Cyber Security Tip & Tricks
Showing posts with label US. Show all posts
Showing posts with label US. Show all posts

Saturday, December 27, 2008

U.S. government vulnerable to Internet predators

U.S. government vulnerable to Internet predators

Most Internet users have some awareness of the problem of threats to the entire system from criminals, terrorists and potentially hostile nations, since they encounter it in the form of spyware, viruses and other online nuisances.

However, the most disturbing "cyber" threats are largely invisible to the general public, because they involve attacks on specialized networks used by the armed forces, healthcare professionals, air traffic controllers, financial institutions, public utilities and heavy industry.

Each of these vital components of modern society now relies on Internet Protocol communications to run efficiently, and in most cases the new technology was assimilated without a careful assessment of its vulnerability to attack by outsiders.

Tuesday, November 4, 2008

Beware of debit card skimmers

Police in at least two cities advise consumers not to use their debit
card at a gas pump because there’s no way to be sure it hasn’t been
tampered with.
By Herb Weisbaum
MSNBC
Becki Turner got the call from her bank’s fraud department on Labor
Day. The investigator wanted to know if she had withdrawn $500 from an
ATM in California over the holiday weekend. She hadn’t. She couldn’t.
Turner was home in Puyallup, Wash.

“I was just flabbergasted,” she says. “I had the card with me, the ATM
was in another state, and the person using the machine had to have my
security code.” Turner worried crooks had gotten into the banking
system and stolen her password.

It wasn’t anything that complicated. Puyallup police say thieves
snagged her account information — along with the debit card numbers
and PIN codes of hundreds of other people — at two gas stations in the
area.

They did it by installing their own hard-to-spot card reader, called a
skimmer, on top of the card reader built into the pump. The skimmer is
able to grab the account information from the card without interfering
with the legitimate payment transaction.

The crooks used the stolen data to create (or clone) fake debit cards
that were used at ATMs in Washington State over the Fourth of July
weekend and in Northern California on Labor Day weekend. The bad guys
like three-day holidays because it gives them more time to use the
cards before the unauthorized withdrawals are spotted.

“We are looking at a sophisticated, very well-organized group of
individuals,” says Detective Jason Visnaw with the Puyallup Police
Department. When all the victims from these two incidents are
identified, the total loss could reach half a million dollars.

Why steal debit card numbers? “With a credit card you have to go and
buy merchandise and then you have to fence it or pawn it,” Det. Visnaw
explains. “With a debit card, you’re getting cash money.”

This is not an isolated case. Gas pumps are being compromised in
cities across the country. “We don’t view it as an epidemic, but there
are cases open in at least a half dozen states right now,” says Ed
Donovan, spokesman for the U.S. Secret Service. These investigations
are underway in California, Nevada, Pennsylvania, Delaware and
Washington.

Donovan tells me the Secret Service believes some of these crimes are
inside jobs, involving someone at the service station.

Gas pumps are just the latest target

Skimming credit cards and debit cards is not new. Portable card
readers make it possible for anyone to copy the information stored on
a card’s magnetic stripe. This information is not encrypted so it’s
easy to steal.

“You just run it through the skimmer and it has all the information
right there in plain text,” says former White House cyber security
advisor Howard Schmidt. “It’s very easy to imprint that data on
another magnetic strip and use it somewhere else.”

The first skimming cases were reported at restaurants and stores where
dishonest employees ran cards through their reader before ringing up
the sale. As technology improved, the bad guys developed skimmers for
ATMs. Now they’ve added gas pumps.

The skimmers are designed to slip over the real card reader. They can
be hard to spot. And quite frankly, most of us would never look for
something like this anyway. We want to pay and go.

So how do they get your PIN number? They can hide a little camera in
the skimmer or on the pump. It shows your fingers as you type in the
number.

There are also fake keypads that slip over the real keypad that can
transmit the PIN code as you enter it.

In Las Vegas, police have discovered even more sophisticated
technology – wireless transmitters installed inside the pump. “They
can actually sit in the parking lot with a laptop and get real-time
information as victims use their card,” explains Lt. Robert Sebby of
the Las Vegas Metropolitan Police Department. Because there’s nothing
on the outside of the pump, there’s no way you can tell the pump is
compromised.

Not a safe way to pay

Nancy and Jim Tew no longer use their debit cards to pay at the pump —
and for good reason. They both had their debit card numbers stolen at
one of those gas stations in Puyallup, Wash.

Nancy Tew found out about the theft when her card was rejected at the
grocery store. “To my astonishment, I had no money in the bank,” she
said.

The thieves used her account number at ATMs in Hollywood, Calif., to
steal $600. They got $900 from her husband’s checking account. She
tells me it was “totally bizarre and really scary” to be targeted like
that and not even know it.

The Tews now pay for their gas — with cash or debit card — at the
register. That may sound paranoid, but other victims of this skimming
attack tell me they now do the same thing.

Police in Puyallup and Las Vegas now advise residents not to use their
debit card at a gas pump because there’s no way to be sure it hasn’t
been tampered with.

That’s smart advice and here’s why. Debit cards do not offer the same
fraud protection as credit cards. If crook armed with a skimmer snags
your credit card number and uses it to buy things, you can dispute the
charges with the credit card company. You won’t owe a thing while they
investigate.

If the crook grabs your debit card number, he can go to a cash machine
and pull money out of your checking account. It could take days for
the bank to investigate and put that money back into your account.
During that time checks could bounce or you might not be able to pay
your bills. That’s why the only way I pay at the pump is with a credit
card.

Thursday, May 22, 2008

US Military Botnet - Weapons of Mass Denial

U.S. military is planning to botnet attacks to its enemies computer network. US botnet is a disturbing concept, but next to cluster bombs and cruise missiles it's War Lite. According to Col. Charles W. Williamson III proposes that "...America needs a network that can project power by building an af.mil robot network [botnet] that can direct such massive amounts of traffic to target computers that they can no longer communicate and become no more useful to our adversaries than hunks of metal and plastic. America needs the ability to carpet bomb in cyberspace to create the deterrent we lack." Wow, them's fighting words.
In a real war this would all be devastating for the civilian infrastructure, but I doubt it would stop troops from moving or planes from flying or submarines from diving. Perhaps that's the best reason to follow Williamson's advice: Once deterrents are in place, launching an attack only ends up shooting you in the foot.

Source: eweek

Tuesday, September 18, 2007

The net is an insecure place - US CERT Reminder

If you use Gmail, eBay, MySpace, or any one of dozens of other web-based services, the United States Computer Emergency Readiness Team wants you to know you're vulnerable to a simple attack that could give an attacker complete control over your account.

US CERT warned that Google, eBay, MySpace, Yahoo, and Microsoft were vulnerable, but that list is nowhere near exhaustive. It said the world's biggest websites have yet to fix the gaping security bug, which can bite even careful users who only log in using the secure sockets layer protocol, which is denoted by an HTTPS in the beginning of browser address window. Just about any banking website, online social network or other electronic forum that transmits certain types of security cookies is also susceptible.

The vulnerability stems from websites' use of authentication cookies, which work much the way an ink-based hand stamp does at your favorite night club. Like the stamp, the cookie acts as assurance to sensitive web servers that the user has already been vetted by security and is authorized to tread beyond the velvet rope.

The thing is just about every website transmits these digital hand stamps in the clear, which leaves them wide open to snoops monitoring public Wi-Fi traffic or some other type of network. Once attackers have the cookie, they gain complete access to the victim's account, and depending on the way many cookies are crafted, those privileges may continue in perpetuity - even if the victim changes the account password.

Indeed, awareness of this man-in-the-middle vulnerability is by no means new. For more than a decade people have known that authentication cookies could be manipulated, but somehow it took the folks at Errata Security to make a presentation at Black Hat to remind the world that the risks continue.

If you're waiting for a fix, we recommend you pack a very large lunch. And beyond that, where possible you might switch to Google, which has already gone a long way to closing the hole.

As the only web-based email service we know of that offers a start-to-finish SSL session, the service is among the most resilient to cookie hijacking. Unfortunately, Gmail doesn't enable persistent SSL by default, and has done little to educate its users about its benefits.

The company also offers SSL for its calendar, search history, documents and reader services, and a Google spokesman said security engineers "are actively working to expand capacity to enable HTTPS encryption for all users."

In the meantime, a Firefox extension called CustomizeGoogle provides a simple way to ensure that all sessions with the above-mentioned Google services are automatically protected by SSL.

Friday, September 7, 2007

Pentagon Computer Hacked Into By Chinese

The Chinese military hacked into a Pentagon computer network in June
in the most successful cyber attack on the US defense department, say
American ­officials.

The Pentagon acknowledged shutting down part of a computer system
serving the office of Robert Gates, defense secretary, but declined to
say who it believed was behind the attack.

Current and former officials have told the Financial Times an internal
investigation has revealed that the incursion came from the People’s
Liberation Army.

One senior US official said the Pentagon had pinpointed the exact
origins of the attack. Another person familiar with the event said
there was a “very high level of confidence...trending towards total
certainty” that the PLA was responsible. The defense ministry in
Beijing declined to comment on Monday.

Tuesday, September 4, 2007

2007 Hacker Reverse Engineering Challenge

Similar to the Hacker Challenge in 2006, it is being run by a U.S. company performing security testing and security metric research. The purpose of this challenge is to evaluate the effectiveness of software protections. The results of this effort will be used to improve protection measures.

There will be three distinct, yet related, phases to this contest. The first phase will be a hacker challenge, for which anyone can register to participate. The second stage of the contest will be a market (based on the Phase 1 challenge). Participation in this second phase will be by invitation only, based on performance in the first phase. The third phase of the contest will be a more challenging hacker challenge; this phase may or may not be invitation-only. There are opportunities to earn money in all three phases of the contest.

All file downloads and uploads necessary for the contest will be possible after the participant has logged in. The market will also be visible, at the appropriate time, after logging in.

All payments are in U.S. dollars, and will be made anonymously via PayPal with prizes up to $50,000USD for the three phases.

You can read more here.

http://www.hackerchallenge.org/

Monday, September 3, 2007

E-mail accounts of embassies and Government offices across the world, including India hacked due to lack of Cyber Security

A hacker, Dan Egerstad from Sweden, who published passwords of 100 e-mail accounts of embassies and Government offices across the world, including India, on his website http://derangedsecurity.com. The hacker said he took only a few minutes to figure out the account details.

This shows that there is lack of basic cyber security. Due to the lack of security anyone with moderate skills in security could have figured this out and done it. A cyber security expert said that a POP (Post Office Protocol) server that had not been updated for security could have been exploited by the hacker to get usernames and passwords.

The Indian Express said in their website that they were sent a test mail to the Indian Ambassador in China on her official email ID and, using the password posted online, to check the authenticity and was able to access it. These email IDs contained important official details including phone numbers, commercial documents, official correspondence and personal mails.

Within hours of the story appearing in the Indian Express, the DRDO mail server was shut down and all embassy e-mail accounts were taken offline by the Ministry of External Affairs (MEA). However, it will take cyber forensic experts several days to get an idea of how much confidential material was illegally accessed.

DRDO confirmed that the hacked account belonged to a Defense Scientific Information and Documentation Centre (DESIDOC) official, but it was rarely used. The Ministry of Defense (MoD), however, said it was conducting a detailed investigation into the incident.

Tuesday, August 28, 2007

Caller ID Spoofing to be made illegal in the USA

The US Congress recently approved a bill that will make it illegal to spoof Caller ID in the USA. This Act may be cited as the `Truth in Caller ID Act of 2007'.

The title of the act is “A bill to amend the Communications Act of 1934 to prohibit manipulation of caller identification information”

It was introduced on February 28, 2007 and updated 27th June 2007.

PENALTIES
(A) CIVIL FORFEITURE-
(i) IN GENERAL- Any person that is determined by the Commission, in accordance with paragraphs (3) and (4) of section 503(b), to have violated this subsection shall be liable to the United States for a forfeiture penalty. A forfeiture penalty under this paragraph shall be in addition to any other penalty provided for by this Act. The amount of the forfeiture penalty determined under this paragraph shall not exceed $10,000 for each violation, or 3 times that amount for each day of a continuing violation, except that the amount assessed for any continuing violation shall not exceed a total of $1,000,000 for any single act or failure to act.
(ii) RECOVERY- Any forfeiture penalty determined under clause (i) shall be recoverable pursuant to section 504(a).
(iii) PROCEDURE- No forfeiture liability shall be determined under clause (i) against any person unless such person receives the notice required by section 503(b)(3) or section 503(b)(4).
(iv) 2-year STATUTE OF LIMITATIONS- No forfeiture penalty shall be determined or imposed against any person under clause (i) if the violation charged occurred more than 2 years prior to the date of issuance of the required notice or notice or apparent liability.
(B) CRIMINAL FINE- Any person who willfully and knowingly violates this subsection shall upon conviction thereof be fined not more than $10,000 for each violation, or 3 times that amount for each day of a continuing violation, in lieu of the fine provided by section 501 for such a violation. This subparagraph does not supersede the provisions of section 501 relating to imprisonment or the imposition of a penalty of both fine and imprisonment.

Source: Library of Congress

Monday, July 30, 2007

Cyber Crime – Hacking - Software Engineer arrested from Chennai

Cyber Crime – Hacking - Software Engineer arrested from Chennai

One M.S. Ramasamy, a 37 year old Software Engineer from Avadi, had arrested on 27.07.07 by the Chennai Cyber Crime Police on charges of hacking and stealing confidential and proprietary information from the server of a US IT Company. He was a former employee of that IT Company. Police framed charges under Section 66 of the IT Act, 2000 which dealing with Hacking and Section 408 of the IPC which dealing with Criminal Breach of Trust by Clerk or Servant.

In its press release Chennai Police said that Mr. Ramasamy had reportedly hacked into the company’s headquarter computer system when he was working as an Engineer in Caterpillar India Private Limited during January and February this year.

The accused accessed the company’s server located at Peoria in Illinois, US, by using another employee’s User ID and password and downloaded confidential information. A closed circuit camera recorded the activities of the sever room. By analyzing the server log and the visuals from the camera Police tracked the accused. Police arrested the hacker from an IT Company at Hosur, where he was employed. The Police confiscated the hard disk and pen drive containing the files.

Source: Hindu

Friday, June 1, 2007

Internet Spam King Robert Soloway, 27 was arrested by US Police


A man nicknamed the "spam king" for allegedly sending out millions of junk e-mails has been arrested in the US.
Robert Soloway, 27, was arrested in Seattle, Washington, after being indicted on charges of mail fraud, identity theft and money laundering.
Mr Soloway allegedly sent millions of e-mails on hijacked computers. Using computers secretly infected with orders to send out millions of his e-mails. Such computers are known as "zombies" because their owners often have no idea they have been hijacked for another purpose.

According to prosecutors, Mr Soloway was responsible for tens of millions of unsolicited e-mails promoting his own company between November 2003 and May 2007.
He is said to have frequently changed the web address of his internet marketing business to avoid being caught.
A US lawyer said Mr Soloway was the first person to be prosecuted for sending out spam e-mails using federal laws against identity theft.
Prosecutors want to seize the sum of $773,000 (£391,000) that Mr Soloway is said to have made from his firm.
If convicted of all the charges, he also faces a fine of $250,000 (£126,500) and a maximum prison term of 65 years.


Video on Robert Soloway Arrest.
Source: BBC News

AddThis Social Bookmark Button

Recent Comments