Wednesday, November 24, 2010

Aviation Security Threats and Realities

Via STRATFOR (Security Weekly) -

Over the past few weeks, aviation security — specifically, enhanced passenger-screening procedures — has become a big issue in the media. The discussion of the topic has become even more fervent as we enter Thanksgiving weekend, which is historically one of the busiest travel periods of the year.

[...]

We believe that this review will help establish that there is a legitimate threat to aviation, that there are significant challenges in trying to secure aircraft from every conceivable threat, and that the response of aviation security authorities to threats has often been slow and reactive rather than thoughtful and proactive.

[...]

While understanding that the threat is very real, it is also critical to recognize that there is no such thing as absolute, foolproof security. This applies to ground-based facilities as well as aircraft. If security procedures and checks have not been able to keep contraband out of high-security prisons, it is unreasonable to expect them to be able to keep unauthorized items off aircraft, where (thankfully) security checks of crew and passengers are far less invasive than they are for prisoners. As long as people, luggage and cargo are allowed aboard aircraft, and as long as people on the ground crew and the flight crew have access to aircraft, aircraft will remain vulnerable to a number of internal and external threats.

This reality is accented by the sheer number of passengers that must be screened and number of aircraft that must be secured. According to figures supplied by the Transportation Security Administration (TSA), in 2006, the last year for which numbers are available, the agency screened 708,400,522 passengers on domestic flights and international flights coming into the United States. This averages out to over 1.9 million passengers per day.

Another reality is that, as mentioned above, jihadists and other people who seek to attack aircraft have proven to be quite resourceful and adaptive. They carefully study security measures, identify vulnerabilities and then seek to exploit them. Indeed, last September, when we analyzed the innovative designs of the explosive devices employed by AQAP, we called attention to the threat they posed to aviation more than three months before the Christmas 2009 bombing attempt. As we look at the issue again, it is not hard to see, as we pointed out then, how their innovative efforts to camouflage explosives in everyday items and hide them inside suicide operatives’ bodies will continue and how these efforts will be intended to exploit vulnerabilities in current screening systems.

[...]

This ability to camouflage explosives in a variety of different ways, or hide them inside the bodies of suicide operatives, means that the most significant weakness of any suicide-attack plan is the operative assigned to conduct the attack. Even in a plot to attack 10 or 12 aircraft, a group would need to manufacture only about 12 pounds of high explosives — about what is required for a single, small suicide device and far less than is required for a vehicle-borne improvised explosive device. Because of this, the operatives are more of a limiting factor than the explosives themselves; it is far more difficult to find and train 10 or 12 suicide bombers than it is to produce 10 or 12 devices.

[...]

There has been much discussion of profiling, but the difficulty of creating a reliable and accurate physical profile of a jihadist, and the adaptability and ingenuity of the jihadist planners, means that any attempt at profiling based only on race, ethnicity or religion is doomed to fail. In fact, profiling can prove counterproductive to good security by blinding people to real threats. They will dismiss potential malefactors who do not fit the specific profile they have been provided.

In an environment where the potential threat is hard to identify, it is doubly important to profile individuals based on their behavior rather than their ethnicity or nationality — what we refer to as focusing on the “how” instead of the “who.” Instead of relying on physical profiles, which allow attack planners to select operatives who do not match the profiles being selected for more intensive screening, security personnel should be encouraged to exercise their intelligence, intuition and common sense. A Caucasian U.S. citizen who shows up at the U.S. Embassy in Nairobi or Dhaka claiming to have lost his passport may be far more dangerous than some random Pakistani or Yemeni citizen, even though the American does not appear to fit the profile for requiring extra security checks.

However, when we begin to consider traits such as intelligence, intuition and common sense, one of the other realities that must be faced with aviation security is that, quite simply, it is not an area where the airlines or governments have allocated the funding required to hire the best personnel. Airport screeners make far less than FBI special agents or CIA case officers and receive just a fraction of the training. Before 9/11, most airports in the United States relied on contract security guards to conduct screening duties. After 9/11, many of these same officers went from working for companies like Wackenhut to being TSA employees. There was no real effort made to increase the quality of screening personnel by offering much higher salaries to recruit a higher caliber of candidate.

There is frequent mention of the need to make U.S. airport security more like that employed in Israel. Aside from the constitutional and cultural factors that would prevent American airport screeners from ever treating Muslim travelers the way they are treated by El Al, another huge difference is simply the amount of money spent on salaries and training for screeners and other security personnel. El Al is also aided by the fact that it has a very small fleet of aircraft that fly only a small number of passengers to a handful of destinations.

[...]

While it is impossible to keep all contraband off aircraft, efforts to improve technical methods and procedures to locate weapons and IED components must continue. However, these efforts must not only be reacting to past attacks and attempts but should also be looking forward to thwart future attacks that involve a shift in the terrorist paradigm. At the same time, the often-overlooked human elements of airport security, including situational awareness, observation and intuition, need to be emphasized now more than ever. It is those soft skills that hold the real key to looking for the bomber and not just the bomb.

Tuesday, November 23, 2010

Instant Analysis: New Issue of Inspire Magazine

http://www.icsr.info/blog/Instant-Analysis-New-Issue-of-Inspire-Magazine

This is an ICSR Instant Analysis of Recent AQAP Propaganda written by Senior Fellow Shiraz Maher

The latest edition of Al Qaeda’s ‘Inspire’ reveals more details about the recent airline bomb plot which emanated in Yemen.

‘Inspire’ is an English-language magazine produced quarterly by al-Qaeda in the Arabian Peninsula (AQAP). Its latest ‘special edition’ reveals more details of the plot and an insight in the strategic mindset of AQAP. The magazine is divided into three parts: a discussion of the strategic objectives (including its economic impact), the religious objectives, and technical information on the bomb itself.

[...]

Operational background

AQAP called this project ‘Operation Haemorrhage’ (in the magazine they use the American spelling: ‘Hemorrhage’).

[...]

Strategic Objectives

It now seems clear that the primary objective of this attack was not the synagogues to which the parcels were addressed. The objective of the plot is discussed twice in different articles. The first says:
The operation was to be based on two factors: The first is that the packages pass through the latest security equipment. The second, the spread of fear that would cause the West to invest billions of dollars in new security procedures.
The other states:
From the start our objective was economic. Bringing down a cargo plane would only kill a pilot and co-pilot.
The ‘head of operations’ claims that the primary aim was economic:
The air freight is a multi-billion dollar industry…For the trade between North America and Europe air cargo is indispensable and to be able to force the West to install stringent security measures sufficient enough to stop our explosive devices would add a heavy economic burden to an already faltering economy.
According to the magazine, the ink cartridge plot cost AQAP just $4200 (£2615), demonstrating how a relatively cheap operation can still inflict massive economic and financial damage. This is something AQAP is keen to underscore, telling readers:
Two Nokia mobiles, $150 each, two HP printers, $300 each, plus shipping, transportation and other miscellaneous expenses add up to a total bill of $4,200. That is all what Operation Hemorrhage cost us. In terms of time it took us three months to plan and execute the operation from beginning to end. On the other hand this supposedly "foiled plot", as some of our enemies would like to call, will without a doubt cost America and other Western countries billions of dollars in new security measures.
That is what we call leverage. A $4,200 operation will cost our enemy billions of dollars. In terms of time and effort, three months of work for a team of less than six brothers would end up costing the West hundreds of thousands, if not millions, of hours of work in an attempt to protect itself from our packages of death.

North Korean Artillery Attack on a Southern Island















AFP PHOTO - Hattip to Public Intelligence

This picture taken on November 23, 2010 by a South Korean tourist shows huge plumes of smoke rising from Yeonpyeong island in the disputed waters of the Yellow Sea on November 23, 2010



http://www.stratfor.com/analysis/20101123_north_korean_artillery_attack_southern_island

North Korea and South Korea have reportedly traded artillery fire Nov. 23 across the disputed Northern Limit Line (NLL) in the Yellow Sea to the west of the peninsula. Though details are still sketchy, South Korean news reports indicate that around 2:30 p.m. local time, North Korean artillery shells began landing in the waters around Yeonpyeongdo, one of the South Korean-controlled islands just south of the NLL. North Korea has reportedly fired as many as 200 rounds, some of which struck the island, injuring at least 10 South Korean soldiers, damaging buildings and setting fire to a mountainside. South Korea responded by firing some 80 shells of its own toward North Korea, dispatching F-16 fighter jets to the area and raising the military alert to its highest level.

South Korean President Lee Myung Bak has convened an emergency Cabinet meeting, and Seoul is determining whether to evacuate South Koreans working at inter-Korean facilities in North Korea. The barrage from North Korea was continuing at 4 p.m. Military activity appears to be ongoing at this point, and the South Korean Joint Chiefs of Staff are meeting on the issue. No doubt North Korea’s leadership is also convening.

[...]

While the South Korean reprisals — both artillery fire in response by self-propelled K-9 artillery and the scrambling of aircraft — thus far appear perfectly consistent with South Korean standard operating procedures, the sustained shelling of a populated island by North Korea would mark a deliberate and noteworthy escalation.

The incident comes amid renewed talk of North Korea’s nuclear program, including revelations of an active uranium-enrichment program, and amid rumors of North Korean preparations for another nuclear test. But North Korea also on Nov. 22 sent a list of delegates to Seoul for Red Cross talks with South Korea, a move reciprocated by the South, ahead of planned talks in South Korea set for Thursday. The timing of the North’s firing at Yeonpyeongdo, then, seems to contradict the other actions currently under way in inter-Korean relations. With the ongoing leadership transition in North Korea, there have been rumors of discontent within the military, and the current actions may reflect miscommunications or worse within the North’s command-and-control structure, or disagreements within the North Korean leadership.




North Korea v South Korea: Mapping Every Incident from 1958 to 2010
http://www.guardian.co.uk/news/datablog/2010/nov/23/north-korea-yeonpyeong-island-incidents-map

This is obviously not the first time this has happened - there have been over 150 incidents since the Korean War in 1950, that we know about. The reason we do know about these is because of an exhaustive report by the Congressional Research Service, published in 2007. It covers every incident, from diplomatic hostilities, through to the more serious events where people have died.

We wanted to map those events, using Google Fusion tables - and that's what you can see above. There are some hefty caveats here. Where we didn't know the precise location, we have made an educated guess, based on reports and the location details we do have. The other thing worth noting is that this was compiled in the US - a report compiled in Pyongyang would look very very different.

Exploit Code For Stuxnet Windows Task Scheduler Bug Posted

Via Threatpost.com -

Exploit code is now publicly available for one of the four previously undisclosed Windows vulnerabilities that the Stuxnet worm exploits. The availability of exploit code for the Windows Task Scheduler bug used by Stuxnet makes the bug somewhat more dangerous, as there is currently no patch available for the flaw.

The Windows Task Scheduler exploit code was added to the Exploit Database over the weekend and is designed for use against systems running Windows Vista, Windows 7 or Windows Server 2008. The Task Scheduler bug is just one of several vulnerabilities that the Stuxnet worm uses in its attack routine. It's one of the less severe of that group of flaws, in that it's only used for privilege escalation once an attacker has already compromised a machine.

Microsoft has not released a patch for the Task Scheduler vulnerability as yet. The company has patched three other bugs used by Stuxnet, including the LNK flaw that was one of the things that originally brought the worm to researchers' attention earlier this year.


---------------------------------------------------------------------------------------------------------------------------

On Saturday, Nov 20th, the unpatched Task Scheduler exploit was also added to Metasploit.

https://www.metasploit.com/redmine/projects/framework/repository/revisions/11079/changes/scripts/meterpreter/schelevator.rb

Monday, November 22, 2010

Chinese National Stole Ford Secrets Worth More Than $50 Million

Via Threatpost.com -

A ten year veteran of the U.S. automaker Ford Motor Company pleaded guilty in federal court on November 17 to charges that he stole company secrets, including design documents, worth more than $50 million and sharing them with his new employer: the Chinese division of a U.S. rival of Ford's.

Xiang Dong ("Mike") Yu admitted to copying some 4,000 Ford Documents to a external hard drive, including system design specifications for Ford's cars after surreptitiously taking a job with a competitor in 2006.

Under the plea agreement, announced last week, Yu faces a sentence ranging from five to six years in prison and a fine of up to $150,000 for a theft of trade secrets valued at between $50 million and $100 million, according to a statement by Barbara L. McQuade, the United States Attorney for the Eastern District of Michigan.

According to the Plea Agreement, Yu obtained documents containing prized Ford design documents, including those for components such as an Engine/Transmission Mounting Subsystem, Electrical Distribution system, Electric Power Supply, Electrical Subsystem and Generic Body Module. Yu was a Product Engineer at Ford, where he had worked since 1997, but the documents taken had no connection to his work at Ford.

Yu did not inform Ford of his decision to take a position with a competitor prior to leaving the country with the documents on December 20, 2006, He later e-mailed his supervisor at Ford from China to inform him that he was leaving the company. Yu later accepted a job with a Chinese based competitor of Ford's, Beijing Automotive Company, of Shenzhen, China, in November, 2008.

He was taken into custody by the FBI in October, 2009, after stopping over in Chicago on a return trip to China. An analysis of the laptop computer Yu carried at the time included copies of 41 Ford system design specification documents.

How the DEA Tracked Viktor Bout

Via Newsweek.com -

When celebrated Russian arms dealer Viktor Bout landed last Tuesday night at Stewart International Airport in upstate New York—before being whisked to Manhattan to appear the next day in front of a district-court judge—it marked the end of a saga known to the Drug Enforcement Administration as Operation Relentless. The man who ran it tells NEWSWEEK the affair began with a challenge from the White House.

After 9/11, law-enforcement agencies had expanded jurisdiction to arrest foreign nationals living outside the U.S. but accused of crimes against Americans. Michael Braun, the DEA’s head of operations from 2004 until 2008, had overseen a string of high-profile global arrests, including that of Monzer Al Kassar, a member of the Palestinian Liberation Front and, in his day, the world’s second-biggest arms dealer. Braun says that a colleague on the National Security Council, congratulating the DEA team on Kassar’s 2007 arrest (he’s serving a 30-year sentence), suggested it go after public enemy No. 1: Bout. According to Braun, the NSC official, whom Braun wouldn’t name, said, “Every other three-letter agency in town had been tracking him.” Could the DEA succeed where they had failed? “We said, ‘OK, yeah, let’s see what we can do here,’?” says Braun, who now runs a firm supporting State and Pentagon efforts to train law-enforcement personnel worldwide.

Posing as buyers for the Colombian insurgent group FARC, the DEA—which had played the same trick on Kassar—trapped Bout in a March 2008 sting operation in Bangkok; Thai police arrested him at the behest of the U.S., provoking a two-year battle with Russia, which wanted to keep Bout from being extradited to America. But last Monday, the Thais—who received periodic reminders from Washington of their privileged trade status—agreed to let the U.S. have Bout. (He pleaded not guilty, and his next hearing is scheduled for Jan. 10.)

Why were the Russians so anxious to keep Bout out of American hands? Known as "Africa’s merchant of death," Bout is thought by U.S. officials to have built an empire worth perhaps $6 billion. According to a U.N. report, he supplied arms to Angola, the Democratic Republic of the Congo, Liberia, Rwanda, Sierra Leone, and Sudan (not to mention Afghanistan). "Bout had the ability to acquire the most sophisticated weapons systems that the former Soviet bloc could offer," Braun says. "He could not have acquired the weapons systems he did without complicity at the highest ranks of the government and military in Russia." Yevgeny Khorishko, a spokesman for the Russian Embassy, says, "Russian officials were never involved in any activities of Mr. Bout, if there were any activities—and there is no proof of that."


-----------------------------------------------------------------------------------------------------------------

Nov 16, 2010 - DEA Press Release
http://www.justice.gov/dea/pubs/pressrel/pr111610.html
After more than two years of legal proceedings, alleged international arms dealer Viktor Bout has been extradited to the Southern District of New York from Thailand to stand trial on terrorism charges, the Justice Department announced today.

April BGP Route Hijack: Sifting Through the Confusion

Via McAfee Research Blog -

A lot has been written in recent days since we have posted the blog on the 18 minute traffic redirection issue earlier this week and the U.S. – China Economic and Security Review Commission report came out discussing it. Unfortunately, some media did get a few points wrong that I would like to address:

1. There is absolutely no proof that this was an intentional attack. Routing hijacks happen fairly frequently and most of them are accidental nature. We believe they do demonstrate a frightening lack of security in the fundamental building blocks on the Internet and that the security and the routing communities need to take steps to address those vulnerabilities — and soon.

2. A lot of media reports have claimed that ’15% of Internet traffic was hijacked’. That is a false statement. Based on our analysis, there were 53,353 network routing prefixes that had been announced false on April 8th, out of a total of roughly 330,000 network routes that existed in routing tables at that time. That amounts to 15% of the networks on the Internet, not necessarily 15% of the traffic. It is very difficult to estimate how much of the traffic was actually redirected and the true estimate can only come from the owner of the network that has routed all of this traffic

3. Craig Labovitz from Arbor Networks has posted a very good and detailed analysis of Arbor’s traffic estimate on this hijack. Unfortunately, Craig posted this analysis for the IDC Beijing China Telecom (AS23724), which was indeed the original announcer of the incorrect routes. However, China Telecom (AS4134) was the network that actually distributed that route to the public Internet. Thus, that is the network whose traffic levels should be measured to determine the true impact of the route redirection, as it would be the first (and quite likely last) recipient of the packets which would have been redirected.

This topic is unfortunately highly technical and very difficult to explain to people not fully immersed into the BGP routing jargon. Nevertheless, this incident underscores the very serious problems that exist on the Internet due to the system of trust that has been put in place more than 3 decades ago when this network was first invented. As Vint Cerf, the father of the Internet, as he is known, has said – ‘The Internet was an experiment that never ended’. It is now time for us as a community to come together to build more security into the core of the Internet to protect this vital global economic resource.

BackTrack 4 R2 Released

http://www.backtrack-linux.org/backtrack/backtrack-4-r2-download/

Yes, the time has come again, for a new kernel, and a new release of BackTrack. Codenamed "Nemesis". This release is our finest release as of yet with faster Desktop responsiveness, better hardware support, broader wireless card support, streamlined work environment.

Bypassing Microsoft's Export Address Table Address Filter (EAF)

http://skypher.com/index.php/2010/11/17/bypassing-eaf/

In early September this year Microsoft released their Enhanced Mitigation Experience Toolkit v2.0 (EMET), which includes a new “pseudo”-mitigation called Export address table Address Filter (EAF). I decided to have a look at how this mitigation attempts to prevent exploits from succeeding and how an attacker might bypass it. For people that suffer from tl;dr syndrome, I’ve put my conclusion up front:

It is my conclusion that EAF should be effective at preventing most current shellcode from executing and therefore a useful mitigation. However, it is relatively simple to bypass. Proof of concept code to do this can be found here. I expect that if EAF becomes a common mitigation, attackers will update their shellcodes to bypass it. I cannot think of any effective way in which EAF can be updated that would not be relatively simple to bypass as well.


-------------------------------------------------------------------------------------------------------------------------------

As SkyLined indicates the post was released and then pulled back...but it stayed in Google's cache and was accessible to anyone that looked for it last week. Thanks to @shazzzam for the heads up on it last week.

This bypass was all but expect by Microsoft....as stated in Page 10 of the EMET 2.0 User Guide.

Please note this is a pseudo mitigation designed to break current exploit techniques. It is not designed to break future exploits as well. As exploit techniques continue to evolve, so will EMET.
EAF is just another hoop that the attacker has to jump through, just like the Heapspray Allocation migitation provided by EMET. Can they be bypassed? Sure. But you have to plan to bypass them first.

In my view, the Mandarotry ASLR feature of EMET is one of the most useful mitigations provided by the tool....but sadly, Windows XP doesn't support ASLR, so you will have to be on Windows Vista, Windows 2008 or Windows 7 to get the benefits.

Foreign Cyber Spies Target British Defence Official

Via The Register UK -

Foreign spies targeted a senior British defence official in a sophisticated spear phishing operation that aimed to steal military secrets.

The plan was foiled last year when the official became suspicious of an email she received from a contact she had met at a conference.

The official showed the highly personalised message to Ministry of Defence IT experts, who then found the attachment contained malware designed to leak classified material to a foreign intelligence agency.

The MoD declined to comment on the incident, which was briefly discussed at a recent conference by Simon Kershaw, its head of defence security and assurance.

The Register, however, has established that the foreign spies' target was Joanna Hole, who until her retirement in March was the MoD's head of safety and sustainable development. She had responsibility for business continuity and regularly briefed ministers and forces chiefs.

In a previous role, according to her LinkedIn profile, Hole represented the MoD at the highly sensitive COBRA emergency committee.

Kershaw did not name the foreign power behind the operation, but China is the most likely culprit. Its huge online espionage effort was a major motivator of the recent government decision to spend £650m in improved cyber security over four years.

Sunday, November 21, 2010

Clues to Stubborn Secret in C.I.A.’s Backyard

Via NYTimes.com -

It is perhaps one of the C.I.A.’s most mischievous secrets.

“Kryptos,” the sculpture nestled in a courtyard of the agency’s Virginia headquarters since 1990, is a work of art with a secret code embedded in the letters that are punched into its four panels of curving copper.

“Our work is about discovery — discovering secrets,” said Toni Hiley, director of the C.I.A. Museum. “And this sculpture is full of them, and it still hasn’t given up the last of its secrets.”

Not for lack of trying. For many thousands of would-be code crackers worldwide, “Kryptos” has become an object of obsession.

[...]

The code breakers have had some success. Three of the puzzles, 768 characters long, were solved by 1999, revealing passages — one lyrical, one obscure and one taken from history. But the fourth message of “Kryptos” — the name, in Greek, means “hidden” — has resisted the best efforts of brains and computers.

And Jim Sanborn, the sculptor who created “Kryptos” and its puzzles, is getting a bit frustrated by the wait. “I assumed the code would be cracked in a fairly short time,” he said, adding that the intrusions on his life from people who think they have solved his fourth puzzle are more than he expected.

So now, after 20 years, Mr. Sanborn is nudging the process along. He has provided The New York Times with the answers to six letters in the sculpture’s final passage. The characters that are the 64th through 69th in the final series on the sculpture read NYPVTT. When deciphered, they read BERLIN.

But there are many steps to cracking the code, and the other 91 characters and their proper order are yet to be determined.

“Having some letters where we know what they are supposed to be could be extremely valuable,” said Elonka Dunin, a computer game designer who runs the most popular “Kryptos” Web page.

Saturday, November 20, 2010

Threat Revealed: Terrorists Believed to Be Planning Attack in Berlin

Via Spiegel.de (Germany) -

SPIEGEL has learned that terrorists may have been planning an attack on the Reichstag, the home of the German parliament and one of the most popular tourist destinations in Berlin. Two suspected culprits are already believed to be in Berlin.

According to information obtained by German security authorities, al-Qaida and associated groups are believed to be planning an attack on the Reichstag building in Berlin, the headquarters of Germany's parliament and also an attraction visited by thousands of tourists every day. As part of the attack, terrorists would seek to take hostages and perpetrate a bloodbath using firearms.

The information about the alleged plans came from a jihadist who is currently abroad and has reportedly contacted the German Federal Criminal Police Office (BKA) several times in recent days. The jihadist apparently wants to abandon the group. The information provided by the jihadist informant was apparently the reason behind German Interior Minister Thomas de Maizière's decision to hold a press conference on Wednesday warning of an imminent attack in the country.

According to the caller, the terror cell is comprised of six people -- two of whom are believed already to have traveled to Berlin six to eight weeks ago, and are now staying in the city. Four other perpetrators -- a German, a Turk, a North African and a further man the jihadist could not identify -- are currently waiting to travel to Germany. The attacks are purportedly being planned for February or March.

The second warning backing de Maizière's concerns came from the United States. The US federal police, the FBI, sent a cable to the BKA two weeks ago noting another possible further attack. A Shiite-Indian group known as the "Saif," or sword, is believed to have engaged in a pact with al-Qaida and to have sent two men to Germany to carry out an attack there.

Both were believed to be traveling to the United Arab Emirates on Nov. 22, where they would be supplied with new travel papers so that they could continue on to Germany. The suspects allegedly already posess visas for Europe's Schengen zone of visa-free travel. The FBI has named Mushtaq Altaf bin-Khadri as the man behind the attack plans.

The man believed to be trying to smuggle the would-be terrorists into Europe is 54-year-old weapons dealer Dawood Ibrahim, who the United Nations believes is a major backer of terrorism. He is considered to be one of the men behind the terror attacks perpetrated in Mumbai in November 2008. The FBI and Germany's BKA both consider the message to be extremely important. However, the US foreign intelligence service, the CIA, and both the German foreign intelligence service, the BND, and its domestic counterpart, the Office for the Protection of the Constitution, are skeptical.


--------------------------------------------------------------------------------------------------------------

http://www.longwarjournal.org/threat-matrix/archives/2010/01/dawood_ibrahim_al_qaeda_and_th.php

The Congressional Research Service has issued a solid report on the nexus between criminal syndicates and terrorist groups. Entitled "International Terrorism and Transnational Crime: Security Threats, U.S. Policy, and Considerations for Congress," the report has a section devoted to Dawood Ibrahim, the criminal don of South Asia. The report acknowledges that Dawood is aligned with al Qaeda, the Lashkar-e-Taiba, and Pakistan's Inter-Services Intelligence agency.

--------------------------------------------------------------------------------------------------------------

Page 15 of the CRS report...

Dawood Ibrahim’s D-Company, a 5,000-member criminal syndicate operating mostly in Pakistan, India, and the United Arab Emirates, provides an example of the criminal-terrorism “fusion” model. The U.S. Department of Treasury designated Ibrahim as a Specially Designated Global Terrorist (SDGT) under Executive Order 13224 in October 2003. In June 2006, President George W. Bush designated him, as well as his D-Company organization, as a Significant Foreign Narcotics Trafficker under the Foreign Narcotics Kingpin Designation Act (hereafter “Kingpin Act”). D-Company is reportedly involved in several criminal activities, including extortion, smuggling, narcotics trafficking, and contract killing. The organization has also reportedly infiltrated the Indian film-making industry, extorting producers, assassinating directors, distributing movies, and pirating films.

Application Security Guide for the Acrobat Family of 9.x Products

http://learn.adobe.com/wiki/download/attachments/64389123/AcrobatApplicationSecurity.pdf?version=1

Most users have reasons to care about security, but in enterprise settings security concerns are heightened by the value of the hardware, software, and data that comprise a company’s network. Administrators need to configure and maintain clients across the organization, and workflow architects need to create secure end-to-end workflows. Caring for the integrity of expensive networked systems and critical data certainly consumes much in the way of IT resources.

This Application Security Guide describes configuration details for the Acrobat family of products, including enhanced security, scripting controls, attachments, and any other features. The primary goal here is to encourage enterprise stakeholders who configure and deploy clients to manage them in a secure way. While the content here is primarily aimed at administrators, other potential audiences include:
  • Workflow owners and IT folks who are responsible for the integrity of their networked environment.
  • Technically savvy end users that need to customize their application’s security capabilities.

Friday, November 19, 2010

Ongoing DDoS Against Abuse.ch Services - ZeuS Tracker & SpyEye Tracker

According to tweets published by @abuse_ch, an ongoing DDoS attack against the name servers of abuse.ch has caused their services to be inaccessible. Their ISP has failed to mitigate the attack at this point.

In the meantime, here are the backup URLs....

ZeuS Tracker - https://87.106.254.198/
SpyEye Tracker - https://82.165.47.254/

Kudos to Abuse.ch for fighting the good fight. Clearly, the trackers are causing damage which forced these blackhats to waste both bots and money to facilitate the DDoS attack.

Faux-Targeted Attacks and the Magic of Cold Reading

http://blog.zeltser.com/post/1609709966/faux-targeted-attacks

Mass-scale computer attacks are sometimes mistaken for campaigns that target the concerned organization, causing unnecessary stress and expenses. The reason for the confusion is similar to the reason why a fortune teller seems to know so much about the customer whom he just met for the first time.

[...]

People are more aware of targeted computer attacks now than a year ago. This is, in part, the result of the publicity associated with the term Advanced Persistent Threat (APT), which highlighted the existence and success of a particular category of targeted attacks.

Targeted computer attacks are scary. It’s very difficult to resist targeted threats. Moreover, they feel very personal: targeted attack scenarios pierce the shield of emotional detachment that security professionals develop after being exposed to numerous security incidents.

[...]

Fortune tellers practice the magic of cold reading, whereby they seem to know the person’s history, worries and weaknesses by merely looking at him. They often accomplish this by making generalized statements that are true for most people, with the expectation that the subject will find a way to make the statement apply to himself.

This approach to cold reading relies on the Forer effect, which refers to people’s tendency to accept vague “personality descriptions as uniquely applicable to themselves without realizing that the same description could be applied to just about anyone.”

[...]

Computer attackers use a similar approach when social-engineering messages to make them feel personally-relevant to victims. A related phenomenon is people’s tendency to see patterns where none were intended; this is called illusory pattern perception.

Taken together, these psychological factors provide an explanation for why individuals believe they might be victims of targeted attacks, even when they are actually dealing with generic mass-scale incidents.

If you believe your organization is dealing with a targeted attack, you’re right to worry. But keep in mind that some attacks that feel targeted, aren’t. Consider all perspectives on the incident before making the diagnosis.

Public Intelligence - Afghan Landscapes

















A girl looks South into the mountains surrounding Lower Kajakan Village in the Shinwari District of Afghanistan. Photo by David Elmore of the United States of America.

----------------------------------------------------------------------------------------------

Check out the Public Intelligence Blog for some other greats landscape photos.

Thursday, November 18, 2010

EFF: The Case Against COICA

https://www.eff.org/deeplinks/2010/11/case-against-coica

EFF is deeply disappointed to report that the Senate Judiciary Committee approved the COICA Internet censorship bill this morning, despite bipartisan opposition, and countless experts pointing out how it would be ineffective, unconstitutional, bad for innovation and the tech economy, and would break the Internet.

Notably, Senator Feinstein and Senator Coburn commented on the need for more work on elements of the bill — an important consideration as negotiations shift to the Senate at large. The bill is unlikely to come up again until next session, and in the meantime, we look forward to educating Congress about the dangers in COICA, and joining others to oppose this or any other infringement "solution" that threatens lawful speech online.

Adobe Reader X - Now Available

http://blogs.adobe.com/asset/2010/11/adobe-reader-x-is-here.html

Since we first announced the development of a sandbox for Adobe Reader on July 20, 2010, there has been a tremendous level of interest in the sandboxing topic — and an equal level of anticipation for Adobe Reader X.

[...]

Today, all of the hard work has come to fruition, and we are happy to announce that Adobe Reader X (with Protected Mode, aka sandboxing, on Windows) is now available! To download the new version of Adobe Reader, visit www.adobe.com/reader.

Adobe’s product security initiatives are focused on reducing both the frequency and the impact of security vulnerabilities. Adobe Reader Protected Mode represents an exciting new advancement in mitigating the impact of attempted attacks. While sandboxing is not a security silver bullet, it provides a strong additional level of defense against attacks. Even if exploitable security vulnerabilities are found by an attacker, Adobe Reader Protected Mode will help prevent the attacker from writing files or installing malware on potential victims’ computers.

For more information on Adobe Reader X and on Adobe Reader X Protected Mode in particular, see the following blog posts:

Kryptos Artist to Reveal Rare Clue to Baffling CIA Sculpture

Via Wired.com (Threat Level) -

Kryptos sleuths may finally get some help cracking the CIA sculpture that has confounded amateur and professional cryptographers for two decades.

Artist Jim Sanborn, who created the cypher sculpture in 1990 for CIA headquarters in Langley, Virginia, plans to release a new clue to help puzzle detectives solve the last 97 characters of his masterpiece. The new clue is to be revealed in a New York Times article this weekend, to mark the 20th anniversary of the sculpture, which was dedicated Nov. 3, 1990.

It will be the first clue Sanborn has revealed in four years, after he corrected a typo in his sculpture in 2006 to keep crypto detectives from being derailed in their search for solutions.

Sanborn wouldn’t disclose the clue to Threat Level but said only cryptically that it will "globalize" the sculpture. Asked if this meant it would take the sculpture off the CIA grounds and out of the United States, he conceded it would.

"I personally think it’s a significant clue," he said. "I’m throwing it out there. It just makes that many fewer characters people have to figure out."

Sanborn said he’d been thinking about revealing a clue for a long time but couldn’t decide on the right occasion until the 20th anniversary and his birthday coincided in the same month.

"I don’t have that many decades...left in me," the 65-year-old artist said.

The 12-foot-high, verdigrised copper, granite and wood sculpture is inscribed with four encrypted messages, three of which have been solved. The sculpture’s theme is intelligence gathering (Kryptos is Greek for “hidden”).

It features a large block of petrified wood standing upright, with a tall copper plate scrolling out of the wood like a sheet of paper. At the sculpture’s base is a round pool with fountain pump that sends water in a circular motion around the pool. Carved out of the copper plate are approximately 1,800 letters, some of them forming a table based on an encryption method developed in the 16th century by a Frenchman named Blaise de Vigenere.

Sanborn sells replicas of the sculpture for $150 at the International Spy Museum in Washington, D.C., and other locations.

n 1998, CIA analyst David Stein cracked three of the four messages using paper and pencil and about 400 lunch-time hours. Only his CIA colleagues knew of his success, however, because the agency didn’t publicize it. A year later, California computer scientist Jim Gillogly gained public notoriety when he cracked the same three messages using a Pentium II.

Tuesday, November 16, 2010

iPhone Forensics White Paper

http://viaforensics.com/education/white-papers/iphone-forensics/

This white paper is intended for forensic analysts, corporations and consumers who want to understand what personal information is stored on the iPhone and how to recover it. The research reveals the vast amount of personal information stored on Apple’s iPhone and reviews techniques and software for retrieving this information.

Cybercriminals, Insiders May Work Together To Attack Businesses

Via DarkReading.com -

For 19 months, an employee at Johns Hopkins Hospital allegedly stole patients' identities, feeding the information to a four outsiders who used the data to charge up more than $600,000 in goods on store credit. Jasmine Amber Smith, 25, has been charged with using her inside access to fuel the identity theft ring.

Employees working with cybercriminals may be not be the norm for security breaches, but it's not a rare crime, either, experts say. It's not unusual for cybercriminals to gain inside access through bribery and solicitation, two components of social engineering, according to Verizon Business' Data Breach Investigations Report. Social engineering accounted for 28 percent of breaches analyzed in the report, with solicitation and bribery leading to nearly a third of those breaches.

"These were scenarios in which someone outside the organization conspired with an insider to engage in illegal behavior," the report says. "They recruit, or even place, insiders in a position to embezzle or skim monetary assets and data, usually in return for some cut of the score."

[...]

Because partnerships between cybercriminals and insiders are still uncommon, companies should focus their defenses on mainstream practices and tools for monitoring employee behavior, says Phil Neray, vice president of security strategy for Guardium, an IBM company.

An employee could stay within their authorized limits and still steal from the company, Neray observes.

"The only way to handle that is to rely on other forms of security than just identity and access management," Neray says. "The bad guys may have someone on the inside -- or a copy of the log-in credentials for your most sensitive systems -- so you have to start using anomaly detection, not just at the network level, but at the user-activity level."

Most of the cases of insider cooperation analyzed by Verizon Business -- which included data from the U.S. Secret Service -- involved embezzlement from banks, retailers, or the hospitality industry. Companies in those industries should have policies and technology in place to catch insiders focused on cash.

The report from Forrester found that aerospace, defense, electronics and consulting companies had far more to lose from the theft of corporate secrets. A rogue employee stealing corporate information is generally the most expensive breach, according to that report.

Monday, November 15, 2010

Rule #1 for Pirate Hostages: Don’t Get Stoned

Via Wired.com (Danger Room) -

Don’t get high, don’t piss anyone off, and try to smile every once in a while: These are just some of the handy tips that can help you make your captivity in the hands of Somali pirates more enjoyable.

The waters around the Horn of Africa are getting more dangerous for seafarers. Hijackings by Somali piratesshootouts with mercs and hijack attempts against warships continue and pirates are holding hostages for as long as 13 months. EU Navfor, the European Union’s naval forces countering piracy off the coast of Somalia, has responded to this crisis with a handy pamphlet, “Surviving Piracy Off the Coast of Somalia,” containing all the wisdom you need to make the most of your captivity. are on the upswing this year, deadly

One tip from elementary school is particularly helpful: Just say no to drugs. Khat is a leaf with amphetamine-like effects common in Somalia, particularly among pirates, and may be available to you while detained on board your captured ship.  Though borrowing from your captors’ stash may provide you with some “temporary relief” from the drudgery of captivity, it can bad for your health in the form on an acute pirate beatdown. The “negative effects of withdrawal symptoms and increased tension due to cravings,” the pamphlet warns,  can irritate your pirate hosts and result in “unnecessary violence.” In other words, nobody likes a cranky junky, particularly not pirates, so be smart and politely decline if offered drugs.

Adobe to Issue Emergency Updates for Reader, Acrobat

http://www.adobe.com/support/security/bulletins/apsb10-28.html

Adobe is planning to release updates for Adobe Reader 9.4 and earlier 9.x versions for Windows, Macintosh and UNIX, and Adobe Acrobat 9.4 and earlier 9.x versions for Windows and Macintosh to resolve critical security issues, including CVE-2010-3654 noted in Security Advisory APSA10-05, CVE-2010-4091 referenced in the Adobe PSIRT blog ("Potential issue in Adobe Reader"), and the Adobe Flash Player update as noted in Security Bulletin APSB10-26. Adobe expects to make updates for Windows and Macintosh available on Tuesday, November 16, 2010. An update for UNIX is expected to be available on Monday, November 30, 2010.

Sunday, November 14, 2010

Stuxnet Breakthrough: Frequency Converter Drives

http://www.symantec.com/connect/blogs/stuxnet-breakthrough

Thanks to some tips from a Dutch Profibus expert who responded to our call for help, we’ve connected a critical piece of the puzzle.

Since our discovery that Stuxnet actually modifies code on PLCs in a potential act of sabotage, we have been unable to determine what the exact purpose of Stuxnet is and what its target was.

However, we can now confirm that Stuxnet requires the industrial control system to have frequency converter drives from at least one of two specific vendors, one headquartered in Finland and the other in Tehran, Iran. This is in addition to the previous requirements we discussed of a S7-300 CPU and a CP-342-5 Profibus communications module.

A frequency converter drive is a power supply that can change the frequency of the output, which controls the speed of a motor. The higher the frequency, the higher the speed of the motor.

The new key findings are:
  • We are now able to describe the purpose of all of Stuxnet’s code.
  • Stuxnet requires particular frequency converter drives from specific vendors, some of which may not be procurable in certain countries.
  • Stuxnet requires the frequency converter drives to be operating at very high speeds, between 807 Hz and 1210 Hz. While frequency converter drives are used in many industrial control applications, these speeds are used only in a limited number of applications.
  • Stuxnet changes the output frequencies and thus the speed of the motors for short intervals over periods of months. Interfering with the speed of the motors sabotages the normal operation of the industrial control process.
  • Stuxnet’s requirement for particular frequency converter drives and operating characteristics focuses the number of possible speculated targets to a limited set of possibilities.
Stuxnet monitors the current operating frequency of these motors, which must be between 807 Hz and 1210 Hz, before Stuxnet modifies their behavior. Relative to the typical uses of frequency converter drives, these frequencies are considered very high-speed and now limit the potential speculated targets of Stuxnet. We are not experts in industrial control systems and do not know all the possible applications at these speeds, but for example, a conveyor belt in a retail packaging facility is unlikely to be the target. Also, efficient low-harmonic frequency converter drives that output over 600Hz are regulated for export in the United States by the Nuclear Regulatory Commission as they can be used for uranium enrichment. We would be interested in hearing what other applications use frequency converter drives at these frequencies.

Once operation at those frequencies occurs for a period of time, Stuxnet then hijacks the PLC code and begins modifying the behavior of the frequency converter drives. In addition to other parameters, over a period of months, Stuxnet changes the output frequency for short periods of time to 1410Hz and then to 2Hz and then to 1064Hz. Modification of the output frequency essentially sabotages the automation system from operating properly. Other parameter changes may also cause unexpected effects.

With this discovery, we now understand the purpose of all of Stuxnet’s code. We’ve modified our paper, in particular multiple subsections of the Modifying PLCs section, to include the finer details. Since we are far from experts in industrial control systems, we appreciate any feedback or further tips or explanation of some of the data. You can click on my name at the top of the blog post to get in touch.

We’d like to sincerely thank the Dutch Profibus expert who got in touch, serving as the catalyst to this breakthrough in understanding the purpose and potential targets of Stuxnet.

Here is the link to the updated paper.

Friday, November 12, 2010

Koobface: Inside a Crimeware Network

http://www.infowar-monitor.net/2010/11/koobface/

The Information Warfare Monitor (Citizen Lab, Munk School of Global Affairs, University of Toronto and The SecDev Group, Ottawa) announce the release of Koobface: Inside a Crimeware Network by Nart Villeneuve, with a foreword by Ron Deibert and Rafal Rohozinski.

This report (PDF) documents the inner workings of Koobface—a botnet that spreads by compromising the computers of users of social networking platforms and placing them under the control of the botnet’s operators for the purpose of monetization.

[...] 

Overview

Between April and November 2010, the Information Warfare Monitor conducted an investigation into the operations and monetization strategies of the Koobface botnet. The researchers discovered archived copies of Koobface’s infrastructure on a well-known Koobface command and control server. The data revealed a wealth of information about the inner workings of the botnet, including information on the malware, code, and database used to maintain the botnet as well as its monetization strategies. With this data, the Information Warfare Monitor was able to gain an in-depth understanding of how Koobface worked.

Koobface: Inside a Crimeware Network details Koobface’s propagation strategies, counter-security measures, and business model. The report contributes to the cybercrime literature by shedding light on the malware ecosystem that enables and sustains cybercriminal activity, and by demonstrating that it is possible to leverage the mistakes made by cybercriminals in order to better understand the scope of their operations.

Main Findings:
  • Koobface relies on a network of compromised servers that are used to relay connections from compromised computers to the Koobface command and control server. This creates a complex and tiered command and control infrastructure.
  • Koobface maintains a system that uses social networking platforms, such as Facebook, to send malicious links. Social networking platforms allow Koobface to exploit the trust that humans have in one another in order to trick users into installing malware and engaging in click fraud.
  • Koobface exists within a crime-friendly malware ecosystem that consists of buyers and sellers of the tools and infrastructure required to maintain a botnet. Koobface operators rely on relationships with other botnet operators and cybercriminals to sustain their operations.
  • The operators of Koobface have been able to successfully monetize their operations. Through the use of pay-per-click and pay-per-install affiliate programs and forcing compromised computers to install malicious software and engage in click fraud, the Koobface operators earned over US$2 million between June 2009 and June 2010.
  • The operators of Koobface are employing technical countermeasures to ensure that the operations of the botnet remain undisrupted. The operators regularly monitor their malicious links to ensure that they have not been flagged as malicious.
  • Botnet operators benefit from the fact that their criminal acts spread across multiple jurisdictions. Issues of overlapping jurisdictions and international politics often complicate investigations and hinder law enforcement and takedown efforts. Furthermore, cross-border investigations are at times hampered by a lack of priority and willingness to respond. This is because criminal activity in any one jurisdiction appears minimal while in fact the sum of Koobface’s criminal activities is significant.

The Subconscious Art of Graffiti Removal


the subconscious art of graffiti removal (excerpt) from matt mccormick on Vimeo.

http://dirtythirdstreets.com/wherever/the-subconscious-art-of-graffiti-removal/

The Subconscious Art of Graffiti Removal is a tongue-in-cheek documentary directed by filmmaker Matt McCormick and narrated by Miranda July, who you might know from Me and You and Everyone We Know.

If you’ve ever admired the arrangement of gray squares on concrete, this video is for you.

Medvedev: Russia's Spies Must Learn From Betrayal

Via Reuters (AP) -

President Dmitry Medvedev told Russia's once mighty spy agency on Friday to put its house in order after a senior spymaster betrayed a network of agents to the United States.

The Foreign Intelligence Service (SVR) is grappling with the network's betrayal by the head of Moscow's deep cover spying operations in the United States, one of Russia's most serious intelligence failures since the end of the Cold War.

"There should be an internal investigation and lessons should be drawn," Medvedev told reporters at a briefing after the Group of 20 summit in Seoul.

Asked about a report in the newspaper Kommersant which broke the story, Medvedev said: "For me the Kommersant publication is not news, I knew about it on the day it happened."

Kommersant identified the man as Colonel Shcherbakov and said he was responsible for unmasking a Russian spy ring in the United States in June. The arrest of its members humiliated Moscow just days after a summit in Washington between Medvedev and President Barack Obama.

The detained agents were exchanged in July for Russians suspected of spying for the West in a Cold War-style spy swap.

They returned to a heroes' welcome in Moscow, singing patriotic songs with Prime Minister Vladimir Putin, himself a former KGB spy, and receiving awards from Medvedev at a private Kremlin ceremony.

Putin said at the time they had been betrayed but the seniority of the U.S. mole and the fact that Shcherbakov was able to slip out of Russia have added to speculation that SVR chief Mikhail Fradkov could be sacked.

"The alleged spy was a senior Russian official and thus one with great access to highly sensitive information, such as the identities and operations of operatives in the United States," said Jay LeBeau, a former CIA official.

"He would have been in a position to do enormous damage to Russian intelligence interests.

"One can be sure that this fellow provided his U.S. handlers with other information as well."

The failure has weakened the spy agency's position in Moscow, prompting a debate about whether it should be merged with the Federal Security Service (FSB), the main successor of the Soviet-era KGB.

Monday, November 8, 2010

Danger to IE Users Climbs as Hacker Crimeware Kit Adds Exploit

Via NetworkWorld -

An exploit of an unpatched Internet Explorer vulnerability has been added to a popular crimeware kit, a move that will probably push Microsoft to fix the flaw with an emergency update, a security researcher said Sunday.

Meanwhile, a prominent vulnerability expert has sided with Microsoft, which has said the bug will be difficult to exploit in Internet Explorer 8 (IE8), the most popular version of the company's browser.

Last week, Microsoft warned users of its IE6, IE7 and IE8 browsers that hackers were already exploiting a vulnerability in the programs by tricking them into visiting malicious or compromised Web sites. Once at such a site, users were subjected to a "drive-by" attack that required no action on their part to succeed

Symantec was the first to report the IE bug to Microsoft after the antivirus vendor captured spam posing as hotel reservation notifications sent to select individuals within several organizations.

On Sunday, Roger Thompson, chief research officer of AVG Technologies, said that an exploit for the newest IE flaw had been added to the Eleonore attack kit, one of several readily-available toolkits that criminals plant on hacked Web sites to hijack visiting machines, often using browser-based attacks.

"This raises the stakes considerably, as it means that anyone can buy the kit for a few hundred bucks, and they have a working zero-day," said Thompson in on his company's blog.

Microsoft has promised to patch the vulnerability, but last week said that the threat didn't warrant an "out-of-band" update, the company's term for a fix outside the usual monthly Patch Tuesday schedule. Microsoft will deliver three security updates Nov. 9, but won't fix the IE bug then.

Thompson disagreed with Microsoft's assessment.

"I think they'll have to [do an out-of-band update]," Thompson said via instant message on Sunday when asked to bet whether Microsoft will release an IE fix before Dec. 14, the next regularly-scheduled patch date after Tuesday. "I expect attacks will accelerate."

However, AVG -- like Microsoft and Symantec -- has so far seen only a small number of attacks leveraging the vulnerability.

The exploit added to Eleonore may have been cadged from the Metasploit open-source penetration testing kit. Last Thursday, researcher Joshua Drake added an exploit module for the IE bug to Metasploit.

"We do see a lot of exploits essentially cut and pasted from Metasploit [proof-of-concepts]," said Thompson.

Microsoft has urged IE users to enable DEP, or data execution prevention, for IE7, use IE8 or IE9, or run one of its automated "Fix-it" tools to add a custom CSS template to their browsers as protection until a patch is available.

Sunday, November 7, 2010

Introducing: SpyEye Tracker

http://www.abuse.ch/?p=2958

The SpyEye Tracker is another project by abuse.ch. It is similar to the ZeuS Tracker with the slight difference that SpyEye Tracker tracks and monitors malicious SpyEye Command&Control Servers (and not ZeuS C&Cs). SpyEye Tracker provides blocklists in different formats (eg. for Squid Web-Proxy or iptables) to avoid that infected clients can access the C&C servers. Additionally, SpyEye Tracker should help ISPs, CERTs and Law Enforcement to track malicious SpyEye C&C servers which are their responsibility.

---------------------------------------------------------------------------------------------------------------

Excellent move to keep the pressure of the criminal underground that utilizes these trojans.

As a funny side note, at least one the comments posted on the Zeus/Speye merger thread [on the underground forums] highlighted the fact that a SpyEye tracker didn't exist and thus was more "hidden" than ZeuS.

Gap filled.

Saturday, November 6, 2010

10 Reasons Why Blocking Awlaki Youtube Speeches is Counter-Productive

http://icsr.info/blog/10-Reasons-Why-Blocking-Awlaki-Youtube-Speeches-is-Counter-Productive

Interesting article by Howard Clark discussing the possible negative effects of censoring Anwar al-Awlaki's on Youtube. Fighting radicalisation is a tricky area.

In a positive move, a Yemeni judge has issued an order on Nov 6th that the Anwar al-Awlaki has to be caught dead or alive, for alleged links to al-Qaeda and involvement in the killing of foreigners.

Friday, November 5, 2010

Hackers Break into OECD Computer System

Via EUObserver.com -

The OECD, the Paris-based club of the world's 33 richest countries, has been successfully hacked by people looking for sensitive information on money laundering, high-level corruption and tax evasion.

OECD spokesman Stephen Di Biasio told EUobserver by phone from France on Thursday (4 November) that the body first detected "unusual" activity in its IT network in August and is still battling to get malware out of its computers three months later despite calling in help from the French security services and private cyber-defence companies.

"We've got a team trying to close down their points of entry, but we're not in a position today to say we've cleared them out of our system," he said.

"What we know is it's quite a sophisticated attack. We've got quite high levels of security protocols at the OECD and this has been able to bypass those security measures ... What we are seeing is that it's not a destructive attack. It's obviously fishing for information. Because the OECD works in such a broad array of areas, they are searching around to see what they can get."

Mr Di Biasio said the malware appears to have got in via a USB memory stick and that the attacks are coming from "different geographical areas, quite a few points in Asia." He was unable to say if the assault involves a government or a private entity.

"The suspicion is it came in via USB keys. Our agents travel around the world. They often go to conferences - there are exchanges of information, exchanges of USB keys."

The OECD describes itself as a body which "brings together the governments of countries committed to democracy and the market economy." It collects economic data and conducts inter-governmental talks on issues including high-level government and corporate corruption, money laundering and tax evasion. Its members include 20 EU countries, as well as Canada, Israel, Japan, Switzerland, Turkey and the US.

Detecting Algorithmically Generated Malicious Domain Names

http://conferences.sigcomm.org/imc/2010/papers/p48.pdf

ABSTRACT

Recent Botnets such as Conficker, Kraken and Torpig have used DNS based “domain fluxing” for command-and-control, where each Bot queries for existence of a series of domain names and the owner has to register only one such domain name. In this paper, we develop a methodology to detect such “domain fluxes” in DNS traffic by looking for patterns inherent to domain names that are generated algorithmically, in contrast to those generated by humans. In particular, we look at distribution of alphanumeric characters as well as bigrams in all domains that are mapped to the same set of IP-addresses. We present and compare the performance of several distance metrics, including KL-distance, Edit distance and Jaccard measure. We train by using a good data set of domains obtained via a crawl of domains mapped to all IPv4 address space and modeling bad data sets based on behaviors seen so far and expected. We also apply our methodology to packet traces collected at a Tier-1 ISP and show we can automatically detect domain fluxing as used by Conficker botnet with minimal false positives.

[...]

CONCLUSIONS

In this paper, we propose a methodology for detecting algorithmically generated domain names as used for “domain fluxing” by several recent Botnets. We propose statistical measures such as Kullback-Leibler divergence, Jaccard in- dex, and Levenshtein edit distance for classifying a group of domains as malicious (algorithmically generated) or not. We perform a comprehensive analysis on several data sets including a set of legitimate domain names obtained via a crawl of IPv4 address space as well as DNS traffic from a Tier-1 ISP in Asia. One of our key contributions is the relative performance characterization of each metric in different scenarios. In general, the Jaccard measure performs the best, followed by the Edit distance measure, and finally the KL divergence. Furthermore, we show how our methodology when applied to the Tier-1 ISP’s trace was able to detect Conficker as well as a botnet yet unknown and unclassified, which we call as Mjuyh. In this regards, our methodology can be used as a first alarm to indicate the presence of domain fluxing in a network, and thereafter a network security analyst can perform additional forensics to infer the exact algorithm being used to generate the domain names. As future work, we plan to generalize our metrics to work on n-grams for values of n > 2.

AQAP Claims Responsibility for Parcel Bomb Plot

Via CNN -

The Yemen-based arm of the al Qaeda terrorist network claimed responsibility Friday for last week's plot to send explosive devices on cargo planes bound for the United States.

Al Qaeda in the Arabian Peninsula, which had been suspected in the plot, posted its claim on various radical Islamist websites, saying, "We will continue to strike blows against American interests and the interest of America's allies."

The statement also claimed the group is responsible for the crash of a UPS cargo plane in Dubai, United Arab Emirates, on September 3.

Investigators said earlier this month they had failed to turn up any evidence that terrorism was involved in that crash, which killed the two pilots aboard, according to a U.S. government official.

About 45 minutes after UPS Flight 6 departed Dubai International Airport for Cologne, Germany, the crew declared an emergency due to smoke in the cockpit. They asked to return to Dubai, but shortly before the plane could get to the airport it crashed.

Officials in the United Arab Emirates have said -- and a U.S. official confirmed -- that the plane's cockpit voice recorder has been examined and nothing on it indicates an explosion. Explosions have distinctive sound signatures, and that would have been recorded on the device, the official said.

The UAE said it has "eliminated the possibility of an onboard explosion, following a detailed onsite investigation of the wreckage."

A U.S. counterterrorism official said Friday that while "there are very strong indications that AQAP was responsible for plotting last week's disrupted cargo plane plot ... we can't confirm at this point their claims about the early September incident."

White House counterterrorism chief John Brennan said Sunday that the United States is "looking very carefully" at the September crash to see if it could be related to the recent terror threat involving cargo aircraft.


---------------------------------------------------------------------------------------------------------------

According to SITE Intel Group...
Al-Qaeda in the Arabian Peninsula (AQAP) claimed the recently discovered plot involving explosive parcels, and also claimed responsibility for the downing of a UPS cargo plane in Dubai in September 2010. In a communiqué issued on jihadist forums on November 5, 2010, AQAP said that it kept quiet its activity behind the September incident, and questioned why the media did not attribute responsibility to them earlier. They rhetorically answered that it is perhaps because the Obama Administration wanted to hide the incident so as to conceal security failure before the US midterm elections. AQAP declared to Obama: “We struck three blows to your aircraft within one year.
---------------------------------------------------------------------------------------------------------------

Evan Kohlmann of Flashpoint Partners confirms the release by AQAP thru a series of tweets on his twitter...
Al-Qaida in the Arabian Peninsula (AQAP) has issued an official communique claiming credit for the latest UPS cargo bomb plot from Yemen.

In its statement, AQAP also claimed to have placed explosives in the cargo hold of a UPS 747 aircraft that crashed leaving Dubai on Sept. 3.

AQAP: "We say to Obama: we planned three attacks targeting your planes within the past year, and we shall continue, Allah-willing."

AQAP: "We intend on publicizing this idea.. and broadening its application to include civilian airplanes in the West as well as cargo ones."

AQAP has accused the Obama admin of "covering up" AQ's role in downing a UPS flight on Sept. 3 "because of the American midterm elections."

----------------------------------------------------------------------------------------------------------------

The full AQAP statement can be seen in Arabic over at the jihadology.net..
http://jihadology.net/2010/11/05/new-statement-from-al-qa%E2%80%99idah-in-the-arabian-peninsula-package-operations-of-attrition/

Thursday, November 4, 2010

Hong Kong to Vancouver - Man in Disguise Boards International Flight

Via CNN -

Canadian authorities are investigating an "unbelievable" incident in which a passenger boarded an Air Canada flight disguised as an elderly man, according to a confidential alert obtained by CNN.

The incident occurred on October 29 on Air Canada flight AC018 to Vancouver originating in Hong Kong. An intelligence alert from the Canada Border Services Agency describes the incident as an "unbelievable case of concealment."

"Information was received from Air Canada Corporate Security regarding a possible imposter on a flight originating from Hong Kong," the alert says. "The passenger in question was observed at the beginning of the flight to be an elderly Caucasian male who appeared to have young looking hands. During the flight the subject attended the washroom and emerged an Asian looking male that appeared to be in his early 20s."

After landing in Canada, Border Services Officers (BSOs) escorted the man off the plane where he "proceeded to make a claim for refugee protection," the alert says.

[...]

"We can confirm that officials from the CBSA met a passenger arriving off AC018 Hong Kong to Vancouver on October 29 and the matter is still under investigation," said Air Canada spokesman Peter Fitzpatrick, who noted that "there are multiple identity checks before departure at the Hong Kong international airport, including Chinese government-run Hong Kong passport control, which Hong Kong originating passengers must undergo."

Hong Kong officials said they are aware of the incident and would call back with more information later.

Jennifer Bourque, regional communications officer for the CBSA, confirmed that "we intercepted an individual, on October 29, attempting to enter Canada under false pretenses on-board an Air Canada flight."

"CBSA can confirm that the foreign national is currently in CBSA detention," she said. "The individual will present before an IRB hearing. The officials of the CBSA will not disclose further information on this file."

Because of Privacy Act regulations, she said, she cannot provide details about specific cases.

"However, I can tell you that CBSA officers examine all passengers arriving on international flights at Vancouver International Airport," she said. "CBSA works closely with air carriers and local, national and international law enforcement partners, to ensure the safety of our borders and our communities. Getting the right information at the right time is a key element in keeping Canada's border closed to safety and security threats."

The agency would not discuss when or why the man put on the disguise or details about how he boarded the plane. But the alert indicated that the suspect boarded the plane with a board pass belonging to another passenger.

"It is believed that the subject and the actual United States Citizen passenger (whose date of birth is 1955) performed a boarding pass swap, with the subject using an Aeroplan card as identification to board the flight," the alert said.

Aeroplan is a credit card where card holders can earn frequent flyer miles.


----------------------------------------------------------------------------------------------------------------------

CBSA - Intelligence Alert
http://i2.cdn.turner.com/cnn/2010/images/11/04/disguise.artist.pdf


----------------------------------------------------------------------------------------------------------------------

My first guess?

Planned extraction of an intelligence asset or potential source, either by CA or the US.

Yemen Ink Bomb Defused 17 Minutes Before Detonatation

Via Dailymail.co.uk -

The ink bomb found at a British airport was defused just 17 minutes before it was due to explode, it was claimed yesterday.

Al Qaeda planners believed the plane carrying it would have been over the Atlantic or the U.S. mainland when it was primed to go off in a Lockerbie-style attack.

But the plane made an unscheduled refuelling stop at East Midlands Airport because of the weight of its cargo. Such was the expertise of the bombmaker and the sophistication of the device that it took a bomb disposal expert seven attempts to establish that it was viable and defuse it.

The bomb hidden in a printer cartridge contained 400 grams of the powerful explosive PETN – 50 times more than needed to punch a hole in the aircraft’s skin – and was wired to a mobile phone.

The SIM card had been removed so it could not receive calls and the Yemen-based bombmaker set up either the alarm or timer functions to detonate the device.

French Interior Minister Brice Hortefeux said yesterday it had been ‘defused only 17 minutes before the moment it was set to explode’ but did not elaborate.

Al Qaeda had carried out a ‘dry run’ to see how long the package would take to arrive in the U.S.

According to U.S. intelligence, the test run in mid-September involved a package containing books, a computer disc and religious literature, but no explosives. The aim was to allow bombmakers to work out the timing to trigger the device so it would cause maximum damage.

[...]

Home Secretary Theresa May likened the plot in a speech on Wednesday to Lockerbie and said : ‘It could have destroyed the aircraft on which it was being carried, over the UK, over the U.S. or on the ground.

[...]

Mr Hortefeux suggested yesterday that disaster had been just minutes away when he told told France’s state-run France-2 television: ‘One of the packages was defused only 17 minutes before the moment that it was set to explode.’

While police, government and intelligence sources in Britain refused to comment publicly, privately a number of senior security sources disputed the claim, saying they ‘did not recognise’ the 17-minute figure and stressing that tests were still taking place on the device.

However, when challenged, French officials repeated the time and said that the device referred to had been the one at East Midlands airport.

In the U.S., counter terrorism sources were quoted by CBS News as confirming that 17 minutes was left on the clock of the device found in the UK.

Investigators in Britain are said to be ‘angry and frustrated’ at the leaks surrounding the inquiry from the U.S. which they described as ‘damaging and counter productive’.

Meanwhile, German intelligence sources disclosed the plane had been forced to change schedule and stop in the UK because of the weight of the cargo.

If the plane had flown directly to the US, without stopping in Britain, then the device is likely to have gone off as it approached America.


---------------------------------------------------------------------------------------------------------------------

http://www.stratfor.com/weekly/20101101_al_qaeda_unlucky_again_cargo_bombing_attempt
As long as AQAP’s operational leaders and its bombmakers — like Ibrahim Hassan Tali al Asiri, brother of the suicide bomber in the Prince Mohammed bin Nayef attack — remain free, they will continue trying to exploit security vulnerabilities and attack U.S. and Saudi targets. So far, the group has come close to pulling off several spectacular attacks but has suffered unlucky breaks that have caused each attack to fail. However, to paraphrase an old Irish Republican Army taunt, they only have to get lucky once.

Operation Choke Hold: 45 Mexican Drug Cartel Suspects Arrested in Atlanta

Via CNN -

Federal agents arrested 45 people in Georgia believed to be members of a top Mexican drug cartel and confiscated nearly $2.4 million in cash, authorities said Thursday.

The arrests were made by members of the federal Drug Enforcement Administration, the Clayton County District Attorney's Office and other law enforcement agencies, the DEA said. The investigation, called Operation Choke Hold, started in May 2009.

The suspects are believed to be connected with La Familia Michoacana, which "was responsible for the importation of bulk quantities of cocaine, heroin, methamphetamine, and marijuana into the metro Atlanta area," the DEA said.

In addition to distributing narcotics in metro Atlanta, the drug-trafficking organization also shipped large quantities to Florida, Alabama, Indiana, Illinois and North Carolina, the DEA said.

During the arrests, the DEA said in a release, authorities seized 46 pounds of methamphetamine, a clandestine methamphetamine laboratory, nearly 95 pounds (43 kilograms) of cocaine, 4,120 pounds of marijuana, 20 firearms and $2.349 million.

The La Familia Michoacana cartel is based in the state of Michoacan, in southwestern Mexico.


-------------------------------------------------------------------------------------------------------

On October 22, 2009, U.S. federal authorities announced the results of a four-year investigation into the operations of La Familia Michoacana in the United States dubbed Project Coronado. It was the largest U.S. raid ever against Mexican drug cartels operating in the U.S. In 19 different states, 303 individuals were taken into custody in a coordinated effort by local, state, and federal law enforcement over a two-day period. Seized during the arresting phase was over 62 kilograms (140 lb) of cocaine, 330 kilograms (730 lb) of methamphetamine, 440 kilograms (970 lb) of marijuana, 144 weapons, 109 vehicles, and two clandestine drug laboratories.

The investigative efforts in Project Coronado were coordinated by the multi-agency Special Operations Division, comprising agents and analysts from the DEA, FBI, U.S. Immigration and Customs Enforcement, Internal Revenue Service, U.S. Customs and Border Protection, U.S. Marshals Service and ATF, as well as attorneys from the Criminal Division's Narcotic and Dangerous Drug Section.

Wednesday, November 3, 2010

MS Internet Explorer Zeroday - Microsoft Security Advisory (2458511)

http://www.microsoft.com/technet/security/advisory/2458511.mspx

Microsoft is investigating new, public reports of a vulnerability in all supported versions of Internet Explorer. The main impact of the vulnerability is remote code execution. This advisory contains workarounds and mitigations for this issue.

The vulnerability exists due to an invalid flag reference within Internet Explorer. It is possible under certain conditions for the invalid flag reference to be accessed after an object is deleted. In a specially-crafted attack, in attempting to access a freed object, Internet Explorer can be caused to allow remote code execution.

At this time, we are aware of targeted attacks attempting to use this vulnerability. We will continue to monitor the threat environment and update this advisory if this situation changes. On completion of this investigation, Microsoft will take the appropriate action to protect our customers, which may include providing a solution through our monthly security update release process, or an out-of-cycle security update, depending on customer needs.

[...]

Mitigating Factors:

• Data Execution Prevention (DEP) helps protect against attacks that result in code execution and is enabled by default in Internet Explorer 8 on the following Windows operating systems: Windows XP Service Pack 3, Windows Vista Service Pack 1, Windows Vista Service Pack 2, and Windows 7.

• Protected Mode in Internet Explorer on Windows Vista and later Windows operating systems helps to limit the impact of the vulnerability as an attacker who successfully exploited this vulnerability would have very limited rights on the system. An attacker who successfully exploited this vulnerability on Internet Explorer 7 or Internet Explorer 8 could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less affected than users who operate with administrative user rights.

• In a Web-based attack scenario, an attacker could host a Web site that contains a Web page that is used to exploit this vulnerability. In addition, compromised Web sites and Web sites that accept or host user-provided content or advertisements could contain specially crafted content that could exploit this vulnerability. In all cases, however, an attacker would have no way to force users to visit these Web sites. Instead, an attacker would have to convince users to visit the Web site, typically by getting them to click a link in an e-mail message or Instant Messenger message that takes users to the attacker’s Web site.


-----------------------------------------------------------------------------------------

http://www.symantec.com/connect/blogs/new-ie-0-day-used-targeted-attacks

-----------------------------------------------------------------------------------------

Suggested Actions -> Workarounds ->

Override the Web site CSS style with a user defined CSS
Deploy the Enhanced Mitigation Experience Toolkit
Enable Data Execution Prevention (DEP) for Internet Explorer 7 [& 6]
Read e-mails in plain text
Set Internet and Local intranet security zone settings to "High" to block

Tuesday, November 2, 2010

Stuxnet Under the Microscope v1.2

http://www.eset.com/resources/white-papers/Stuxnet_Under_the_Microscope.pdf

Updated Stuxnet paper by ESET, with full description of unpatched Task Scheduler vulnerability.

See Page 39-41.

Monday, November 1, 2010

U.S. Official: Possible 'Dry Run' from Yemen Intercepted Weeks Ago

Via CNN -

The United States intercepted a shipment of packages a few weeks ago that was headed for Chicago, Illinois, and might have been a "dry run" by al Qaeda in Yemen, according to a U.S. official.

The official told CNN "there were some packages that attracted our attention several weeks ago that were interdicted and searched, but nothing other than books and literature were found in them." The official said there were concerns about the packages because they were shipped from Yemen and "there were connections to someone tied to the al Qaeda affiliate in Yemen." The story was first reported by ABC News.

The official said it is now believed the terrorists were "trying to learn something about the system," how packages move from overseas locations to the United States.

The official would not comment on where the packages were to be delivered in Chicago.

According to the official, the reason the United States mobilized so quickly last week when tipped off about possible bombs in cargo packages coming from Yemen was because of the previous incident.

"It's why we pulled out all of the stops," the official said.

Cargo Plane Bomb Plot: Saudi Double Agent 'Gave Crucial Alert'

Via The Guardian UK -

The plot to place bombs on US-bound cargo planes was foiled as a result of a long-running and heavily financed Saudi operation to infiltrate al-Qaida in Yemen, Gulf security experts said today.

The operation is part of a concerted attempt by the US and its allies to destroy al-Qaida in the Arabian Peninsula (Aqap) before it gets a stranglehold on Yemen. The impoverished country is fast emerging as the second major front in the battle with al-Qaida, alongside the Afghanistan-Pakistan border.

Yemeni officials said today that the critical tip-off had come from Jabir al-Fayfi, a Saudi jihadist who defected to the authorities in Riyadh last month. However, security professionals said the 11th-hour Saudi tip, including parcel tracking numbers, that led to the interception of the bombs on Friday appeared to be based on far more recent, up-to-the minute intelligence.

Vincent Cannistraro, a former CIA counter-terrorism chief with longstanding ties with Gulf spy agencies, said Saudi intelligence had succeeded in placing a number of double agents within Aqap.

"Aqap found out about one of them, who they assassinated," Cannistraro said, adding that at least one Saudi agent survived and was the source of the key tip-off. "There is current stuff coming out from Aqap which is more specific than [Fayfi] could provide."

Sami Alfaraj, head of the Kuwait Centre for Strategic Studies, agreed that Fayfi was unlikely to have been the sole source for the Saudi warning. "There are many factors in an operation like this," Alfaraj said. "The officials involved who I am talking to are saying that the Gulf intelligence agencies are finding it easier to penetrate al-Qaida cells. They are not as impregnable as they once were. They recruit from a limited pool, looking for engineers for example, and that concentration on a limited pool makes it easier for the intelligence agencies."

Alfaraj added that jihadists who are acquitted by courts or leave rehabilitation programmes and return to Yemen are now more easily tracked due to better surveillance techniques and equipment.

Intelligence officials would not comment on the Saudi operation, but several sources confirmed that Saudi Arabia had considerably expanded its counter-terrorism operations against Aqap in recent years, particularly after an assassination attempt against the head of that programme, Prince Nayef bin Abdul-Aziz, in August last year.


----------------------------------------------------------------------------------------------------------------------

Last year, AQAP laid out it's desire to use electronic devices in plots, according to Evan Kohlmann of Flashpoint Partners....

http://twitter.com/#!/IntelTweet/status/29279676498
In October 2009, Al-Qaida in the Arabian Peninsula (Yemen) published an article advising how to build, conceal, and use explosive devices.

http://twitter.com/#!/IntelTweet/status/29279732466
AQAP: Construct bombs disguised as "any electronic device like a stereo... or a picture frame, a paper folder, or a letter envelope."

http://twitter.com/#!/IntelTweet/status/29282213815
AQAP: Use bombs to target "airports in Western crusader countries... on their planes, or in their residential complexes, or their subways."

US Civil Rights Organisation Prepares for New 'Crypto War'

Via H-Online.com -

The Electronic Frontier Foundation (EFF) reports that it has filed lawsuits against three agencies of the US Department of Justice demanding the release of documents justifying the need for stronger internet surveillance measures. The civil rights organisation justifies its action by citing the head of the FBI, who has publicly claimed that it is necessary to install back doors in electronic communication systems in order to preserve the ability of the security services to intercept information. The FBI is now being called on to provide evidence of the posited gaps in protection. The EFF is also using the Freedom of Information Act to demand examples from the Drug Enforcement Administration (DEA) and the Department of Justice Criminal Division that show their staff have been impeded in performing surveillance of online communications by the lack of these requested measures.

The EFF has been prompted to take action by reports that the government is working on a law to make it easier to eavesdrop on internet telephony, encrypted email and instant messaging (IM). The legislation would require developers of peer-to-peer (P2P) communications solutions, such as instant messaging or internet telephony applications, to design their applications to be susceptible to surveillance. The FBI wants suppliers and ISPs to ensure that investigators can be provided with plain text versions of all messages. The EFF sees echoes of the 'crypto war' in the 1990s, when government agencies spent several years demanding either, the integration of deliberate vulnerabilities into, or the provision of spare keys for, cryptographic products. The EFF has reiterated its arguments from the debate held at that time – that the plans create security risks, will not stop criminals and will harm law-abiding businesses and citizens.

An EFF lawyer stated that the Obama government's plans "would have enormous privacy and security ramifications for American Internet users." She believes that proper debate needs to be based on the information which the EFF has now requested and which Washington has so far refused to provide. The agencies against which the EFF has filed lawsuits are also being requested to provide information on any talks already held with technology companies, industry associations or Congress, on expansion to surveillance legislation. The EFF believes that a thorough and realistic evaluation is required in order to determine whether the absence of back doors is genuinely impeding investigators.