able to prevent all attempted terrorist attacks.
DHS Plans Cyber Security Wiki
The Homeland Security Department plans to develop a “cyber ops wiki” that agencies can use to improve collaboration on cybersecurity efforts, according to a notice from the department.
The wiki will be used by DHS’ National Cyber Security Center (NCSC) and the six other federal cybersecurity centers as a collaboration tool and a way to develop improved situational awareness, communication and information sharing, DHS said in a notice published on Aug. 11 on the Federal Business Opportunities Web site.
Amy Kudwa, a DHS spokeswoman, said "NCSC is engaging industry expertise to develop a Web 2.0/3.0-enabled collaboration platform — this is an important piece of the larger NCSC vision of meaningful collaboration across government."
[...]
"The 'cyber ops wiki' ... will provide a capability for near-real-time information sharing and collaboration on cyber security incidents, as well as be a repository of technical information," Kudwa said. She added that DHS envisions that when completed the wiki "will leverage the individual strengths and technical competencies" of the government's cybersecurity centers run by defense, civilian, intelligence and law enforcement departments and agencies.
DHS said in the notice it intends to negotiate and award a sole-source contract with an company named WiiKnoInc based in Austin, Texas, to work on the project.
Stealth B-2 Bomber Upgrades Detailed
A fresh wave of structures, systems and weapons upgrades is being rolled into the Northrop Grumman B-2 as part of efforts to keep the stealth bomber in the front line to 2050 and beyond.
[...]
A key upgrade recovering from a slow start is the delayed B-2 radar modernization program (RMP). Under the RMP, the mechanically scanned antenna of the Raytheon APQ-181 Ku-band multimode navigation and attack radar is being replaced with an active electronically scanned array (AESA). The effort is now well underway, with five aircraft expected to be flying by year-end. Northrop Grumman, which manages the RMP, was awarded a $382-million system development and demonstration (SDD) contract by the Air Force in 2004.
Integration and other issues stalled the RMP and forced Northrop Grumman and El Segundo, Calif.,-based Raytheon Space and Airborne Systems to set up a "tiger team" to get the effort back on track, says Northrop Grumman vice president and B-2 program manager Dave Mazur. "A lot of decisions were being made and technical risks being pushed down the road to meet a ‘need date,' so we basically said ‘let's stop and re-group,'" he adds.
The upgrade, which also included a new power supply and modified receiver/exciter as well as the AESA antennae (two per shipset), was instigated because of an upcoming frequency spectrum conflict with emerging digital TV satellite signals. However, the hold-ups have had a knock-on effect because the RMP was designed in conjunction with other systems upgrades as part of efforts to provide the bomber with an "open architecture" for later modifications. "It's basically two years late, and all the upgrades are backed up," says Wheeler. "Now my biggest drawback is getting enough aircraft because they're going through the upgrades."