Monday, December 18, 2006

Post No. 501 - HSBC Closing Accounts For Good

Very interesting read over at Light Blue Touchpaper.

Sound like anti-terror or AML regulations to me for sure.

I just noticed that this is post 501. Pretty good for just starting last Oct.

Anyways, I want to say thanks to all the readers out there...so thanks for reading.

Happy Monday

Sunday, December 17, 2006

Mars Rovers Experience Four-Digit Date Issue (Y2K Anyone?)

Via ScienceNow.org -

SAN FRANCISCO, CALIFORNIA--Spirit and Opportunity are painting a considerably different picture of Mars from what NASA's mission scientists had expected when the twin rovers set down separately on the red planet in January 2004. Designed expressly to look for signs of water, both craft have found such signs in the rocks and soil lying in their paths. But what's surprising and disappointing is the water seems only to have lurked beneath the Martian surface. Lakes, rivers, and oceans seem to have been almost totally absent from the planet's history.

Reporting here today at the annual meeting of the American Geophysical Union, members of the Mars Exploration Rover science team declared both machines basically healthy--although Spirit remains partially crippled by a right-front wheel drive motor that failed nine months ago. So far, Spirit has logged 1047 sols, or Martian days, and Opportunity has been operating for 1026 sols. The Mars rovers' project manager, John Callas of NASA's Jet Propulsion Laboratory in Pasadena, California, quipped that crossing the 1000-sol threshold created a problem, because the rovers' software was not designed to handle four-digit dates. "But it's a good problem to have," Callas said.

----------------------------

The Mar Rovers were projected to only be going for three months....but they are looking at three years right now. Very cool.

Organized Crime Groups Probe ATM Weaknesses

Via MSNBC.com -

Researchers who work for an Israeli computer security company say they have discovered a fundamental weakness in the system that banks use to keep debit card PIN codes secret while they are transported across bank networks – a flaw that they say could undermine the entire debit card system.

The U.S. Secret Service is investigating the matter, and MSNBC.com obtained a memo compiled by the agency that indicates that organized criminals are systematically attempting to subvert the ATM system and unscramble encrypted PIN traffic.

The report has ignited a debate within the banking industry, with many financial industry experts downplaying the seriousness of the flaw and outside experts divided on its implications. But there is no disputing the impact that such a hack would have if successful.

----------------------------------

This article is several weeks ago, but still very interesting. We all remember the Mini-bank password issues from the Fall.

The Virtual Relationship Myth

Via TechDirt -

There's a new study out about how people online are making friends online -- which is hardly a surprising fact. However, where the reporting on it gets weird is that the press keeps referring to these relationships as "virtual" friendships, as if the people aren't real. The people are very real, and the friendships aren't "virtual" at all. It's just that the conversations are often kept up digitally. It's also weird to see quotes like: "More than a decade after the portals of the worldwide web opened to the public, we are now witnessing the true emergence of the internet as the powerful personal and social phenomenon we knew it would become." That's really a rewriting of history. The internet has always succeeded as a communications platform. Things like email, BBS's, IRC and Usenet were very much about the social aspect long before the web itself even came along. To claim that it's suddenly reached its potential is misleading. It's just that people are finally recognizing that the social and communications aspect is what the internet does well, instead of trying to force it into being a broadcast medium.

---------------------------------------------------

I personally think that Mike has hit the nail directly on the head....because I know he is right.

I-Hacked Video: Making a Beer Can PadLock Shim

http://www.i-hacked.com/content/view/243/48/

Why drink beer at Defcon 14? To make lock shims, of course.

That 2 hour delay was crazy that morning.

Quote of the Vid - "The Red Badge doesn't mean I neseccarily know what is happening..."

Saturday, December 16, 2006

Engineer Indicted on Economic Espionage

Via SignOnSanDiego.com -

SAN JOSE – A Silicon Valley engineer stole trade secrets from a San Jose software company and tried to sell them to foreign governments, prosecutors alleged Thursday.

Xiaodong Sheldon Meng, 42, a Chinese national with Canadian citizenship, was indicted on 36 felony counts, including economic espionage to benefit a foreign government and violations of military technology export laws.

Prosecutors say Meng stole the underlying code for software made by Quantum3D Inc. that is used to train military fighter pilots, and tried to sell it to the Thai and Malaysian air forces and a company with ties to China's military.

No foreign government or agent was named as a conspirator in the case.

Under U.S. law, anyone attempting to sell such information overseas must first obtain a license from the State Department and is subject to strict regulations. Xiaodong never applied for or received such a license.

His case marks only the third time prosecutors have charged someone with economic espionage to benefit a foreign government, the most serious crime under the Economic Espionage Act of 1996. It carries up to 15 years in prison. Theft of trade secrets can bring 10 years.

Guilty pleas were expected Thursday afternoon in one of the other two cases under the economic espionage act. That case involves Fei Ye and Ming Zhong, two other Silicon Valley engineers with ties to China. Their conviction would be the first since the economic espionage law was enacted.


(Props to my friend Fergie for the find)

Underground Auction - Vista Zero-Day, Bots & More

Via Eweek.com -

Underground hackers are hawking zero-day exploits for Microsoft's new Windows Vista operating system at $50,000 a pop, according to computer security researchers at Trend Micro.

The Windows Vista exploit—which has not been independently verified—was just one of many zero-days available for sale at an auction-style marketplace infiltrated by the Tokyo-based anti-virus vendor.


In an interview with eWEEK, Trend Micro's chief technology officer, Raimund Genes, said prices for exploits for unpatched code execution flaws are in the $20,000 to $30,000 range, depending on the popularity of the software and the reliability of the attack code.

Bots and Trojan downloaders that typically hijack Windows machines for use in spam-spewing botnets were being sold for about $5,000, Genes said.

[...]

A custom Trojan capable of stealing online account information can be bought for between $1,000 and $5,000, while a botnet-building piece of malware can cost between $5,000 and $20,000, Genes said.

Credit card numbers with valid PINs are sold for $500 each, while billing data that includes an account number, physical address, Social Security number, home address and birth date can be found for between $80 and $300.

The auction marketplace is also selling driver's licenses for $150, birth certificates for $150, Social Security cards for $100, and credit card numbers with security code and expiration date for between $7 and $25.

PayPal or eBay account credentials are available for $7, Genes said.

-------------------------

(Props to my friend Fergie for the find)

New Pentagon Counterinsurgency Manual Released

Via the Secrecy News -

The U.S. Army has completed a long-awaited new manual (large pdf) presenting military doctrine on counterinsurgency. It is the first revision of counterinsurgency doctrine in twenty years.

In several respects, the new doctrine implicitly repudiates the Bush Administration's approach to the war in Iraq.

"Conducting a successful counterinsurgency campaign requires a flexible, adaptive force led by agile, well-informed, culturally astute leaders," the foreword states.

The new manual emphasizes the importance of planning for post-conflict stabilization, and it stresses the limited utility of conventional military operations.

"The military forces that successfully defeat insurgencies are usually those able to overcome their institutional inclination to wage conventional war against insurgents."

A copy of the new 282 page unclassified manual was obtained by Secrecy News.

See "Counterinsurgency," U.S. Army Field Manual 3-24, December 15, 2006 (12.9 MB PDF).

MS Releases IE7 Patch to Address Slow Phishing Feature

When you use Windows Internet Explorer 7 to visit a Web page, the computer may respond very slowly as the Phishing Filter evaluates Web page contents.

http://support.microsoft.com/kb/928089

This patch was released on Black Tuesday, but was not pushed down via Windows Update. Get it if you use the anti-phishing feature of IE7.

Friday, December 15, 2006

New Windows Explorer & Media Player 10 DoS Exploits

CVE-2006-6602 - Publish Date: 12/15/2006
explorer.exe in Windows Explorer 6.00.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service via a crafted WMV file.

CVE-2006-6601 - Publish Date: 12/15/2006
Windows Media Player 10.00.00.4036 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service via a MID file with a malformed header chunk without any track chunks, possibly involving (1) number of tracks of (2) time division fields that are set to 0.

Credit to SehaTo for both.

You might remember him from the Windows Media ASX DoS Exploit.

PoC Exploits for Both = http://www.security.nnov.ru/Gnews936.html

MIT launches iFIND App For Stalking Your Friends

Via Engadget.com -

When we first spotted MIT's location-tracking WiFi network last year, the stalking capabilities were interesting, but not fully realized. Now with this new iFIND app of theirs, WiFi positioning takes on a whole new level of geeky functionality at the Boston campus. At its core, iFIND is a peer-to-peer application that allows users to control the flow of their own location information, eliminating the privacy concerns of a centralized tracking system. Built on top of that functionality are all sorts of interesting buddy list capabilities to track and chat with friends, and choose who can track you. You can also set up meeting places with friends, even using the system to pick a spot at the "center of gravity" of a group of friends for the ultimate in geek cred. Anyone with an MIT email address can use the system, and future functionality includes the ability to share data anonymously with users found with the system, or to alert the police to your position in an emergency without divulging your identity -- all for the truly paranoid, but fun stuff all the same.

Backframe – JavaScript Hacking Framework

Backframe Attack Console was started as an experiment to create a full featured attack console for exploiting web browsers, web users and remote applications. Those who are familiar with XSS Proxy or even BEEF might already be familiar with the core principles of the project.

The console is based on simple client-server interaction. Both parts are required for successful operation. The server, also known as the attack channel, providesfunctionalities for establishing bi-directional communication with remote clients. On the other hand, the console is responsible for interacting with the channel providing the necessary toolkit for launching attacks against these clients.

The result of these core principles is an easy to use and understand web-client-oriented attack framework that keep the data, the presentation layer, and the underlying logic apart. This design is known as "the separation of concerns model". This is highly effective practice which allows to easily extend upon the core elements.

http://www.gnucitizen.org/backframe/docs/index.htm

Online Example - http://www.gnucitizen.org/backframe/application.htm

MS Internet Explorer 7 (DLL-load hijacking) Code Execution Exploit PoC

/*
Copyright (C) 2006-2007 Aviv Raff
http://aviv.raffon.net
Greetz: hdm, L.M.H, str0ke, SkyLined


Compile and upload to the victim's desktop as one of the following hidden DLL files:
- sqmapi.dll
- imageres.dll
- schannel.dll


Run IE7 and watch the nice calculators pop up.
Filter fdwReason to execute only once.


Tested on WinXP SP2 with fully patched IE7.
For testing/educational purpose only!
*/

Please note that this isn't your normal drive-by-download type of vulnerability. The DLL would need to be uploaded to the victim's PC.

http://www.milw0rm.com/exploits/2929

Nano-Cables Convert Light into Electricity

Via NewScientistTech.com -

Nanocables that convert light into electricity could one day be used to power nano-robots.

The cables are 16 nanometres in diameter and several micrometres long. They resemble the light-harvesting antennae used by some bacteria and transform light into electricity in a similar way to the semiconductors in solar panels, albeit on a much smaller scale.


"This is the first example of a photoconducting nanostructure," says Takanori Fukushita of the University of Tokyo, Japan, a member of the team that built the cables.

The hollow cables can grow up to several micrometres long. To build them, Fukushita and colleagues created a compound containing hexabenzocoronene (HBC), two carbon-12 chains, and trinitrofluorenone (TNF). They placed the compound in a solution of tetrahydrofuran and bubbled methane vapour though it, causing the compound to self-assemble into hollow cables.

The HBC, which sheds electrons when hit by light, formed the inside of the cable wall, and the TNF, which readily accepts electrons, coated the outside of the wall.


Each time a photon hits the cable from outside it passes through the outer layer and knocks an electron loose from the inner layer. This causes the electron to jump to the outer layer and leave behind a positively charged "hole". These separated charges can then generate a current.

To test the nanocables, the researchers placed one on a silicon surface and applied a voltage across it. When light was shone onto the surface, a current began flowing down the cable between two electrodes. When the light was switched off, the current stopped.

At the moment, the cables cannot produce usable electricity from sunlight alone, as current does not flow well through the outer layer of TNF. The next step, Fukushita says, is to modify the outer layer, perhaps by attaching carbon-60 molecules (buckyballs), so it acts as a semiconductor and allows more current to flow.

Once this has been achieved, the nanocables could be fitted to nano-sized robots or micro-machines and power their movements, suggests Franz Würthner at the University of Würzburg in Germany. Their similarity in size and function to the antennae used by bacteria for photosynthesis means it might also be possible to connect them to such organisms, creating hybrid devices, he says.

--------------------------------------------

Very interesting. Now if someone can just make cybernetic light-powered bateria to keep my car clean...

Hackers Take Over Email, Then Demand Ransom

Via ZDNet India -

A Hotmail user logged into their account this week to find that scammers had deleted all their e-mails except for one, which was from a hacker demanding cash in exchange for restoring the lost information, according to Websense.

Websense said this scam is a variant of ransomware, which is a malicious program that encrypts documents on the victim's computer and asks for a payment in order to decrypt the files. Had this been the owner or an employee of a small business, the company's intellectual property (IP) would have been at risk.

Joel Camissar, country manager at Websense ANZ, said that the Hotmail account of the victim is thought to have been hacked after they used a spyware-infected computer in a Spanish Internet cafe. The hackers had deleted everything from their inbox, outbox and removed all their contacts.

Camissar warned that the same thing could easily happen in Australia to somebody accessing their corporate Webmail account, which would most likely have serious consequences.

"Somebody could have used the Internet caf? to access their Outlook Web access account -- their password would then be compromised because the password for that account would be the same as their regular work access.

"The intellectual property could be very valuable. Imagine if it's the director of a company and they have [e-mails containing] confidential schematics or financial results," said Camissar.

Earlier this year, antivirus firms warned that criminals were increasingly using ransomware and warned that small businesses were most at risk.

David Emm, senior technology consultant at Kaspersky UK, said: "Within a corporation, the IT department normally backs up files. The danger is where attacks are launched at smaller businesses (without IT departments) and individuals".

Thursday, December 14, 2006

UK Online Banking Fraud Up 8000%

Via BBC News -

The Financial Services Authority (FSA) told peers it was "very concerned" about the growth in "phishing".

Phishing involves using fake websites to lure people into revealing their bank account numbers.

The amount stolen is still relatively small but it is set to go up by 90% for the second year running, peers heard.

Between January and June 2005, the number of recorded phishing incidents was 312, the Lords science and technology committee was told.

The figure for the same period this year was 5,059, according to banking trade body Apacs figures.

The amount of cash stolen in the first half of 2006 was £23.2m, the committee was told, and was likely to be £22.5m in the second half of the year.

'Industrialised'

The increase was put down by Apacs security chief Philip Whitaker to better detection.

But Mr Whitaker told peers the criminals behind "phishing" scams were also becoming increasingly "industrialised" in their approach.

Lord Paul said the committee had been told one bank was being targeted far more than any other.

But Apacs director of communication Sandra Quinn rejected the peer's call to name the bank concerned, saying it would breach commercial confidentiality.

She said Apacs was there to represent the banking industry not the consumer, and had no plans to make public its list of banks being targeted by fraud.

--------------------------------------------

It kinda sound like this is based on just the reported phishing sites, so take the hard figure with a gain of salt...however this doesn't mean the real number is lower, sadly it is most likely even higher than 8000%.

Phishing and spam are the "cash crop" of organized crime rings. When all other money making tricks fail, they can always depend on phishing and spam to work.

Wednesday, December 13, 2006

Microsoft Releases OS X Office 2004 Update By Mistake

Via SANS ISC -

Microsoft accidentally released an update named 11.3.1 for Office 2004 (the Apple Mac version) today.

It did contain an unspecified security fix and stability improvements. After asking what it fixed we got the reply it was actually a pre-release that was made available through auto-update.

The wasn't intended to be released and hence has been pulled. See the MSRC blog for more details.

Microsoft is also recommending to uninstall the patches, although to be honest I've no idea how to actually do that.

-Swa Frantzen -- Section 66

Holiday Decorations Can Create Major Wi-Fi Disturbances

Via Arstechnia.com -

It sounds like something the MythBusters "Build Team" could have busted or confirmed in a couple of hours. Holiday decorations... Christmas lights, garland, those big blow-up snowmen... they're all putting the hurt on WiFi?

That's the word from AirMagnet, Inc., a company that develops and sells WiFi networking analysis and troubleshooting tools. The company says that it monitored office WiFi health before and after holiday decorations were deployed, and their survey found that Old Saint Nick has some splainin' to do.

According to the survey, the addition of Christmas and holiday ornamentation (trees, decorations, etc.) to a standard office setting reduced wireless signal strength by 25 percent. Furthermore, AirMagnet claims that signal deterioration was increased by a factor of one-third, and made signal distribution more uneven, reducing strength by an additional 10 percent in different locations.

"When new elements are introduced into an enterprise environment they have the potential to seriously affect the performance of the Wi-Fi network, by deflecting, absorbing or otherwise interfering with the wireless signal," said Chia-Chee Kuan, CTO and vice president of engineering for AirMagnet. "During the holidays, it could be the decorations in an office, at other times it could just as easily be a new microwave oven or a metal shelving unit." AirMagnet's ploy in all of this is to draw attention to the company as a developer of WiFi analysis tools, and to be honest, we find it pretty humorous.

It's the metal contained in many Christmas decorations that is the culprit for these wireless shenanigans. Whether or not this spells bad news for those of you planning to erect a Festivus pole is anyone's guess, but at the very least you'll have the chance to air your grievance in ritual fashion.

UCLA Computer Security Breach Exposes 800,000 Students

Via Washington Post -

LOS ANGELES -- The University of California, Los Angeles alerted about 800,000 current and former students, faculty and staff on Tuesday that their names and certain personal information were exposed after a hacker broke into a campus computer system.

It was one of the largest such breaches involving a U.S. higher education institution.

The attacks on the database began in October 2005 and ended Nov. 21 of this year, when computer security technicians noticed suspicious database queries, according to a statement posted on a school Web site set up to answer questions about the theft.

Acting Chancellor Norman Abrams said in a letter posted on the site that while the database includes Social Security numbers, home addresses and birth dates, there was no evidence any data have been misused.

The letter suggests, however, that recipients contact credit reporting agencies and take steps to minimize the risk of potential identity theft. The database does not include driver's license numbers or credit card or banking information.

"We have a responsibility to safeguard personal information, an obligation that we take very seriously," Abrams wrote. "I deeply regret any concern or inconvenience this incident may cause you."

School representatives did not return calls for additional comment.

The breach is among the latest involving universities, financial institutions, private companies and government agencies. A stolen Veterans Affairs laptop contained information on 26.5 million veterans, and a hacker into the Nebraska child-support computer system may have gotten data on 300,000 people and 9,000 employers.

Security experts said the UCLA breach, in the sheer number of people affected, appeared to be among the largest at an American college or university.

"To my knowledge, it's absolutely one of the largest," Rodney Petersen, security task force coordinator for Educause, a nonprofit higher education association, told the Los Angeles Times.

Petersen said that in a Educause survey released in October, about a quarter of 400 colleges said that they had experienced a security incident in which confidential information was compromised during the previous 12 months, the newspaper reported.


In 2005, a database at the University of Southern California was hacked, exposing the records of 270,000 individuals.

This spring, Ohio University announced the first of what would be identified as five cases of data theft, affecting thousands of students, alumni and employees _ including the president. About 173,000 Social Security numbers may have been stolen since March 2005, along with names, birth dates, medical records and home addresses.

Jim Davis, UCLA's chief information officer, said a computer trespasser used a program designed to exploit an undetected software flaw to bypass all security measures and gain access to the restricted database that contains information on about 800,000 current and former students, faculty and staff, as well as some student applicants and parents of students or applicants who applied for financial aid.

"In spite of our diligence, a sophisticated hacker found and exploited a subtle vulnerability in one of hundreds of applications," Davis said in the statement.

The university's investigation so far shows only that the hacker sought and obtained some of the Social Security numbers. But out of an abundance of caution, the school said, it was contacting everyone listed in the database.

About 3,200 of those being notified are current or former staff and faculty of UC Merced and current or former employees of the University of California Office of the President, for which UCLA does administrative processing.

Teenager Ran Internet Banking Scam Worth Nearly 50K

Via Stuff.co.nz -

A 16-year-old who police sent on a computer training course to improve his behaviour has admitted using a computer in an attempt to defraud banks of nearly $45,000.

The Upper Hutt teenager faces 26 fraud charges after hacking into people's internet banking accounts in August and September.

Police say he posted a computer virus on an internet message board and used it to capture details from people's personal computers.

Westpac, ANZ and ASB were all hit. The biggest transaction involved $6323, but the banks agreed to reimburse the losses.

The scam, combined with the boy's age, has raised fresh questions about the security of internet banking. It is just six months since banking ombudsman Liz Brown said banks had been slow to introduce two-factor authentication measures to fight internet fraud.

Judge Pat Grace remanded the youth to a secure residential facility in Palmerston North when he appeared in Upper Hutt Youth Court yesterday.

"You had set up quite a sophisticated operation to obtain some $50,000 from unsuspecting users of the internet.

"With the seriousness of this offending, I must be considering a custodial sentence as far as you are concerned, and because of that I'm going to decline your application for bail."

The youth, who cannot be named, has also admitted unrelated charges of kidnapping, aggravated robbery, threatening behaviour, unlawfully taking a motor vehicle, reckless driving, failing to stop and a string of driving offences. He is understood to owe about $35,000 in fines.

The computer fraud is believed to have been committed at his parents' home while he was unemployed.

The court is awaiting a psychological and social workers' report before hearing submissions on which court he should be sentenced in.

He faces up to five years' imprisonment if sentenced in the district court.

Constable Chris Muir said the youth decoded large amounts of information from people's computers to get account numbers and passwords.

"He just keeps the things he wants. He is a very clever boy."

It was possible that others had been targeted but had not complained to police.

About $15,000 had been recovered. The outstanding money had mainly been sent to the bank accounts of several co-offenders, who were also before the courts.

"It's very concerning that someone can basically sit at home and get everything off the internet and do what they want."

The police electronic crime lab's national manager Maarten Kleintjes said internet banking fraud was becoming more sophisticated.

He would not say if it was increasing, because banks shared the information with police in confidence.

Two-factor authentication - in which customers are issued with a new security code each time they log on - was the best way to guard against internet banking fraud.

Though it was compulsory in many countries, several major New Zealand banks - Westpac, ANZ and National - were yet to introduce the technology.

"The attacks are now being taken to a new level whereby people's machines are deliberately infiltrated with very sophisticated spyware, Mr Kleintjes said.

"They basically take control of your machine. They access your bank accounts but also steal your identity."

------------------------------------

The question is...was this young kid truly at the top of the scam? I find it hard to believe, but it is possible. The article only states that he uploaded the virus, did he also create the virus? If he didn't create the virus, then we have to ask who did...and what was their take on the scam?