Friday, May 30, 2008
Quote of the day
New IT Term of the day
New IT Term of the day
password
A secret series of characters that enables a user to access a file, computer, or program. On multi-user systems, each user must enter his or her password before the computer will respond to commands. The password helps ensure that unauthorized users do not access the computer. In addition, data files and programs may require a password.
Ideally, the password should be something that nobody could guess. In practice, most people choose a password that is easy to remember, such as their name or their initials. This is one reason it is relatively easy to break into most computer systems.
Russian nuclear power websites attacked amid accident rumors
23/ 05/ 2008
http://en.rian.ru/russia/20080523/108202288.html
MOSCOW, May 23 (RIA Novosti) - Hackers attacked Russian nuclear power websites that allow users to check radiation background amid false rumors of a nuclear accident in northwest Russia, a nuclear industry official said on Friday.
On Tuesday and Wednesday, several Internet forums carried reports of radioactive emissions from the Leningrad Nuclear Power Plant near St. Petersburg, and of a planned evacuation of local residents.
A spokesman for the Rosatom state nuclear corporation said the cyber attacks had been planned and coincided with the release of the reports.
"People who stand to lose out from the Russian nuclear power industry's development have an incentive to spread false rumors of an accident at the nuclear plant," he said.
"This was a planned action by hackers, which has brought down almost all sites providing access to the Automatic Radiation Environment Control System (ASKRO), including the Leningrad NPP site, the rosatom.ru site, and others. For several hours users were unable to reach the sites and obtain reliable information on the situation at the plant."
ASKRO is part of a permanent environment and sanitary control system, one of whose functions is to inform the population on radiation security. Access to the system is open to all visitors on a number of Russian nuclear industry websites. The system works in real-time.
Access to ASKRO data has now been fully restored, the spokesman said.
He said this was not the first incident of its kind in Russia. Last year, after similar false reports of an accident at the Volgodonsk nuclear plant, several dozen people, believing they could offset radiation damage by consuming large amounts of iodine, fell ill after poisoning themselves.
Banks not reporting cybercrime to protect image : Police
The Canadian press
28 May 2008
http://canadianpress.google.com/article/ALeqM5jr3niVbLuNtqPL5mrNxhvqw8naRA
MONTREAL — Online banking and other Internet transactions may not be as secure as many Canadians believe, say law-enforcement officials who accuse financial institutions of under-reporting cybercrime.
Fraud investigators say they are worried publicity-shy private-sector organizations like banks avoid telling police when cybercriminals strike.
"Banks are often victims and we know that they only declare very few of the crimes committed against them," said Yves Francoeur, who heads the Montreal police brotherhood.
The RCMP's anti-fraud centre has tried to push the financial sector to be more up front with authorities.
But they claim the major players in the industry fear their reputations will be tarnished by having embarrassing cases such as identity theft exposed in public.
"It's all about image," said Cpl. Louis Robertson. "It's not in their best interests to do this."
The Mounties believe the $35 million of mass-market fraud reported in 2007 represents at most 10 per cent of all incidents.
"If we extrapolate, we are looking at, minimum, $500 million a year," Robertson said, noting the figure does not include losses stemming from identity theft.
"It's really hard to give a definite picture of the problem to our MPs and the powers in Ottawa when you don't even have a clear picture yourself."
Criminals make use of phishing e-mails and other forms of social engineering technology to steal personal information, which can in turn be used to defraud retailers and financial institutions.
Social engineering fraudsters work from the belief that its easier to trick someone into giving up information than to steal it from them.
Phishing, for example, fools consumers into providing sensitive information by making an e-mail seem to come from a bank or credit card company.
The Canadian Bankers Association denies its members have been reticent to reports such incidents to police.
"We have to all work together to fight a lot of this crime," said association spokeswoman Maura Drew-Lytle. "Banks co-operate with police across the country."
Yet the problem of under-reporting cybercrime is considered serious enough that the Canadian Association of Police Boards has approached the bankers association about developing an anonymous reporting mechanism.
"Even companies that aren't reporting said we need a confidential mechanism to report," said Canadian Association of Police Boards president Ian Wilms.
"What they told us is that reputational risk is their biggest concern."
A recent report on cybercrime by the association of police boards cited the need for mandatory reporting of economic cyber-security incidents.
Without an accurate handle on the extent to which financial institutions are victimized, few police forces are willing to dedicate the resources needed to fight financial forms of cybercrime.
Of the 62,000 police officers in Canada, only about 250 are tasked with cybercrime, usually with a focus on child pornography.
"We have priorities and if we look at the order of these priorities, financial institutions are at the bottom," said Christian Emond, an officer with the Montreal police's economic crimes unit.
Street gangs, organized crime and terrorism top the force's list of eight priorities.
"When you get the eighth spot, the resources accorded are going to be limited," Emond said.
And yet there are several indications that electronic forms of bank fraud and identity theft are getting worse.
Interac, which links bank machines and debit terminals across Canada, pegged 2007 losses from debit card skimming at $106.8 million, up from $94.6 million a year earlier and $44 million in 2003.
"Certainly the losses are increasing, but so are our efforts to fight it," Drew-Lytle said.
Most consumers have been shielded from the effects of increased cybercrime thanks to client-friendly policies at many banks. The $106.8 million taken from debit-card users last year was all reimbursed.
But some wonder how much longer financial institutions will be able to absorb these costs given rapidly rising rates of cybercriminality.
"Those industries that have been hit are sucking up their losses as the cost of doing business," Wilms said.
"As this grows, perhaps you'll see a behavioural change, and you'll be responsible for your own account."
Hacker takes $50,000 a few cents at a time
28th May 2008
http://www.pcpro.co.uk/news/201252/hacker-takes-50000-a-few-cents-at-a-time.html
A hacker has used a loophole to collect more than $50,000 from Google Checkout and online brokerage firms, a few cents at a time.
When opening an online brokering account it is common practice for companies such as E-trade and Schwab to send a tiny payment - ranging from only a few cents to a couple of dollars - to verify that the user has access to the bank account listed. Services such as Google Checkout and Paypal use a similar tactic to verify credit and debit cards linked to accounts.
According to court documents, Californian Michael Largent used an automated script to open 58,000 such accounts, collecting many thousands of these small payments into a few personal bank accounts.
Largent also performed the same trick with Google's Checkout service, cashing more than $8,000 alone from the service.
He is currently free on bail pending a court judgement on charges of wire, bank and mail fraud
for his antics with the online brokerage sites, although his similar approach to getting cash out of Google has not been pursued by police as of this time.
When his bank contacted him about the thousands of small payments, Largent explained that he had read the terms of service of the sites he was targeting, and believed he was doing nothing wrong, claiming that he needed the money to pay off debts.
However, Largent used false names, including cartoon characters, as well as false addresses and social security numbers, which opened him to conviction under laws on mail, bank and wire fraud.
Co-operation and Education is Key
by Geok Meng Ong
May 28, 2008
I was at the APWG CeCOS II conference in Akasaka, Tokyo, Japan the last two days. It was encouraging to see many members from not only academics, security vendors, and anti-phishing groups but also many law enforcement agencies including Interpol, Kyoto Prefacture Police amongst others. There were also several presentators from the Online Gaming community.
Having such a diverse turn-out certainly helps push the greater awareness of a multinude of cyber crime issues. It was very encouraging to see everyone are agreeing on better co-operation in shutting down rogue sites, tracking the bad guys and protecting the users. There was also the video crew from NHK, to bring the CeCOS message across to Japanese TV viewers.
Dr. Uchida-san from The Institute of Information Security and Steve Sheng from Carnegie Mellon University (CMU) also presented a different angle of the issue, from the psychological and educational aspects. Both of which compliment the policy and technology countermeasures.
Shinsuke Honjo and I gave a presentation on Monday to highlight on how malware authors are now going all out to attack on victims from all cultures. They can craft spam, phishing sites or malware to target diverse cultures and groups of Internet users in the Asia Pacific region. It was interesting for us to have our research corroborated with data from other speakers at the event. Terence Park, researcher from KrCERT/CC, in particularly demonstrated how a Korean document viewer was used as a bait, to install a password stealer. This was another classic example of how malware authors, can be using different localized techniques to get their victims.
Overall, the message that seems to be very consistent throughout are - co-operation and education. In tackling a global issue like cyber crime, these are both important factors not only in tracking and prosecuting the criminals, but also in better protecting Internet businesses and users.
Editor’s comments -
CeCOS II was a well organized summit. The organizing team especially Peter Cassidy, Foy Shiver and Kana deserve big applause from all speakers and participants.
This Day in History
Thanks for your Visit
