WISH YOU A HAPPY AND SECURE YEAR 2009

Sunday, January 4, 2009

Quote of the day

Quote of the day

At his best, man is the noblest of all animals; separated from law and justice he is the worst

Aristotle

New IT Term of the day

New IT Term of the day


TCP SYN attack


A sender transmits a volume of connections that cannot be completed. This causes the connection queues to fill up, thereby denying service to legitimate TCP users. A TCP SYN attack (also called SYN attack) is a common type of Denial of Service attack.

Internet sites could be given 'cinema-style age ratings'

OPINION : Internet sites could be given 'cinema-style age ratings'

Internet sites could be given cinema-style age ratings as part of a UK Government crackdown on offensive and harmful online activity to be launched in the New Year, the Culture Secretary says.

By Robert Winnett, Deputy Political Editor

Telegraph, UK

27 Dec 2008

http://www.telegraph.co.uk/scienceandtechnology/technology/technologynews/3965051/Internet-sites-could-be-given-cinema-style-age-ratings-Culture-Secretary-says.html

Culture Secretary Andy Burnham says internet sites could be given 'cinema-style age ratings'

Internet sites could be given 'cinema-style age ratings', Culture Secretary says Photo: MARTIN POPE

In an interview with The Daily Telegraph, Andy Burnham says he believes that new standards of decency need to be applied to the web. He is planning to negotiate with Barack Obama’s incoming American administration to draw up new international rules for English language websites.

The Cabinet minister describes the internet as “quite a dangerous place” and says he wants internet-service providers (ISPs) to offer parents “child-safe” web services.

Giving film-style ratings to individual websites is one of the options being considered, he confirms. When asked directly whether age ratings could be introduced, Mr Burnham replies: “Yes, that would be an option. This is an area that is really now coming into full focus.”

ISPs, such as BT, Tiscali, AOL or Sky could also be forced to offer internet services where the only websites accessible are those deemed suitable for children.

Mr Burnham also uses the interview to indicate that he will allocate money raised from the BBC’s commercial activities to fund other public-service broadcasting such as Channel Four. He effectively rules out sharing the BBC licence fee between broadcasters as others have recommended.

His plans to rein in the internet, and censor some websites, are likely to trigger a major row with online advocates who ferociously guard the freedom of the world wide web.

However, Mr Burnham said: “If you look back at the people who created the internet they talked very deliberately about creating a space that Governments couldn’t reach. I think we are having to revisit that stuff seriously now. It’s true across the board in terms of content, harmful content, and copyright. Libel is [also] an emerging issue.

“There is content that should just not be available to be viewed. That is my view. Absolutely categorical. This is not a campaign against free speech, far from it; it is simply there is a wider public interest at stake when it involves harm to other people. We have got to get better at defining where the public interest lies and being clear about it.”

Mr Burnham reveals that he is currently considering a range of new safeguards. Initially, as with copyright violations, these could be policed by internet providers. However, new laws may be threatened if the initial approach is not successful.

“I think there is definitely a case for clearer standards online,” he said. “More ability for parents to understand if their child is on a site, what standards it is operating to. What are the protections that are in place?”

He points to the success of the 9pm television watershed at protecting children. The minister also backs a new age classification system on video games to stop children buying certain products.

Mr Burnham, himself a parent of three young children, says his goal is for internet providers to offer “child-safe” web services.

“It worries me - like anybody with children,” he says. “Leaving your child for two hours completely unregulated on the internet is not something you can do. This isn’t about turning the clock back. The internet has been empowering and democratising in many ways but we haven’t yet got the stakes in the ground to help people navigate their way safely around…what can be a very, very complex and quite dangerous world.”

Mr Burnham also wants new industry-wide “take down times”. This means that if websites such as YouTube or Facebook are alerted to offensive or harmful content they will have to remove it within a specified time once it is brought to their attention.

He also says that the Government is considering changing libel laws to give people access to cheap low-cost legal recourse if they are defamed online. The legal proposals are being drawn up by the Ministry of Justice.

Mr Burnham admits that his plans may be interpreted by some as “heavy-handed” but says the new standards drive is “utterly crucial”. Mr Burnham also believes that the inauguration of Barack Obama, the President-Elect, presents an opportunity to implement the major changes necessary for the web.

“The change of administration is a big moment. We have got a real opportunity to make common cause,” he says. “The more we seek international solutions to this stuff – the UK and the US working together – the more that an international norm will set an industry norm.”

The Culture Secretary is spending the Christmas holidays at his constituency in Lancashire but is planning to take major decisions on the future of public-service broadcasting in the New Year. Channel Four is facing a £150m shortfall in its finances and is calling for extra Government help. ITV is also growing increasingly alarmed about the financial implications of meeting the public-service commitments of its licenses.

Mr Burnham says that he is prepared to offer further public assistance to broadcasters other than the BBC. However, he indicates that he does not favour “top-slicing” the licence fee. Instead, he may share the profits of the BBC Worldwide, which sells the rights to programmes such as Strictly Come Dancing to foreign broadcasters.

“I feel it is important to sustain quality content beyond the BBC,” he said. “The real priorities I have got in my mind are regional news, quality children’s content and original British children’s content, current affairs documentaries – that’s important. The thing now is to be absolutely clear on what the public wants to see beyond the BBC.

“Top-slicing the licence fee is an option that is going to have to remain on the table. I have to say it is not the option that I instinctively reach for first. I think there are other avenues to be explored.”

Castle Cops shuts up shop

END : Castle Cops shuts up shop

Sad demise of volunteer security community

By John Leyden

29th December 2008

http://www.theregister.co.uk/2008/12/29/castlecops_closes/

Updated CastleCops (http://www.castlecops.com), the volunteer security community, has called it a day.

For six years CastleCops campaigned against internet fraud by running malware and phishing scam investigations and take-downs. CastleCops also ran volunteer training programs, as well as maintaining other services including computer virus clean-up assistance to ordinary punters.

Since the organisation was established in 2002, CastleCops has maintained close ties with other members of the anti-malware community and law enforcement to make the internet a cleaner and safer environment. Despite its sterling work in multiple areas, CastleCops has long had problems with funding and hostile actions by cybercriminals. For example, CastleCops has been the target of repeated denial of service attacks as well as attempts by crooks to discredit the site.

Paul Laudanski was the main man behind CastleCops for three years before he took up (http://www.geek.com/articles/microsoft/castlecops-paul-laudanski-accepts-job-at-microsoft-20080613) a full-time job as an internet safety investigator with Microsoft back in June. The failure to replace Laudanski made the announcement that CastleCops was closing sadly predictable, at least in retrospect. The announcement itself (below) took the wider security community a little by surprise.

You have arrived at the Castle Cops website, which is currently offline. It has been our pleasure to investigate online crime and volunteer with our virtual family to assist with your computer needs and make the Internet a safer place. Unfortunately, all things come to an end. Keep up the good fight folks, for the spirit of this community lies within each of us. We are empowered to improve the safety and security of the Internet in our own way. Let us feel blessed for the impact we made and the relationships created.

CastleCops pledged to refund donations for its upkeep made through PalPal. Donations to the service made by cheque can't easily be refunded and will be passed onto the Internet Software Consortium (not the Internet Storm Centre as we initially incorrectly reported) by the middle of March, unless instructions to the contrary are received.

SBI fixes website after hacking attack

HACKED : SBI fixes website after hacking attack

28 Dec 2008

http://timesofindia.indiatimes.com/Business/SBI_fixes_website_after_hacking_attack/articleshow/3903956.cms

MUMBAI: The country's largest lender State Bank of India said on Sunday that it has resolved the "technical problem" with its website , which had become temporarily unavailable due to a reported hacking attempt.

An attempted attack caused a shutdown of SBI’s website on Saturday. “There has been an attempt to disrupt the system,” a senior official confirmed. But he refused to divulge any further details. While the bank’s internet banking site www.onlinesbi.com was operational, its sites www.statebankofindia.com and www.sbi.co.in were down on Saturday.

"I don't want to use the word 'hacking'. It was a temporary technical problem which was resolved by yesterday evening," the public sector bank's Deputy Managing Director (IT) R P Sinha said on Sunday.

After the restoration of the website, Sinha stressed that the technical fault did not affect any transactions, including fund transfer and there was no loss of customer data.

Late on Saturday evening, officials said that the bank was targeting to get its website operational by 9 pm. Later, the bank put up a message stating that site was under maintenance and directed online applicants to clerical positions to the Institute of Banking Personnel Selection site.

SBI is the country’s largest bank with over three million online customers. The number of people with access to internet banking has increased dramatically after SBI installed its core banking solutions in over 11,100 branches across the country. In the past too, government websites have been attacked by hackers who left behind anti-India slogans.

Last year, Bank of India’s website had fallen victim to hackers who planted malware on the site that installs itself on the user’s computer and transmits sensitive information to the hacker. Besides this there have been phishing attempts on customers of various banks where the hacker puts up a website identical to that of a bank to steal passwords.

India has to gear up to face the virtual assault

ATTACK : India has to gear up to face the virtual assault

Bhuvan Bagga

January 2, 2009

http://indiatoday.digitaltoday.in/index.php?option=com_content&task=view&id=24165&sectionid=4&issueid=86&Itemid=1

New Delhi, It is not just terror on the ground that India is worried about any more. The Computer Emergency Response Team of India (CERT-In) estimates that Pakistan- based hackers have attacked Indian networks more than 100 times since the November 26 strike on Mumbai.

According to Gulshan Rai, director, CERT-In–the specialised arm of India’s Information Technology ministry – network hacks from Pakistan- based programmers have been “naïve but effective”.

Says Rai: “As soon as the dust over the November 26 attacks settled and the Pakistani role in it became clear, Pakistan- based hackers have defaced more than 100 Indian websites with anti- India messages. Other attacks include those on government networks and networks of government- affiliated agencies.” In fact, the IT ministry has its own informal list of “most wanted” Pakistan- based hackers. Cyberlord, an Internet nickname of one such has executed 70 attacks on Indian Web sites. Similarly yusufislam (58 attacks), el_ muhammed (46 attacks), iranianboysblackhat (52 attacks), mirim (35 attacks) and cracker_ child (103 attacks) lead the way for Pakistan-origin cyberspace strikes.

Experts even say that these are “the Dawoods, the Zaki-ur-Rehman Lakhvis and the Masood Azhars of the virtual world”. They are strongly anti-Indian and several of them work freelance for anti-Indian outfits in the real world.

It is not just hackers from Pakistan.

Says Rai: “In 2008, Chinabased entities broke into one State Bank of India website and took complete control. Luckily it was only a consumer information site. But also remember that almost every bank has critical financial data online and it does not take a genius to realise what would happen if a hacker — especially one that is statesupported — took over the site, and deleted or manipulated all financial records.” CERT- In recorded 401 cybersecurity- related incidents in November 2008 and a total of 291 defaced websites — primarily by agents based out of Pakistan, China, Russia, Iran and America.

On November 29, a cyber security related blog on ZD Net reported that a “virus outbreak had affected 75 percent of all systems at the largest US military base in Afghanistan. The intrusion was severe enough to necessitate the briefing of the President. We don’t know the source of the attack but signs point to state actors, with the most popular contenders either being Russia or China”.

The West woke up to the threat early, even going on to make the ahead of its time Sandra Bullock starrer Hollywood blockbuster The Net in 1995. With the kind of attacks we’ve been facing in 2008, India should strengthen its cyber security force many fold.

A senior IPS officer told Mail Today: “We don’t really have advanced cyber security systems, certainly not as strong as in the US or in the UK. We also need strong state support to thwart such attacks.”

A Delhi Special Cell Police officer said: “The US, Russia and China officially allow the use of ethical hackers to solve Internet crime and cybersecurity breaches. However, in India, a police officer can be arrested for asking for funds to hire a hacker, since hacking itself is illegal. The Indian state does not differentiate between ethical hacking and subversive hacking. Yet, the police are expected to show results.”

Cyber security experts say that they want to ask for state funding and laws structured to current reality and advancements. The Special Cell officer told Mail Today: “Our officers lack basic knowledge. It is a known fact that India- based hackers get sold to the highest bidder, and some of the best hacking minds in India work for China, the US or Russia. Today, I can send an email to any agency in a way that it would seem to have emerged from any other country.

I can break into sites and networks and steal the most strategic secrets. Alok Mukhopadhyay, an Associate at the Institute for Defense Studies and Analyses, says: “Information or rather disinformation warfare is the one for the 21st century.

The wars are now being fought over the Internet – not only through attempts of hacking, stealing and defacing, but through a smokescreen of disinformation.” It is not that cyberwars are unknown. Americans routinely target the Chinese and Russian hackers. The Chinese and the Russian state arms retaliate the same way with virus attacks, hacking and defacing.

The Special Cell officer said: “At a time when information is the key and an ever bigger proportion of it is in the cyberspace — India better buckle up fast — because if we lose this fight, the physical fight would only become even tougher.”

What they specialise in

China – Known to be keeping a very close watch on India’s Networks, specially government ones. Known for being good at putting in spywares.

Russia – Known for launching up very aggressive financial attacks. Primarily into stealing critical data, oganisation’s or military’s for financial benefits.

Pakistan – Primarily into anti-India propaganda, and Website defacing and damaging the primary information pool

Eastern Europe – Hacking into financial instruments and stealing data.

Middle East including Iran – Into Islamic propaganda, specially into anti- India doctored stories of Hindu-Muslim disunity.

Nigeria - Famous for black dollar scam.

The infamous hackers

Yusufislam – 58 websites defaced/ attack incidents in recent months

El_ muhammed – 46 websites defaced/ attack incidents in recent months

Iranianboysblackhat – 52 websites defaced/ attack incidents in recent months

Cracker_ child – 103 websites defaced/ attack incidents in recent months

Mirim – 35 websites defaced/ attack incidents in recent months

This Day in History

Thanks for your Visit