Showing posts with label Krebs On Security. Show all posts
Showing posts with label Krebs On Security. Show all posts

Monday, October 6, 2014

Nerd News: "Silk Road Lawyers Poke Holes in FBI’s Story"

Brian Krebs has an interesting article up,  http://krebsonsecurity.com/2014/10/silk-road-lawyers-poke-holes-in-fbis-story/, about the trial of alleged leader of Silk Road.

Short version, government's explanation for how they found the hidden servers appears to be BS.

This seems like they are hiding real way & means that they discovered the information.

Which, though IANAL, isn't legal as I understand it, in US Trials, there is a step called "Discovery" see http://www.americanbar.org/groups/public_education/resources/law_related_education_network/how_courts_work/discovery.html & http://en.wikipedia.org/wiki/Civil_discovery_under_United_States_federal_law.

So unlike TV or Movie Courtroom drama, there isn't surprise evidence introduced in the middle of the trial.

There are several reasons why information isn't supposed to be hidden during Discovery.

Discovery reduces wasting time, Judges generally have more cases than they can get to in any given time period, so as a practical matter, parties are encouraged to settle before Court date.

It also reduces some types of false testimony & evidence, or at least makes it easier to illuminate that it is occurring.


Wednesday, June 11, 2014

Security & Hacking: Windows Patch Tuesday Reminder

In case you forgot, yesterday was patch Tuesday for Windows.

Some critical fixes in this patch, for quick details on Patch Tuesdays I always recommend Brian Krebs posts http://krebsonsecurity.com/2014/06/adobe-microsoft-push-critical-security-fixes-4/

Thursday, May 29, 2014

TrueCrypt Alternatives

Updated:  Wanted to add https://www.grc.com/misc/truecrypt/truecrypt.htm green shaded box (scroll down a little) shows correspondence from devs of Truecrypt.

TL:DR Confirms that this was just an odd way of quitting.


****

For the couple people that might have missed drama with TrueCrypt see http://krebsonsecurity.com/2014/05/true-goodbye-using-truecrypt-is-not-secure/

TL:DR Looks like people(s) behind TrueCrypt are done supporting it & suggest people use something else, additionally version released with this information only decrypts previously encrypted data, won't encrypt.

In light of this situation, many people are looking for alternatives, best list I have found so far, though I know very little about the suggestions, is http://www.ghacks.net/2014/05/29/list-truecrypt-encryption-alternatives/

Thursday, January 16, 2014

Cliff's Esport Corner SITREP

As many of you have noticed, I haven't had many posts lately.

IRL stuff, my significant other had some surgery, and needed help 24/7 for some time afterwards.

Very happy to say that everything went very well for her, and that she is recovering quickly, though not quickly enough to make her happy ^_^

Things are to the point where I can start posting regular again, though it will probably start slowly and build back up to normal pace.

I didn't get to follow CES 2014 news very closely, so I would welcome anything of interest or comment about that, either in comment section or on Twitter @CliffsEsport or link https://twitter.com/CliffsEsport

I have been following the Target Credit Card Hack with great interest though, working on blog post about it, but can strongly reccomend Brian Krebs articles on it http://krebsonsecurity.com/2014/01/a-first-look-at-the-target-intrusion-malware/

IIRC Brian was the one that broke the story originally, http://krebsonsecurity.com/2013/12/sources-target-investigating-data-breach/, I remember seeing his Tweet about his Mom being interviewed about it at Target, while my girlfriend was still in the hospital.

Thanks to all my readers!

And a special thanks to everyone who offered good wishes, support, & prayers for my girlfriend's surgery & recovery, it was greatly appreciated by both of us!

Wednesday, April 17, 2013

Update on SWATting of Brian Krebs

http://krebsonsecurity.com/2013/04/swatting-incidents-tied-to-id-theft-sites/

Brian provides more details on his specific case, but most interesting part to me, was the fact that TTY are not supposed to keep records.

I probably should have realized that before, I thought main point was it made it easier for attacker to spoof phone number/location for SWATting.


Wednesday, March 20, 2013

Security & Hacking: "Microsoft confirms compromise of “high-profile” Xbox Live accounts"

Source & full story at http://arstechnica.com/security/2013/03/hackers-that-took-over-xbox-live-accounts-may-be-behind-ddos-attack-on-ars/ :

"We are aware that a group of attackers are using several stringed social engineering techniques to compromise the accounts of a handful of high-profile Xbox LIVE accounts held by current and former Microsoft employees," Microsoft officials said in a statement sent to Ars. "We are actively working with law enforcement and other affected companies to disable this current method of attack and prevent its further use."

This ties in with Brian Kreb's recent blog post, http://krebsonsecurity.com/2013/03/the-obscurest-epoch-is-today/ were he details what he has learned so far about person(s) that SWATted him.

Oddly those people appear to have been involved in the hack or social engineering attack against Mat Honan, which Honan wrote about http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard and a later more polished article (link is good, but you may need to refresh sometimes to get it to work) http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-honan-hacking/all/.

To see all my posts about the Mat Honan Hack click this Mat Honan Label, additional Labels can be found at bottom left of every post, and in Label Cloud at left side of Blog.

Friday, February 15, 2013

Security & Hacking: "Exploit Sat on LA Times Website for 6 Weeks"

Makes me laugh & cry http://krebsonsecurity.com/2013/02/exploit-sat-on-la-times-website-for-6-weeks/

Snippet:
The Los Angeles Times has scrubbed its Web site of malicious code that served browser exploits and malware to potentially hundreds of thousands of readers over the past six weeks.


Saturday, February 2, 2013

Hardware Hacking: "Pro-Grade Point-of-Sale Skimmer"

http://krebsonsecurity.com/2013/02/pro-grade-point-of-sale-skimmer/

I wonder if this is actually how Barnes & Noble was hacked? 

http://cliffsesportcorner.blogspot.com/2012/10/security-hacking-thieves-rig-barnes.html

And for whatever reasons they don't want to disclose the connection?

Comments on Brian Krebs post are well worth reading as well, I learned BT is legit for POS (Point of Sale) devices transmitting Credit Card data as long as it is encrypted.

Link (PDF) https://www.pcisecuritystandards.org/pdfs/PCI_DSS_Wireless_Guideline_with_WiFi_and_Bluetooth_082211.pdf

Really well done work, wish I could solder as well as whoever did that!




Sunday, January 20, 2013

Security & Hacking: Java exploit Number ∞

http://nakedsecurity.sophos.com/2013/01/20/java-hacker-boasts-of-finding-two-more-unpatched-holes/

http://krebsonsecurity.com/2013/01/new-java-exploit-fetches-5000-per-buyer/

Seems like you can find new/more Java exploits a lot faster than they can be patched, so if your concerned about security, stop using Java on Browsers!

Course, if you want to make sure Blackhat Hackers don't starve, keep using it, </sarcasm>

Friday, January 18, 2013

PSA Security & Hacking: Shylock Banking Trojan now spreading via Skype

Primary source https://www.csis.dk/en/csis/blog/3811

As someone that is computer security conscious, I avoid online banking completely.

For friends, family, & others that insist on online banking I suggest either of the following:

  • Use a Live CD, Brian Kreb has excellent articales on how to do this http://krebsonsecurity.com/2012/07/banking-on-a-live-cd/ or http://krebsonsecurity.com/banking-on-a-live-cd/
  • Use a recent iOS device, iPhone 4S or newer, iPad 2 or newer, iPod Touch 5th generation or newer.  There are significant hardware security improvements that started with those respective devices. 
I also strongly suggest if using the iOS devices, to turn off Simple Passcode, and use a Pass Phrase, even if you don't lock your iOS device all the time, this will enable whole device encryption.

Clear instructions & screenshot for turning off Simple Passcode http://www.computerworld.com/s/article/9231627/Kenneth_van_Wyk_Shutting_down_security_gotchas_in_iOS_6?taxonomyId=17&pageNumber=1

The reason for this, is that a hacker with right software, can use a computer to try passwords, they can also bypass the 10 try feature.

So if your using the Simple Passcode, which is just a 4 digit number, they will probably be able to hack it in less than an hour.

However, if you use a Pass Phrase, like I <3 my iPad.  I hate green beans! the hacker will have a much more difficult time.  [Note, don't use that pass phrase, it is just to illustrate the concept.]

Since instead of only 4 numbers, there are 34 characters, counting the blank spaces, plus your using uppercase letters , lowercase letters, numbers, special characters, and blank spaces.

The hacker won't have any idea how long your password is, and by using at least one of all possible upper/lower case, numbers, symbols, and blank spaces you make hackers job a lot harder.

For more on passwords see http://cliffsesportcorner.blogspot.com/2012/05/steve-gibsons-haystacks-needles.html

Additional links:


Security & Hacking: Malware 2 Years ago USB Battery Charger Backdoor

Energizer Battery Charger Software Included Backdoor http://krebsonsecurity.com/2010/03/energizer-battery-charger-software-included-backdoor/

Energizer DUO USB battery charger software allows unauthorized remote system access http://www.kb.cert.org/vuls/id/154421

This is from 2010, so certainly not new concept, I hadn't heard of this specific hack before though, & to be honest, don't think I would have expected this, before reading Brian Kreb's article on it.

Though I was aware of the Vodafone issue that some of the Energizer Duo articles/comments mentioned http://research.pandasecurity.com/vodafone-distributes-mariposa/

To be clear, there wasn't Malware on the USB device itself, but in the software you could download from Energizer to monitor the device.

I didn't find any articles explaining how the Malware got inserted into the Energizer software, but some stories suggested it might have been in place for ~3 years.

If anyone has any more detail on this I would be interested in learning it.

Schneier also posted about it http://www.schneier.com/blog/archives/2010/03/back_door_in_ba.html


Wednesday, November 7, 2012

Security & Hacking: "Cyberheists ‘A Helluva Wake-up Call’ to Small Biz"

http://krebsonsecurity.com/2012/11/cyberheists-a-helluva-wake-up-call-to-small-biz/

And they say crime doesn't pay,
"The St. Louis, Missouri-based firm first learned that things weren’t quite right on Wednesday, May 30, 2012, when the company’s payroll manager logged into her account at the local bank and discovered that an oversized payroll batch for approximately $180,000 had been sent through late Tuesday evening."


I don't know about you, but $180,000 sounds like good pay to me.

Security & Hacking: Flash update Nov 6, 2012


Another Flash update http://krebsonsecurity.com/2012/11/adobe-ships-election-day-security-update-for-flash/

Wednesday, October 24, 2012

Security & Hacking: "Thieves rig Barnes & Noble PIN pads to steal credit card data"

http://nakedsecurity.sophos.com/2012/10/24/barnes-noble-pin-pad-credit-card/

Not clear yet if this attack used Skimmers or Hacking.

Note that the FBI asked Barnes and Noble to sit on this for a month, so actual attack happen a while ago, and not clear yet how long it had been active.

Days?  Weeks?  Months?  Years?

I suspect Skimmer's of some type myself in this attack, but could have been software hack or something else.

For more on Skimmers see Krebs article "Would you have Spotted this ATM Fraud?" for even more you can see Brian Krebs entire series on Skimmers at his "All about Skimmers" were he has collected all his articles in one spot, with short intro to each article and link to full individual story.

Friday, October 19, 2012

" Fake AV Vendors Feel Credit Card Crunch"

Another really excellent article from Brian Krebs http://krebsonsecurity.com/2012/10/rogue-pharma-fake-av-vendors-feel-credit-card-crunch/

Not sure how to accurately summarize this article, but he opens with:
"New research suggests that companies behind some of America’s best known consumer brands may be far more effective at fighting cybercrime than any efforts to enact more stringent computer security and anti-piracy laws."
He then mentions that things like SOPA have been pushed by legislators, but that the data suggests brand holders already handle things very well.


Tuesday, October 16, 2012

Security & Hacking: " Scrap Value of a Hacked PC"

http://krebsonsecurity.com/2012/10/the-scrap-value-of-a-hacked-pc-revisited/

EXCELLENT Article with clear picture showing what Hackers gain from hacking a computer, even a simple one just used for web surfing and email!

Brian Kreb's security blog is one of my favorite!

Think this article illustrates why, lot of computer people understand computer security, but I know as a writer just how hard it can be to communicate concepts at times.

This illustration is brilliant!

It really is an outline in visual form:
  1. Web Server
  2. E Mail Attacks
  3. Virtual Goods
  4. Reputation Hijacking
  5. Bot Activity
  6. Account Credentials
  7. Financial Credentials
  8. Hostage Attacks
Followed by simple details so non computer security geeks will understand that "Reputation Hijacking" means they take control of your Facebook/Twitter/etc.

Learned about a new Bot myself today from this artical, the CAPTCHA Solving Zombie, Krebs' answered question about that in the comments with this link http://www.inwyrd.com/blog/2010/03/hijacking-koobfaces-captcha-solver/