WISH YOU A HAPPY AND SECURE YEAR 2009

Sunday, August 9, 2009

Quote of the day

Quote of the day

Our real enemies are the people who make us feel so good that we are slowly, but inexorably, pulled down into the quicksand of smugness and self-satisfaction.

Sydney Harris

New IT Term of the day

New IT Term of the day


darknet


Short for dark Internet, in file sharing terminology, a darknet is a Internet or private network, where information and content are shared by darknet participants anonymously. Darknets are popular with users who share copy protected files as the service will let users send and receive files anonymously — that is, users cannot be traced, tracked or personally identified. Usually, darknets are not easily accessible via regular Web browsers.

ATTACK : Attackers Took Shots at Wi-Fi Network at Black Hat

ATTACK : Attackers Took Shots at Wi-Fi Network at Black Hat

by Brian Prince

August 4, 2009

It should come as no surprise that at a security conference called 'Black Hat' there would be a fair amount of shenanigans going on over the WLAN network.

According to Aruba Networks, which provided the Wi-Fi network at the conference last month in Las Vegas, attackers were up to their usual tricks. The company tracked and analyzed all attempted attacks throughout the event.

Here is what they found:

BLACKHAT 2009 STATS:

Security stats:

  • 9 suspected rogue access points were detected.
  • 175 attempts by a wireless user to access the Aruba mobility controller were blocked by the Aruba firewall.
  • 23 impersonation attacks were detected.
  • 71 non-Blackhat access points were detected.
  • 154 denial-of-service attacks were detected.

In some ways, the numbers were an improvement from 2008; in some ways not. For example, fewer rogue access points were detected this year. On the other hand, there were 130 more denial-of-service attacks detected in 2009. Check out these numbers:

BLACKHAT 2008 STATS:

Security stats:

  • Each day there were between 10-15 rogue APs detected (rogue defined as an AP that was advertising the conference SSID of "BlackHat").
  • 49 users attempted to connect to rogue APs and were blocked by RFprotect, which generated 709 shielding actions
  • 362 attempts by a wireless user to access the Aruba mobility controller were blocked by the Aruba firewall.
  • 221 attempts by a wireless user to ARP poison the default gateway were blocked by the Aruba firewall.
  • 140 port scans (nmap or similar) from wireless users to other wireless users were detected and blocked by the Aruba firewall.
  • 57 non-Blackhat APs were detected
  • 24 denial of service attacks were detected. The average duration of each attack was 24 seconds.

The stats are a reminder that whether you are at a security conference or at a local Starbucks, it is best to keep your guard up.

CHINA : Hacker Schools Become Big Business

CHINA : Hacker Schools Become Big Business

By Matthew Harwood

08/05/2009

http://www.securitymanagement.com/news/china-hacker-schools-become-big-business-006017

Long known as a prominent source of cyberattacks worldwide, China has seen the emergence of online training schools that teach students the skills necessary to either be a network defender or a cybercriminal.

These "hacker schools," as they're known, are also big business, generating $34.8 million last year, reports China Daily.

Students can enroll in online classes for as little as a few hundred yuan.

While some schools advertise themselves as training the next generation of security experts, many worry a percentage of the students will use their skills to commit various cybercrimes, such as identity theft or stealing trade secrets.

Wang Xianbing—a security consultant for a prominent online hacking school, Hackbase.com—likens the training provided by the Web site to that of the locksmith trade.

"It's like teaching lock picking," he told Beijing Today. "No one can guarantee the student will become a professional locksmith rather than a future thief."

Rather it's up to the individual and his conscience whether to use his knowledge for good or evil, Wang said. Interviewed by China Daily, he said that the company's students are explicitly told not to use their knowledge for illegal activities.

"Lots of hacker schools only teach students how to hack into unprotected computers and steal personal information," said Wang. "They then make a profit by selling users' information."

Imparting such knowledge, even with caveats, runs obvious risks. Last year alone, according to China Daily, hacking cost the Chinese economy approximately $1 billion. Globally, Symantec estimates cybercrime cost firms a total of $1 trillion in 2008, reported CNet.com in January.

But money isn't the only motivation, reports China Daily.

A 25-year-old hacker school student from Shanghai surnamed Wang, said most of his "classmates" simply enroll in hacker school for personal reasons, such as spying on relatives, showing off their computer-savvy skills or taking revenge on a rival's Websites, rather than making money.

Wang described the Catch-22 of teaching a new generation of security experts the tools of the trade: "They have to learn how to attack a Web site before they can learn how to defend it."

Also see -

http://www.radioaustralianews.net.au/stories/200908/2647252.htm?desktop

CONTROL : Malaysia considering internet filter

CONTROL : Malaysia considering internet filter

Reuters

06 August 2009

http://mt.m2day.org/2008/content/view/25355/84/

MALAYSIA is considering the establishment of an Internet filter, similar to China's abandoned 'Green Dam' project, a source familiar with the process told Reuters on Thursday.

News of the proposal emerged within days of police arresting nearly 600 opposition supporters at a weekend rally denouncing a government that has ruled this Southeast Asian country for 51 years.

A vibrant Internet culture has contributed to political challenges facing the government, which tightly controls mainstream media and has used sedition laws and imprisonment without trial to prosecute a blogger.

'They (the government) are looking to tweak the technical and legal details of implementing this Internet filter, setting the stage for its implementation late this year or next year,' said the source, who declined to be identified.

No one from the government was available for comment.

Malaysia plans to double home Internet penetration to 50 per cent by the end of next year with a new broadband project.

New Information, Communication and Culture Minister Rais Yatim, whose ministry issued the tender, also plans to secure control over the content and monitoring division of Malaysia's Internet regulator, a second source said.

'The minister wants to focus more on enforcement in the coming year,' the source said.

Malaysia, with a population of 27 million, attracted foreign technology companies such as Microsoft Corp and Cisco Systems to invest and guaranteed that the government would not impose controls on the Internet.

Ms Rais said last month that wider broadband access required more regulation.

'With the good comes the bad through the broadband over the Internet,' he said. 'We will introduce certain measures to overcome the bad.'

THREAT : Cyber security threat to India is real

THREAT : Cyber security threat to India is real

Vicky Nanjappa

Rediff.com

August 05, 2009

http://news.rediff.com/special/2009/aug/05/cyber-security-threat-to-india-is-real.htm

The demand for better methods to enforce cyber security has grown stronger since the November 26 attacks in Mumbai

India has a dedicated organisation, CERT-In -- which operates under the auspices of the department of communication and information technology -- to tackle cyber crimes. However, the agency is not a prosecuting body.

An officer at CERT-In told rediff.com over the telephone from New Delhi that although the agency does not have the legal power to examine cyber crimes, it can probe cases referred to the organisation.

CERT-In, which covers both government and military areas, says the threats relating to cyber security are on the rise. Common targets include critical infrastructure like telecommunication, transportation, energy and finance.

The attackers are not confined to information infrastructures and geographical boundaries. They exploit network interconnections and navigate easily through the infrastructure. More worryingly, these cyber criminals are becoming more skilled at masking their behaviour.

CERT-In consists a group of professionals headed by a director who investigate cases referred to the agency. It submits a report to the police station that has sought the agency's help following which a chargesheet is filed.

Why not a single agency?

Senior police officers say it is difficult to have a single agency looking at such cases.

If a crime is committed in a particular state, it is easier for police officers of that state to probe the case. At present, one police officer adds, no one person has complete charge of cyber security.

Although the Union government drafts all cyber laws and CERT-In assists in investigations, the final call can be taken by the cyber crime wings based in the states.

The only other national agency which can probe cyber crime cases is the Central Bureau of Investigation.

The prosecuting agency

The ministry for communication and information technology governs the system pertaining to cyber security. While the ministry is largely involved in drafting laws, the actual job on the ground is handled by the cyber-crime wings in the states.

The law is clear that a complaint pertaining to a cyber crime or threat can be assigned only to the jurisdictional cyber crime wing in each state. An inspector general of police heads each cyber crime wing; a superintendent of police, inspectors and sub inspectors report to her/him. Only this department can file a chargesheet and prosecute individuals involved in cyber criminal activity.

The inspector general of police reports to the state police chief.

An officer in the Karnataka cyber crime wing said it is often difficult to crack a case as the cell does not have enough IT professionals. In such cases, CERT-In's assistance is sought.

Experts feel the process of investigating a cyber crime is cumbersome under the present set-up. It is difficult to have a national level agency which takes a final call since Indian law clearly states that cases will be probed on a jurisdictional basis for all practical purposes.

R Srikumar, a former Karnataka police chief and chairman of the Cyber Society of India (Karnataka chapter), says that trained personnel could be inducted into cyber crime cells so that the procedure of referring the matter to another agency and then waiting for a report to proceed with the prosecution can be avoided.

Professor Chandrashekar, a forensics expert and a member of the CSI, believes dedicated teams of IT professionals should be appointed by respective state governments to work with the cyber crime wings.

Former CBI Director R Raghavan launched the first cyber society in Tamil Nadu. Professor Chandrashekar explains that the society's role is to train professionals in cracking cyber crimes.

He says the society will sign a Memorandum of Understanding with the National Law School, Bengaluru, to introduce a course in cyber security. The course will issue a certificate to certified cyber crime investigators.

Cyber crime wings in the states could then employ such certified investigators.

Although private security agencies investigate cyber crimes, the Union government has not made full use of their services as is the case in some countries.

Sources say the government may seek the skills of private agencies in select cases, but would prefer to improve official cyber crime wings since such cases often involve national security.

Sunday, July 26, 2009

Quote for the Day

Quote of the day

Happiness must be cultivated. It is like character. It is not a thing to be safely let alone for a moment, or it will run to weeds.

Elizabeth Stuart Phelps

(1844-1911, Writer)

New IT Term of the day

New IT Term of the day


microblog


A type of blog that lets users publish short text updates. Bloggers can usually use a number of service for the updates including instant messaging, e-mail, or Twitter. The posts are called microposts, while the act of using these services to update your blog is called microblogging. Social networking sites, like Facebook, also use a microblogging feature in profiles. On Facebook this is called "Status Updates".

BEWARE : Repair Shops Hack Your Laptops

BEWARE : Repair Shops Hack Your Laptops

July 22, 2009

Mark White, home affairs correspondent

http://news.sky.com/skynews/Home/UK-News/Sky-News-Undercover-Laptop-Investigation-Repair-Shops-Caught-Hacking-Into-Personal-Files/Article/200907315343387?lpos=UK_News_Top_Stories_Header_0&lid=ARTICLE_15343387_Sky_News_Undercover_Laptop_Investigation%3A_R

Some computer repair shops are illegally accessing personal data on customers' hard drives - and even trying to hack their bank accounts, a Sky News investigation has found.

In one case, passwords, log-in details and holiday photographs were all copied onto a portable memory stick by a technician.

In other shops, customers were charged for non-existent work and simple faults were misdiagnosed.

An investigator from the Trading Standards Institute said he was "shocked" by the findings.

The investigation was carried out using surveillance software loaded onto a brand-new laptop.

It operated without the user being aware that every event that took place on the computer was being logged.

All activity on the screen was captured in still images, and the identity of whoever was using the computer was recorded using the laptop's built-in camera.

Sky engineers then created a simple, easily diagnosable fault, by loosening the connection of the internal memory chip.

This prevented Windows being able to load. To get things working again, the chip would simply need to be pushed back into position.

The investigation targeted six different computer repair shops. All but one misdiagnosed or overcharged for the fault.

The most serious offender was Revival Computers in Hammersmith, West London.

Shortly after identifying the real fault, an engineer called our undercover reporter to say the computer needed a new motherboard, which would cost £130.

Tests carried out by our internal Sky engineer after the diagnosis revealed there was nothing wrong with it.

The surveillance software then recorded one technician browsing through the files on the hard-drive, including private documents and intimate holiday photos, including some of our researcher in her bikini.

As he snooped through the files, he is seen smiling and showing the pictures to another colleague.

Later on in the same shop, a second technician loads up the machine and also looks through the photos, which are inside a folder clearly marked 'private'.

He then plugs his own portable memory stick into the laptop and copies files, including passwords and photos, into a folder labelled "mamma jammas".

Inside one of the documents copied to the memory stick was a text file containing passwords for Facebook, Hotmail, eBay and a NatWest bank account.

Once the technician had discovered this information, he opened a web browser on the laptop and attempted to log into the back account for around five minutes.

The only reason he was unsuccessful was because the details were fake.

When confronted over the findings, staff at Laptop Revival said they did not want to respond to Sky News on camera.

However in a telephone conversation, they denied all knowledge of the alleged abuses.

When shown the findings, Richard Webb, an e-commerce investigator for Trading Standards said: "I'm really quite shocked, both in the range of potential problems this has revealed - people overcharging, mis-describing the faults - but also people attempting to steal personal details.

"It's a big abuse of trust. If you were expert in computers you wouldn't have to hand in your machine to be repaired. They know that.

"They know you won't be able to tell what they've done afterwards, they know you're putting your trust in them and unfortunately, as we're seeing, there are too many people willing to abuse that trust.

"What you've shown is that there is a much wider problem in the industry than we knew about.

"It suggests we need to look at the area again and we do need to test it like you have done, but with a view of taking criminal enforcement action if these problems are found and evidenced."

SPY : Did Etisalat Spied BlackBerry Customers?

SPY : Did Etisalat Spied BlackBerry Customers?

BlackBerry customers revolt after spyware scandal

If your customers think that you tried to spy on them, that's not going to be good for business.

23 July 2009

http://www.sophos.com/blogs/gc/g/2009/07/23/blackberry-customers-revolt-after-spyware-scandal/

That's the message that's presumably being heard loud-and-clear by telecoms company Etisalat, which has found itself in the middle of a storm of negative headlines after it was revealed that an update it sent to BlackBerry users in the United Arab Emirates, which claimed to improve performance of the mobile device, was actually spying on them.

RIM, makers of the Blackberry smartphone beloved by businesspeople around the world, say that the spyware update sent out by Etisalat actually worsened battery life and reception, and (most worryingly) was designed to "to send received messages back to a central server."

Potentially, the patch gave Etisalat the ability to read any emails and text messages sent from their customers' BlackBerry devices.

Now, an online survey conducted by the Arabian Business website reveals that more than 50% of Etisalat's BlackBerry customers are planning to ditch the UAE telecoms provider in the wake of the spyware. It's hard not to feel sympathetic with those aggrieved customers. After all, as Erin Andrews just demonstrated, no-one likes to be watched without their knowledge.

Curiously, the offending patch appears to have been written by a US-based company called SS8, who develop electronic surveillance solutions for intelligence agencies.

Quite why Etisalat may have wanted to distribute a spyware update to monitor its customers is still unclear. So far they have declined to comment on the claims of spyware, restricting their public comment on the matter to the following statement:

Etisalat today confirmed that a conflict in the settings in some BlackBerry devices has led to a slight technical fault while upgrading the software of these devices.

This has resulted in reduced battery life in a very limited number of devices. Etisalat has received approximately 300 complaints to date, out of its total customer base which exceeds 145,000.

These upgrades were required for service enhancements particularly for issues identified related to the handover between 2G to 3G network coverage areas.

Customers who have been affected are advised to call 101 where they will be given instructions on how to restore their handset to its original state. This will resolve the issue completely.

RIM has published an update which removes the application from affected BlackBerry smartphones.

PREDATOR : Indian “Internet predator” held in U.S.

PREDATOR : Indian “Internet predator” held in U.S.

PTI

24 July 2009

http://www.hindu.com/2009/07/24/stories/2009072455341300.htm

Washington: In possibly the first such case involving an Indian in the U.S., police in Pennsylvania have arrested an Indian engineer on charges of using Internet for soliciting young girls for sex.

In a statement, the Pennsylvania Attorney General Tom Corbett said Nityanand Gopalika (30), here on a work visa, allegedly used an Internet chat room to approach what he believed was a 13-year old girl from the Pittsburgh area.

The “girl” was actually an undercover agent from the Child Predator Unit. According to the criminal complaint filed by the Attorney General’s Child Predator Unit, Gopalika engaged in a series of chats over several days questioning the girl about her sexual experience and describing the sex acts he wished to engage in. Gopalika is also accused of sending the girl two obscene web cam videos.

Gopalika was arrested on July 1 when he arrived at a predetermined meeting location.

Following a search of his vehicle, agents seized two laptop computers, a digital camera, a cell phone allegedly containing a partially completed text message to the “child,” directions to the meeting location and a bag of condoms. Gopalika was preliminarily arraigned on July 1 and lodged in the Butler County Jail in lieu of $15,000 cash bail, pending a preliminary hearing on Friday.

FINED : HSBC companies slapped with US$5M fines over data breach

FINED : HSBC companies slapped with US$5M fines over data breach

By Jo Best,

ZDNet Asia

July 23, 2009

http://www.zdnetasia.com/news/business/0,39044229,62056295,00.htm

Three HSBC companies have been hit with fines after the financial services watchdog found they weren't doing enough to protect customers' data.

The U.K. Financial Services Authority (FSA) fined HSBC Life 1.6 million pounds (US$2.6 million), HSBC Actuaries 875,000 pounds (US$1.4 million) and HSBC Insurance Brokers 700,000 pounds (US$1.1 million)--making a total of 3.1 million pounds (US$5.1 million) in penalties between them.

Due to the fact the three firms settled with the FSA, their fines were discounted by 30 percent--the original charges totaled 4.55 million pounds (US$7.47 million).

The FSA handed down the fines after an investigation found customer data was sent without encryption to third parties and via couriers, and left in unlocked cabinets and shelves openly.

Staff were also not given proper training over how to spot and deal with risks like identity theft, the FSA found.

Clive Bannister, group managing director of HSBC Insurance, said the company regrets falling short in dealing with customers' data.

"While this is a serious matter, no customer reported any loss from these failures. We are doing everything possible to prevent a recurrence. We have implemented even more rigorous systems, better checks and more training for our people. We believe our customers can have confidence that we are doing everything we can to protect their privacy," he said in a statement.

Two of the HSBC companies recorded losses of data: in 2007, HSBC Actuaries lost an unencrypted floppy disk in the post, containing the details of 1,917 pension scheme members, including addresses, dates of birth and national insurance numbers; while 2008 saw HSBC Life lose an unencrypted CD containing the details of 180,000 policy holders in the post. Those affected have been alerted to the losses by the companies.

Margaret Cole, director of enforcement at the FSA, described the losses as "disappointing".

"All three firms failed their customers by being careless with personal details which could have ended up in the hands of criminals. It is also worrying that increasing awareness around the importance of keeping personal information safe and the dangers of fraud did not prompt the firms to do more to protect their customers' details," she said in a statement.

The three companies have now improved staff training and use encryption when data is being moved.

Friday, July 24, 2009

Quote of the day

Quote of the day

You can have anything you want -- if you want it badly enough.

You can be anything you want to be, have anything you desire, accomplish anything you set out to accomplish -- if you will hold to that desire with singleness of purpose.

Robert Collier

(Publisher)

New IT Term of the day

New IT Term of the day


chicken boner


A slang term used in reference to an inexperienced spammer. The reference implies that the person is a low-life who spends all their time in front of the computer with "fried chicken bones littering the floor".

FINED : UK Consultant Handed £5,000 Fine Over Database Breach

FINED : UK Consultant Handed £5,000 Fine Over Database Breach

by Desire Athow

21 July, 2009,

http://www.itproportal.com/portal/news/article/2009/7/21/consultant-handed-5000-fine-over-database-breach/

A man behind an illicit database containing details of construction workers has been slapped with a fine of £5,000 for infringing the UK Data Protection Act at Knutsford Crown Court and required to pay a further £1,187.20 in costs.

Last week, Ian Kerr, the founder of The Consultancy Association (TCA) which illicitly held and sold confidential information of employees, has been found guilty of data breaches and eventually ordered to pay considerable fines.

Kerr was sentenced by the Court following an investigation by the Information Commissioner’s Office, which disclosed that he conducted a secret operation to vet construction workers for job in the industry.

David Smith, Deputy Information Commissioner, commented on the case by saying, “Ian Kerr colluded with construction firms for many years flouting the Data Protection Act and ignoring people's privacy rights. Trading people's personal details in this way is unlawful and we are determined to stamp out this type of activity.”

It was ascertained by the Court that the database created by TCA held information on as many as 3,213 construction workers and was utilised by around 40 construction companies.

The information watchdog is said to take enforcement action against 17 construction companies that paid Kerr for information on workers, in the wake of any representations made by the firms.

JAILED : Two years in jail for IT director who wiped medical data

JAILED : Two years in jail for IT director who wiped medical data

Ex-employee deleted crucial organ donation records

By Jaikumar Vijayan

www.computerworlduk.com

21 July 2009

http://www.computerworlduk.com/management/security/data-control/news/index.cfm?RSS&NewsId=15841

An IT director at an organ donation organisation has been sentenced to two years in prison for intentionally deleting numerous records and other data after being fired from her job.

Danielle Duann, 51, who worked at an organ procurement centre for more than 200 hospitals in Texas, was also sentenced to three years of supervised release upon completion of her term and ordered to pay more than $94,000 in restitution to her former employer, LifeGift Organ Donation Center.

Duann in April had pleaded guilty to one count of unauthorised access to a protected computer.

Court documents filed in connection with the case describe what is becoming an increasingly familiar tale of companies victimised by insiders.

Duann was hired by LifeGift in 2003 and put in charge of overseeing the company's entire IT infrastructure and fired in November 2005 for reasons not specified in court documents.

At the time of her termination, Duann was informed in writing that all her access rights had been revoked. The company also took steps to lock all administrator accounts to which Duann was known to have access.

Despite such steps, Duann still managed to access LifeGift's network from her home on the same evening she was fired, via a VPN account that she appears to have previously set up without anyone's knowledge.

Once inside the network, Duann used an administrator account belonging to another LifeGift employee to log into several servers, including the company's organ donor database server and main accounting server, multiple times.

Over the next several hours, she then deleted donor records, accounting invoice files, database and software applications, backup files and the software tokens needed to run some applications.

In a bid to cover her tracks, Duann manually deleted all logs of her VPN sessions with the company's network. She also disabled the activity logging functions on the database and accounting servers -- making it impossible for LifeGift to identity all of the individual files and applications she deleted, the court documents said.

Duann's sabotage, however, was discovered the next morning by an employee of a network services company that had just been hired by LifeGift to provide backup and disaster recovery services for the non-profit. The employee noticed someone deleting files in real-time from a VPN connection, which he quickly terminated.

The VPN connection logs and IP address was later traced back to Duann's home Internet connection. A subsequent search of Duann's home and computer systems by the FBI uncovered more evidence that linked her to the sabotage.

Like countless similar incidents, this one highlights the challenges that companies face when it comes to protecting data and systems from malicious insiders. In this case, the sabotage occurred even though LifeGift appears to have taken most of the measures that security experts recommend when employees leave the company or are fired.

For instance, the company immediately revoked Duann's access privileges after terminating her and disabled all administrator accounts to which she had had previous access. The fact that Duann still managed to access the company's servers just hours later, highlights how difficult it can sometimes be to stop insiders who plan to do harm.

THREAT : Cyber attack a threat to London Olympics

THREAT : Cyber attack a threat to London Olympics

Organizers feel that a potential cyber attack posed a unique challenge for the London 2012 Olympics

Avril Ormsby

July 22, 2009

http://www.ciol.com/Global-News/News-Reports/Cyber-attack-a-threat-to-London-Olympics/22709122606/0/

LONDON, UK: Olympic organizers are "very alive" to the threat of a cyber attack on the London 2012 Olympics, made more challenging because of its evolving nature, senior Interior Ministry officials said on Tuesday.

Ticketing systems, the transport network and hotel bookings as well as security are among potential targets.

Olympic security officials are also planning for the possible diversion of aircraft to protect airspace around the venues from terrorist attacks, the officials said.

The greatest threat to security at the Games is international terrorism, the government's latest "Safety and Security Strategy" report said.

"There's no current evidence of a terrorist threat to 2012," one of the Interior Ministry officials said.

"But if you look at precedents for sporting events, and to some degree about Olympic events, it would not be beyond the point of imagination to imagine a terrorist threat to 2012 nearer the time."

Metropolitan Police Assistant Commissioner Chris Allison said it was likely there would be a terrorist threat at the Games but he pointed to Britain's "long history of delivering safe sporting events".

Threats Change

Despite the British government on Monday lowering the threat level from international terrorism from "severe" to "substantial", security planning for the Games will be based on an assumed threat level of severe -- the second highest level.

Interior Minister Alan Johnson said in a statement that security planning was "progressing in good time and to budget".

A total of 600 million pounds ($980 million) has been put aside for security, but Interior Ministry officials said if the threat increased it could put upward pressure on costs.

The officials, who declined to be named, said a potential cyber attack posed a unique challenge because it was constantly changing and that more funds were being directed at the problem of computer attacks.

"The general challenge reflected in cyber is anticipating what threats will look like three years out, and threats change, the nature of terrorism changes and the nature of serious crime changes as well, and cyber specifically is a really good example of a moving threat," one of the officials said.

"I think we are very alive to the cyber (issue) and we are very alive to the fact that at the moment it is difficult to predict what it will look like with specific reference to the Games in 2012."

Officials are also drawing up plans for protecting water and air space around Olympic venues from possible attack, including possibly diverting aircraft. It is expected diversions would most likely affect smaller, private aircraft.

"We do expect there will have to be some management of air space," another of the Interior Ministry officials said.

"We do not expect that any airports will have to be closed."

TOPPER : U.S. Is Top Spam-Producing Country

TOPPER : U.S. Is Top Spam-Producing Country

The US has been named the world's biggest spam-producing country, says security vendor Sophos.

By Carrie-Ann Skinner

PC Advisor (UK)

July 21, 2009

http://www.cio.com/article/497728/U.S._Named_As_Top_Spam_Producing_Country

The US has been named the world's biggest spam-producing country.

Security firm Sophos said the US was responsible for 15.6 percent of all spam received between April and June this year - that's one in every six junk emails.

The US was closely followed by Brazil, which produced 11.1 percent of all spam, and Turkey, which generated 5.2 percent.

Russia, which was second on Sophos' Dirty Dozen list a year ago, has now fallen to ninth place and was only responsible for 3.2 percent of all spam between April and June.

Graham Cluley, senior technology consultant for Sophos, said: "Barack Obama's recent speech on cybersecurity emphasised the threat posed by overseas criminals and enemy states, but these figures prove that there is a significant problem in his own back yard. If America could clean up its compromised PCs it would be a considerable benefit to everyone around the world who uses the net".

Sunday, July 19, 2009

Quote of the day

Quote of the day

When it is dark enough, you can see the stars.

Charles Beard

New IT Term of the day

New IT Term of the day


spamware


Software that is used by spammers to send out automated spam e-mail. Spamware packages may also include an e-mail harvesting tool.

This Day in History

Thanks for your Visit