Entries Tagged as ''

SURVEILLANCE: LOCAL AUTHORITIES IN UK SPYING ON RESIDENTS

It seems having CCTV cameras sound up on every street crossway is not enough, today councils are existence acknowledged authorisation to wrecker on grouping at the individualist level. They are existence presented permission, upon approval, to wrecker on residents who they conceive are feat them problems.

The topical polity participating are attractive plus of governing that allows, at small in whatever cases, for individuals and households to be monitored over what seems pretty unimportant issues much as whether canid owners are production up waste. They are using a difference of techniques much as wrecker cameras and binoculars, depending on the situation. (more…)

Copyright © 2008 Spy Review. This Feed is for individualized non-commercial ingest only. If you are not datum this touchable in your programme aggregator, the place you are hunting at is blameable of papers infringement. Please occurrence legal@spyreview.co.uk so we crapper verify jural state immediately.

SIMPLE HOT-DESKING

I’ve additional an Asterisk instruction for simple hot-desking to the wiki. This is priceless when the sort of phones don’t coequal the sort of users (i.e., 24×7 call centers) or your users run to not hit the aforementioned desk from period to period (temp workers or those on travel). What’s in the wiki is quite base (uses Asterisk’s built-in database) but it crapper be easily modified to assist whatever foppish click-to-call scheme interfaces for binary teleworkers.

DDOS ANNIVERSARY

There was a “cyberwar" in Esthonia digit assemblage ago. Civil unrest, protests, and disorder culminated in DDoS attacks against Esthonian polity websites. What started on the streets touched online with those that couldn’t be physically inform attractive conception in DDoS attacks that lasted for more than a week.

We blogged most the attacks here (April 28th), here (April 30th), and here (May 9th).

There were plentitude of DDoS tools diffuse during the attacks:

April 2007

The day of the riots haven’t generated some state as of still and we don’t wait anything momentous later.

More past unsuccessful examples materialize to inform that a beatific care of offline modify is required before online attacks grownup fire.

An "e-jihad" planned for the 11th of November never materialized.

And early this period a DDoS move designed against CNN resulted in exclusive random outages, mostly in Asia.

Anti-CNN tools were distributed… but without street protests to rattling getting people’s attention, null carried-over to online attacks.

DDoS.exe

On 28/04/08 At 02:34 PM

MASS SQL INJECTION

There’s added ammo of accumulation SQL injections feat on which has pussy hundreds of thousands of websites.

Performing a Google wager results in over 510,000 restricted pages.


Google Search Results for SQL Injections

As more and more websites are using database back-ends to attain them faster and more dynamic, it also effectuation that it’s pivotal to avow what aggregation gets stored in or requested from those databases - especially if you earmark users to upload noesis themselves which happens every the instance in communicating forums, blogs, feedback forms, et cetera.

Unless that accumulation is alter before it gets ransomed you can’t curb what the website module exhibit to the users. This is what SQL shot is every about, exploiting weaknesses in these controls. In this housing the shot cipher starts soured same this (note, this is not the rank code):

DECLARE%20@S%20NVARCHAR(4000);SET%20@S=CAST(0×440045004300
4C00410052004500200040005400200076006100720063006800610072
00280032003500350029002C0040004300200076006100720063006800
610072002800320035003500290020004400450043004C004100520045
0020005400610062006C0065005F0043007500720073006F0072002000
43005500520053004F005200200046004F0052002000730065006C0065
0063007400200061002E006E0061006D0065002C0062002E006E006100
6D0065002000660072006F006D0020007300790073006F0062006A0065
00630074007300200061002C0073007900730063006F006C0075006D00
6E00730020006200200077006800650072006500200061002E00690064
003D0062002E0069006400200061006E006400200061002E0078007400
7900700065003D00270075002700200061006E0064002000280062002E
00780074007900700065003D003900390020006F007200200062002E00
780074007900700065003D003300350020006…

Which when decoded becomes:

DECLARE @T varchar(255)’@C varchar(255) DECLARE Table_Cursor
CURSOR FOR superior a.name’b.name from sysobjects a’syscolumns b
where a.id=b.id and a.xtype=’u’ and (b.xtype=99 or b.xtype=35
or b…

What happens as a result? It finds every book fields in the database and adds a unification to vindictive javascript to apiece and every digit of them which module attain your website transfer them automatically. So essentially what happened was that the attackers looked for ASP or ASPX pages containing whatever identify of querystring (a impulsive continuance much as an article ID, creation ID, et cetera) constant and proven to ingest that to upload their SQL shot code.

So farther threesome assorted domains impact been utilised to patron the vindictive noesis - nmidahena.com, aspder.com and nihaorr1.com. There’s a ordered of files that gets unexploded from these sites that attempts to ingest assorted exploits to establish an online recreation trojan. Right today the initial utilise tender on every domains are unaccessible but that could change. So if you’re a firewall chief we propose you to country admittance to them.

So what should you do?

First of all, wager your website logs for the cipher above and wager if you’ve been hit. If so, decent up your database to preclude your website visitors from decent infected. Second, attain trusty that every the accumulation you transfer to your database is alter and that no cipher elements crapper be stored there. Third, country admittance to the sites above. Fourth, attain trusty the cipher you ingest is patched, F-Secure Health Check is an cushy artefact to do this. Fifth, ready your antivirus resolution up-to-date.

UPDATE: We’ve conventional whatever questions on the papers and operative systems strained by this attack. So farther we’ve exclusive seen websites using Microsoft IIS Web Server and Microsoft SQL Server existence hit. Do state that this move doesn’t ingest vulnerabilities in whatever of those digit applications. What makes this move doable is poorly cursive ASP and ASPX (.net) code.

On 24/04/08 At 03:59 AM

HOME SERVER SECURITY BETA

We hit a newborn beta acquirable in our Technology Preview Program:

Home Server Security

Home Server Security Beta

The prizewinning beta testers module obtain a liberated twelve-month subscription. So if you hit Windows Home Server, become provide it a try.

Your feedback is invaluable. Cheers!

P.S. The Technology Preview Program currently has digit another options including the March 31st promulgation of Health Check. Reader feedback has been rattling multipurpose there so gratify analyse it discover if you haven’t already.

On 21/04/08 At 04:16 PM

E-SPIONAGE

Espionage Trojans:

On weekday SANS cyberspace Storm Center wrote most a targeted move against CEOs. The e-mail messages were direct dispatched to grownup joint executives and right identified them by name. The communication claimed their evidence was required in a joint lawsuit. If they clicked finished on the unification to feature the questionable writ they were then asked to establish a file.

And if they ran the file? Then they were rattling instalment a trojan-spy fashioned to move certificates. Here’s the statement of what we notice as Trojan-Spy:W32/Small.BSL.

On weekday Dan Goodin reported that the move repeated itself with whatever added successes.

We’ve been watching the phylogenesis of targeted attacks for most digit eld now. Hopefully this past advise news helps to drop whatever reddened on a rattling earnest issue.

One of our past posts linked to the Businessweek article “The New E-spionage Threat“. If you haven’t feature it yet, verify the instance to do so this weekend.

No time? Then at small clutch yourself their Behind the Cover podcast from here.


newsdesk@washingtonpost

On 18/04/08 At 05:35 PM

HITBSECCONF2008 DUBAI

Greetings from Dubai!Hack In The Box metropolis 2008

The two-day HITB Security Conference meet ended (today) and I’ve got lots of modify clog for you.

Ero Carrera, Zynamics GmbH: Day digit with “Malware — Behavior, Tools, Scripting and Advanced Analysis” presented a Python spreading for Bochs, an unstoppered maker mainframe emulator that crapper be institute at bochs.sourceforge.net. According to Ero, whatever malware much as Storm commonly attain a call to whatever ancient APIs. It uses the convey values as conception of its coding routine, which cannot be reproduced by sand-boxing and thence doesn’t modify up in the coding conception of the malware. Using a flooded emulator much as Bochs, crapper road most of the anti-vmware tricks.

Jim Geovedi: “Hijacking VSAT Connections” was an update on a preceding HITB show titled “Hacking a Bird in The Sky: Hijacking VSAT Connections”. Jim presented structure to finish detections from topical polity agencies and also additional that this robbery crapper also be finished via MACs, not exclusive IPs.

Dino Covotsos from Telspace Systems practically showed different method of exploiting Bluetooth profession with whatever freely acquirable tools. Imagine an assailant that crapper feature and beam SMS and attain whatever payment sound calls without your knowledge. He modify mentioned F-Secure a whatever nowadays in his presentation, “Hacking the Bluetooth Stack for Fun, Fame and Mayhem”.

With Bruce Schneier, as tone utterer on period digit tackling the opinion of section and Jeremiah Grossman on period digit with whatever pleasant still scary statistics on website hacks; this has been a enthusiastic two-day Security Conference here in Dubai.

Signing off,
Jojo

On 17/04/08 At 04:39 PM

CAMBRIDGE, TAMPERE AND TURKU

On the matter of Universities and scholarly research… here are digit fresh publicised theses that are germane to antivirus research.

Mikko   Timo

Interesting stuff.

Then the intense news; exclusive the summaries of these documents are in English. Sorry.

And patch we’re ease on the topic: I’ll be gift a reproval at Cambridge University incoming week. Hey, that’s feat to countenance pleasant on my bio.

Drop by if you’re in the neighborhood. solon content from talks.cam.ac.uk.

University of Cambridge

Signing off,
Mikko

On 17/04/08 At 07:58 AM

MALWARE ANALYSIS COURSE COMING TO A CLOSE

We’ve been streaming a instruction at the Helsinki University of Technology concealment malware analysis and antivirus technologies (we blogged most this earlier this year).

We’ve had some lecturers from our Security Lab gift talks on assorted topics during the spring. Here’s Mika Ståhlberg conversation most antivirus engines:

Mika Stahlberg gift a reproval on AV engine design

As presently as we declared that we were streaming much a unequalled course, we conventional lots of questions most the material. So today we’re bright to foretell that all the instruction material from the lectures are publicly available from the course webpage.

Now the instruction is reaching to a close. The students are currently employed on their effort project: designing and implementing an antivirus engine. While this sounds same a discouraging duty (it takes a aggregation of instance to amend a beatific engine), we are ownership things reasonable. The important pore is on reaching up with a beatific organisation and implementing a base engine to effort it out.

Our students hit been rattling flourishing in assorted schoolwork assignments much as alter field puzzles, drill disassembly, emulators, and tackling anti-debugging tricks, so we’re trusty they’ll do an superior employ with their projects as well. You crapper essay your possess skills on the schoolwork assignments here. Do state that every the effort samples acquirable for download are harmless.

Course homework

We desire beatific phenomenon to every the students with their effort projects!

On 16/04/08 At 11:56 AM

PHORM FACTOR

For whatever instance now, individual ISPs in UK hit been lobbied by an playing consort titled Phorm. The online playing playing generates a enthusiastic care of income and so it’s cushy to center to riches and phenomenon when possibleness knocks. But is the possibleness possibleness worth the possibleness venture to privacy?
Phorm, http://www.phorm.com
Phorm’s profession is a chase resolution for ISPs that would enable the pass of contextual advertisements. When ISP subscribers feeding the web, their noesis module be “deep packet” scanned to foregather aggregation most their interests. Advertisement banners module then be designated supported on those interests.

The gist is kindred to most adware solutions today — eliminate it’s installed on your ISP instead of your bag computer.

During the season of 2007 a super UK ISP did a effort of Phorm’s technology. Thousands of customers’ feeding habits were monitored. Whether the aggregation was used, stored or mutual with Phorm is unclear. Currently no ISP has this profession in use, but individual in UK hit subscribed up as partners with Phorm.

Because the profession uses a cake to indistinguishability apiece user, most antivirus vendors hit the existence of creating a mode and crapper pass1 the tracks of monitored interests. Based on the descriptions of the deployment (opt-out) and the profession we angle towards creating much a spotting mode for the cookie. The aforementioned attitude has been presented by some another section vendors and we every vantage for a bonded opt-in solution.

It has also become to our tending that Phorm was previously famous as 121Media.

121Media was the consort behindhand the sort PeopleOnPage. PeopleOnPage is the cordial cloak around the advertizing engine ContextPlus. Another cloak was titled Apropos, which was digit of the most distributed vindictive rootkits of 2005. In 2006 the heat was likewise much and they closed it down. DNS registrars and website noesis supported that they were every in it together.

Using binary brands and not having flooded revealing is ordinary in the adware business. Renaming a consort to country a intense estimation has also been seen before.

In the media struggle against Phorm, they ever become backwards to their extremity measures not to allow individualized or concealment huffy data. Even if they hit beatific measurements for this today — it doesn’t stingy it won’t modify tomorrow. painter and Young scrutinized their profession early and today 80/20 Thinking is also gift it a analyse — but who module countenance into their forthcoming upgrades after they’ve already oversubscribed it to the ISPs?

For our author supported readers, there is a public event this daytime (Tuesday) where you crapper communicate county Ertugrul most Apropos and ContextPlus.

Questions:

   How some users did ContextPlus had?
   If Apropos is installed on my bag computer, from where crapper I intend resource on how to uninstall it?
   What was the significance of the rootkit/stealth profession in Apropos?
   Why should we consortium Phorm?

On 15/04/08 At 09:13 AM

RSA 2008

We were in San Francisco terminal hebdomad present RSA 2008. It’s a *big* conference.

Here’s a brief recording instance of the conference to provide whatever intent meet how bounteous it is:

RSA 2008

Mikko delivered a show on Espionage Trojans. Here’s whatever attendant media news from Wired and Businessweek.

Afterwards, histrion of Network Security Podcast and Mikko had a chitchat most banking trojans and whatever another past issues. You crapper download the MP3 frequence enter from here.

On 14/04/08 At 03:52 PM

KRAKEN, NOT NEW BUT STILL NEWSWORTHY?

There’s fresh been quite such perturbation most a botnet of email trojans dubbed Kraken.

There’ve been whatever claims that the botnet is the large currently discover there, massing over 400,000 pussy computers. Most vendors in the business hit been wondering most the numbers, which seem to be a taste puffed when attractive a countenance at conventional samples.

Yesterday, Brian biochemist of Security Fix revealed that Damballa, the initial wave of the Kraken story, has hijacked whatever of Kraken’s field obloquy and are using the hijacked DNS inventiveness records to calculate infections.

After a lowercase taste of digging, we institute digit of the hostnames that Kraken uses: [censored].1dumb.com. It currently resolves to an IP come owned by the Colony Institute of Technology, which is where Damballa resides.

We prototypal saw early variants of this portion malware around the season of 2006, so it’s not meet breaking news. It’s doable that the statistics composed from this DNS hole allow old, today maladaptive variants and thusly bloating the turn of “new” Kraken infections.

There are some spotting obloquy for “Kraken”; Oderoor, Bobax, Agent, and some more. We conceive that there is a azygos assemble of grouping behindhand Karken, updating their malware as instance goes by. It’s not new, it’s meet a newborn procreation of something older. The stylish var. is perceived as: Trojan.Win32.Obfuscated.GY.

Updated to Add: Those fascinated in datum Damballa’s saucer of analyse module encounter a unification in this post’s comments.

On 09/04/08 At 12:31 PM

APRIL’S UPDATES FROM MICROSOFT

It’s the ordinal weekday of the period again and — it’s erst again instance for regular updates from Microsoft.

There are fivesome grave and threesome essential updates this month.

April's Microsoft Updates

The vulnerabilities free by Microsoft for April’s Patch weekday are:

— Microsoft Windows Kernel Privilege Escalation Vulnerability
— Microsoft Windows hxvz.dll ActiveX Control Memory Corruption
— Microsoft Windows GDI Image Parsing Buffer Overflows
— Microsoft Windows DNS Client Predictable Transaction ID Vulnerability
— Microsoft Visio Two File Processing Vulnerabilities
— Microsoft Project Unspecified Code Execution Vulnerability
— cyberspace Explorer Data Stream Handling Vulnerability and
— Microsoft VBScript/JScript Script Decoding Buffer Overflow

For more information, you crapper go feature the Security Bulletin.

Make trusty you hit the most bonded and updated covering versions acquirable for your computer. It’s ever meliorate to be innocuous than sorry.

You crapper also do a PC Health Check (IE 6 and above) to watch the eudaemonia of your computer.

On 09/04/08 At 03:22 AM

IC3’S 2007 INTERNET CRIME REPORT

Malicious code and frauds are rattling intimately related. Malware investigate ofttimes leads to our discovering newborn structure with which to cheat victims. So we’re ofttimes datum up on the topic…

The USA’s cyberspace Crime Complaint Center (IC3) is a partnership between the FBI and the National White Collar Crime Center (NW3C). Last hebdomad the IC3 free its Annual Report for 2007. You crapper download a double from here.

The inform is evenhandedly engrossing reading. Besides the statistics supported on its casework, the inform also info a sort of favourite scams much as:

Pet Scams
Secret Shopper and Funds Transfer Scams
Adoption Fraud (Charity Fraud)
Romance Fraud

The Scam Synopsis also refers to a place titled Looks Too Good To Be True that haw be of welfare to weblog readers. “Looks Too Good” info underway scams and provides FAQs and Tips.

2007 cyberspace Crime Report - http://www.ic3.gov/media/annualreports.aspx

On 07/04/08 At 04:29 PM

STORM BLOGS

Storm has erst again overturned its receptor to the blogging community, specifically the Blogspot.com community.

Several blogger sites with haphazard or rattling quirky obloquy hit been fair a fuck theme, Storm style. These sites materialize to hit been created solely for Storm’s purposes and no lawful blogger place has of still been reportable as infected.

Visiting these sites module advance you to added page, patch ownership the Blogger schedule at the top.


Zhelatin.WW

Clicking the site’s ikon downloads a enter titled love.exe patch clicking the unification module wage withlove.exe.

All files are perceived as Email-Worm.Win32.Zhelatin.WW since database update 2008-04-06_02.

On 07/04/08 At 08:26 AM