Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Wednesday, December 26, 2012

IRONIC PRIVACY FAIL: Facebook Founder's Sister Suffers Photo Leak

Well, if the sister of Facebook founder Jerry Zuckerberg screwed up her own privacy settings, what chance do the rest of us have?

...Mark Zuckerberg's sister Randi has complained about a Facebook privacy breach.

Randi, the former head of marketing for Facebook and the executive producer of Bravo's reality series Silicon Valley, complained when Callie Schweitzer, director of marketing and projects at VoxMedia, posted a photo of Randi and her family (including Mark) reacting to the new Poke app. Randi originally circulated the photo on Facebook to her friends, but Schweitzer posted it publicly on Twitter:


...Zuckerberg and Schweitzer have since deleted the conversation, but according to BuzzFeed, Schweitzer originally wrote "@randizuckerberg demonstrates her family's response to Poke" with a link to the pic. Randi then replied "@cschweitz: Not sure where you got this photo. I posted it only to friends on FB. You reposting it on Twitter is way uncool."

The article implies that Schweizer was not actually connected directly to Randi, but had simply subscribed to her updates.

So the failure was presumably either user error by Randi or facilitated by the vagaries of Facebook's notoriously nebulous privacy settings.

It doesn't help that this particular incident follows hot on the heels of Instagram's (a Facebook acquisition) public relations disaster.

It remains to be seen whether Facebook will get this privacy thing right, balancing the need to generate top-line growth with the privacy requirements of a fickle user community.


Hat tip: BadBlue Tech News.

Tuesday, November 27, 2012

CLICK: Hotel Keycard Attack Just Got Real in Texas

Ruh roh:

You may remember a vulnerability in four million keycard locks presented at the Black Hat conference in July. Hacker Cody Brocious showed he could insert a device he built for less than $50 into the port at the bottom of the common hotel lock, read a key out of its memory, and open it in seconds...

...Two months later, it turns out at least one burglar was already making use of that technique to rob a series of hotel rooms in Texas. The Hyatt House Galleria in Houston has revealed that in at least three September cases of theft from its rooms, the thief used that Onity vulnerability to effortlessly open rooms and steal valuables like laptops...

...at least two other hotels in Texas were hit with the attack. Onity has been criticized for its less-than-stellar response to a glaring vulnerability in its devices. The Hyatt says Onity didn't provide a fix until after its break-ins, forcing the hotel to plug its locks' ports with epoxy. And even now, Onity is asking its hotel customers to pay for the full fix, which involves replacing the locks' circuit boards.

Sebastian Anthony has a suitable and pithy response to Onity's, eh, carelessness:

The hack in its entirety is detailed on Brocious’s website, but in short: At the base of every Onity lock is a small barrel-type DC power socket (just like on your old-school Nokia phone). This socket is used to charge up the lock’s battery, and to program the lock with a the hotel’s “sitecode” — a 32-bit key that identifies the hotel. By plugging an Arduino microcontroller into the DC socket, Brocious found that he could simply read this 32-bit key out of the lock’s memory. No authentication is required — and the key is stored in the same memory location on every Onity lock... The best bit: By playing this 32-bit code back to the lock… it opens. According to Brocious, it takes just 200 milliseconds to read the sitecode and open the lock.


As for how Onity justifies such a stupendously disgusting lack of security, who knows. Generally, as far as managerial types go, securing a system seems like a frivolous expense — until someone hacks you. In non-high-tech circles, hacks like this are par for the course — usually, a company doesn’t hire a security specialist until after its first high-profile hack. For a company that is tasked with securing millions of humans every night, though, it would’ve been nice if Onity had shown slightly more foresight.

My advice: bar the hotel room door and secure it with a chair against the door jamb. Oh, and don't leave valuables in the room safe either. That's easily hacked too.

(Just wondering: isn't it about time security hardware companies started taking security more seriously?)


Friday, November 23, 2012

ANOTHER REASON TO USE THE CHROME BROWSER: The 100,000 Star Experiment

Seriously, this is way cool.


Ready for a mind-blowing trip? Google‘s got you covered with its “100,000 Stars” Chrome experiment, visualizing our stellar neighborhood in a way you’ve never seen.

Using either your mouse or a trackpad, “100,000 Stars” lets you fly around in a sophisticated 3D graphic of our galaxy, taking a close look at the stars that are relatively close to Earth. Try zooming way out, where you can peer at the edge of the Milky Way, and see if it makes you feel like we did, finding ourselves wishing we could zoom out even farther.

Or you can click the “take a tour” button on the upper left to be swept away to the most interesting stars in our galaxy, or click on a star to get more info. And don’t miss the variety of views you can get, showing you the actual density of the stars in our galaxy. It’s spectacular.

Beyond its value as a fascinating toy, “100,000 Stars” is a demo of current web technology. It shows you 3D graphics and plays music by Mass Effect composer Sam Hulick. It accomplishes this magic using an alphabet soup of cool browser tech, including WebGL, CSS3D and Web Audio. And, you don’t need to be using the Chrome browser either. We noticed it works just as well in Firefox...

As Adam Koblim reminds us on the Google Chrome blog, the "mist of 100,000 measurable stars is a tiny fraction of the sextillions of stars in the broader universe."

Dude. Just check it out.


P.S.: If you don't use the Chrome browser, I'd highly recommend it. It's Google's free, high performance browser that can be downloaded in a jiffy.

Wednesday, October 17, 2012

SHOCKING: Hacker Demonstrates Ability to Kill Anyone With a Pacemaker Inside a 30-Foot Radius

Remind me, if you will, to get a secure pacemaker when I reach that stage of my life. That is, if Obamacare hasn't banned them or killed me by that point.

Hacked terminals capable of causing pacemaker deaths


IOActive researcher Barnaby Jack has reverse-engineered a pacemaker transmitter to make it possible to deliver deadly electric shocks to pacemakers within 30 feet and rewrite their firmware.

The effect of the wireless attacks could not be overstated — in a speech at the BreakPoint security conference in Melbourne today, Jack said such attacks were tantamount to “anonymous assassination”, and in a realistic but worse-case scenario, “mass murder”.

In a video demonstration, which Jack declined to release publicly because it may reveal the name of the manufacturer, he issued a series of 830 volt shocks to the pacemaker using a laptop.

The pacemakers contained a “secret function” which could be used to activate all pacemakers and implantable cardioverter-defibrillators (ICDs) in a 30 foot -plus vicinity.

Each device would return model and serial numbers.

“With that information, we have enough information to authenticate with any device in range,” Jack said.

In reverse-engineering the terminals – which communicate with the pacemakers – he discovered no obfuscation efforts and even found usernames and passwords for what appeared to be the manufacturer’s development server.

As we learned with Stuxnet, many embedded devices were never designed with security in mind. And it only takes one clever attack to raise awareness.

Hopefully our medical device, power and telecommunications companies are remediating these kinds of vulnerabilities as we speak.


Thursday, August 2, 2012

Geniuses at EPA get hacked: personal data of up to 8,000 employees exposed, including bank accounts and SSNs

And these are the masterminds who want to regulate all industrial activities in the U.S.?

EPA security breach exposes personal information of 8,000 people


A computer security breach at the Environmental Protection Agency exposed the Social Security numbers and banking information of nearly 8,000 people, most of them current employees, the EPA confirmed...

...The agency currently is funding about $5 billion under almost 700 active contracts, according to May 31 data... Included among the exposed information was Social Security numbers, bank routing numbers and home addresses...

...Federal agencies reported more than 40,000 security incidents that placed sensitive information at risk during 2010 — a 650 percent increase compared with five years ago, according to an October 2011 report from the Government Accountability Office.

Meanwhile, the EPA's delightful attempts to regulate CO2 -- now definitely proven not to affect global temperatures -- will cost America trillions.


Sunday, July 8, 2012

Keeping your online identity safe now that every tweet in history is going to be saved in the National Archives

Theresa Payton, writing at Infosec Island, has some solid advice for Twitter users.

We have mentioned before that Twitter will send every tweet to the National Archives and the Library of Congress, so watch what you tweet.

...New tools are popping up and they can unleash a treasure trove of data in moments.  For the 140 million and growing user base that tweets over 400 million tweets per day this might be a little more than alarming.

...In the early days, people were tweeting, uploading pictures with geocodes, doing location check ins.  Many felt like they were just sharing all this information with a small group of people.

But these tweets leave behind clues that tell bad guys, potential employers, people you might date, people you might want to forget a lot about you.

What you may not realize is, that all Twitter accounts are searchable.  To test it on yourself and loved ones, try a tool like Topsy  http://topsy.com/

Tips to Stay Safe:

1.  Tweet about a location AFTER you leave

2.  Think about the tweets you do, do they show a pattern of behavior that puts you in the best light for those that don’t know you?  do they provide patterns that you would not want a bad guy to see?

3.  If you post photos make sure geocodes are turned off unless you like someone tracking your digital tracks.

RESOURCES:

Here are a few of the Twitter search tools out there:
  • If you want to look for local tweeps that leave their location information turned on, check out Nearby Tweets: http://nearbytweets.com
  • If you want to see what tweets are the most popular, try searching on Tweetmeme: http://tweetmeme.com
  • Anyone that wants to track tweets by a specific location, including one on a Google Map, try Areaface: http://www.areaface.com

In general, disclose as little about yourself online as you possibly can. And a little misinformation always helps too.

Thursday, June 28, 2012

CFTC hacked: But don't worry, I'm sure they'll never get to your super-secret health records

Not to worry: it's only the U.S. Commodity Futures Trading Commission that got hacked, which regulates the nation's derivatives market.

Breach At U.S. Regulatory Agency Puts Employee Data At Risk

The U.S. Commodity Futures Trading Commission, which governs the nation's derivatives markets, has disclosed that it suffered a data breach in May, exposing the Social Security numbers and personal information of its employees.

According to a news report about the CFTC breach, an employee ath the commission received a phishing email on May 21 and input information into a fraudulent website. A third party was then able to illegally enter the employee’s account, which had access to personnel information, according to a copy of an email sent to agency employees that described the incident.

"The email account contained emails and attachments with the names, Social Security numbers, and possibly other sensitive personally identifiable information of certain individuals," according to the email description.

But I'm sure the hundreds of thousands of bureaucrats involved in health care will never click on a phishing email and expose Americans' most sensitive medical records.


Wednesday, June 27, 2012

Don't click on this!

After all, it could be a social-engineering attack.

McAfee and Guardian Analytics have revealed the results of a months-long study that uncovered a global financial services cyber-crime operation. "Operation High Roller" targeted the online banking accounts used by high-net worth individuals and companies.

The attacks ranged from the EU, to Latin America, and most recently to the U.S. All sizes of banks were targeted, from global institutions to local credit unions. As for the size of the thefts: "the total attempted fraud could be as high as €2 billion."

Initially, the infection pattern seen in Europe was similar to other SpyEye and Zeus fraud activities, but performed hands-free, automated transactions. This is the standard flow:

• A Phishing email is sent to individuals or businesses that bank with a specific financial institution
• The email contains a disguised link. When the victim clicks the link, they visit a web page that starts a malicious sequence:
  – The page contains a blackhole exploit kit or other similar framework. The kit will look for an appropriate vulnerability in the victim’s browser, and upon finding one, will load exploit scripts that compromise the victim’s computer.
  – The exploit script installs a Downloader Trojan.
  – The Downloader Trojan then will install SpyEye or Zeus on the victim’s device.
  – The next time the victim logs into online banking, the malware will check certain parameters, such as the type of accounts and account balances. If the client parameters are what the malware is seeking, the SpyEye/Zeus Trojan contacts the command and control server and pulls down the appropriate web inject for the victim’s financial institution. The web inject carries a JavaScript payload.
• The fraud process starts when the account holder subsequently attempts to log into his account from the infected computer
• The victim sees his standard, genuine bank portal, but it displays the fraudsters’ custom JavaScript web injection to capture the information needed for the victim’s bank
• The injected script takes control of the session and contacts the fraudsters’ server for specific instructions. It may insert content within the session, such as a transaction field or error message. For example, as the victim logs in, he may be asked to answer a security question and get an error. The error message creates the delay that allows the fraudster’s software to perform the transaction.
• At this point the victim has not actually authenticated and typically is stalled with a “please wait” message for about 60 seconds (see Figure 4).


• If during the automated attack, the financial institution requests a transaction authorization number (TAN), the fraudsters’ client-side web injection displays a fake TAN page to the victim and the malware proceeds as follows:
  – The malware collects the TAN from the victim’s screen and presents the authentic TAN to the financial institution to enable the fraudulent transaction, while delaying the victim from accessing their account.
  – The malware uses the intercepted credentials to initiate a silent, separate transaction to a mule account (either individual or business) or in one case, a prepaid debit card.
  – The malware looks up a valid mule account from a separate database, automating a traditionally manual step in the process. The transaction is performed in a hidden iFrame, a parallel instance of the online banking session on the client that operates in the background. The code navigates to the transaction page and initiates an automated form submission that adds the mule information.
• The user is allowed to proceed with the session
• The mule withdraws the money and converts it to a Western Union or Liberty Reserve payment that he remits to the fraudster. The mule retains a small percentage of the take, and the money is untraceable within a few days.
To conceal the theft, the malware will stay resident in memory on the victim’s computer. It will alter the victim’s bank statement to show a false balance, remove line items associated with the transaction, and block printing of statements that would show the true account balance and transaction sequences.

Put simply, don't click on any email you don't have 100 percent confidence in. Even one from me.



Sunday, June 24, 2012

How the "Flame" cyber-attack targeted Windows Update

The recently discovered malware called "Flame" has been termed "one of the most complex threats ever discovered". It targeted Windows Update -- a feature of Windows that continually updates Windows-based PCs as new security problems are discovered -- to deliver a malicious software package of amazing complexity.

For tech junkies interested in how the attackers co-opted Windows Update, this presentation by Alex Sotirov dissects the attack in exquisite detail.


Which in no way excuses the outrageous national security leaks by the Obama administration decried by Democrat and Republican alike.


Friday, June 1, 2012

Another day, another leak of highly classified information designed to benefit Obama 2012: Details of the Stuxnet cyber-attack on Iran revealed

The Sophos Naked Security Blog summarizes another leak of highly classified information published by The New York Times, which -- coincidentally, I'm sure -- is spun to benefit President Obama's reelection campaign.

The report comes from David E. Sanger, the Chief Washington correspondent at The New York Times and author of the upcoming book "Confront and Conceal: Obama’s Secret Wars and Surprising Use of American Power"... Here is a quick summary of the claims made in the report:

Feeling threatened by the possibility that Iran would enrich uranium at a nuclear facility at Natanz that could be used to create weapons of mass destruction, US President George W Bush initiated a plan to seize control of computer systems at the plant.


The first part of the plan (dubbed "Olympic Games") was to embed spying code that would send back information about the computer systems' operations and draw up a blueprint of how the computers controlled centrifuges at the plant. After months of waiting for the information to be relayed, the National Security (NSA) and Israeli computer experts created a worm (Stuxnet) that would allow them to attack from within the plant.

According to the report, the USA felt compelled to involve Israel in the plan to prevent the country launching a pre-emptive military strike of their own against the nuclear facility... The USA secretly built a replica of Natanz's computer systems, including centrifuges handed over by Libyan leader Colonel Gaddafi in 2003, to test their malware...

Tests were successful, and the worm's orders to slow down and speed up the centrifuge's delicate parts caused them to suffer damage. At one point, it's said that debris from a damaged centrifuge was laid across the conference table at the White House's Situation Room to demonstrate the malware's potential power.

With the malware deemed ready, it was introduced into the Natanz plant via infected USB memory sticks by spies and unwitting workers with physical access to computer systems... As centrifuges failed, Iranian workers would close down the systems looking for signs of sabotage - not realising that their computer systems were compromised.

Days before Barack Obama was inaugurated as US President, George Bush successfully urged him to continue the classified "Olympic Games" program...

The attacks on the nuclear plant's systems continued, but potential disaster struck in mid-2010, when it became clear that "an error in the code" had allowed Stuxnet to spread beyond Natanz's systems and infect computers in the outside world...

As usual, the Times tries to overly emphasize President Obama's involvement when, in fact, Bush 43 initiated the effort and reportedly had to beg his successor to continue the project.

To this day, Stuxnet remains the most amazing virtual ordnance in history.


Related:
The Illustrated Guide to Stuxnet
The 5 Most Amazing Details of the Stuxnet Cyberbomb
Juxtaposed Iranian Headlines o' the Day

Hat tip: BadBlue.com/tech.

Thursday, May 31, 2012

Traveling abroad? You may want to leave the laptop at home

Government Security News reports that international travelers should have absolutely zero confidence in the Internet connections provided by foreign hotels.

The FBI is warning traveling commercial and government laptop users that malicious programs can worm their way onto their machines through hotel connections overseas through bogus software updates.

A May 21 bulletin from the FBI’s Internet Crime Complaint Center (IC3) warns that malware disguised as innocuous software updates awaits unwary travelers as they log onto hotel-hosted Internet connections. The agency said recent analysis from its investigators and other government agencies showed that Cyber criminals are targeting travelers through pop-up windows while they connect to the Internet in their hotel rooms. Apparently, criminals set up bogus hotel connections to intercept traffic before the hotel guest can reach the legitimate hotel connection.

It said recent cases show the malware presents the traveler with a pop-up window telling them to update a widely-used software product.

In these instances, the travelers attempting to set up the hotel room Internet connection and was presented with a pop-up window notifying the user to update a widely used software product, it said. The pop-up window looks like a common software update notice, according to the agency. If the laptop user clicks on “accept” to install the update, they install the malware.

IC3 recommended all government, private industry, and academic personnel traveling abroad be extra cautious before updating software using hotel Internet connections. It also recommended checking the author or digital certificate of any prompted update to see if it corresponds to the software vendor. If it doesn’t, it may reveal an attempted attack, it said.

The only way to even try to mitigate these kinds of threats is to surf immediately to a known SSL proxy site (e.g., your company's SSL VPN). By surfing to a known SSL site first, you can avoid the most common man-in-the-middle (MITM) attacks.

A typical MITM attack delivers a non-SSL web page to your browser, but also includes some very special (and unwelcome) malware. The intent is to exploit your browser's vulnerabilities using specially crafted HTTP/HTML-based attacks. Or, in the case, the MITM attempts a social engineering attack, using the promise of a software update.

Surfing directly to a safe SSL site may help -- but isn't guaranteed -- to mitigate the threat. SSL to a trusted site is, in nearly all cases, impossible to MITM. But I say it isn't guaranteed because a hotel could deliver a landing page (e.g., to prompt you to enter the hotel's Internet pass-phrase) prior to letting you surf SSL. And that landing page could theoretically launch an attack.

The best advice would be to dispense with the laptop on your trip abroad. If you can't do that, travel with a pristine (newly imaged) laptop and then get it re-imaged when you return.


Tuesday, May 15, 2012

Chinese-made smartphones include lovely bezel design and a backdoor into all your data, but mostly a backdoor into all your data

The People's Republic of China (or PRC) is a land rife with slave labor, pollution, intellectual property theft, and repression of religion. In other words, it's Thomas Friedman's (pronounced: fried-man's) ideal society.

And the cyberwar that the PRC (or, rather, the People's Liberation Army or PLA) is waging worldwide, much of it against American assets, continues apace, unremarked upon by the President, his sycophants or the State Department.

Exhibit 9 million: A lovely backdoor installed on Chinese-made smartphones:

The ZTE Score M is an Android 2.3.4 (Gingerbread) phone available in the United States on MetroPCS, made by Chinese telecom ZTE Corporation.

There is a setuid-root application at /system/bin/sync_agent that serves no function besides providing a root shell backdoor on the device. Just give the magic, hard-coded password to get a root shell:

$ sync_agent ztex1609523
# id
uid=0(root) gid=0(root)

Nice backdoor, ZTE.


darn, geek.com says it is real.....

If anyone reading this owns a ZTE Score M Android smartphone, your device has been found to include a backdoor allowing root access without user authentication.
The discovery of the backdoor comes via a post on the text storage website Pastebin. It has since been confirmed via Reddit by Justin Case of Cunning Logic and TeamAndIRC. He has confirmed with someone at ZTE that the backdoor does indeed exist and that a fix is in the works.

Oh look, we'll just make a master key!  You locked that door?  :-)
Nice guys, nice.... oh and ZTE makes more than phones -- they're the 5th largest telecommunications manufacturer in the world. 

It's imperative that more Americans become aware of the danger to our information infrastructure posed by the PLA. I, for one, would be hard-pressed to trust any technology made in the PRC.

And that's a lesson that many companies have learned the hard way.


Tuesday, February 28, 2012

Google offers $1 million reward to hackers who exploit Chrome

There's security and then there's security.

Google has pledged cash prizes totaling $1 million to people who successfully hack its Chrome browser at next week's CanSecWest security conference.

Google will reward winning contestants with prizes of $60,000, $40,000, and $20,000 depending on the severity of the exploits they demonstrate on Windows 7 machines running the browser. Members of the company's security team announced the Pwnium contest on their blog on Monday. There is no splitting of winnings, and prizes will be awarded on a first-come-first-served basis until the $1 million threshold is reached.

...At last year's competition, Internet Explorer and Safari were both toppled but no one even attempted an exploit against Chrome (despite Google offering an additional $20,000 beyond the $15,000 provided by contest organizer Tipping Point).

Chrome is currently the only browser eligible for Pwn2Own never to be brought down. One reason repeatedly cited by contestants for its lack of attention is the difficulty of bypassing Google's security sandbox.

If you're still surfing with Internet Explorer, I would recommend giving Chrome a try. It's fast, secure and free. You can download it here.


Hat tip: @KimZetter.

Wednesday, December 28, 2011

Harbinger of Future Events: New York Times Emails Millions of Subscribers to Tell Them Their Subscriptions Are Cancelled

Paul Krugman hardest hit:

The New York Times mistakenly sent an e-mail on Wednesday to more than eight million people who had shared their information with the company, erroneously informing them that they had canceled home delivery of the newspaper.

The Times Company, which initially mischaracterized the mishap as spam, apologized for sending the e-mail. The people who received the message represented a cross section of readers who had given their e-mail addresses to the newspaper, said Eileen Murphy, a spokeswoman for the Times Company.

...The e-mail urged recipients to consider continuing their subscriptions to The Times at 50 percent off for 16 weeks. The message sent off a flood of Twitter reactions and calls to The Times...

...She said the e-mail had been sent by a Times employee and not Epsilon Interactive, a third-party service the company uses to communicate with subscribers.

I'm thinking this is just the first step in a self-fulfilling prophecy.


The 10 Funniest Passwords Exposed by the Stratfor Breach


10 ABC News: jonathan.d.greenberger@abc.com:stephanopoulos
 9 Goldman Sachs: joseph.aiken@gs.com:derivative
 8 MSNBC: gary.nease@msnbc.com:Seaweed1
 7 Goldman Sachs: amy.lee@gs.com:password
 6 New York Times: kewald@nytimes.com:9295
 5 Soros? david.steinberg@soros.com:secret
 4 Fred Burton, VP of Stratfor: burton@stratfor.com:stratfor
 3 Standard Bank: ravi.bhatia@standardbank.com:ravi
 2 Control Risks: jennifer.harbison@control-risks.com:research
 1 Goldman Sachs: muneer.satter@gs.com:bulls***

Bonus Banking Password UBS: paul.brewer@ubs.com:1234



Monday, December 26, 2011

Breaking: Statement on the 2.7 million emails obtained from Stratfor

More than 48 hours after it was rooted, the website of intelligence firm Stratfor Research remains down. In fact, as of this moment, even its temporary server (showing an "Under Maintenance" page) is inaccessible, perhaps due to an ongoing denial-of-service attack.

Via Wikileaks, the following statement describes some of the motives for the compromise.

In the wake of the recent operation by which Stratfor's servers were compromised, much of the media has focused on the fact that some participants in the attack chose to use obtained customer credit card numbers to make donations to charitable causes. Although this aspect of the operation is indeed newsworthy, and, like all things, should be scrutinized and criticized as necessary, the original purpose and ultimate consequence of the operation has been largely ignored.

Stratfor was not breached in order to obtain customer credit card numbers, which the hackers in question could not have expected to be as easily obtainable as they were. Rather, the operation was pursued in order to obtain the 2.7 million e-mails that exist on the firm's servers. This wealth of data includes correspondence with untold thousands of contacts who have spoken to Stratfor's employees off the record over more than a decade. Many of those contacts work for major corporations within the intelligence and military contracting sectors, government agencies, and other institutions for which Anonymous and associated parties have developed an interest since February of 2011, when another hack against the intelligence contractor/security firm HBGary revealed, among many other things, a widespread conspiracy by the Justice Department, Bank of America, and other parties to attack and discredit Wikileaks and other activist groups. Since that time, many of us in the movement have dedicated our lives to investigating this state-corporate alliance against the free information movement. For this and other reasons, operations have been conducted against Booz Allen Hamilton, Unveillance, NATO, and other relevant institutions. The bulk of what we've uncovered thus far may be reviewed at a wiki maintained by my group Project PM, echelon2.org.

Although Stratfor is not necessarily among the parties at fault in the larger movement against transparency and individual liberty, it has long been a "subject of interest" in our necessary investigation. The e-mails obtained before Christmas Day will vastly improve our ability to continue that investigation and thereby bring to light other instances of corruption, crime, and deception on the part of certain powerful actors based in the U.S. and elsewhere. Unlike the various agents of the U.S. Government, the hacking team that obtained this information did not break down the doors of the target, point guns at children, and shoot down any dogs that might have been present; Anonymous does not resort to SWAT tactics, and this is simply one of many attributes that separate the movement from the governments that have sought to end our campaign and imprison our participants. Of course, such points as these will not prevent our movement from being subjected to harsher scrutiny than is given to those governments which are largely forgiven their more intrusive tactics by virtue of their status as de facto holders of power in a world that has long been governed in accordance with the dictate that might makes right.

Incidentally, many of us are more than happy to proceed according to that amoral dictate if we find it to be necessary. And, increasingly, we have found it to be so.

Barrett Brown
Project PM
irc.project-pm.org


Sunday, December 25, 2011

Post-attack: Stratfor Research website still down after 24 hours

The website of intelligence firm Stratfor Research remains down more than 24 hours after it was rooted and defaced.

A comment on ZeroHedge by "Osgo" seems to summarize some of the key issues.

I find it astounding how people who just have no f'ing idea about INFOSEC, Anonymous, 4Chan, or Lulzsec... who still think AOL is the Internetz... are suddenly Armchair Warrior Commando Supremo, ready to wreak havoc upon enemies of capitalism... actually thinking that WikiLeaks, etc..is some sort of black-ops, Soros-scheming, FEMA camp-making endeavor ready to enslave their family, firmly ensconced in their gated community where most of the cars are shiny and their kids a little too clean... get some f'ing perspective, people, this is the Internetz equivalent of you driving around in your old '73 Camaro with a few too many Oly's in you as you took out your neighbors mailboxes, laughing with glee, later discovering your erstwhile girlfriend's angora sweater along with the twin treasures within.

Stratfor's site wasn't updated, patched well or maintained in a way commensurate with their public image. Indeed, it was a public secret that anyone could read ALL the articles in Google's cache... what they just went through is typical... Podunk site from a few years ago grows exponentially without proportionate security measures that EXCEEDED growth. While they hired and promulgated new authors, contributors and analysts with a pantload of letters after their names, they 'prolly didn't hire enough IT/web developers/security folks 'cause let's face it...they're usually considered a cost center, not a name that would bring in new subscribers/biz/accolades. I seem to remember they had open positions for interns... not pro's... go figure....

Every org. has growing pains... but the pain point here? The manageable risk that was unfortunately overlooked by "America's Private CIA" endeavor? By promoting and evangelizing themselves as an alternate intelligence organization, they failed to take into account good OPSEC. Here we have hundreds of records soon to be available, dead-drop names, sovereign ID's, aliases and a Who's-Who of people and corps. who just don't wanna be found....easily cross-referenced with other public disclosures... that any counter-intel org. could use to their great advantage. At this point it may even be an issue of maskirovka, but certainly the intrusion in no way approaches a sovereign level of expertise, IMHO...

This has got to be a flat-out awful Christmas for everyone involved with Stratfor. The company's website is a crucial element of its marketing and service delivery arms; yet, as Osgo implies, the organization's I.T. function may have received short shrift.


Saturday, December 24, 2011

Screenshots: Stratfor Research Website Pwnt by Attackers

The website of intelligence firm Stratfor Research appears to have been defaced and then DOSed (suffered a denial-of-service attack) by attackers.

The message traffic (below) -- if accurate -- portrays a defiant IT manager offering a, eh, perhaps unwise challenge.

The Google cache recorded some of the content including shadow files and other sensitive info apparently rooted from Stratfor's servers. I've tactfully redacted some of the more sensitive info.

// OH STRATFOR. IF YOU ONLY KNEW WHAT ALL IS ABOUT TO GO DOWN.
// 'BUT WAIT', YOU ASK. 'IS THIS IT?' 0H N0, WE GOT MORE IN STORE...
// BUT FOR NOW, SOME INSPIRING WORDS OF WISDOM FROM IT MANAGER FRANK GINAC:

"You do realize how preposterous it is to suggest that stratfor simply
shutdown completely for 2 days, right? The plan that you've attached paints a
gloom and doom picture claiming no chance that such a move will succeed. Does
that really seem a rationale conclusion?"

// YOU DONT EVEN KNOW THE EXTENT OF THE GLOOM AND DOOM WE HAVE PLANNED, FRANK


"Attended the TakeDownCon security conference. Focus of the conference was on
wireless and mobile security. No vendors pushing product or service at this
conference. Instead, great presentations by renowned white hat hackers (good
hackers) and security experts. Bottom line is that no mobile platform is
secure, including the Blackberry, but there are best practices that minimize
the risk of their use within the enterprise. We will be incorporating these
best practices in our operation over the coming months."

// INCORPORATING PRACTICES FROM "GOOD WHITE HAT HACKERS"? HOW'D THAT WORK OUT?

"It blew my mind to discover that our email server backups are being stored on
the same physical server. I'm affectionately referring to these little
discoveries as 'Mooney turds'."

// SO SAD WE RM'D YOUR MAIL SERVER AND ALL BACKUPS, FRANK

"Most if not all of us use professional and social networking sites like
LinkedIn and Facebook. All offer levels of privacy ranging from wide open
where everyone can see your profile, activities, and posts to closed allowing
only your immediate connections (or friends) access. As a private intelligence
company we must all take extra care to protect our personal information from
those who would use that information to exploit us personally or
professionally. Although we don't have hard and fast rules on how to set your
privacy settings nor do we restrict use of such sites, I suggest that you
temper your need to share with prudence and consider the business that we are
in. It's also important to check your privacy settings regularly to ensure
that the sites you use haven't changed the meaning or scope of privacy
settings -- we've all heard or read the news regarding this practice at
Facebook. I suggest that you never include any information in your profile --
regardless of privacy setting -- that could be used to compromise your
identity. Specifically, never include: your birth date, your exact street
address (although this information can usually be found on the web quite
easily), your cell phone number, SSN or other government issued ID number
(that should be obvious), or any other information that someone could use to
compromise your identity if your account were compromised."

// EVEN WITH ALL THE BEST SECURITY PRACTICES LEARNED FROM THE "RENOWNED WHITE
// HAT HACKERS" WE STILL MANAGED TO STEAL ALL YOUR PERSONAL INFORMATION. UMAD?

Interesting, to say the least.

Update: Cryptome:

Subject: Important Announcement from STRATFOR
Date: Sat, 24 Dec 2011 19:49:58 -0500
From: STRATFOR

Dear Stratfor Member,

We have learned that Stratfor's web site was hacked by an unauthorized party. As a result of this incident the operation of Stratfor's servers and email have been suspended.

We have reason to believe that the names of our corporate subscribers have been posed on other web sites. We are diligently investigating the extent to which subscriber information may have been obtained.

Stratfor and I take this incident very seriously. Stratfor's relationship with its members and, in particular, the confidentiality of their subscriber information, are very important to Stratfor and me. We are working closely with law enforcement in their investigation and will assist them with the identification of the individual(s) who are responsible.

Although we are still learning more and the law enforcement investigation is active and ongoing, we wanted to provide you with notice of this incident as quickly as possible. We will keep you updated regarding these matters.

Sincerely,

George Friedman

STRATFOR
221 W. 6th Street, Suite 400
Austin, TX 78701 US

Update II: Police-Led Intelligence:

PLI is far more concerned about the state of the classified information provided by STRATFOR to the US Government... STRATFOR maintains separate classified and unclassified networks and information, and PLI understands that none of the STRATFOR data has been spared the attention of the hacking group. Of course, had STRATFOR placed any classified data on the server which we know has been hacked, they’d be in blatant violation of the laws of the US and of common sense, but it’s against the law why? Because it’s happened before.

If classified data has been compromised in the hack, it will create a larger impact – and response – than if it is unclassified commercial intel. In addition, Sabu, a leading member of the group, boasted on Twitter that... "Over 90,000 Credit cards from LEA, journalists, intelligence community and whitehats leaked and used for over a million dollars in donations..."

The AntiSec/LulzSec crowd, on the AnonymousIRC Twitter channel, has promised that this is the first of many attacks.


Tuesday, December 13, 2011

Beware the co-worker with a camera-equipped spywatch

Given the proliferation of micro-cameras and mobile devices, I guess any expectation of privacy we might have had ended, oh, about 12 minutes ago.

A story has reached me of one [particular IT worker]. I won't betray his place of employment, save to say that it is in a large corporation in New York. I will, though, betray his simple method of, well, amusing himself. He takes pictures of the ladies in his office with his watch. His gentlemanliness is such that he takes these pictures without them knowing.

What he does with them is still open to conjecture. However, it seems that his watch is the SVP MW09.

How can I possibly know this? This particular IT guy thinks there's nothing wrong with wandering around the office taking covert pictures. Perhaps he even believes it's part of a subtle seduction technique.

Oddly, last week he thought there was nothing wrong with admitting to one of the subjects of his covert photography what he is doing... [and she] asked that I might make others aware of the possibilities that these no doubt fine pieces of technology offer to the unscrupulous.

She told me: "How do I know what kind of pictures he already has and how long he's been doing this?"

...Clearly anyone in any place of work could buy one of these watches... So, as you wander into your office tomorrow morning, admire everyone's watch--and then check it for a hidden camera. Just, you know, for fun.

The next growth industry: counter-surveillance tools that can help detect and defeat spy-cams and the like.


Monday, October 31, 2011

Security: Humans are always the weakest link

Good article in today's Wall Street Journal describing the weakest link in the information security chain. The summary? You can have your firewalls, your intrusion prevention systems, your endpoint security systems, your anti-virus, your spam filters, your zero-day detection appliances, your application-aware firewalls, and the rest.

But then there's this:

Chris Patten called a large investment-management firm to report that he was going through a divorce and was worried that his wife had set up an account under a false name.

And with that story—entirely plausible but in this case a lie—a customer-service representative turned over customer account numbers and other details with a readiness that makes banks and other companies cringe.

Mr. Patten, a 35-year-old cybersecurity expert who was with the U.S. Air Force before he started working for a consulting firm in Kansas City, Mo., didn't actually use or sell the data, which he gathered in running a test for the investment firm of its security arrangements. But the ease with which the employee was persuaded to divulge the information points to a troubling trend, security experts and law enforcement officials say.

As banks and other large companies spend large amounts of money on building firewalls and using complex technology to fortify their systems, it is often their own employees who are letting identity thieves in the door...

User education and awareness are good starting points. And solid browsers that can help point out phishing attempts certainly help.

But the fact remains: social engineering is just too damn easy and there's no silver bullet. What's that old quote? "Make it idiot-proof, and someone will make a better idiot."