Quote of the day
The two greatest obstacles to democracy are, first, the widespread delusion among the poor that we have a democracy, and second, the chronic terror among the rich, lest we get it.
Edward Dowling
IT and Related Security News Update from Centre for Research and Prevention of Computer Crimes, India (www.crpcc.in) Courtesy - Sysman Computers Private Limited, Mumbai
Quote of the day
The two greatest obstacles to democracy are, first, the widespread delusion among the poor that we have a democracy, and second, the chronic terror among the rich, lest we get it.
Edward Dowling
TCB
Short for trusted computing base. TCB refers to the totality of protection mechanisms (hardware, firmware and software) that provide a secure computing environment. The TCB includes everything that must be trusted -- access control, authorization and authentication procedures, cryptography, firewalls, virus protection, data backup, and even human administration -- in order for the right level of security to work.
MOTIVE : Russian hackers target U.S., Europe for profit and politics
By Alex Rodriguez, Tribune correspondent
chicagotribune.com
December 26, 2008
www.chicagotribune.com/news/chi-russia-hackers2_rodriguezdec26,0,5001855.story
MOSCOW — Not long ago, the simple, anonymous thrill of exposing chinks in American software was enough of a payoff for a Russian hacker.
Today it's cash. And almost all the targets are in the United States and Europe, where Russia's notorious hackers pilfer online bank accounts, swipe social security numbers, steal credit card data and peek at e-mail log-ins and passwords as part of what some estimate to be a $100 billion-a-year global cyber-crime business.
And when it's not money that drives Russian hackers, it's politics—with the aim of accessing or disabling the computers, Web sites and security systems of governments opposed to Russian interests. That may have been the motive behind a recent attack on Pentagon computers.
A new generation of Russian hacker is behind America's latest criminal scourge. Young, intelligent and wealthy enough to zip down Moscow's boulevards in shiny BMWs, they make their money in cyber-cubbyholes that police have found impossible to ferret out.
From behind the partition of anonymous online hacking forums, they boast about why they use their programming savvy to spam and steal, mostly from the West.
"Why should I take a regular job after graduating and exert myself to earn just $2,000 a month, rather than grab this chance to make money?" says a Russian hacker on a cyber-crime forum that specializes in credit card fraud.
Cyber-crime, by some estimates, has outpaced the amount of illicit cash raked in by global drug trafficking. Hackers from Russia and China are among the chief culprits, and the threat they pose now extends far beyond spam, identity theft and bank heists.
Besides the recent attack on computers at the U.S. Defense Department, which may have originated in Russia, according to military leaders in Washington, Russian hackers also are believed to be behind highly coordinated attacks that brought down government Web sites in Estonia in 2007 and in U.S.-allied Georgia when war broke out between Russian and Georgian forces in August.
They're even suspected of hacking into the computer systems of Barack Obama and John McCain during the presidential campaign; technical experts hired by Obama's campaign suspected the attacks may have come from Russia or China, according to Newsweek.
So far there has been no evidence of a link between the Russian government and any of the attacks on American, Georgian and Estonian Web sites and computers. Nevertheless, the need to ramp up security of American cyberspace is being discussed with greater urgency in Washington. Earlier this month, a commission on cyber-security delivered a report to Congress calling for the creation of a new White House office that would gird the U.S. against computer attacks from hackers and foreign governments.
According to the commission, "unknown foreign entities" in 2007 hacked computers at the Departments of Defense, Homeland Security and Commerce, as well as NASA. Hackers broke into Defense Secretary Robert Gates' unclassified e-mail and probe Defense Department computers "hundreds of thousands of times each day," said the commission, a panel of leading government and computer industry experts.
A senior State Department official told the commission that the department had lost thousands of gigabytes of data due to computer attacks, and among the Homeland Security divisions reporting computer break-ins was the Transportation Security Administration. Hacking attacks compromising intellectual property have cost U.S. companies billions of dollars, the report stated.
"The damage from cyber attack is real," the report continued. "Ineffective cybersecurity, and attacks on our informational infrastructure in an increasingly competitive international environment, undercut U.S. strength and put the nation at risk."
After the Soviet collapse in 1991, Russian hackers were primarily motivated by mischief. "Back then it was simple hooliganism," said Vladimir Dubrovin, a hacker in the late 1990s and now a Russian computer security expert.
Today, however, most hackers in Russia are in it strictly for the money. Cyber-crime gangs approach computer programming graduates from Moscow's technical universities with offers of making sums of $5,000 to $7,000 a month, a far cry from Russia's average monthly salary of $640, says Nikita Kislitsyn, editor of Hacker, a glossy Russian magazine with how-to information for budding hackers.
Yevgeny Kaspersky, chief executive of Moscow-based Kaspersky Lab, one of the world's leading computer security firms, says Russian hacking flourishes as "a cyber-criminal ecosystem" of spammers, identity thieves and "botnets," vast networks of infected computers controlled remotely and used to spread spam, denial-of-service attacks or other malicious programs. A denial-of-service attack floods a Web site with inquiries, forcing its shutdown.
To ply online banking accounts, Russian hackers rely on viruses that record keystrokes as customers type log-ins and passwords. Russian-made viruses are believed to be behind several major online heists, including the theft of $1 million from Nordea Bank in Sweden in 2007 and $6 million from banks in the United States and Europe that same year.
Viruses and other types of "malware" are bought and sold for as much as $15,000, Kislitsyn says. Rogue Internet service providers charge cyber-criminals $1,000 a month for police-proof server access.
Botnets relied on for cyber-crime can also be used to lash out at political enemies, computer security experts say. Most analysts agree that criminal botnets were used by Russian hackers to shut down Estonian government and banking Web sites after the tiny Baltic republic angered Russians by moving a Soviet war memorial from downtown Tallinn in 2007.
"The Internet can now be used to attack small countries," Kaspersky said. "There are Russian and Chinese hackers that have the power to do that."
CHINK : VeriSign's SSL for Securing Web sites Cracked
Group says it used flaw in hashing algorithm to create fake digital certificates for Web sites
Robert McMillan
IDG News Service
December 30, 2008
http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9124558
With the help of about 200 Sony Playstations, an international team of security researchers has devised a way to undermine one of the algorithms used to protect secure Web sites — a capability that the researchers said could be used to launch nearly undetectable phishing attacks.
To accomplish that, the researchers said today that they had exploited a bug in the MD5 hashing algorithm used to create some of the digital certificates used by Web sites to prove they are what they claim to be. The researchers said that by taking advantage of known flaws in the algorithm, they were able to hack VeriSign Inc.'s RapidSSL.com certificate authority site and create fake digital certificates for any Web site on the Internet.
Hashes are used to create a digital "fingerprint" that is supposed to uniquely identify a given document and can easily be calculated to verify that the document hasn't been modified in transit. But the flaw in the MD5 algorithm makes it possible to create two different documents that have the same numerical hash value.
That, the researchers said, explains how someone could create a digital certificate for a phishing site that has the same fingerprint as the certificate for a genuine Web site. They added, though, that they don't expect to see any actual attacks using the flaw that they exploited — a point that Microsoft Corp. seconded in a security advisory in which it downplayed the threat to Internet users.
Using their farm of Playstation 3 machines, the researchers built a rogue certificate authority that could issue bogus certificates. The Playstation's Cell processor is popular with code breakers because it is particularly good at performing cryptographic functions.
The researchers planned to present their findings today at the Chaos Communication Congress, a hacker conference being held in Berlin. Even before their talk took place, it already was the subject of speculation within the Internet security community.
The team that did the research work included independent researchers Jacob Appelbaum and Alexander Sotirov, as well as computer scientists from the Centrum Wiskunde & Informatica, the Ecole Polytechnique Federale de Lausanne, the Eindhoven University of Technology and the University of California, Berkeley.
Although the researchers believe that a real-world attack using their techniques is unlikely, they say their work shows that the MD5 algorithm should no longer be used by the certificate authority companies that issue digital certificates. "It's a wake-up call for anyone still using MD5," said David Molnar, a Berkeley graduate student who worked on the project.
In addition to VeriSign, TC TrustCenter AG, EMC Corp.'s RSA unit and Thawte Inc. use MD5 to generate their digital certificates, according to the researchers. They said that VeriSign also uses the algorithm on a certificate service offered through its Japanese Web site, in addition to RapidSSL.com.
Exploiting the MD5 bug to carry out an attack would be hard, because cybercrooks would first have to trick a victim into visiting the malicious Web site that hosts a fake digital certificate. That could be done, however, by using what's called a man-in-the-middle attack. Last August, for example, security researcher Dan Kaminsky showed how a major flaw in the Internet's Domain Name System could be used to launch such attacks.
And with this latest research, it's now potentially easier to attack Web sites that are secured using Secure Sockets Layer (SSL) encryption, which relies on trustworthy digital certificates. "You can use Kaminsky's DNS bug combined with this to get virtually undetectable phishing," Molnar said.
"This isn't a pie-in-the-sky talk about what may happen or what someone might be able to do, this is a demonstration of what they actually did with the results to prove it," HD Moore, director of security research at BreakingPoint Systems Inc., wrote in a blog post about the researchers' findings.
Cryptographers have been gradually chipping away at the security of MD5 since 2004, when a team lead by Shandong University's Wang Xiaoyun demonstrated flaws in the algorithm.
Given the state of research into MD5, certificate authorities should have upgraded to more secure algorithms such as SHA-1 "years ago," said Bruce Schneier, a noted cryptography expert and chief security technology officer at BT PLC.
RapidSSL.com will stop issuing MD5-based digital certificates by the end of January and is looking for ways to encourage its customers to move to new certificates after that, said Tim Callan, VeriSign's vice president of product marketing. But first, Callan added, VeriSign wants to get a good look at the new research.
Molnar and his team have communicated their findings to VeriSign indirectly, via Microsoft, but they have yet to speak directly to VeriSign, out of fear that it might take legal action to quash their talk. In the past, companies sometimes have obtained court orders to prevent security researchers from talking at hacker conferences.
Callan said he wished that VeriSign had been given more information ahead of time. "I can't express how disappointed I am that bloggers and journalists are being briefed on this but we're not, considering that we're the people who have to actually respond," he said.
While Schneier said he was impressed by the math behind this latest research, he said that there are already far more important security problems on the Internet — weaknesses that expose large databases of sensitive information to attackers, for example.
"It doesn't matter if you get a fake MD5 certificate, because you never check your certs anyway," he said. "There are dozens of ways to fake that, and this is yet another."
BREACH : RBS WorldPay breach exposes 1.5 million
Payment processor buries bad news
By John Leyden
29th December 2008
http://www.theregister.co.uk/2008/12/29/rbs_worldpay_breach/
RBS WorldPay belatedly admitted last week that hackers broke into its systems.
The attack against the electronic payment services firm leaves to to 1.5 million payroll and gift card holders in the US at risk of fraud. Up to 1.1 million social security records were also exposed as a result of the breach.
The affected pre-paid cards include payroll cards and open-loop gift cards. PINs for all PIN-enabled cards are being reset as a precaution. RBS WorldPay has pledged to make sure its customers are not left out of pocket as a result of any fraud stemming from the attack. The firm is also offering 12 months complimentary membership to a credit monitoring service to those whose personal information was exposed as a result of the breach.
RBS WorldPay notified law enforcement and regulators about the attack on 10 November but waited until 23 December before publishing advice to potentially affected customers. The timing of its announcement raises suspicions that the firm is releasing bad news at a time when it is likely to go largely unnoticed.
The attack has been linked to the fraudulent misuse of 100 payroll cards, all of which have since been deactivated.
Details of the attack itself, much less who might have pulled it off, remain sketchy. RBS WorldPay has pledged to improve its security defences to prevent similar attacks in future.
RBS WorldPay's statement on the attack, and its response, can be found here (PDF format)
http://www.rbsworldpay.us/RBS_WorldPay_Press_Release_Dec_23.pdf
SCENARIO : Crime to boom as downturn blooms
By Mark Ward, Technology correspondent,
BBC News
2008/12/30
http://news.bbc.co.uk/go/pr/fr/-/2/hi/technology/7797946.stm
With the economic downturn affecting every corner of the globe, it is perhaps no surprise that it is likely to affect hi-tech criminals over the next 12 months.
In contrast to many ordinary people, hi-tech criminals are likely to see opportunities to prosper rather than suffer in the downturn.
So say some experts looking forwards to 2009 and what it will mean for the computer security world.
"Crime tends to rise when you have more unemployment," said Mikko Hypponen, chief research officer at F-Secure.
"If you look, in general, where the attacks are coming from you can find social reasons behind them," he said.
"It's not a technical problem, it's social," he said.
Easy money
Layoffs of many people familiar with net technology may tempt more into crime, he said, simply because their chances of being caught are slim. Equally, he said, the punishments for those that are caught are not harsh.
Those that did turn to hi-tech crime would find, he said, an underground service economy that will sell them all the bits they need to get started as a net criminal.
Some security firms fear that making people redundant could also trigger a wave of crime as aggrieved workers strike back at their employers.
This could mean that the intellectual property that a company relies on to keep going, such as its customer database, is copied and walks out of the door when employees pack up and leave.
"The damage that insiders can do should not be underestimated. It can take just a few minutes for an entire database that has taken years to build to be copied to a CD or USB stick," said Adam Bosnian, a spokesman for Cyber-Ark.
"With a faltering economy companies need to be especially vigilant about protecting their most sensitive data against nervous or disgruntled employees," he said.
Card games
"I would imagine that fraud is going to increase next year," said Carl Clump, chief executive of Retail Decisions that helps firms spot and tackle credit card fraud.
Even with the global economic slump, he said, fraud had been increasing year on year and there was no reason to expect that 2009 would buck that trend.
Widespread economic malaise would only act as a fillip to that rising tide, he said.
"It's a lucrative area and it's relatively easy to do," said Mr Clump.
Security initiatives such as chip and pin may have tackled fraud at some points, said Mr Clump, but that meant fraudsters had focussed on the next weakest area.
In particular, he said, many fraudsters have moved on to so-called Card Not Present fraud which is typically carried out via e-tail sites on the net.
Figures released in September by the Association of Payment and Clearing Services (APACS) which represents the UK's card firms showed that CNP fraud was up 18% on 2007 to £161.9m. Over the same period losses from UK online banking fraud rose by 185%.
Those unwilling to become spammers or phishers, said Mr Clump, might well be a tempted into low-grade fraud - especially if they have lost their job or are struggling to make ends meet.
"In times like these people take desperate measures," he said.
Dan Hubbard, chief technology officer at Websense, said the grim times could tempt people to make choices they would not make in better times.
"Gambling tends to go up when economies are down," he said.
This might make people more willing to work alongside web criminals and act as money launderers or mules.
Mr Hubbard said the ongoing development of the web, mash-ups and semantic technologies could introduce new vulnerabilities.
"These will all add another level of complexity to the web," he said.
"It will create a rich user experience but behind the scenes it is grabbing data from all over the place," he warned.
Unless that was properly managed and thoroughly checked for security loopholes it could prove tempting for criminal groups.
"There are more targets than ever," said Mr Hubbard.
Thanks for your Visit