Saturday, 17 November 2012

Ransomware - A Major Threat To Internet Security

Ransomware is emerging as a major cybercrime strategy, threatening to oust fake anti-virus software as the most popular cyber-attack next year, new research by IT security firm Symantec shows.

A total of 2.8% of victims of ransomware pay a "ransom" of up to £280 to regain access to their computers which have been blocked by cryptoviruses. Victims are tricked into making the payments after receiving fake messages that look like they have been issued by police authorities. Such messages often tell users they must pay a penalty for browsing illegal content.



Cybercriminals pocket £3 million annually from blackmailing users to pay to free their PCs from the malicious software, with one criminal group having tried to plague 495,000 computers in just 18 days, Symantec said, as quoted by IT Pro.

The first cases of ransomware were found in 2009 and were mainly limited to Eastern Europe and Russia.

However, this type of cybercrime is spreading to Western Europe, the USA and Canada, Symantec said. Criminal gangs have been traced back to a single unidentified person who apparently creates ransomware on request.

As consumer demand shifts to mobile devices and the cloud, cyber-attacks will increasingly focus on Secure Sockets Layer (SSL) certificates used by mobile apps, Symantec believes. Meanwhile, according to an earlier report by IT Pro, security experts have identified a new malware strand that steals image files from PCs and dispatches them to a remote server.

Wednesday, 2 May 2012

Have You Been Called From 002538020308?

Many people report having been called from the international number 002538020308.


The scenario is like this: 


Always an english speaking foreigner (Indian sounding). Different name used on each call - Jess, Smith, Stephen, Wayne, & others.


Different Company names have included: Windows security center, Creative Solutions, MPC Help, Windows Service Center, Windows Security Maintenance, 24/7 PC Help, etc.


Sometimes they say they are calling "on behalf of Microsoft", or offer to do a free PC health check, or even directly tell you that your system has been compromised and it has got viruses.


Is this a SCAM?


The New Zealand Internal Affairs Anti-Spam Compliance unit is reiterating it’s warning about a cold caller who offers to fix a problem with home computers. It has received several calls and emails from people who have received similar calls.

Senior investigator Toni Demetriou says a Dunedin computer company had received an infected PC for repairs from a customer who had been taken in by the scamster and police were investigating.

“We now believe the calls are being made from overseas, not from New Zealand as originally suspected, and quite a lot of people are receiving them,” Mr Demetriou said.  “The caller can be quite convincing. On one occasion he handed the conversation across to a ‘supervisor’ in an attempt to make the call sound more professional and convincing. 

“He also gives various explanations for the calls such as phoning from a reputable and well-known international company, maybe a security and anti-virus vendor, suggesting the PC has been infected by a virus and needs repairs.

“The sole purpose of the call is to convince someone to login to a website.  They are given a website name and once they are at the website home page they are then given a six digit code to log into that website.

“Essentially what then happens is that the person is handing over control of their computer to the person they are talking with.   If you follow the instructions you will be allowing and authorising remote access to your computer.  Just about anything could then happen.

Viruses, malware, key logging software could be installed onto the computer.  Any information on the PC could be taken and any sensitive usernames or login credentials and passwords may also be logged and obtained as you continue to use your computer in the future.  If you log into your bank the information could be captured and your account compromised.  The computer may also become part of a botnet and used for spamming activities.”

Mr Demetriou said unauthorised access to a computer system is an offence under the Crimes Act.  Similarly, if the computer is infected through that unauthorised access and used for spamming activities, the Department of Internal Affairs, which enforces the Unsolicited Electronic Messages Act, would investigate.    

If anyone believes their PC has been infected and compromised the Department recommends that it is inspected and repaired by a computer servicing company. 

Wednesday, 16 November 2011

Facebook Blames ‘Coordinated Spam Attack’ for Surge in Porn Imagery

Facebook said today that a “coordinated spam attack” was to blame for the posting of pornographic and violent images on the news feeds of unsuspecting Facebook users.

The issue, which first started appearing on Facebook pages a couple days ago according to ZDNet, has generated a growing wave of revulsion online as some users took to Twitter to complain of graphic and lurid imagery that goes far beyond ordinary porn.

“I noticed Facebook porn in my friend feed. New feature? No. A Facebook ‘virus’ shows hardcore porn and violent,” tweeted Christopher Justice, a CEO of an Austin-based online design firm.  Justice later told Digits that he has asked employees at his firm, who use Facebook “like a telephone,” to proceed with caution.

In a statement this afternoon Facebook said that some Facebook users were tricked into pasting and executing “malicious javascript” in their browser URL bar, causing them to share offensive content without knowing it.  Facebook said that it is working on addressing browser vulnerability exposed by the bad code and that it has built “enforcement mechanisms” to shut down malicious Facebook pages and accounts.
“We’ve put in place backend measures to reduce the rate of these attacks and will continue to iterate on our defenses to find new ways to protect people,” a Facebook spokesman said.

Writing on the blog for Internet security firm Sophos earlier today, senior technology consultant Graham Curley said while the while the exact nature of the problem was not known, “What’s clear, however, is that mischief-makers are upsetting many Facebook users and making the social networking site far from a family-friendly place,” Curley wrote.

Facebook has a no-nudity policy and requires that members be at least 13 years old.  Users are encouraged to report questionable content via links on Facebook pages. The social network also removes pornography on its own initiative.

Digits contacted Curley for more guidance on what users can do.  Because details remain sketchy, he said, it’s hard to give advice. “However, we would continue to recommend that users tighten their privacy settings, lock down as much as possible their friends’ ability to tag them in posts and picture, and run up-to-date anti-virus software on their computers.”


He suggested that firms wishing to protect their staff from offensive content might consider blocking Facebook access until the problem is solved.

The problem comes as Facebook gears up to unveil a massive profile page redesign to its 800 million users. The redesign, called Timeline, will take each and every action a user has made on Facebook, and organize them chronologically.  As one can imagine, no one is going to want their online diary soiled by a speck of violent imagery.

Whoever or whatever is to blame, the damage needs to be contained and fast, wrote Curley. “It’s precisely this kind of problem which is likely to drive people away from the site.”







Tuesday, 1 November 2011

Symantec: Hackers Hit Chemical Companies

Cyber attacks traced to China targeted at least 48 chemical and military-related companies in an effort to steal technical secrets, a U.S. computer security company said Tuesday, adding to complaints about pervasive Internet crime linked to this country.
The targets included 29 chemical companies and 19 others that make advanced materials used by the military, California-based Symantec Corp. said in a report. It said the group included multiple Fortune 100 companies but did not identify them or say where they were located.
"The purpose of the attacks appears to be industrial espionage, collecting intellectual property for competitive advantage," said the report.
Security experts say China is a center for Internet crime. Attacks against governments, companies and human rights groups have been traced to this country, though finding the precise source is nearly impossible. China's military is a leader in cyberwarfare research but the government has rejected allegations of cyberspying and says it also is a target.
The latest attacks occurred between late July and September and used e-mails sent to companies to plant software dubbed "PoisonIvy" in their computers, Symantec said. It said the same hackers also were involved in attacks earlier this year on human rights groups and auto companies.
Symantec said it traced the attacks to a computer system owned by a Chinese man in his 20s in the central province of Hebei. It said that when contacted, the man provided a contact who would perform "hacking for hire."
Symantec said it could not determine whether the Chinese man was a lone attacker, whether he had a direct or indirect role or whether he hacked the targets for someone else. It called him Covert Grove based on a translation of his Chinese name.
The U.S. and Chinese governments have accused each other of being involved in industrial espionage.
Security consultants say the high skill level of earlier attacks traced to China suggests its military or other government agencies might be stealing technology and trade secrets to help state companies.
The chairman of the U.S. House of Representatives Intelligence Committee, Rep. Mike Rogers, said last month that Chinese efforts to steal U.S. technology over the Internet had reached an "intolerable level." He called on the U.S. and other governments to pressure Beijing to stop.
Another security firm, McAfee Inc., said in August it had found a five-year-long hacking campaign that it called Operation Shady Rat against more than 70 governments, international institutions, corporations and think tanks.
In February, McAfee said hackers operating from China stole information from oil companies in the United States, Taiwan, Greece and Kazakhstan about operations, financing and bidding for oil fields.
Thousands of Chinese computer enthusiasts belong to hacker clubs and experts say some are supported by the military to develop a pool of possible recruits. Experts say military-trained civilians also might work as contractors for companies that want to steal technology or business secrets from rivals.
China has the world's biggest population of Internet users, with more than 450 million people online, and the government promotes Web use for business and education. But experts say security for many computers in China is so poor that they are vulnerable to being taken over and used to hide the source of attacks from elsewhere.
Last year, Google Inc. closed its China-based search engine after complaining of cyber attacks from China against its e-mail service.
That case highlighted the difficulty of tracking hackers. Experts said that even if the Google attacks were traced to a computer in China, it would have to be examined in person to be sure it wasn't hijacked by an attacker abroad.

Wednesday, 10 August 2011

Hackers Threaten To Destroy Facebook!


Notorious hacker collective Anonymous on Tuesday threatened to “kill” Facebook on Nov. 5, according to a YouTube video spotlighted on official channels used by the group.
“Your medium of communication you all so dearly adore will be destroyed,” the group wrote in a transcript of its YouTube video. “If you are a willing hacktivist or a guy who just wants to protect the freedom of information then join the cause and kill facebook [sic] for the sake of your own privacy.”
Facebook did not immediately respond with an official comment about the threat.
Anonymous claims it is doing Facebook users a service because the company is “selling information to government agencies.” It also asserts that Facebook’s privacy controls are a joke and that users cannot actually delete their accounts.
“Everything you do on Facebook stays on Facebook regardless of your ‘privacy’ settings, and deleting your account is impossible, even if you ‘delete’ your account, all your personal info stays on Facebook and can be recovered at any time,” the group wrote. “Changing the privacy settings to make your Facebook account more ‘private’ is also a delusion. Facebook knows more about you than your family.”
Nov. 5 is Guy Fawkes Day, which commemorates when Fawkes and others placed explosives under the British House of Lords in 1605. The Guy Fawkes mask and story was popularized in the ten-issue comic series V for Vendetta and the movie based upon it.
The @YourAnonNews Twitter account appeared to confirm the video was actually issued by Anonymous, with a tweet on Tuesday night stating: “Remember remember the fifth of November the FaceBook treason and plot…”
The threat to destroy Facebook comes only a day after the group successfully hacked and defaced the Syrian Ministry of Defense’s website. Anonymous has gained much exposure in the last year with attacks on PayPal, Visa, Amazon, Bank of America, and various world governments. The group was blamed for the massive attack on Sony’s PlayStation Network but it denied involvement.
Even though Anonymous has had success in hacking some major websites in the past, it’s questionable that it would be successful against Facebook. When you consider that the hacking group has given Facebook several months to prepare for an attack, it’s extremely unlikely Facebook would be brought down. But when you’re talking about a group of hackers with an aim to sow dischord, you can never be certain.
The roughly made YouTube video issued by Anonymous can be watched below:


Tuesday, 9 August 2011

DefCon Kid Hacker Uncovers Zero-Day Exploit


 A number of media sources have made light of DefCon's "Kids Village", but a 10-year old hacker discovered an entire class of vulnerabilities and presented her findings as well or better than most of the conference's attendees.
The hacker goes by the handle CyFi, and she co-founded "DefCon Kids Village" -- a series of presentations for 60-odd aspiring hackers aged 8-16 who attended the conference in Las Vegas. The theme for the first year of the Kids Village was responsible hacking...although admittedly, some of the "white hat" skills demonstrated included lock picking and various Google hacks.
CyFi's own presentation was called "Apps—A Traveler of Both Time and Space, And What I Learned About Zero-Days and Responsible Disclosure." In it, she demonstrated how she could manipulate the clock on her cell phone to fool apps into thinking that more time had passed -- but there are a few other steps that CyFi, in the spirit of "responsible disclosure", did not spell out for the listeners.
"I'll show a new class of vulnerabilities I call TimeTraveler," CyFi's summary read. "By controlling time, you can do many things, such as grow pumpkins instantly. This technique enables endless possibilities. I'll show you how...Thank you AT&T, DEFCON, EFF and Lookout!!!!! :)"
The pumpkins were part of a social farming game that can be found on iOS and Android devices. Their slow growth (and CyFi's impatience) was the catalyst for the hacker's coding experiments. CyFi discovered that the code and clock alterations enable any number of changes to occur instantly within the framework of the game -- thus, the "new class of vulnerabilities".
In the true spirit of DefCon, CyFi di not divulge her 'real' name. Nor did she mention the names of the games that she'd hacked (i.e., "responsible disclosure"). However, she did proudly admit to being a "a ten-year-old hacker, artist and athlete living in California" who "really likes coffee, but her mom doesn’t let her drink it."

By James Lee Phillips, who is a Senior Writer & Research Analyst for IBG.com. With offices in Dallas, Las Vegas, and New York, & London, IBG is quickly becoming the leading expert in Internet Marketing, Local Search, SEO, Website Development and Reputation Management
     

Monday, 20 June 2011

Sega says 1.3 million affected by data breach


The hack that took down Sega's online gaming service late last week has affected 1.3 million customers.
That was one of the details confirmed by the publisher on Sunday.
A cyber attack on the publisher's Sega Pass service - a subscription-based feature that allows gamers to play unlimited Sega games online - forced the service to be shut down.
"We have identified that a subset of  SEGA Pass members emails addresses, dates of birth and encrypted passwords were obtained. To stress, none of the passwords obtained were stored in plain text. Please note that no personal payment information was stored by SEGA as we use external payment providers, meaning your payment details were not at risk from this intrusion," Sega wrote in an e-mail to its customers.
On Sunday, Sega confirmed 1.3 million people were affected but did not have an estimate for when Sega Pass would be back online. The company said it is working on increasing its security.
The Sega Pass website has been replaced with a terse message that reads, "SEGA Pass is going through some improvements so is currently unavailable for new members to join or existing members to modify their details including resetting passwords. We hope to be back up and running very soon. Thank you for your paitence." (sic)
This of course comes just off the heels of Sony's massive data breach which forced the Playstation Network offline for over a month, resulting in what is estimated to be billions of dollars in damages.
Unlike Sony's service, Sega Pass is not an e-commerce platform for other publishers, so the damage is limited only to Sega itself. But with such a large number of users affected, it isn't a small attack by any means.