Anti Virus Softwares

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Friday, 26 October 2007

How Many Websites Can a Hacker Hack without Being Prosecuted?

Posted on 14:35 by Unknown
Apparently the answer to that is TENS OF THOUSANDS, or more.

IskorpitX, the tutor of an entire generation of Turkish hackers, will shortly be able to claim that he has broken into 200,000 websites. (He's currently at 191,000 according to one popular hacker watching website).

Brasilian hacker, Fatal Error, runs a distant second, having broken in to "only" 32,000 websites according to the same source.

Wouldn't you say that would make them "targets of interest" for law enforcement activity? Sadly, that is not the case. Perhaps, you think to yourself, they have only attacked "low value" websites. Perhaps they are brand new to the scene? If only that were the case! Fatal Error, who lists many US Government websites, and even my home state of Alabama government websites, among his victims, has been actively attacking websites since 2002.

IskorpitX has been defacing websites since at least 2003, and has the governments of Argentina, Australia, Brazil, China, Columbia, France, India, Italy, Korea, Malaysia, Peru, the Philippines, Thailand, Venezuela and South Africa among his many victims. Of course the US government is on the list as well (such as the National Endowment for the Humanities), as well as Harvard University and Bank of America.

IskorpitX even has his own YouTube videos!

http://www.youtube.com/watch?v=ahqSeJvM2XU

http://www.youtube.com/watch?v=jTah9ckvV3Y

Other Turkish "Cyber Warriors" have even done television news interviews about why they hack websites!

http://www.youtube.com/watch?v=w4QgEsuTZrM


Here's one interesting hacker this week and the victims which are still laying around in Google's Cache:

I found it interesting because this hacker is doing SQL Exploits such as we've seen on several high profile attacks in the past including the National Institutes of Health and the United Nations. In this case, a content management system is being SQL injected to replace "titles" of things with the name of the hacker.

Google for the string "OwneD by RootDamages by FasT", and you'll find some interesting victims among the 26,100 pages being returned.

How about The Department of Veterans Affairs and their Cooperative Studies program?

www.vacsp.gov/news.cfm
www.csp.gov/news.cfm

(Although the Malaysian government also got a visit:

www.mygeoportal.gov.my/faq.cfm

Or the Michigan Bar Association?

www.michbar.org/news.cfm

Systems Integrator "Regan Technologies"?

www.rtcorp.com/news.cfm

The Esalen Center for Theory & Research still has pages with the title "OwneD by RootDamages by FasT", such as:

http://www.esalenctr.org/display/confpage.cfm?confid=10&pageid=105&pgtype=1

As does Applied Robotics:

http://www.arobotics.com/about/company_news/news_details.cfm?ID=17

But they weren't just limited to News articles. I think I'd feel very safe using a shopping cart where every product in the online store had been renamed to "OwneD by RootDamages by FasT", such as those at MetroPole360:

http://www.metropole360.com/productcat.cfm?productCatID=3

But you don't have to be a business to have an insecure webserver. Just ask the National Limousine Association, or the NorWest Dog Training Club:

http://209.85.165.104/search?q=cache:d_YOcnX94A4J:norwestdogtraining.co.nz/Newsletter.cfm

http://209.85.165.104/search?q=cache:aN6AmMtGh0kJ:www.limo.org/scriptContent/t_inside.cfm

One subject "that comes up over and over again on Ducati Online" is "OwneD by RootDamages by FasT" according to this news article:

http://www.ducati.net/faq.cfm?id=4

They're even having a conference on the topic in Brasil at the Psychology Congress. September 7th was their conference on "OwneD by RootDamages by FasT". They expected 6 thousand people to attend.

So how many websites will these hackers be allowed to deface before someone decides to arrest them?
Read More
Posted in | No comments

Monday, 15 October 2007

Is Your Fifth Grader Smarter Than a Laughing Cat?

Posted on 06:27 by Unknown
Have you seen the television show "Are You Smarter Than a Fifth Grader?" I've been thinking about a variation of that question as I consider the newest version of The Storm Worm.

This morning on the "Good Morning, Alabama" show as I discussed the Storm Worm, the weatherman laughed and said "Fortunately, I pretty much stay awy from laughing cats". So do most adults with bank accounts. Ask the question another way though. "Is there anyone who uses your computer who is into laughing cats?"

Laughing Cat Storm Worm


Twenty of the Twenty-nine anti-virus products I scanned this particular virus with (using Virus Total), did not report an infection. As of this writing, ClamAV, F-Prot, F-Secure, Microsoft, Panda, and Symantec were among the anti-virus programs who said "No Virus Found" to this current malware. ( Click for Results of this scan.)

Previous versions of the Storm Worm have used things such as Greeting Cards, an NFL Game Tracker, Labor Day greetings, Fourth of July greetings, and even Virus Alerts as means to trick people into visiting the malware site.

UAB's Computer Forensics research area will continue to study and document the storm worm until we can find a way to identify the criminals and bring them to justice.

I'll be giving a Public Lecture on Botnets this Friday (October 19th) at the Hull University Center Auditorium.
Read More
Posted in | No comments

Saturday, 22 September 2007

Is the Internet a Prosecution-Free Zone?

Posted on 08:03 by Unknown
Jörg Ziercke, the chief of the Bundeskriminalamt (BKA) in Germany, was quoted in a
press release on the BFK website, following a simultaneous phishing raid in Bad Homburg, Düsseldorf, Köln, Frankfurt and Elmshorn. His words lay down an interesting challenge:

"This case shows once more: Criminal organizations are increasingly using the Internet in order to make enormous profits with an allegedly low risk of discovery." He said that prosecutors are constantly facing new challenges regarding Cyber Crime, but that "the Internet cannot develop into a prosecution-free zone."

That's exactly what's at risk. We have to decide whether the Internet is going to be patrolled and prosecuted just like the streets and alleys of our cities, or whether we are going to allow crime to occur unabated there.

In the BKA case, two women, aged 22 and 23, and six men, aged from 20 to 36 years old, have been imprisoned pending their court appearance. Two others are also charged but were not taken into custody.

Sounds good, and congratulations to the BKA! But what about all the other phishers? So far in September, we've made positive confirmation on more than THREE THOUSAND phishing sites in UAB's Computer Forensics Research lab. We can't continue to allow it to take 18 months before a phishing investigation leads to charges.

The more evidence we gather, and the more relationships we find between phishing campaigns, the greater the chance that we can get some law enforcement action.

Remember, if you hear of someone who has been a victim of Identity Theft, Phishing, or any other Cyber Crime, please make sure they fill out a complaint at the Internet Crime and Complaint Center, http://www.ic3.gov/.

Also, if there has not been a financial loss, phishing sites still need to be reported! When you receive a phishing email, please help by sending it to:

pirt@castlecops.com

or by using the webform at:

http://www.castlecops.com/pirt

Let's make sure the Internet doesn't become a "Prosecution-Free Zone".
Read More
Posted in | No comments

Tuesday, 4 September 2007

TJX: From Florida to the Ukraine?

Posted on 03:52 by Unknown
Last week the media lit up with speculations that 24 year old Ukrainian hacker, Maksym Yastremskiy, who had been arrested in Turkey on August 2nd, may be behind the TJX Credit Card hack. The Boston Globe's Ross Kerber may have had the best coverage with his story "Suspect
named in TJX credit card probe"
on August 21. The story quoted Greg Crabb of the US Postal Inspection Service's global investigations division. Crabb said Maksym was "likely the largest seller of stolen TJX numbers". TJX, the financial company in the TJ Maxx conglomerate, believes that as many as 45.7 million credit cards were stolen during a breach during 2005 and 2006, which captured credit card transactions all the way back to 2003.

How's your Turkish? This August 2nd article , "Antalya'da yakalanan Ukraynalı hacker 80 bin kişiyi dolandırmış", interviews Turkish police officer, Feyzullah Arslan, who arrested Maksym after a sting in a luxury night club in Kerem, Turkey.



Using a "follow-the-money" investigative technique, the investigation began with 10 guilty pleas in Florida back in March from a crew of careless cyber criminals who had racked up millions of dollars of purchases from Wal-Mart and other Florida retailers using stolen credit cards that tracked back to TJX. The Florida investigation actually started when Gainesville police were contacted regarding two local Wal-Mart stores who had made individual gift-card sales in the amounts of $18,000 and $24,000. HINT: IF SOMEONE WANTS $24,000 IN WAL-MART GIFT CARD, THERE MAY BE A CRIME LYING ABOUT.

Those cards were used at a Sam's Club in Miami, along with many other cards, to buy large quantities of electronics and jewelry. At that time, the cards were all tracked back to TJX, and an estimate of the loss from the database hack was released in the news -- Gainesville police Sergeant Ray Barber revealed "They estimate the loss from that hack job to be around $8 million", although this particular crew had only rung up $1 million in charges so far. (See, for example: "Florida police make arrests in TJX, Winners credit card theft".

The first six, arrested March 19, were:

Irving Jose Escobar, 18
Reinier Camaraza Alvarez, 27
Julio Oscar Alberti, 33
Dianelly Hernandez, 19
Nair Zuleima Alvarez, 40
Zenia Mercedes Llorente

All ten, including the additional:

Erick Fernandez Rodriguez
Hector Alfaro Rodriguez
Alexis Arcia
Armando Ochoa

have Mugshots posted on eweek.com.




In a USA Today story a map of Irving Escobar's shopping spree, where he bought as many as 60 $400 gift cards in a single location, and then spent the money from November 1st to January 18th, is mapped out.



The big break in this first case came when an alert Wal-Mart employee followed the gift card purchases out of the store and recorded their license plate number. (For more, see the March 24, 2007 Boston Globe story by Ross Kerber, quoted here: Scam May Be Tied to Stolen TJX Data

A second Florida-based TJX gang plead guilty in late June. This group was charged with possessing 172,000 sets of credit card data, which had been used to make at least $75 Million in bogus credit card charges. Arrested in this scam were:

Miguel Alegria, 46, of Hialeah, FL
Raynier Pupo, 22, of Miami, FL
Ariel Montero, 32, of Aventura, FL
Javier Padron-Bravo, 35, of Aventura, FL
Julio Lopez, 30, of Hialeah, FL
and Anett VIllar, 26, of Hialeah, FL



Alegria, Pupo, Montero, and Padron-Bravo plead guilty to conspiracy in exchange for a plea agreement that included cooperation.

The Nashville Secret Service ran the investigation as "Operation Blinky" named for the first suspect's online name, which they co-opted as an undercover identity. For more see: TJX, Polo Data Surfaces In Another Credit Card Bust.
Read More
Posted in | No comments

Friday, 31 August 2007

The World v. AllofMP3.com & Russian Copyright Law

Posted on 04:34 by Unknown
Music collectors on the Internet got a mixed message this week as a Russian court found that Denis Kvasov, the head of AllofMP3.com was innocent of all charges.

While Napster, iTunes, WalMart and other online music retailers sell songs for 75 cents to 99 cents each, AllofMP3.com had nearly as large a selection and sold tracks for a mere 10 cents apiece or entire albums for $1 apiece.

The US-based music industry cried foul, and the US Department of Commerce agreed, making the closure of AllofMP3.com a requirement in Russia's 2006 attempt to join the World Trade Organization. Eight online music sites in Russia were shut down, and criminal charges brought against their owners in July, prior to the WTO Summit.

The company's website made clear that users should make sure the use of AllofMP3.com did not violate copyright laws in their home country.

No news on the RIAA Lawsuit against AllofMP3.com, where they are asking for $150,000 in damages for each of the 11 million songs in their catalog, or a $1.65 Trillion lawsuit.

In Russia, the copyright law requires that selling copyrighted material is legal, if a 15% royalty payment is paid to ROM, the Russian Organization for Multimedia and Digital Systems. Oleg Nezus, speaking for ROM, says that all of the major record labels have royalty payments waiting for them in Russia, but EMI and Universal have refused to accept their payments - not wanting to send the message that 10 cent downloads are adequate for their constituents.

Zemchenkov, of the Russian Anti-Piracy Organization was praising Russia's newly beefed up anti-piracy laws, which carry penalties of up to six years in prison for DVD pirates, as recently as April -- see: Hollywood Reporter: Putin Beefs Up Penalties for Piracy. Now, he is saying this lack of action against AllofMP3.com "sets a very bad precedent".

Zemchenkov, whose organization has the support of the Motion Picture Association (MPA), has been active in the Coalition for Intellectual Property Rights, and has attended all of the meetings of the "Russian Federation IP Working Group". CIPR also produces a monthly newsletter about IPR issues in Russia. In their most recent issue they conclude their summary of the case with this statement:


the court was not convinced that EMI, Warner and Universal Music have rights to the music sold by Allofmp3


citing as their source this August 16th article in vedomosti.ru:

Вину Allofmp3 не доказали (Not Guilty Allofmp3 Vindicated)

Суд оправдал бывшего гендиректора “Медиасервисез”, владевшей музыкальным интернет-магазином Allofmp3. Прокуратура обвиняла его в нарушении прав звукозаписывающих компаний, но суд не нашел доказательств того, что EMI, Warner и Universal Music действительно владеют правами на музыку, которую продавал Allofmp3.

Which means (gar's rough computer-assisted translation):

Court absolved former general director MediaServices who owned the internet music shop Allofmp3. The office of the public prosecutor accused it of violating the rights of the production companies, but the court did not find evidence that EMI, Warner, and Universal Music really own rights for the music which was sold on Allofmp3.


The prosecutor in the case, had claimed that from September 4, 2003 until December 1, 2005, Kvasov had infringed on the rights of Universal, Warner, and EMI by distributing music for which they owned the rights.

The ruling went on to find there was no reason they could not return to business, which AllofMp3.com announced on their website this morning with the headline "The Service Will Be Resumed".

The press release, dated August 31st, says:

"The service will be resumed in the foreseeable future. We are doing our best at the moment to ensure that all our users can use their accounts, top up balance and order music."

This is a major blow to copyright holders around the world, as it sends a message that as long as you pay your license fee to the Russians, you can sell anything you want for any price you want. The Russians did have 1600+ arrests for copyright infringment in 2006, but it is believed these were cases against people who hadn't paid their local "fees".

A survey of Intellectual Property brand owners conducted in 2006 by CIPR had found that 6% believed the situation with regards to IPR in Russia had improved significantly while 46% believed it had improved slightly. (See Survey Results). I wonder what they will think after this ruling?
Read More
Posted in | No comments

Tuesday, 28 August 2007

How Far Would You Travel for $7 Million in Gold?

Posted on 06:49 by Unknown
How far would you travel for $7 million in gold bars? For Igor Klopov of Moscow, Russia, the answer was "all the way to Manhattan".

In an August 16, 2007 Press Release from the Manhattan District Attorney's office the full scheme was laid out as charges were pressed against Klopov and his four American co-conspirators.

Klopov found his inspiration as he read the Forbes 400 Richest People, determining that these would be the perfect victims. Using a combination of computer hacking, open source investigation, and actually hiring private detectives, he built profiles on his targets, but he felt safer using Americans to do his dirty work.

Using Monster.com and CareerBuilder.com, Klopov recruited Americans who would act as his agents to do the "real world" work. Klopov provided them with First Class air fare, 5-star hotels, limousine service, fake identities, and all of the false documents necessary to accomplish his frauds.

The co-defendants who were charged last week include:

Westley Watson, 37, Detroit MI
Lee Monopoli, 41, Fort Lauderdale, FL
James Dalton, 33, Konroe TX
Richard Hoskins, 29, London KY

JP Morgan Chase alerted law enforcement when they realized that James Dalton was attempting to withdraw $7 Million from the account of Charles Wyly. The Manhattan Identity Theft Task Force went into action, setting up an undercover sting.

In this operation, an undercover Secret Service agent managed to get himself "recruited" by Klopov. As proof that the transaction was completed, he arranged to have himself photographed with $7 Million in gold bars, which Klopov decided to come and handle himself.

He "snuck in" to the country on a private plane to meet the undercover officer, who arrested him at the airport in New York back in May.
Read More
Posted in | No comments

Monday, 20 August 2007

Aggrevated Identity Theft Law in Action

Posted on 06:19 by Unknown
There are so many interesting angles to the story this week about a case in Tucson, Arizona. The conviction actually went down in March 2007, with Jacob Vincent Green-Bressler, now 21 years old, being one of the 16 individuals who had been indicted in 2005 for trafficking in stolen identities. (See: Global Web Fraud Case has 17 Local Indictments in the Arizona Star, November 8, 2005.

Green-Bressler and company were not identity thieves themselves. They were not putting together phishing sites. They instead served in the role of "cashiers". A "cashier" in the Identity Theft business is someone who is willing to perform the risky role of converting the stolen identity information into an ATM Card and using that counterfeit card to drain a bank account.

During their time of activity, Jacob's gang obtained identities for 4,500 individuals from criminal conspirators in at least 20 countries, including Vietnam, Pakistan, Jordan, Egypt, the Philippines, Macedonia, Romania, Estonia, Lebanon, Mexico, France and the United Kingdom. They then used those identities to create counterfeit ATM cards which they used to steal and send overseas nearly $300,000 from various banking accounts. As their commission on these services, Jacob and friends kept $148,000 -- a 50% commission!

So what does this have to do with the Aggravated Identity Theft Law?

Jacob's original sentence would have been sixty months for his crime, but because of Title 18 section 1028A - the Aggravated Identity Theft Act, a mandatory +2 years is added to the jail time. With criminals getting so many light sentences for cyber crimes, its nice to see someone getting the Extra Two.

That's one of the reasons the Attorney General supported this act back in 2002. See this Congressional Testimony from Dan Collins, the Chief Privacy Officer of the US Department of Justice at the time. S.2541, the "Identity Theft Penalty Enforcement Act" was a good idea, and one that should be used more often in the courts.

The full list of defendants in this case:

Robbin Shea Brown, 24
Jacob Vincent Green-Bressler, 19
Joshua Trever Lee Breshears, 20
David Lee Merrill, 25
Corrine Dazette Perez, 24
Richard Daniel Staton, 24
Rollin Edward Vaughn II, 23
Randi Michelle Rodela, 20
Joseph David Wallum, 20
Joseph Robert Jando, 21
Martin Corey Halula, 19
James Dennis Olsen, 19
Steven Don Olsen, 23
Christopher James Griffin, 23
Daniel Roy Leon Mendez, 20
Robin Duane Brown, 52
Ana Marie Honeycutt, 32

(See: http://www.usdoj.gov/usao/az/press_releases/2005/2005-199(Brown%20etal).pdf )

I look forward to seeing how many of the others also get a taste of the Aggravated Identity Theft penalties!
Read More
Posted in | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • From Russia, With Love . . . new Postcard spam spies on your PC
    Isn't it nice to have friends who send you postcards? The UAB Spam Data Mine is especially fortunate in that way. Beginning the evenin...
  • Happy New Year! Here's a Virus! (New Year's Postcard malware)
    I've been busy this week looking at the various defacements (see ComputerWorld , and ABC News ) and other cyber attacks (see yesterday...
  • Tempting Photo Attachments Lead to Fake AV
    One of today's largest malicious spam campaigns continued an occasional theme we've been seeing for a few weeks. A subject line, fo...
  • Vista Security Features
    BitLocker Drive Encryption A Real-world Windows Vista BitLocker Tip BitLocker Drive Encryption BitLocker Drive Encryption Frequently Asked Q...
  • A Prominent American Express Phish
    Every once in a while we see a spam campaign where we dig in to the complexity, expecting to find malware, and find that the criminal has ju...
  • Money Laundering $1 at a time - a win for the UK's PCeU
    In London a little-known police unit called the Police Central E-Crime Unit (PCeU) has scored another big win. For several years people hav...
  • 2008: Looking back on a Year of Spam and Malware
    Happy New Year! As we get ready for the New Year, there are quite a few security folks making predictions for 2009. I think my friend Dan...
  • Most Dangerous Cities for Cyber Crime?
    Symantec Riskiest Cybercrime Cities Symantec released a study today in conjunction with Sperling's Best Places today. According to thei...
  • ACH Spammer switches to Shortened URLs
    For many weeks now the spammers behind one particular malware family have been fighting a running battle to keep their malware-hosting domai...
  • Lin Mun Poo: Hacker of the Federal Reserve and ...?
    ** UPDATE: Poo arraigned and in custody ** On October 21, 2010, Malaysian citizen Lin Mun Poo landed at the JFK airport in New York and and ...

Categories

  • Blogs
  • Calendar
  • china
  • Communities
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • Drivers
  • email
  • Excel 2007
  • facebook
  • fake av
  • Features
  • Firewall
  • Gadgets
  • gumblar
  • Hardware
  • Hotmail
  • IE7
  • Internet Explorer 7
  • koobface
  • law enforcement
  • malware
  • Microsoft
  • Outlook
  • pharmaceuticals
  • phishing
  • PowerPoint 2007
  • public policy
  • Ready Boost
  • ReadyBoost
  • Security
  • Sidebar
  • Software
  • spam
  • Tutorials
  • twitter
  • twitter malware
  • USB
  • Virtual PC
  • Vista
  • waledac
  • Wallpaper
  • Websites
  • Windows
  • Windows Live
  • Windows Vista
  • Word 2007
  • zbot

Blog Archive

  • ▼  2013 (17)
    • ▼  November (1)
      • Tempting Photo Attachments Lead to Fake AV
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (93)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (7)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ►  2008 (109)
    • ►  December (7)
    • ►  November (17)
    • ►  October (12)
    • ►  September (10)
    • ►  August (23)
    • ►  July (14)
    • ►  June (3)
    • ►  May (8)
    • ►  April (6)
    • ►  March (2)
    • ►  February (3)
    • ►  January (4)
  • ►  2007 (37)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  April (2)
    • ►  March (2)
    • ►  February (2)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile