Hack The Planet

Because if you don't, who will?

Thursday, February 25, 2010

Cloud computing killed the Reich

This is quite possibly one of the funniest things I have seen in a while. The sad part is that it is an accurate portrayal of so many companies.

[youtube=http://www.youtube.com/watch?v=VjfaCoA2sQk]

posted by holliday at 10:19 am  

Friday, February 19, 2010

Two schools tied to Google compromise

When Google came out and said they had been hacked and that they had found that the hacks originated in China it seemed that all they could find was one compromised machine in Taiwan. Now with help from the NSA they have traced the attacks back to IP’s originating from two schools, Shanghai Jiaotong University and the Lanxiang Vocational School in China.

The evidence still doesn’t show who actually did the hacking, or if it even originated in China. Another country could even be using the school as a gateway to perform the attacks knowing that relations between China and America are strained. Of course, the fact that the US did so poorly in a recently simulated cyber attack doesn’t help matters either.

Then again, a school that Peng Yinan, one of the most prolific Chinese hackers, teaches at from time to time is a pretty likely candidate for an attack to come out of. It will be interesting to see if they can find any other evidence besides an IP.

posted by holliday at 11:09 am  

Thursday, February 18, 2010

The Birds and the Bees

A wily hacker in Russia thought it would be good fun to place a pornographic movie on the big screen along the city’s Garden Ring Road for any driver that needed a lesson in the Birds and the Bees to see. He was later arrested but explained his actions by stating he “originally wanted to stream the video on a commercial screen of a shopping mall in Moscow”, and didn’t imagine that “thousands of people would see the porn flick in the center of the city”.

posted by holliday at 1:53 pm  

Tuesday, February 16, 2010

One compromised machine

Recently, Brian Krebs, has been posting a lot about companies losing money to hackers who have money mules transferring stolen funds all over the globe (mostly to Eastern Europe it seems). The hack is pretty simple. A user with a vulnerable endpoint gets hit with the Zeus Trojan or a variant by viewing a compromised site. The endpoint can then pass on the infection to other endpoints on the network. Once it infects an endpoint that accesses the companies bank accounts the fun begins. The hackers setup many sub $10,000 dollar transfers to the mule accounts and then have the mules wire them the money.

Recently one infected machine at a Michigan Insurance firm cost them $150,000. That is a lot of money to lose (they are working with their bank to recover it but that usually only ends poorly) for not having an up to date machine. One bad hack can make you realize that a good security setup is much cheaper in the long run.

The second part of the story that I found interesting is that the bank would use “two factor” authentication by having the customer enter their user name and password, and then answer a security question. The President of the Insurance firm says “They had some very detailed information. [The thieves] knew our patterns, they knew our passwords, my mother’s middle name, favorite sports team. And this is all information I don’t even have written down anywhere.” So what he is saying is that it is impossible to find out his mother’s middle name online doing a quick search? Or that he hasn’t worn a jersey of his favorite sports team in some picture that has been tagged with his name on facebook? And that is assuming that the hackers even entered that information. The bank says they see someone enter it but it could be from a compromised machine with someone legitimately logging in and the hackers are just piggy backing.

Hackers don’t play these elaborate bank heists that require years of training and some elite knowledge that only they possess. They just wait until some lazy user goes to a compromised web site and gets infected with their Trojan. Then it is game, set and match.

posted by holliday at 4:19 pm  

Friday, February 12, 2010

If you teach a man how to not Phish

The Login Helper site has put out a great flow chart to help users determine if an email is risky to open or not. The nice part about this flow chart is that it is easy enough for anyone to follow.

posted by holliday at 2:14 pm  

Wednesday, February 10, 2010

Privacy and Anonymity

We are in a new era of humanity where everything you do is being taped, recorded and broadcast for the world to see. Who is doing this? Is it some secret government cabal? Some clan of hackers so elite that they can capture your every movement? No, sadly it is just you and your computer.

I fought the Facebook battle for a long time. I finally succumbed to the madness to build up possible references and contacts for my career. It wasn’t long before everyone and their grandmother had requested to make me their friend even though I may not have known them personally or hadn’t spoken to them in over a decade. All of these people are opening up their lives and their families to me, and even to my “friends”. They aren’t concerned with this. Only 1 in 3 Facebook users even reviewed the changes to the privacy settings that Facebook pushed out. Only 1 in 3 people cared enough about their privacy to make sure that the entire (internet connected) world didn’t have full access to their lives. 1984 isn’t going to happen, it has and we have let it.

To me privacy and anonymity go hand in hand. Recently Bruce Schneier posted an article about anonymity on the internet and how certain people in the government are trying to abolish this by forcing every user everywhere to authenticate when they access the web. This is supposed to stop hackers and criminals from participating in the online world. The first commenter said it best “If you outlaw anonymity on the Internet, only outlaws will have anonymity on the Internet.”

posted by holliday at 5:35 pm  

Thursday, January 28, 2010

How far they have fallen

It has been a long time since 1984 and it seems Apple has forgotten that they once proclaimed to be about fighting Big Brother and conformity. Apple has released a product this week (iPad) that is more locked down, more restrictive and wants you to conform more than any other on the market. Apparently innovation is too much work so they just made their iPhone bigger and gave it a new, sillier name. The iPad, for when you absolutely, positively want to run just one thing at time….as long as that thing is not flash based, uses USB and it complies with the draconian rules of the Apple App Store.

posted by holliday at 10:03 pm  

Thursday, January 28, 2010

Digital forensics and DNA

This week, tomorrow actually, DARPA is having a workshop for the Cyber Genome Program to try and find a way to collect digital DNA. Taking this straight from their page:

“The objective of the Cyber Genome Program is to produce revolutionary cyber defense and investigatory technologies for the collection, identification, characterization, and presentation of properties and relationships from collected digital artifacts of software, data, and/or users to support DoD law enforcement, counter intelligence, and cyber defense teams. Digital artifacts may be collected from live systems (traditional computers, personal digital assistants, and/or distributed information systems such as ‘cloud computers’), from wired or wireless networks, or collected storage media. The format may include electronic documents or software (to include malicious software – malware). The Cyber Genome Program will encompass several program phases and technical areas of interest. Each of the technical areas will develop the cyber equivalent of fingerprints or DNA to facilitate developing the digital equivalent of genotype, as well as observed and inferred phenotype in order to determine the identity, lineage, and provenance of digital artifacts and users.”

It is very interesting how not too long after we are discussing cyber warfare with China that DARPA is tasked with finding a way to prove “Whodunit”. But how effective can they really be at determining the true culprit of a malicious attack? I find that many folks already assume China or some East European faction is hacking the US at any given time and that if some government official came out and said they were no one would question them. Is there a political need to confirm who the attacker is? I am sure we would like there to be one but really, when it comes down to it who besides the team at DARPA would have the ability to call them on it? I find it alarming that they claim to be looking for a way to track someone through digital DNA when not even real DNA can be trusted anymore.

posted by holliday at 4:28 pm  

Wednesday, January 27, 2010

You knew it would happen but the PS3 has been hacked

The PS3 has been one of the most secure gaming devices, lasting well over 3 years before it finally got hacked. Geohot, of iPhone hacking fame, first cracked the PS3 and has now released the hack into the wild to see what others could do with it. It will be interested to see how quickly homebrew software becomes available now that it is possible.

posted by holliday at 9:27 am  

Wednesday, January 27, 2010

Twice in 24 hours?

TechCrunch got hit again. Not 24 hours since they were previously hacked and their site defaced they got hit again. Maybe this is why everyone is so up on discussing APT (Advanced Persistent Threat).

This attack on TechCrunch is not truly what folks are discussing around APT because so far it doesn’t look like the hackers were trying to acquire any trade secrets, and the hack probably wasn’t that advanced though I haven’t read any specific details of the actual hack. What I find interesting is the persistent piece. This goes back to an idea from a previous post about Threat Modeling. What do you do when you are the target of a group of malicious hackers?

The first thing you would need to do is find out that you are under attack. For TechCrunch it was a bit late as they found out when they saw that their web page had been defaced. For Google vs China they were able to track back to the source but the attack had been going on for weeks. So how do you find out before you are compromised? Sometimes there is no way. But sometimes there is.

Using a layered approach to your network security you are not just trying to stop attackers but you are trying to find out how they are attacking you and maybe even what they want. By correlating logs and activity from your Routers, Firewalls, IDS’, Web Servers, and other devices on your network you should be able to build a pretty clear picture of what is happening on your network. By monitoring these you can build a map of how you are being attacked (and you are even if you aren’t the specific target) and then you can formulate a plan to make sure you are not vulnerable to the attacks.

The first step doesn’t have to be denial.

posted by holliday at 9:19 am  
« Previous PageNext Page »

Powered by WordPress