Monday, July 13, 2009

DoD Seeks Defense Against Denial-of-Service Attacks

Via FCW.com -

The Defense Information Systems Agency wants commercial products that could help network administrators detect and react to distributed-denial-of-service (DDOS) attacks, according to a request for information posted today.

In such attacks, an individual or group attempts to bring down a Web site by overwhelming it with traffic.

The agency is interested in solutions that could give administrators a clear and timely picture of what is happening on their networks, alert them in the event of suspicious activity and provide options for mitigating attacks, the notice states.

“The goal of this solution is to detect and mitigate all DDOS attempts to disrupt [Defense Department] network communications and to detect internal assets displaying anomalous behavior across the Internet-to-NIPRnet boundary,” the notice states.

---------------

About damn time?

There are several articles making the rounds on the net...claiming the government ignored warnings from South Korea relating possible cyber attacks.

But did they even need a warning relating to DDoS??

Sure...in my view, DDoS isn't a super huge threat when compared to SCADA and other real "hacking" attacks...but Mafiaboy took out Yahoo!, Amazon.com, Dell, E*TRADE, eBay, and CNN in early 2000.

Isn't 9 years enough of warning?

Anti-Terror Judge Named Greek Intelligence Chief

Via oregonlive.com -

Greece's top judge involved in organized crime and terrorism cases has been named as the new director of the country's National Intelligence Service.

The appointment was announced Monday as Greek authorities are grappling with a resurgence of terrorist bombings and shootings by far-left domestic groups.

Senior judge Dimitris Papangelopoulos takes over from Ioannis Corantis, a veteran diplomat who headed the service since 2004.

Militant attacks have increased in recent months following the fatal police shooting of an Athens teenager in December, which sparked the country's worst rioting in decades.

McCain Moves to Cut F-22 Funding

Via Military.com -

Sen. John McCain moved Monday to eliminate $1.75 billion recently inserted into the proposed 2010 defense budget for more fighter jets from Lockheed Martin.

The Arizona Republican, along with Michigan Democrat Carl Levin, filed an amendment to cut the extra money for seven more F-22's. The Senate Armed Services Committee last month narrowly approved the additional funding requested by Georgia Republican Saxby Chambliss.

McCain and Levin, the committee's chairman, voted against the additional finds. The full Senate may vote on the defense spending bill this week. The House last month voted to include a $369 million down payment for 12 additional fighters to its version of the defense bill.

The White House has threatened to veto legislation that includes money for more of the radar-evading jets.

On the Senate floor, McCain said he also will strongly recommend the White House veto the defense bill if lawmakers don't act to end F-22 production.

Supporters of the F-22 have said capping production at 187 aircraft is too risky with potential adversaries like Iran, North Korea and China looming.

McCain disputed such arguments. Focusing on timely delivery of the Joint Strike Fighter, also built by Lockheed Martin, is in the best interest of the country and will be a weapon system that can meet future threats, he said.

Chambliss and other lawmakers who represent districts where F-22 production jobs are at stake have lobbied hard to keep the program. Lockheed's primary manufacturing plant is in Georgia, but key parts of the plane also are made in Texas and California.

McCain said the rationale for keeping a weapon system should never be about job creation, but about defending the nation.

The extra money would extend production of the F-22 beyond the 187 aircraft that Defense Secretary Robert Gates says are needed. Gates has argued that buying any more of the jets, which cost $140 million a piece, will undermine the Pentagon's ability to increase the size of U.S. ground forces and purchase gear for fighting unconventional wars against insurgents.

------------------------

See more over @ DoDBuzz.com

The vaunted invincibility of the F-22 founders on two incurable flaws: First, the plane’s so-called “low probability of intercept” radar may now be easily detected, thanks to the proliferation of spread spectrum technology in cell phones and laptops. That creates an environment where, if the F-22 pilot turns on his radar, he announces his presence over hundreds of miles. Even better for the enemy, the radar makes an unmistakable beacon for opposing missiles.

Second, when combat forces F-22 pilots to turn off radars, they’ll find themselves forced into a close-in, maneuvering fight. Compromised by stealth and heavy radar electronics, the plane’s agility, short range missiles, and guns are nothing special — as one of us observed at Nellis Air Force Base in Nevada when an F-16 “shot down” an F-22 in exercises.

As for the plane’s advertised ability to cruise supersonically the F-22’s low fuel capacity (27% of takeoff weight, only two thirds of what’s needed for combat-useful supersonic endurance in enemy airspace) reduces this to an air show trick. Why the big fuel shortfall? To make room for stealth technologies and radar electronics.

In summary, a vote for continuing F-22 production is a vote to decay pilots’ skills, to deny them a truly great fighter, to shrink the number of pilots and planes we can field, and to reward Congress’ unending appetite for pork. The new 2010 Defense Authorization bill should be vetoed if a single F-22 is added.

How to Use Electrical Outlets and Cheap Lasers to Steal Data

Via NetworkWorld -

If attackers intent on data theft can tap into an electrical socket near a computer or if they can draw a bead on the machine with a laser, they can steal whatever is being typed into it.

How to execute these attacks will be demonstrated at the Black Hat USA 2009 security conference in Las Vegas later this month by Andrea Barisani and Daniele Bianco, a pair of researchers for network security consultancy Inverse Path.

“The only thing you need for successful attacks are either the electrical grid or a distant line of sight, no expensive piece of equipment is required,” Barisani and Bianco say in a paper describing the hacks.

The equipment to carry out the power-line attack could cost as little as $500, and the laser attack gear costs about $100 if the attacker already owns a laptop with a sound card, says Barisani. Carrying out the attacks took about a week, he says.

“We think it is important to raise the awareness about these unconventional attacks and we hope to see more work on this topic in the future,” Barisani and Bianco say in their paper. Others with more time and money could doubtless create better spying tools using the same concepts, they say.

In the power-line exploit, the attacker grabs the keyboard signals that are generated by hitting keys. Because the data wire within the keyboard cable is unshielded, the signals leak into the ground wire in the cable, and from there into the ground wire of the electrical system feeding the computer. Bit streams generated by the keyboards that indicate what keys have been struck create voltage fluctuations in the grounds, they say.

Attackers extend the ground of a nearby power socket and attach to it two probes separated by a resistor. The voltage difference and the fluctuations in that difference – the keyboard signals – are captured from both ends of the resistor and converted to letters.

To pull the signal out of the ground noise, a reference ground is needed, they say. “A “reference” ground is any piece of metal with a direct physical connection to the Earth, a sink or toilet pipe is perfect for this purpose (while albeit not very classy) and easily reachable (especially if you are performing the attack from [a] hotel room,” they say in their paper.

Since keyboards and mice signals are in the 1 to 20 kHz range, a filter can isolate that range for listening, they say.

Variations in individual keyboards and mice result in each keyboard signaling in a slightly different frequency range. With careful filtering, that makes it possible to zero in on a particular keyboard in an environment where many keyboards are in use, the researchers say.

The attack proved successful when tapping electric sockets located up to 15 meters from where the target computer was plugged in the researchers say.

This method would not work if the computer were unplugged from the wall, such as a laptop running on its battery. The second attack can prove effective in this case, Bianco’s and Barisani’s paper says.

Attackers point a cheap laser, slightly better than what is used in laser pointers, at a shiny part of a laptop or even an object on the table with the laptop. A receiver is aligned to capture the reflected light beam and the modulations that are caused by the vibrations resulting from striking the keys.

This modulation is converted to an electrical signal that is fed into a computer soundcard.

“The vibration patterns received by the device clearly show the separate keystrokes,” the researchers’ paper says. Each key has a unique vibration pattern that distinguishes it from the rest. The spacebar creates a significantly different set of vibrations, so the breaks between words are readily apparent.


Analyzing the sequences of individual keys that are struck and the spacing between words, the attacker can figure out what message has been typed. Knowing what language is being typed is a big help, they say.

Laptop lids, especially shiny logos and areas close to the hinges, provide the most easily read vibrations.

Anyone worried about this type of attack can make sure there is no line of sight to the laptop, move position frequently while typing and polluting the signal by striking random keys and later deleting them with the backspace key.

While they admit their hacking tools are rudimentary, they believe they could be improved upon with a little time, effort and backing.

“If our small research was able to accomplish acceptable results in a brief development time (approximately a week of work) and with cheap hardware,” they say. “Consider what a dedicated team or government agency can accomplish with more expensive equipment and effort.”

Vulnerability in Microsoft Office Web Components Control Could Allow Remote Code Execution

Via SAS Internet Storm Center -

Microsoft has released an advisory related to an Office Web Components ActiveX vulnerability, it is available here. This vulnerability exists in the ActiveX control used by IE to display Excel spreadsheets. The CVE entry for the vulnerability is CVE-2009-1136. Microsoft mentions that they are aware of active exploits against this vulnerability, although we at the SANS Internet Storm Center haven't seen it used or mentioned in public as of yet. Which may tend to indicate it has been used in targeted rather than broad based attacks. At the moment there is no patch, there is a workaround, and it can be automated for enterprise deployment. The specific CLSIDs to set the killbit for are:

{0002E541-0000-0000-C000-000000000046}
{0002E559-0000-0000-C000-000000000046}

Start working on this on ASAP. The impact is remote code execution with the privileges of the logged in user running Internet Explorer, and might not require user intervention. As in browse to a nasty web site and be pwn3d.

Advisory: http://www.microsoft.com/technet/security/advisory/973472.mspx

KB article: http://support.microsoft.com/kb/973472

SRD blog: http://blogs.technet.com/srd/archive/2009/07/13/more-information-about-the-office-web-components-activex-vulnerability.aspx

MSRC blog: http://blogs.technet.com/msrc/archive/2009/07/13/microsoft-security-advisory-973472-released.aspx

[...]

Update1: The vulnerability is being actively exploited on web sites. More to follow.

Sunday, July 12, 2009

Tools of the Trade - Microsoft Video ActiveX Control 0day Edition

Cody Pierce of TippingPoint DVLabs recently blogged a detailed technical analysis of the recent Microsoft Video ActiveX Control (msvidctl.dll) 0day, which many are expecting Microsoft to patch early next week.

Microsoft also plans to patch the currently open Directshow vulnerability...

--------------------

On to the tools....

On July 11th, Sun released Virtual Box v3.0.2. VirtualBox is a general-purpose full virtualizer for x86 hardware. This is a maintenance release of VirtualBox 3.0 which improves stability and performance. Check out the changelog for all the details.

On July 9th, Frederic Raynal & Guillaume Delugre released origami 1.0.0-beta0. Origami is a Ruby framework designed to parse, analyze, edit, manipulate, forge, exploit PDF files. This is NOT a PDF rendering library. It aims at providing a scripting tool to generate and/or analyze malicious PDF files. As well, it can be used to create on-the-fly customized PDFs, or to inject (evil) code into already existing documents.

On July 8th, Gabriel Campana released Fuzzgrind 090622. Fuzzgrind is a fully automatic fuzzing tool, generating test files with the purpose of discovering new execution paths likely to trigger bugs and potentially vulnerabilities. It is based on the concept of symbolic execution.

On July 8th, Drew Yao of Apple Product Security announced the release of CrashWrangler. CrashWrangler is basically Apple's version of the !expoitable tool released by Microsoft. It is a set of tools to determine if a crash is an exploitable security issue, and if a crash is a duplicate of another known crash. The exploitability diagnosis is intended to be used when you have a reproducible test case, but the duplicate detection can be run on any crash log. CrashWrangler supports Mac OS X 10.5 and later. The toolset is free to anyone with a ADC account.

On July 8th, Terence Stenvold released Harald Scan v0.2. Harald Scan is a Bluetooth discovery scanner written in Python. It determines Major and Minor device classes according to the Bluetooth SIG specification and attempts to resolve a device's MAC address to the largest known vendor/MAC address list.

On July 7th, VLC Media Player 1.0 was released. VLC media player is a highly portable multimedia player for various audio and video formats as well as DVDs, VCDs, and various streaming protocols without external codec or program. This major release introduces many new features, new formats and new codecs to the VLC multimedia framework and fixes a very high number of bugs that were present in the 0.9.x or 0.8.6 versions.

On June 27th, Tor-ramdisk 20090627 was released. Tor-ramdisk is an i686 uClibc-based micro Linux distribution whose sole purpose is to securely host a Tor server purely in RAM. Check out the changelog for all the details.

On June 26th, Maxim Bourmistrov released Trafscrambler v0.1. Trafscrambler is an anti-sniffer/IDS NKE (Network Kernel Extension) for Mac OS X. This initial release implements SYN-decoy, Pre/Post connections SYN, TCP reset, and zero window attacks. Author tested this on x86 OS X versions 10.5.6 and 10.5.7. It should work on PPC and older releases as well.

On June 25th, Nmap 4.90 RC1 was released. This release fixed a hanging bug in OS X. Check the changelog for all the details.

On June 25th, CCleaner v2.21.940 was released. CCleaner is a freeware system optimization, privacy and cleaning tool. It removes unused files from your system - allowing Windows to run faster and freeing up valuable hard disk space. Check the version history for all the details.

On June 25th, Tor v2.0.35 was released. Tor is a network of virtual tunnels that allows people and groups to improve their privacy and security on the Internet. Tor 0.2.0.35 fixes a big bug that was causing Tor relays with dynamic IP addresses to disappear from the network. It also fixes a rare crashbug on fast exit relays. Check out the announcement for all the details.

On June 25th, PHD Virtual released Patch Downloader v6. This tools is a freeware solution to simplify patch downloading for various VMware ESX versions. It ases the pain of downloading patches for various ESX versions from the VMware support site by automating the process for users that cannot use the VMware Update Manager. Now, rather than downloading each patch manually through a Java Download manager, VMware administrators can simply select the version of ESX from the Patch Downloader drop down menu, and select the download location (including folder, drive map, SMB share, etc.).

On June 24th, Kismet-2009-06-R1 was released. Kismet is an 802.11 layer 2 wireless network sniffer. This release drops the "candidate" designation, and is the first full release of the Kismet-Newcore code. It includes a number of UI improvements (better network details, more mouse support, fixed color handling, and nework notes), multiple platform-specific fixes (OS X installation, Nokia ITT bugfixes, and BSD fixes), has improved source handling on Linux, de-cloaked SSID caching, and more. Check out the SVN commit notes for more.

On June 17th, Adobe released Shockwave Player version 11.5.0.600. According to Adobe's Security Bulletin (APSB09-08), this version fixes a vulnerability which could allow an attacker to take control of the affected system.

Russian Military Shot Down Own Planes in Georgian War

Via foreignpolicy.com -

A new report from the Moscow-based Center for Analysis of Strategy and Technology says that half the Russian planes lost in last summer's five-day war were shot down by friendly fire. The latest issue of the Moscow Defense Brief reports that Russia lost six jets in the war with Georgia, not four as officials claimed at the time. At least three were downed by the Russians themselves. The article said:
Russian aircraft were frequently taken by Russian and Ossetian forces for Georgian aircraft, and they were fired upon without identification and in the absence of any aggressive action on their part.
The journal is highly critical of coordination within the Russian military, asserting that the army and the air force ran "completely separate campaigns." It raises concerns as to Russia's capabilities to win a war against a better-trained and better-equipped army in the future.

Pakistani Jets Pound Taliban Hide-outs in South Waziristan

Via Gulfnews.com -

Intelligence officials say fighter jets have pounded suspected militant hide-outs in the South Waziristan tribal region as part of ongoing operations against Pakistani Taliban chief Baitullah Mehsud. At least eight militants were killed.

Meanwhile, police said gunmen ambushed five police officers and a forestry official responding to reports of a dead body in northwestern Pakistan, killing all six.

The fighter jets hit several locations in South Waziristan on Sunday, killing eight militants in one spot, two intelligence officials, who spoke on condition of anonymity because they are not authorised to speak to media, told The Associated Press.

South Waziristan is part of the lawless tribal region along Pakistan's border with Afghanistan, and top Taliban and Al Qaida leaders are believed to be hiding there.

Chinese Spying Claimed in Purchases of NSA Crypto Gear

Via Wired.com -

A Chinese national was indicted this week for conspiring to violate U.S. export law, following a nearly three-year investigation into his alleged efforts to acquire sensitive military and NSA-encryption gear from eBay and other internet sources.

Chi Tong Kuok, of Macau, told Defense Department and Customs investigators that he had been “acting at the direction of officials for the People’s Republic of China,” according to a government affidavit in the case. “Kuak indicated he and PRC officials sought the items to figure out ways to listen to or monitor U.S. government and military communications.”

Kuok was arrested at the Atlanta International Airport last month en route from Paris to Panama, where he allegedly planned to meet an undercover federal agent he believed was going to provide him with military radios. He was transferred to California, where he was indicted (.pdf) Tuesday for money laundering, conspiracy, smuggling and one count of attempting to export a defense article without a license.

[...]

Using a Yahoo e-mail address and a different name, Kuok also allegedly contacted an Arizona company this year that had posted on eBay a KG-175 TACLANE — an NSA designed encryption device used to communicate with classified military computer networks, such as the Defense Department’s SIPRNet.

It’s legal to own the equipment, which can’t access anything without the proper crypto key, but export is tightly restricted. The Arizona company initially refused to ship the NSA gear to Macau, but at the government’s request, later allowed another undercover agent to negotiate a deal with Kuok while posing as a company official.

“In subsequent e-mails, Kuok indicated he was interested in buying the KG-175 if it came with a particular key,” reads an affidavit by John Helsing of the Defense Criminal Investigative Service, who does not elaborate. Kuok allegedly sent the undercover agent $1,700 by Western Union for the crypto device, and then forwarded a list of additional items he wanted. “I am also thinking about if you are FBI or something like that,” Kuok allegedly wrote in an e-mail.

Despite his misgivings, Kuok sent the agent another $10,000 for more PRC-148 radios. “When you send the radios, remove all label and write it as vintage walkie talkie, thank you,” he allegedly instructed.

The undercover agent and Kuok agreed to meet in Panama to complete the delivery. Unfortunately for Kuok, his plane stopped in Atlanta, where he was arrested and held without bail. Investigators reviewed Kuak’s eBay and PayPal accounts and determined he had successfully purchased other export-controlled items online, beginning in 2005.

On Wednesday, the government obtained search warrants for two USB flash drives, a laptop computer and several cell phones Kuok had in his carry-on bag, as well as for a cell phone SIM card in his possession.

“Kuok claimed in his post-arrest interview that his PRC ‘handlers(s)’ gave him a SIM card and instructed him to place it in his phone once he landed in Panama,” wrote Helsing in his affidavit.

Saturday, July 11, 2009

Reinventing the Router - From Packet Management to Flow Management

Via spectrum.ieee.org -

The Internet is broken.
I should know: I designed it. In 1967, I wrote the first plan for the ancestor of today’s Internet, the Advanced Research Projects Agency Network, or ARPANET, and then led the team that designed and built it. The main idea was to share the available network infrastructure by sending data as small, independent packets, which, though they might arrive at different times, would still generally make it to their destinations. The small computers that directed the data traffic—I called them Interface Message Processors, or IMPs—evolved into today’s routers, and for a long time they’ve kept up with the Net’s phenomenal growth. Until now.

Today Internet traffic is rapidly expanding and also becoming more varied and complex. In particular, we’re seeing an explosion in voice and video applications. Millions regularly use Skype to place calls and go to YouTube to share videos. Services like Hulu and Netflix, which let users watch TV shows and movies on their computers, are growing ever more popular. Corporations are embracing videoconferencing and telephony systems based on the Internet Protocol, or IP. What’s more, people are now streaming content not only to their PCs but also to iPhones and BlackBerrys, media receivers like the Apple TV, and gaming consoles like Microsoft’s Xbox and Sony’s PlayStation 3. Communication and entertainment are shifting to the Net.

But this shift is not without its problems. Unlike e-mail and static Web pages, which can handle network hiccups, voice and video deteriorate under transmission delays as short as a few milliseconds. And therein lies the problem with traditional IP packet routers: They can’t guarantee that a YouTube clip will stream smoothly to a user’s computer. They treat the video packets as loose data entities when they ought to treat them as flows.

Consider a conventional router receiving two packets that are part of the same video. The router looks at the first packet’s destination address and consults a routing table. It then holds the packet in a queue until it can be dispatched. When the router receives the second packet, it repeats those same steps, not ”remembering” that it has just processed an earlier piece of the same video. The addition of these small tasks may not look like much, but they can quickly add up, making networks more costly and less flexible.

At this point you might be asking yourself, ”But what’s the problem, really, if I use things like Skype and YouTube without a hitch?” In fact, you enjoy those services only because the Internet has been grossly overprovisioned. Network operators have deployed mountains of optical communication systems that can handle traffic spikes, but on average these run much below their full capacity. Worse, peer-to-peer (P2P) services, used to download movies and other large files, are eating more and more bandwidth. P2P participants may constitute only 5 percent of the users in some networks, while consuming 75 percent of the bandwidth.

So although users may not perceive the extent of the problem, things are already dire for many Internet service providers and network operators. Keeping up with bandwidth demand has required huge outlays of cash to build an infrastructure that remains underutilized. To put it another way, we’ve thrown bandwidth at a problem that really requires a computing solution.

With these issues in mind, my colleagues and I at Anagran, a start-up I founded in Sunnyvale, Calif., set out to reinvent the router. We focused on a simple yet powerful idea: If a router can identify the first packet in a flow, it can just prescreen the remaining packets and bypass the routing and queuing stages. This approach would boost throughput, reduce packet loss and delays, allow new capabilities like fairness controls—and while we’re at it, save power, size, and cost. We call our approach flow management.

Twitter Suspends User Accounts Infected With Koobface Worm

Via DarkReading -

Twitter is warning members that the Koobface worm is on the loose in the Twitterverse, and that the social network is temporarily suspending any accounts it discovers spreading the worm.

In a blog post last night, Twitter said some Twitter users' PCs were infected with a variant of Koobface, which sends phony tweets when the infected user logs onto his or her Twitter account.

"We are currently suspending all accounts that we detect sending such bogus tweets. If we suspend your account, we will send you an email notifying you of the suspension. This email also includes tips for removing the malware from your PC," the Twitter blog said.

As in previous attacks on other social networking sites, the worm's mode of infection is a phony video link that, when clicked, infects the user with the worm. Among the Koobface tweets are messages similar to ones Koobface used on Facebook -- "My home video," "Watch my new private video! LOL :)" and some links purportedly to Michael Jackson video clips, according to Graham Cluley, senior technology consultant for Sophos. Cluley blogged about the attacks today.

Koobface has been used to target users on Facebook, MySpace, and other social networking sites during the past year, spreading via an infected member's profile to his friends' profiles.

Friday, July 10, 2009

Happy Birthday Nikola Tesla

Nikola Tesla (10 July 1856 – 7 January 1943) was an inventor and a mechanical and electrical engineer. Tesla was an ethnic Serb born in the village of Smiljan, Vojna Krajina, in the territory of today's Croatia. He was a subject of the Austrian Empire by birth and later became an American citizen. He is frequently cited as one of the most important contributors to the birth of commercial electricity, a man who "shed light over the face of Earth". He is best known for many revolutionary contributions in the field of electricity and magnetism in the late 19th and early 20th centuries. Tesla's patents and theoretical work formed the basis of modern alternating current (AC) electric power systems, including the polyphase power distribution systems and the AC motor, with which he helped usher in the Second Industrial Revolution.

The SI unit measuring magnetic flux density or magnetic induction (commonly known as the magnetic field "B"), the tesla, was named in his honor (at the Conférence Générale des Poids et Mesures, Paris, 1960), as well as the Tesla effect of wireless energy transfer to wirelessly power electronic devices which Tesla demonstrated on a low scale (lightbulbs) as early as 1893 and aspired to use for the intercontinental transmission of industrial energy levels in his unfinished Wardenclyffe Tower project.

Aside from his work on electromagnetism and electromechanical engineering, Tesla contributed in varying degrees to the establishment of robotics, remote control, radar and computer science, and to the expansion of ballistics, nuclear physics,[8] and theoretical physics. In 1943, the Supreme Court of the United States credited him as being the inventor of the radio.

Lawmaker Wants ‘Show of Force’ Against North Korea for Website Attacks

Via Wired.com (Threat Level) -

A key Republican lawmaker on Thursday urged President Obama to launch a cyber attack against North Korea, or increase international sanctions against the communist country, in the wake of an unknown hacker’s denial-of-service attacks on U.S. and South Korean websites.

Rep. Peter Hoekstra (R-Michigan), the lead Republican on the House Intelligence Committee, said the U.S. should conduct a “show of force or strength” against North Korea for a supposed role in a round of attacks that hit numerous government and commercial websites this week.

Hoekstra, speaking on the conservative America’s Morning News radio show, produced by the Washington Times newspaper, said that “some of the best people in America” had been investigating the attacks and concluded that most likely “all the fingers” point to North Korea as the culprit.

They’re reaching the conclusion that this was a state act and that “this couldn’t be some amateurs,” claimed Hoekstra, in direct opposition to what security experts have actually been saying.

He added that North Korea needed to be “sent a strong message.”

-------------------------------

Rep. Peter Hoekstra's idea of launching a cyber couterattack against North Korea sounds very knee-jerky and just plain wrong at this point.....

Point One

As Gadi Evron points out in his DarkReading article, it is silly to just look at the technical information (IP address, exploits used and malware family) and think you can determine who is behind a series of DDoS attacks.

Only with a complete analysis of all-source intelligence can you even begin to make an educated guess about who and where the attackers are based.

The private sector has a ton of very smart security professionals...but most don't have access to classified intelligence (HUMINT, SIGINT, etc)....and thus are making an educated guess with just the technical (network, malware analysis, etc) information.

Even with that in mind, some of those professionals aren't on board with pointing the finger @ North Korea just yet...
The timing is auspicious, but none of the data I have suggests North Korea," Jose Nazario, a senior security researcher at Arbor Networks, told CSO earlier this week. Joe Stewart, director of director of SecureWorks' counter-threat unit, told Computerworld, "There's nothing in there to suggest that it's state sponsored."

"Still zero evidence of North Korean involvement," said Stewart when contacted Friday for an update.

Point Two

DDoS attacks are noisy....really dangerous and sophisticated cyber attacks are rarely noisy. In general, I would say attacks like Titan Rain and NASA's Avocado have the potential to damage our national safety & security much much more than any DDoS attack.

DDoS attacks are easy to detect, while that targeted attack against a power plant's SCADA is not. This type of attack could easily be a smokescreen for a much more serious targeted attack.

Point Three


DDoS attacks aren't new...the corporate world has been dealing with these for years. DDoS attacks are a favorite among extortionists for example. The all-volunteer group formerly known as Castlecops put such a dent in cybercrime activities...that bad guys have been trying to DDoS them since 2006.

The methods of protecting against DDoS attacks are just as well known. Clearly, in this case...some sites were better prepared than others. According to the malware analysis conducted by the South Korean anti-virus firm Hauri (PDF)....many non-government sites were targeted.

www.yahoo.com
www.voanews.com
www.amazon.com
www.usbank.com

Were these sites down for an extended amount of time? I wonder why?
Perhaps because they were better prepared for just this type of attack.

Nick Shapiro, a White House spokesman, said that as of the night of July 7, all federal Web sites were back up and running and that the attacks “had absolutely no effect on the White House's day-to-day operations."

"The preventative measures in place to deal with frequent attempts to disrupt WhiteHouse.gov's service performed as planned, keeping the site stable and available to the general public, although visitors from regions in Asia may have been affected," he added.

So perhaps instead of taking about counterattack...the government should think about building a better defense overall.

Tamiflu Detected in River Water in Japan

Via Virology.ws -

Tamiflu (Oseltamivir) is one of the few antiviral drugs available for treatment of influenza. Use of the drug has increased substantially because of the emergence of the 2009 H1N1 pandemic strain, against which no vaccine is yet available. A recent study has shown that low levels of oseltamivir can be detected in the aquatic environment. This finding raises the possibility that aquatic birds which harbor influenza virus could be exposed to the antiviral, leading to selection of drug resistant viruses.

[...]

Because Japan is the largest consumer of Tamiflu, the levels of OC were determined in the Yodo River system in the Kyoto and Osaka prefectures. This river was selected because it is distant from the sea and located in a densely populated area. Surface water was collected before (June 2007) and during (December 2007 and February 2008) the flu season. No OC was detected in water samples from June 2007. At the onset of the flu season, December 2007, the antiviral was found at levels between 2 and 7 nanograms per liter (ng/L). At the peak of the flu season, in February, levels increased to 12 – 58 ng/L. Levels of OC were higher in water samples taken near sewage treatment plants, compared with those obtained farther away. The amounts detected are close to the concentration of drug that causes 50% inhibition of virus replication (the IC50) in cell cultures, reported to be between 80–230 ng/L.

The authors suggest that dabbling ducks, a natural reservoir of influenza virus, could ingest OC. As influenza in dabbling ducks is a gastrointestinal infection, the virus would encounter oseltamivir in the gut, which could promote selection of viruses resistant to the drug.

It is not known whether OC in aquatic environments leads to influenza virus resistance to Tamiflu. Clearly additional studies must be done to determine whether the antiviral drug can be found in other waters around the world. Influenza viruses should be isolated from aquatic birds living in OC contaminated environments to monitor resistance to Tamiflu.

PCs Used in Korean DDoS Attacks May Self Destruct

Via Washington Post -

There are signs that the concerted cyber attacks targeting U.S. and Korean government and commercial Web sites this past week are beginning to wane. Yet, even if the assaults were to be completely blocked tomorrow, the attackers could still have one last, inglorious weapon in their arsenal: New evidence suggests that the malicious code responsible for spreading this attack includes instructions to overwrite the infected PC's hard drive.

According to Joe Stewart, director of malware research at SecureWorks, the malware that powers this attack -- a version of the Mydoom worm -- is designed to download a payload from a set of Web servers. Included in that payload is a Trojan horse program that overwrites the data on the hard drive with a message that reads "memory of the independence day," followed by as many "u" characters as it takes to write over every sector of every physical drive attached to the compromised system.

Stewart said he tested the self-destruct Trojan in his lab and found that it indeed erases the hard drive on the compromised system. For now, however, the Mydoom component isn't triggering that feature.

"One possibility is there's a bug in the code and it's supposed to run but it doesn't," Stewart said. "Or, there may be a time factor involved, where it's not supposed to erase the hard drive until a certain time."

Such an order would spell certain disaster for many tens of thousands of Microsoft Windows PCs. Several experts I spoke with yesterday and today estimated that between 60,000 and 100,000 systems may be infected with this potentially suicidal malware.

[...]

Meanwhile, the attacks that slowed washingtonpost.com and several other U.S.-based Web sites have since been focused almost exclusively on Korean Web sites. Alex Lanstein, senior security researcher at Fireeye, a Milpitas, Calif., based computer security firm, said the attackers dropped the U.S. government and commercial Web sites from their hit-list on Tuesday afternoon, after those sites began working with large Internet service providers to filter and block attack traffic.

Lanstein said the unknown attackers have since concentrated the attack on a handful of S. Korean government and commercial Web sites, such as egov.go.kr, Web portal daum.net, online auction house auction.go.kr, and Korean news site chosun.com.

[...]

Update, July 10, 10:00 a.m. ET: South Korean anti-virus firm Hauri has published an exhaustive analysis of this malicious software, available at this link here (PDF). It states that when July 10, AM 00:00 comes, the malicious code deletes files with certain extensions, that the "operating system not found" error appears at the next boot, and that the system cannot then be started normally.

Meanwhile, SecureWorks' Stewart said it looks like it is only the first megabyte of the hard drive that is overwritten. "Still with the [Windows Master Boot Record] and partition table gone, it is enough to make it unbootable and unrecoverable for the normal user with only a Windows CD in recovery mode," Stewart said. "It has subroutines to delete or encrypt files after that, so even more advanced recovery techniques are made more difficult."

Mexico: Economics and the Arms Trade

Via Stratfor (Global Security & Intellgience Report) -

On June 26, the small Mexican town of Apaseo el Alto, in Guanajuato state, was the scene of a deadly firefight between members of Los Zetas and federal and local security forces. The engagement began when a joint patrol of Mexican soldiers and police officers responded to a report of heavily armed men at a suspected drug safe house. When the patrol arrived, a 20-minute firefight erupted between the security forces and gunmen in the house as well as several suspects in two vehicles who threw fragmentation grenades as they tried to escape.

When the shooting ended, 12 gunmen lay dead, 12 had been taken into custody and several soldiers and police officers had been wounded. At least half of the detained suspects admitted to being members of Los Zetas, a highly trained Mexican cartel group known for its use of military weapons and tactics.

When authorities examined the safe house they discovered a mass grave that contained the remains of an undetermined number of people (perhaps 14 or 15) who are believed to have been executed and then burned beyond recognition by Los Zetas. The house also contained a large cache of weapons, including assault rifles and fragmentation grenades. Such military ordnance is frequently used by Los Zetas and the enforcers who work for their rival cartels.

STRATFOR has been closely following the cartel violence in Mexico for several years now, and the events that transpired in Apaseo el Alto are by no means unique. It is not uncommon for the Mexican authorities to engage in large firefights with cartel groups, encounter mass graves or recover large caches of arms. However, the recovery of the weapons in Apaseo el Alto does provide an opportunity to once again focus on the dynamics of Mexico’s arms trade.

--------------------------

The section above is just the main lead-in into yet another very informative article from Stratfor.

The full article linked above is recommended if you are interested in Mexico and arm trafficking in general.

Here is an interesting block that gives you a better understanding on some of those numbers we have heard about...

According to the report, some 30,000 firearms were seized from criminals by Mexican officials in 2008. Out of these 30,000 firearms, information pertaining to 7,200 of them, (24 percent) was submitted to the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) for tracing. Of these 7,200 guns, only about 4,000 could be traced by the ATF, and of these 4,000, some 3,480 (87 percent) were shown to have come from the United States.

This means that the 87 percent figure comes from the number of weapons submitted by the Mexican government to the ATF that could be successfully traced and not from the total number of weapons seized by the Mexicans or even from the total number of weapons submitted to the ATF for tracing. The 3,480 guns positively traced to the United States equals less than 12 percent of the total arms seized in 2008 and less than 48 percent of all those submitted by the Mexican government to the ATF for tracing.

In a response to the GAO report, the U.S. Department of Homeland Security (DHS) wrote a letter to the GAO (published as an appendix to the report) calling the GAO’s use of the 87 percent statistic “misleading.” The DHS further noted, “Numerous problems with the data collection and sample population render this assertion as unreliable.”

Thursday, July 9, 2009

Alleged Iranian and Hezbollah Agents on Trial for Targeting Russian-Operated Radar Station in Azerbaijan

Via The Jamestown Foundation -

A trial of six people accused of terrorism and other serious crimes began on June 24 in Baku, Azerbaijan. Two Lebanese citizens, Karaki Ali Muhammad and Najmaddin Ali Hussein, were charged with treason, revealing secret information abroad, espionage, preparation of acts of terrorism, drug trafficking and arms smuggling. Four Azerbaijani citizens, Javid Mamadov, Vidadi Rasulov, Mushfig Amanov and Afgan Balashev all face similar charges. The alleged terrorist cell planned to bomb the Israeli Embassy in Baku as well as blow up the Russian-operated Qabala radar station. According to investigation records, the group was receiving orders from Iran’s Revolutionary Guards and Lebanon’s Hezbollah. Both Lebanese “had been trained and sent to Azerbaijan by terrorist organizations Hezbollah and al-Qaeda.” (Trend News [Baku], June 10). The suspects allegedly planned to attract local people to cooperate with them in carrying out terrorist attacks in densely populated areas. After getting their instructions from Hezbollah, the two Lebanese arrived in Iran, where agents of the Revolutionary Guards helped them to cross the border into Azerbaijan. Once there, they are alleged to have established a group consisting of local citizens, convincing them to bomb the Qabala radar station (Dayaz, May 27).

The investigation revealed that members of the group visited the Qabala region in August 2007 and took photos of the radar station. Meanwhile, group leader Karaki Ali Muhammad visited Baku several times since 2007 to collect information about Israel’s embassy. During the trial the leader of the ring admitted that he had represented Hezbollah in Iran since 2003 and his monthly wage from this organization was $900. He was ordered to collect information on the Jewish Cultural Center in Baku as well investigate a number of Iranians who “help Israel” (Turan Information Agency [Baku], June 19). Karaki Ali Muhammad was born in 1967 in the Lebanese city of Nabatia but lived for a long time in Tehran. Officially, Muhammad did not have a job while in Tehran, but he accompanied tourists to the holy places of Iran. He assembled tourist groups near Tehran’s al-Nabi Mosque and was hired there by an employee of the Iranian Ministry of Security and Intelligence (Vezarat-e Ettela’at va Anmiat-e Keshvar – VEVAK).

ASCAP Makes Outlandish Copyright Claims on Cell Phone Ringtones

Via EFF -

The Electronic Frontier Foundation (EFF) urged a federal court Wednesday to reject bogus copyright claims in a ringtone royalty battle that could raise costs for consumers, jeopardize consumer rights, and curtail new technological innovation.

Millions of Americans have bought musical ringtones, often clips from favorite popular songs, for their mobile phones. Mobile phone carriers pay royalties to song owners for the right to sell these snippets to their customers. But as part of a ploy to squeeze more money out of the mobile phone companies, the American Society of Composers, Authors, and Publishers (ASCAP) has told a federal court that each time a phone rings in a public place, the phone user has violated copyright law. Therefore, ASCAP argues, phone carriers must pay additional royalties or face legal liability for contributing to what they claim is cell phone users' copyright infringement. In an amicus brief filed Wednesday, EFF points out that copyright law does not reach public performances "without any purpose of direct or indirect commercial advantage" -- clearly the case with cell phone ringtones. If phone users are not infringing copyright law, then mobile phone service providers are not contributing to any infringement.

"This is an outlandish argument from ASCAP," said EFF Senior Intellectual Property Attorney Fred von Lohmann. "Are the millions of people who have bought ringtones breaking the law if they forget to silence their phones in a restaurant? Under this reasoning from ASCAP, it would be a copyright violation for you to play your car radio with the window down!"

ASCAP has responded by saying that it does not plan to charge mobile phone users, just mobile phone service providers. But if ASCAP prevails, consumers could find themselves targeted by other copyright owners for "public performances." Worse, these wrongheaded legal claims cast a shadow over innovators who are building gadgets that help consumers get the most from their copyright privileges.

"Because it is legal for consumers to play music in public, it's also legal for my mobile phone carrier to sell me a ringtone and a phone to do it," said von Lohmann. "Otherwise it would be illegal to sell all kinds of technologies that help us enjoy our fair use, first sale, and other copyright privileges."

The Center for Democracy and Technology and Public Knowledge also joined the EFF brief.

For the full amicus brief:
http://www.eff.org/files/filenode/US_v_ASCAP/US%20v%20ASCAP%20EFF%20ATT%...

For more on this case:
http://www.eff.org/cases/us-v-ascap

Contact:

Rebecca Jeschke
Media Relations Director
Electronic Frontier Foundation
press@eff.org

Merriam Webster: New Words for 2009

http://www.merriam-webster.com/info/newwords09.htm

Hardworking word-lovers everywhere can now learn the meaning of the word staycation ("a vacation spent at home or nearby") along with nearly 100 other new words and senses added to Merriam-Webster's Collegiate Dictionary, Eleventh Edition. America's best-selling dictionary offers its new 2009 entries in its updated print edition and online here at Merriam-Webster.com.

Many of the new words address: concerns about the environment (carbon footprint, green collar), government activities (earmark, waterboarding), health and medicine (cardioprotective, locavore, naproxen, neuroprotective), pop culture (docusoap, fan fiction, flash mob, reggaeton), online activities (sock puppet, vlog, webisode), as well as several miscellaneous terms such as haram, memory foam, missalette, and zip line.

Saudi Arabia Convicts 300 Al-Qaida Suspects

Via Yahoo! News (AP) -

A Saudi criminal court has convicted and sentenced an al-Qaida militant to death and given more than 300 others jail terms, fines and travel bans in the country's first known terrorism trials for suspected members of the terror network, officials said Wednesday.

A Justice Ministry spokesman said the court looked into 179 cases involving the 330 defendants who were found guilty. The spokesman did not give any details on the person sentenced to death, but his punishment suggests he could be a senior member of al-Qaida.

Saudi Arabia has pursued an aggressive campaign against militants since May 2003, when they first began attacks in the kingdom, which is al-Qaida leader Osama bin Laden's birthplace and home to 15 of the 19 Sept. 11 hijackers.

The network's attacks have targeted expatriate residential compounds, oil installations and government buildings.

However, the first known legal proceedings, which have been held in utmost secrecy, apparently did not start until last year. Authorities had been reluctant to resort to trials for terrorism charges that could result in death sentences until they had shown the public that every effort had been made to give the men a chance to renounce their crimes and be rehabilitated.

The 330 are believed to be among the 991 suspected militants that Interior Minister Prince Nayef has said had been charged with participating in terrorist attacks over the past five years.

Sheik Abdullah al-Saadan, the Justice Ministry spokesman, told Saudi TV the court has acquitted "some" defendants. He did not say how many nor did he say when the trials began. There have been vague reports of such trials in local media recently.

"The verdicts ranged from ... jail terms that depend on the nature of the crime and death in one of the cases," al-Saadan said.

He said the rulings also included financial penalties, travel bans and house arrests in the city of the defendants' choice, added al-Saadan. A transcript of his remarks were carried by the official Saudi Press Agency.

Al-Saadan said the verdicts can be appealed. He also said preparations are under way to give access to the press to cover the trials, apparently referring to those of the remaining detainees.

A statement issued by a spokesman for the Bureau of Investigation and General Prosecution said the defendants were accused of belonging to the "deviant group," a euphemism for al-Qaida.

They were also accused of supporting and financing terrorism, going to areas of conflict to fight, and coordinating and communicating with "external parties that seek to conspire against national security by creating chaos and disrupting security," according to the unnamed spokesman.

The statement, also carried by official press agency, said the charge sheets included "incriminating evidence of these dangerous acts and proof that every defendant has carried out the charges against him."

There have been no major attacks since February 2006, when suicide bombers tried but failed to attack an oil facility at the Abqaiq oil complex, the world's largest oil processing facility, in eastern Saudi Arabia.