Showing posts with label Cyber War. Show all posts
Showing posts with label Cyber War. Show all posts

Tuesday, November 12, 2013

Nerd News: TorGuard VPN with Chutzpah


Amusing and interesting article on Ars (though 4chan party van meme is used incorrectly) http://arstechnica.com/security/2013/11/how-one-site-beat-back-botnets-spammers-and-the-4chan-party-van/ about TorGuard, a VPN provider, http://torguard.net/.

Full disclosure:  I have not received any monetary or other compensation from TorGuard, though I am certainly interested in such, since I really admire their Chutzpah!

http://en.wikipedia.org/wiki/Chutzpah

Thursday, April 11, 2013

Security & Hacking: Remote Airplane Hacking

http://www.itworld.com/security/352014/vulnerabilities-aircraft-systems-allow-remote-airplane-hijacking-researcher-says

The article is based on a presentation by "Hugo Teso, a security consultant at consultancy firm N.runs in Germany, who has also had a commercial pilot license for the past 12 years..."

Teso has discovered a serious issue, and the firm he works with "N.runs has been in contact with the European Aviation Safety Agency (EASA)."

Teso says EASA is aiding the effort to test this on real aircraft, instead of simulators and some real hardware.

The EASA should be applauded for this enlightened approach IMO, many companies or even industries, take a far less productive or even antagonistic approach to White Hat discovery of vulnerabilities.




Tuesday, February 26, 2013

More Stuxnet 0.5 News

Symantec original detailed paper Stuxnet 0.5: The Missing Link [PDF] http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/stuxnet_0_5_the_missing_link.pdf

Ars article on it Revealed: Stuxnet “beta’s” devious alternate attack on Iran nuke program, http://arstechnica.com/security/2013/02/new-version-of-stuxnet-sheds-light-on-iran-targeting-cyberweapon/

Symantec's main page http://www.symantec.com/index.jsp

Lots of interesting tidbits, including fact that there are now samples dating back to at least 2005, 2 years prior to previously known oldest sample.

Monday, January 14, 2013

Security & Hacking: Red October Malware

http://arstechnica.com/security/2013/01/red-october-computer-espionage-network-may-have-stolen-terabytes-of-data/

I tweeted about this earlier today, it is still way to early to have solid grasp of the scope of this Malware IMVHO, but the Ars article does good job of giving initial idea of the size of this attack.

Lots of things about this Malware are really impressive, but this part grabbed my attention, from Ars link at top:
One novel feature contained in Red October is a module that creates an extension for Adobe Reader and Microsoft Word on compromised machines. Once installed, the module provides attackers with a "foolproof" way to regain control of a compromised machine, should the main malware payload ever be removed.
"The document may be sent to the victim via e-mail," the researchers explained. "It will not have an exploit code and will safely pass all security checks. However, like with exploit case, the document will be instantly processed by the module and the module will start a malicious application attached to the document."
This is one of the tidbits that make me think this is State sponsored, most criminals are opportunistic, in other words criminals tend to attack easy targets.

There are exceptions, certain types of Terrorist attacks and/or Ideological attacks may chose well defended targets because they are not motivated my economic profit for example.

The amount of effort this shows, for re exploiting a targeted system, after Computer Security removed original exploit, has the definite mark of Military Intelligence to me.

I suggest the Ars article linked at top.

The comments to the Ars article are well worth reading for people wanting to learn more, you can find good insights and resources in the comments section whether your new to Computer Security or an expert yourself.

You do have to screen out the noise to find the signals of course.


Original article from Kaspersky is https://www.securelist.com/en/blog/785/The_Red_October_Campaign_An_Advanced_Cyber_Espionage_Network_Targeting_Diplomatic_and_Government_Agencies

[Edited to add this from link immediately above, Rocra (short for "Red October"), is shorthand name they are using for this Malware, might be useful for additional Google searches.]

I will certainly be blogging more about Red October.

I have created new Label Red October Malware, you can bookmark that, if you want an easy way to check for updates.

I will be adding that Label to the selected labels at left side of Blog.

Labels can be found at bottom left of every blog post, and here is a suggested list of Labels for people interested in Security & Hacking:
I am still looking for ways to improve searches on my blog, so far best I have found is simply using Google with Cliff's Esport Corner in search box, plus topic your interested in like Red October, if a Label doesn't work for you.

I have tested Google's gadget for Blogger, but it wasn't as useful as regular Google for finding material on my blog the last time I tested it.








Thursday, January 3, 2013

Security & Hacking: "Emergence of state-sponsored malware and targeted attacks as major factors"

https://threatpost.com/en_us/blogs/2012-what-have-we-learned-010213

Also, one of the things I am concerned about, is that because things like Stuxnet & Flame became public, the more common criminal Hackers will certainly be able to use many of the sophisticated techniques employed by those State sponsored Cyber attacks.

Then will then package it into things like the Blackhole Exploit kit, so anyone that is willing to spend the money will be able to use those very powerful hacking tools.

It will trickle down so that eventually even Script Kiddies will have the tools they need to cause significant damage to businesses, utilities, etc.

Thursday, November 29, 2012

Security & Hacking: International Atomic Energy Agency (IAEA) Hacked

http://nakedsecurity.sophos.com/2012/11/29/atomic-energy-hack/

"The hackers claimed the security breach was in response to what the group said was Israeli aggression, including the Stuxnet worm and the assassination of a senior Iranian nuclear scientist."

The Hackers are claiming to be from Iran, but AFAIK no evidence to support that, it could be an anti Iran group pretending to be Iran in an attempt to provoke more attacks or sanctions against Iran.

Not saying that it is, but that is a factor that always needs to be remembered in situations like these.

I do wonder though if this is one of the first visible signs of fallout of Stuxnet & Flame, something I am concerned about, have blogged about those concerns before http://cliffsesportcorner.blogspot.com/2012/11/security-hacking-chevron-was-victim-of.html