In school you get the lesson and then take the test;
In life you take the test and then get the lesson.
IT and Related Security News Update from Centre for Research and Prevention of Computer Crimes, India (www.crpcc.in) Courtesy - Sysman Computers Private Limited, Mumbai
In school you get the lesson and then take the test;
In life you take the test and then get the lesson.
clewbie
An Internet slang term that means "clueless newbie".
10 July 2009
By Paul Goble
The Moscow Times
http://www.moscowtimes.ru/article/1328/42/379446.htm
Hacker attacks against sites maintained by political opponents of the Russian government have received a great deal of attention. One target of hackers that has received far less press is Runet sites operated by religious groups, which are increasingly coming under cyber attack, a trend that reflects the importance of the Internet in Russian religious life.
In an article in newspaper Novya Izvestiya, reporter Mikhail Pozdnyaev says that among those who have suffered from hacker attacks are “representatives of all confessions, official and independent information agencies that write about religious news, and popular missionaries."
Because of the diversity of sites and the difficulties involved in determining why a site may have failed and in tracking down those responsible, there are no reliable statistics available on just how widespread this trend is. Consequently, the Novaya Izvestiya journalist describes some of the more high-profile examples of this phenomenon.
Pozdnyaev begins with the hacker attack on the official site of the Maykop and Adygei eparchate of the Russian Orthodox Church this past Sunday. For several hours, he reports, visitors to the site found a page that had nothing to do with religious affairs, though the eparchate’s technical staff was able to restore the site rather quickly.
Officials in the eparchate told Pozdnyaev that they believe that this attack happened when it did because at least some of the faithful are unhappy that Archbishop Panteleimon has been replaced as head of the see by Bishop Tikhon. The hackers, these officials believe, were supporters of Panteleimon.
But exactly who carried out the cyber attack remains unknown in this case, as in others even when the hackers declare themselves — as happened earlier this year — to be representatives of the “ Free Radical Society of Atheists of Bobruisk” or the “Atheist from Shenkursk,” titles that are only user names that reveal little.
A much larger hacking scandal occurred during the controversy over now dethroned Bishop Diomid and his challenge to the Moscow Patriarchate. The “Orthodoxy in the Far East” portal that featured information on his case came under attack twice — once with those responsible posting pornographic pictures and another time with foul language.
The priest who oversees the portal said the hackers were people who supported Diomid and had enough resources to overcome the portal’s defenses. Since then, the Interior Ministry’s Bureau of Special Technical Measures has tracked down the individual involved: He is a citizen of one of the CIS countries, the ministry reported.
Russian prosecutors are seeking to bring this person to justice, the journalist says, but they have not had much luck. And that highlights a serious problem: As Pozdnyaev notes, “catching a hacker is harder that restoring a site that has been attacked.”
Other religious entities that have been targeted include the Estonian Orthodox Church of the Moscow Patriarchate, the official site of the Patriarchate itself following the death of Aleksii II, and Portal-Credo.ru, an independent religious news portal that is often highly critical of the Orthodox Church.
Hacker attacks against web sites maintained by the Russian Orthodox Church, its various subdivisions and even individual clerics, such as Archdeacon Andrey Kurayev, are a relatively new phenomenon, but such attacks have been taking place against Islamic sites on a regular basis for a decade.
At the end of June, hackers took offline for a brief period two of the most important Russian-language Islamic news sites, Islam.ru and IslamNews.ru, both of which have been subject to similar attacks in the past. Pozdnyaev says that it is possible that the hackers are people who “do not share the loyal attitude” of these sites to the government.
Jeremy Kirk,
IDG News Service
July 10, 2009
The state of New York plans to sue the social-networking site Tagged.com for allegedly using deceptive e-mails in order to gain new users, the Office of the Attorney General said Thursday.
From April through June, Tagged sent 60 million e-mails to people saying that members of the site had tagged them in photos but the photos did not exist, according to a news release from the office, lead by Attorney General Andrew M. Cuomo.
The e-mails that people received appeared to come from their friends but did not, which constitutes spam. The recipients were forced to become members of Tagged if they wanted to access the purported photos, the office alleges.
Tagged, which has been around for five years, would then illegally get access to those new users' e-mail address books and send out more messages without those users' knowledge. Tagged will be sued for deceptive e-mail marketing practices and invasion of privacy, the office said.
Tagged CEO Greg Tseng wrote on a company blog that the site did not access peoples' address books without their consent. But Tseng wrote the company realized that the language used to guide users during registration was confusing.
"The registration drive generated some complaints," Tseng wrote. "We immediately stopped using this registration process before being contacted by the Attorney General's office."
On June 16, Tseng wrote in another blog post that the registration drive resulted in 3 million new users for Tagged, but also resulted in 2,000 complaints "from people who invited all the contacts in their e-mail address books but didn't intend to."
"Simply put, it was too easy for people to quickly go through the registration process and unintentionally invited all their contacts," Tseng wrote. Tagged halted the new registration scheme on June 7. It also e-mailed new members telling them how to quit Tagged.
The Attorney General's office said it would seek to stop Tagged from engaging in fraudulent practices and pursue fining the company.
by Diane Bartz and Richard Chang
Jul 14, 2009
http://www.reuters.com/article/technologyNews/idUSTRE56D2H120090714
WASHINGTON (Reuters) - The ever-weakening job market could well lead to an increase in online crime as laid-off workers, especially those with computer skills, turn to scams to support themselves, Cisco Systems Inc said in a mid-year security report to be released on Tuesday.
Disgruntled employees may target their former employers, and Cisco warned that insiders "can be especially damaging for an organization because insiders know security weaknesses."
A former information technology analyst at the Federal Reserve Bank of New York was arrested in April along with his brother on suspicions of taking out loans using false identities. FBI investigators found a flash drive attached to the bank employee's computer with applications for $73,000 in loans in the names of stolen identities, the report said.
Cisco warned companies which use short-term IT consultants or who contract out the tasks to "be particularly vigilant about the level and term of their access to sensitive data."
The report included snippets of a conversation with a botmaster, or someone who remotely takes over computers without users' knowledge and often sells the resulting access to spammers.
The hacker declined to say how much he earned but said "'a guy I know'" can earn $5-10K weekly, by phising (sic) bank accounts." Phishing is the practice of convincing a victim to give up valuable information -- like a password to a bank account. The account can then be emptied.
By Kim Tong-hyung
koreatimes.co.kr
13 July 2009
http://www.koreatimes.co.kr/www/news/biz/2009/07/123_48336.html
South Korea has so big a hole in its cyber security that another wave of online attacks will prove to be as devastating as those of last week.
First, virtually anybody can mount such attacks. Although government officials suspect North Korea may have been orchestrating these virtual attacks, a gang of teenagers could possibly organize and bring the same amount of damage as a nation can, and with a program purchased online for the same price as a song.
When the country was pummeled by a massive distributed denial of service (DDoS) attack over four days until last weekend, it was a handful of private firms that came to the rescue.
In addition, systemic flaws such as over-reliance on Microsoft's Active-X program need to be addressed. Without them, all Korea can do appears to be nothing but pray that no such attacks recur.
The Korea Communications Commission (KCC) admits that more DDoS attacks are a possibility, considering that the types of malicious software that infected scores of Korean computers at homes and offices are programmed to update automatically. Whether the country would be better prepared for another powerful Internet attack is a totally different matter.
``We have been analyzing the malicious codes, and found that the programs were designed to self-destruct after initiating three attacks. We have yet to find a mutated version of the codes,'' said Hwang Cheol-joong, a KCC official.
As of Saturday, more than 97 percent of 77,875 infected computers had been cleared of the malicious programs, the KCC said. The state-run Korea Information Security Agency (KISA) is currently analyzing 22 sample types of the malicious codes.
``It is encouraging that the number of infected computers was fewer than first thought, even when considering the devices that remain unreported. However, considering that these DDoS bots are not controlled by command and control (C&C) operational software, but programmed for automated updates and self-destruction, we need to stay alert. There also might be types of codes that we have yet to discover,'' Hwang said.
The National Intelligence Service (NIS), the country's spy agency, is responsible for protecting public Internet infrastructure from Internet attacks, while KCC and KISA handle the private side.
However, the Ministry of Public Administration and Security deals with breaches within government networks, while the National Police Agency combats ``cyber crimes.''
The complicated relations between these agencies make it difficult for the government to muster a quick and coordinated approach when crisis hits, according to critics, who call for the establishment of a ``control tower.''
``We agree that there should be a more simplified chain of command. The current system has problems,'' Choi See-joong, the KCC chairman, told reporters last week.
It could also be said that Korea was behind for its Microsoft monoculture for Web browsers. In Korea, all encrypted transactions on the Internet are required to be done through Microsoft's ``Active-X'' controls, which work only on Internet Explorer browsers. As a result, the market share of Internet Explorer remains in the high 90s.
However, Active-X is also linked with security concerns, as the controls require full access to the Windows operating system on computers. This means that malicious programs can direct the browser to download files that compromise the user's control of the computer.
``Active-X happens to be one of the ideal tools for malicious codes to be distributed. Even Microsoft is phasing Active-X out due to security worries, but Korea has been a step behind,'' said an official from KTB Solutions, a computer software company.
(Why single out Korea? Most of the countries are ill-prepared for Cyber Security. In fact, in some countries, the concept of Cyber Security exist on paper only - Editor)
Thanks for your Visit