WISH YOU A HAPPY AND SECURE YEAR 2009

Sunday, January 18, 2009

Quote of the day

Quote of the day

The golden opportunity you are seeking is in yourself. It is not in your environment; it is not in luck or chance, or the help of others; it is in yourself alone.

Orison Swett Marden

(1850-1924, Founder of Success Magazine)

New IT Term of the day

New IT Term of the day


Tor


An anonymous Internet communication system based on a distributed network. Tor is a toolset for a wide range of organizations and people that want to improve their safety and security on the Internet. Using Tor can help you remain anonymous while Web browsing, instant messaging, using IRC, SSH, or other applications which use the TCP protocol. The Tor network takes a random pathway through several servers that cover your tracks so no observer at any single point can tell where the data came from or where it's going. Tor also provides a platform on which software developers can build new applications with built-in anonymity, safety and privacy features.

Tor was developed is supported by the Electronic Frontier Foundation.

National Skills Shortage in Computer Forensics

DEMAND : National Skills Shortage in Computer Forensics

Andy Frowen

14 Jan 2009

http://www.content4reprint.com/computers/security/national-skills-shortage-in-computer-forensics.htm

Computer Forensics, or Digital Forensics to give it another name, is something that in todays fast moving environment that has become as much part of policing as walking the beat or patrolling as part of a mobile unit.

As technology progresses and it does so extremely quickly these days, so to do the ways in which technology is applied to crime and its uses by the criminal. Whereas in the past when crime was much more straightforward and involved a physical presence, Computer Crime requires, in some instances, nothing more than a computer, access to the internet, and the personal information of an unwitting individual.

As this type of computer criminal becomes more and more common so too does the need for experts in the field of Computer Forensics Analysis. However in the United Kingdom at the present time there is a shortage of trained professionals in this field which leaves the computer criminal at a distinct advantage.

Computer Forensics is used in a variety of different ways and not simply as a means of producing an auditable trail of data. A Computer Forensics Analysis of a laptop or desktop machine can provide valuable information as to not only how the machine was used to perpetrate a crime, but also who used the machine to commit the crime.

As individuals we all have certain ways of typing and committing words to a page and this is all very much part and parcel of the Computer Forensics Experts job, identifying these common traits and using them to help produce a profile.

The role of Computer Forensics Analysis in a court case is vitally important especially if that case pertains to the use of computers as a means to defraud money or in the distribution of materials deemed illegal such as pornography and child pornography. An expert Computer Witness will be able to provide such analysis to members of the jury, the judge, and the defence and prosecution teams in a way that is both informative and yet easily enough understood so as not to muddy the waters.

Such a witness is invaluable in both the prosecution and defence of a case and can be utilised to provide expert Computer Forensic Analysis and also provide the jury, who are not necessarily familiar with such terms, with easily digestible and retainable information.

Indeed an expert witness may also be able to physically demonstrate to the court just how a criminal has managed to perpetrate a crime especially if this crime is committed over a distance.

As touched upon earlier there is a shortage of such personnel in the United Kingdom at the present time and this is in no small part due to the face that computer crime is on the increase and becoming more sophisticated. Such trained personnel are invaluable to a case and are fully conversant with ACPO (Association of Chief Police Officers) guidelines.

With such a shortage of trained personnel it is fair to say that the floodgates have been opened for the Computer Criminal. He, she or they (it is often common to find such individuals working in cells using complex networks and IT infrastructures) are more likely to evade a thorough investigation and subsequent prosecution without the assistance of trained Computer Expert Witnesses and their informed analysis.

These trained personnel are often in short supply because of the need for more than one discipline when it comes to Computer Forensics Analysis.

Network Forensics is often such that an Computer Forensics Expert will be required to examine the data on a large number of computers either networked together physically (hard-wired) or operating as satellites as part of a Wi-Fi network. This particular type of auditing is particularly useful and often provides vital information in the prosecution of computer crime especially when it is necessary to link together a number of individuals spread over a large geographical area.

It is important to remember also that the analysis provided by a Computer Expert Witness is not only used to help in the prosecution or defence of a case at a judicial level but also can be used in helping to identify and prevent further instances of Computer Crime. Moreover this is something that has, and will have, an impact when it comes to fighting ecrime in the future as the ecriminals and their methods become more sophisticated and harder to track.

419ers take Canadian for $150,000

VICTIM : 419ers take Canadian for $150,000

Textbook scam

By Lester Haines

15th January 2009

http://www.theregister.co.uk/2009/01/15/canadian_419_victim/

A Canadian man who fell for a 419 scam was taken for $150,000 by advance fee fraudsters who conducted a textbook operation to fleece their victim.

John Rempel of Leamington, Ontario, got an email back in 2007 from "someone claiming to be a lawyer with a client named David Rempel who died in a 2005 bomb attack in London", the Windsor Star reports. The email claimed the "deceased" had left $12.8m, and since he had no family "wanted to leave the money to a Rempel".

Rempel, 22, said: “It sounded all good so I called him. He sounded very happy and said God bless you.”

The 419er told Rempel he had to pay $2,500 to transfer the money into his name. He then had to stump for several more documents, some of which cost $5,000. The scammer told Rempel he had to open a bank account in London, with a minimum $5,000 deposit. He said some of the money had been transferred into the account for “safe keeping".

The scammers then upped the ante, sending an email from a "government department" claiming he owed $250,000 tax on his inheritance. Rempel's contact assured him he'd "negotiated the fee down to $25,000".

Rempel decided to travel to London to check that the deal was legit. He made his way to Mexico, where his farm-owning uncle gave him cash and money for a plane ticket. He said: “I had $10,000 in cash in my pocket and my uncle sent another $25,000 when I was over there.”

Once in London, Rempel met "some people" and handed over the $10k. The next day, the 419ers showed their target a suitcase they said contained $10.6m in shrink-wrapped US bills. Rempel demanded further proof, at which point one scammer extracted a bill and “cleansed” it with a liquid “formula" which "washed off some kind of stamp". The process converted the cash into “legal tender", Rempel was told.

Rempel said: “I was like holy crap, is that mine?” he said. “They said ‘yes sir, it’s yours.’ It all sounded legit.”

Rempel went back to his hotel room with the magic formula to wait for the 419ers "so they could cleanse all his money". They, of course, disappeared, later claiming they'd "been held up".

The victim then managed to drop the bottle containing the formula, breaking it. He rang his contact who said he'd get further supplies. Rempel flew back to Leamington and waited several weeks until a call which confirmed more formula was available for $120,000.

Rempel said: “I thought, ‘let’s work on it, nothing is impossible.’”

The 419ers told Rempel they "were willing to meet associates in different countries to get cash for the formula", but that they'd need several plane tickets, at $6,000 a pop.

The scammers subsequently confirmed they'd collected $100,000, but were still $20,000 short. Apparently, there was "a guy in Nigeria who had it, but another plane ticket was required". The contact then insisted he could only get $15,000 of the balance and “begged” Rempel for the remaining $5,000.

Rempel obliged, borrowing the money and defaulting on his credit card and car payments.

A week later, Rempel got the call he'd been waiting for - the cash was ready to go if he could just find an extra $6,900 for "travel costs and to rent trunks to ship the money".

The final contact between Rempel and the scammers was when they called to say they'd arrived at the airport in New York. However, there was a slight snag - security had stopped them and they needed $12,500 for a bribe.

Rempel, still none the wiser but substantially lighter in the wallet, told them: "No way, I’m cleaned out.”

In one last desperate act, Rempel drove to the airport with his parents and 10-year-old brother, but found no trace of his friends or the money. They then went home and called the police.

The final cost of Rempel's mix of greed and remarkable stupidity was $55,000 from his uncle in Mexico, $60,000 from his parents to "cover fees for transferring $12.8 million into his name", plus the money he personally lost - a total of $150,000.

He said: “They’re in it now because of me. If it wasn’t for me, nobody would be in this mess. You think things will work out, but it doesn’t. It’s a very bad feeling. I had lots of friends. I never get calls anymore from my friends. You know, a bad reputation.”

He concluded: “I really thought in my heart this was true."

FBI calls for global cooperation on cyber crime

CALL : FBI calls for global cooperation on cyber crime

International laws needed to combat global threat

Iain Thomson in San Francisco

vnunet.com

14 Jan 2009

http://www.vnunet.com/vnunet/news/2234003/fbi-calls-global-cooperation

www.vnunet.com/2234003

The FBI has called for greater international coordination in anti-hacking laws at the first International Conference on Cyber Security.

The conference was held last week at Fordham University in New York City and was co-sponsored by the FBI. It aimed to bring together commercial companies, law enforcement and private individuals with an interest in curbing online crime.

“The FBI’s goal of sponsoring this conference is to build and forge long-lasting relationships to combat terrorist and criminal use of the Internet,” said Joseph Demarest, head of the FBI’s New York Office.

“The conference is the beginning of greater cooperation on all cyber matters.”

As an example of how such cooperation would work the FBI highlighted the work of the new 24/7 computer intrusion investigation team, which now has 55 member states contributing resources.

The FBI showed an example of how the team responds to attacks, in this example involving an initial intrusion into a bank in Mexico City initially routed through a computer in New York. This was however controlled from a computer in South Korea which was in turn traced to a machine in Thailand, where local police made an arrest.

Thanks to inter-network cooperation the team could backtrace and make an arrest within hours, rather than the weeks and months that traditional online policing would have taken.

“The bottom line is to make sure there are consequences for criminal cyber actions and similar consequences everywhere,” explained Christopher Painter, deputy assistant director of the FBI’s Cyber Division.

“The bad guys need to know there is no free ride.”

Worm infects 3.5M Windows PCs in 2 days

SCALE : Worm infects 3.5M Windows PCs in 2 days

It would make 'one big badass botnet,' says Finnish security company

Gregg Keizer

January 14, 2009

Computerworld

http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9125941&source=NLT_SEC&nlid=38

The computer worm that exploits a months-old Windows bug has infected more than a million PCs in the past 24 hours, a security company said today.

Early Wednesday, Helsinki, Finland-based security firm F-Secure Corp. estimated that 3.5 million PCs have been compromised by the "Downadup" worm, an increase of more than 1.1 million since Tuesday.

"[And] we still consider this to be a conservative estimate," said Sean Sullivan, a researcher at F-Secure, in an entry to the company's Security Lab blog. Yesterday, F-Secure said the worm had infected an estimated 2.4 million machines.

The worm, which several security companies have described as surging dramatically during the past few days, exploits a bug in the Windows Server service used by all supported versions of Microsoft Corp.'s operating system, including Windows 2000, XP, Vista, Server 2003 and Server 2008.

Microsoft issued an emergency patch in late October, fixing the flaw with one of its rare "out of cycle" updates.

The soaring number of infections by Downadup -- also called "Conficker" by some security companies -- prompted Microsoft to add detection for the worm to its Malicious Software Removal Tool (MSRT), the anti-malware utility that the company updates and redistributes each month to Windows machines on Patch Tuesday. The MSRT scans for known malware, then scrubs the system of any it finds.

Like researchers at firms such as Symantec Corp. and Panda Security, Microsoft blamed lackadaisical patching for the infections. "A number of our customers have contacted our support team for assistance with containment in environments that were, largely, not patched when the worm was released," said Cristian Craioveanu and Ziv Mador, two researchers at Microsoft's Malware Protection Center, in a Tuesday blog entry. "Either Security Update MS08-067 was not installed at all or was not installed on all the computers."

Craioveanu and Mador said that the highest number of infection reports had come from the U.S., Canada, Mexico, Korea and several European countries, including the U.K., France and Germany.

Yesterday, F-Secure also reported that it was spying on Downadup's command-and-control process by registering domains it thought the worm would try to use to download additional malware to infected PCs. The worm generates hundreds of possible domain names daily using a complex algorithm, said Mikko Hypponen, F-Secure's chief research officer.

"This makes it impossible and/or impractical for us good guys to shut them all down," acknowledged Hypponen in a blog entry. "The bad guys only need to predetermine one possible domain for tomorrow, register it and set up a Web site, and they then gain access to all of the infected machines. Pretty clever." Even so, F-Secure has registered some of the possible hosting domains so that it can eavesdrop on the attackers and get an idea of the number of infected PCs.

Other security firms have tried to preempt hackers by registering domains that they may use, but with mixed results. Last November, FireEye Inc. tried to stay ahead of criminals operating the "Srizbi" botnet by registering several hundred domains being used to resurrect the infected PC army, but had to give up the game when it got too costly.

"We have registered a couple hundred domains," said Fengmin Gong, chief security content officer at FireEye, at the time. "But we made the decision that we cannot afford to spend so much money to keep registering so many [domain] names."

As soon as FireEye conceded, the hackers were able to re-establish communication with their bots.

Microsoft recommended that Windows users install the October update, then run the January edition of the MSRT to clean up compromised computers.

It's not clear whether the hackers behind Downadup are building a botnet of their own, said Joe Stewart, a senior security researcher at SecureWorks Inc., in an interview today. For the moment, they seem satisfied with feeding victims fake security software, which pesters users with pop-ups until they pay for the worthless program.

However, F-Secure's Hypponen sounded worried about the possibility that machines infected with Downadup would be converted into bots. "It would make for one big badass botnet," he said.

This Day in History

Thanks for your Visit