Internet Domain Registry

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Tuesday, 17 July 2007

New Job!

Posted on 10:10 by Unknown
Just wanted to let my loyal readers (yes, both of you!) know that I have taken a new position.

I am now the Director of Research in Computer Forensics at the University of Alabama at Birmingham. This newly created position is a partnership between the Computer & Information Sciences Department chaired by Dr. Anthony Skjellumand the Department of Justice Sciences chaired by Dr. John Sloan.

Our partnership was the cover article in a recent edition of UAB's magazine. The article, called Bugs in the System, discussed how CIS and JS were working together to create Alabama's first graduate certificate in Computer Forensics. The problem that we are facing is that CyberCrime professionals are either Justice Science majors, with a background in law enforcement but very little computer training, or Computer Science professionals, with a background in technology, but very little knowledge of law enforcement and legal practice. The new certification will be producing graduates who have a combination of knowledge in these areas BEFORE they enter the workforce.

My position, as Director of Research, will be seeking to develop new techniques, tools, and technologies for those who practice CyberCrime investigation, in the legal system, in traditional security companies, and in corporate and government security.
Read More
Posted in | No comments

Wednesday, 24 January 2007

(Blog alert: Taking Vista By "Storm")

Posted on 05:03 by Unknown
Just a note to say I have updated the Birmingham-InfraGard blog with a couple entries that might be of interest to readers here.
Read More
Posted in | No comments

Tuesday, 23 January 2007

Italian Court declares itself Friend of Pirates (or does it?)

Posted on 13:50 by Unknown
I couldn't believe this one.

The Associated Press reported yesterday that Italian high court says file-swapping is not illegal.

In this case, two college students from Turin Politechnic Institute were accused of piracy in 1994, after using the school's network to build a peer-to-peer file sharing network for their classmates.

On January 7, 2007, the Cassation (Italy's equivalent of the Supreme Court) declared that downloading music, videos, and programs from the Internet, even when they are clearly covered by copyright, was not illegal as long as the goal was not distribution for monetary gain.

George Assuma, the President of Italy's watchdog group on copyright law, SIAE (the Italian Society of Authors and Editors), points out that in fairness these students could only be judged by the laws as they stood at the time of their crime. (See his reaction at: Il Presidente Assumma su sentenza Cassazione: Reato downloading non autorizzato di opere.) Since that time, Assuma points out, there are at least four laws which have been added to the court's arsenal which may address these issues more appropriately, not the least of which is the European Union Directive on Copyright, which came into force in October of 2003. But do they help?

A look at the
EU Directive on Copyright shows that Article 5.2(b) says:

in respect of reproductions on any medium made by a natural person for private use and for ends that are neither directly nor indirectly commercial, on condition that the rightholders receive fair compensation which takes account of the application or non-application of technological measures referred to in Article 6 to the work or subject-matter concerned;


So it would seem that this may be a case where the initial panic will subside when people actually understand the true context of the case. The European Directive on Copyright, which would certainly apply in Italy, clearly says that EVEN FOR PRIVATE USE the "rightholder" must "receive fair compensation".



Let's hope the Italians get this cleared up in a way that the Associated Press can understand.

_-_
gar

Read More
Posted in | No comments

Wednesday, 17 January 2007

First CAN-SPAM Jury Conviction?

Posted on 04:19 by Unknown
Although its not the first conviction under the CAN-SPAM Act of 2003, the AOL phisher conviction this week is still newsworthy. At test? Can a Jury actually understand a spam case.

One of the arguments we've seen repeatedly as we try to get prosecutors to push forward with spamming cases is that they are "too technical" or "too boring" for jury appeal. The convictions so far have been largely based on the fact that, when faced with overwhelming evidence, spammers cop a plea.

So what was this case about?

Jeffrey Brett Goodin, a 45 year old resident of Azusa, California, hacked into a large number of EarthLink accounts (poor passwords and dictionary attacks, I believe), and used those accounts to send emails to AOL users. The AOL customers would receive a spam telling them that their AOL billing information needed to be updated, or that they would lose their service.

Following the link in the email would lead to an AOL phishing site - a fake website that looked very official - which would ask personal questions including their billing information.

Although the headline says "AOL Phisher Faces up to 101 Years in Prison", this blogger bets that on the June 11th sentencing we'll be lucky to see 7 years.

One note on "swift action" . . . Goodin was arrested on January 26, 2006 - so just 10 days short of one year later for a trial.

Goodin, who went by the creative hacker alias "The Hacker", had been a fugitive from the law for four months prior to his ultimate capture. On July 24, 2006, Goodin's photograph was posted on the FBI's "wanted" website as a fugitive. The original arrest press release, which credited the Los Angeles Electronic Crimes Task Force, and the Ontario Police Department with supporting the arrest, said Goodin faced up to 30 years in prison.

The additional charges occurred as a result of crimes committed during his four months of "fugitive" status after failing to appear for his bond hearing, according to this later Press Release from the LA FBI office. The additional charges includes Failure to Appear, and Witness Harassment.

Congratulations all around and all that, but ONE jury conviction in three years? With spam comprising 90% of all the email on the planet? Let's get that fixed!

_-_
gar
Read More
Posted in | No comments

Saturday, 6 January 2007

Evidence Handling

Posted on 15:39 by Unknown
Just a link to another article where I blog on Birmingham InfraGard:

Best Practices in Electronic Evidence

_-_
gar
Read More
Posted in | No comments

Friday, 22 December 2006

FAL$E HOPE$ @ CHRI$TMA$

Posted on 04:39 by Unknown
FAL$E HOPE$ was a Federal Trade Commission operation announced on December 12, 2006, which cracked down on Bogus Business Opportunities. Coordinated with the Department of Justice, the US Postal Inspection Service, and law enforcement agencies in 11 states, the report contains more than 100 law enforcement actions! (In the interest of full disclosure, these publicity operations solicit previously investigated cases from parties who wish to be included in the press release. Although the Operation was announced publicly in December of 2006, many of the activities had concluded as early as February of 2005.)

DOJ Actions were primarily in Nevada and the South District of Florida, but had some great cases themselves! In just one such case, AmeriP.O.S., individuals were told they were buying the right to mark kiosks for prepaid debit cards, phone cards, and internet access. Eleven defendants were charged and received hard time from between 24 and 135 months! Restitution was also ordered in the amount of $16,659,826.94! Altogether this group will spend 729 months in prison.

The original DOJ Press Release shows this to have been part of "Project Biz Opp Flop". In Biz Opp Flop DOJ documented 4,000 consumers nationwide who lost more than $60 million in these fraudulent business opportunities. AmeriP.O.S. promised that for their $12,000 investment, purchasers would received several Point of Sale terminals and support in establishing their own territory for the business. 1,500 people fell for the scam. Other companies, "Cash Link", "Tel 2 Net", "Pantheon Holdings" and "Global Resources" were offering the same offer. Global Resources advertised on television, the Internet, and by high pressure telephone calls, promising earnings of $6,480 per month (with a $14,000 minimum investment = two month break even!) 150 investors sent Global Resources $2.5 million! Pantheon got $19 Million from 1,500 consumers! Perfumes Unlimited, another case included in Biz Opp Flop, claimed consumers could earn $150,000 per year selling perfume in racks placed in stores. 150 consumers gave them $1.5 Million to invest. Accomplices were recruited to lie about their own experiences with the business as references to the success of the product.


The US Postal Inspection Service provided their Work at Home/Distributorshipos Case Briefs to the FTC which included many work at home schemes such as "Wealth By Mail, Inc", "GTEC", "Armand & Company", and many others, including one in my home town of Birmingham, Alabama.

In that case, "Employment Solutions" advertised a work at home envelope stuffing business, for which he would send a "start-up" kit for $32. Many folks received the start up kits, but they didn't receive the profits he described!

Perhaps the most successful case among the USPIS actions was "National Brochures / AAA Information Center". In this case, Malcolm Lincoln received 10 years in prison, and his wife three years, and were each ordered to pay $28,282 in restitution to 200 victims. Victims spent between $35.95 and $745.95 to receive their work-at-home business kits, and were promised they would earn between $4 and $21.82 per envelope stuffed. No one ever received a payment. In total over 1,000 people were victimized and the defendants earned more than $400,000!

Some of the claims were ridiculous! "EDI Health Claims Network" said that the customers medical billing business would earn as much as $1,200 per month with just one client! After consumers paid their $5,985, they were told their first client could be found by looking in their local yellow pages!

Many of the business opportunities in the FTC report promise returns of more than $1500 per week, and some as high as $150,000 in their first year!

One company, USA BEVERAGES, INC, (see the separate press release: FTC Halts Bogus Business Opportunity Scam) used Voice Over IP and prepaid cell phones to make it seem that they were calling from the local area, when in reality, they were making their pitches for coffee display racks from Costa Rica. Their website claimed it was a 12 year old company in New Mexico. With this 12 year history, the promise that franchisees would make "no less than $1,055.60 per week" if they operated 13 display racks must have seemed legitimate! Investors gave up between $18,000 and $85,000 each to learn that it was not true.
Read More
Posted in | No comments

Thursday, 21 December 2006

Pump & Dump: SEC gives us a peek!

Posted on 07:06 by Unknown
We all know that the most annoying spammers on the planet today are the ones who are sending out the image based Stock spam that seems to be most gifted at by-passing every form of spam filter. I frequently get the question: "How do these guys make money?"

This week, the Securities and Exchange Commission website has two interesting cases that give us some details. They illustrate two different methods of pump & dump. Account Theft, and False Profile spamming.

Let's look first at the password thief.

SEC Emergency Action Against Foreign Traders - SEC v. Grand Logistic

The subject of this action, Grand Logistic, is a company owned by Evgeny Gashichev who resides in St. Petersburg, Russia. His company operates in Estonia and is licensed as a corporation in Belize. The company exists to speculate in the penny stock market. The way it works is that Evgeny placed $30,000 in an online brokerage account, and began buying penny stocks. Curiously, these stocks, which had seen almost no activity, began to be bought and sold like mad after Evgeny would purchase them.

The charges from the SEC indicate that Evgeny would buy penny stocks from HIS account, and then would log in using stolen credentials to many other accounts, including E*Trade, ScottTrade, and TD Ameritrade accounts and make large purchases from other people's brokerage accounts - without their knowledge or permission - in volumes ranging from 6,000 to 71,000 shares! Then, when the price had risen sufficiently, Evgeny would liquidate the holdings in that account from his own profile.

So how did he do? Evgeny's initial investment grew from $30,000 to $383,000 in just seven weeks!

For more details see: The SEC's Complaint.



Now let's turn our attention to the Stock Spammer case "Red Hot Stocks". This is a case where we get to see the "end of the story", however, as usual, the question remains outstanding whether or not justice has been served. Still, the SEC is to be applauded for their action.

In the current SEC Final Judgement against Red Hot Stocks defendant Dieter Raabe, Raabe was ordered to pay $489,900 in disgorgement, plus prejudgment interest of $215,110 and post judgment interest of $16,300, and a civil penalty of $110,000, for a total of $831,310.

Wow! $831,310 sounds like a great deal of money! But wait, didn't we establish that in 2002 he had already earned $4 million from his fraudulent trading schemes!?!?


This case goes all the way back to an SEC Complaint in 2002 against Red Hot Stocks, where the SEC filing indicates that the defendant had earned more than $4 million through manipulation of the stock market.

In this situation, subscribers of the "Red Hot Stocks" website received a newsletter which contained a false or misleading statement about the dealings of a penny stock company. One of the biggest problems though, from SEC rulings, is that the profiles were made without disclosing that the author and promoter was personally planning to liquidate a large holding once his objectives had been met. There are rules dictating when an "insider" may sell their stock holdings after public statements are made. Raabe was previously accused with James E. Franklin. Franklin operated the companies "Vector Keel Ltd." and "Initial Public Offering Consultants, Inc." who would buy (or receive for services rendered) the stock. Then "Red Hot Stocks" would create online profiles for the companies, and spam the hell out of the profiles waiting for payday.

The actual Red Hot Stocks website is still available thanks to the Archive.org WayBack Machine. Here's a link:

Red Hot Stocks (WayBack Machine link to 1998)

Some of the stocks profiled there include:

AXPL, NTSA, NEOT, LCAV, EZCL, CMYN, GRB.V

So, this case brings to a close Pump & Dump activity which occurred through this "free stock tips" newsletter offered more than 8 years ago!






Many examples of similar scams can be found in the archives of Harvard University's CyberLaw archive on Stock Spam. Here is a great resource listing stock symbols touted by spam, produced by Laura Frieder and Jonathan Zittrain:

Stock Touts (From Harvard CyberLaw)

Their excellent paper, just released 16DEC06, is available here:

Spam Works: Evidence from Stock Touts and Corresponding Market Activity
Read More
Posted in | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Happy New Year! Here's a Virus! (New Year's Postcard malware)
    I've been busy this week looking at the various defacements (see ComputerWorld , and ABC News ) and other cyber attacks (see yesterday...
  • From Russia, With Love . . . new Postcard spam spies on your PC
    Isn't it nice to have friends who send you postcards? The UAB Spam Data Mine is especially fortunate in that way. Beginning the evenin...
  • Help stop the Osama bin Laden Videos on Facebook
    If you have teenage friends, or friends with poor security practices, you will probably notice that your wall has recently filled up with in...
  • Top Brands Imitated by Malicious Spam
    WebSense recently released an InfoGraphic titled "Top Five Subject Lines in Phishing Emails." for January 1, 2013 through Septemb...
  • A Dark and STORMy Night
    Just in time for the spookiest night of the year, the Storm botnet recruitment spam switched to a Halloween flavor. On the evening of Octobe...
  • TJX Update: The San Diego Indictments
    As promised, here is the update regarding the eight individuals charged in San Diego in connection with "the TJX bust". There wer...
  • Facebook Safety & Million Member Facebook Groups
    Two of my friends today invited me to join "Million User" facebook groups. Not that it matters really, but the two groups were: P...
  • Microsoft Security Intelligence Report 2H08
    The Microsoft Security Intelligence Report for the second half of 2008 has been released (the 184 PDF version, available from http://microso...
  • Operation Open Market: The Vendors
    When we wrote last week about Operation Open Market the court documents had not yet been released in a major multi-agency Identity Theft ca...
  • First 2008 Presidential Spam Campaign?
    Does Ron Paul suddenly have a strong support base among foreign computer owners with strange names and multiple personalities? or is it poss...

Categories

  • china
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • facebook
  • fake av
  • gumblar
  • koobface
  • law enforcement
  • malware
  • pharmaceuticals
  • phishing
  • public policy
  • spam
  • twitter
  • twitter malware
  • waledac
  • zbot

Blog Archive

  • ▼  2013 (21)
    • ▼  December (4)
      • Top Brands Imitated by Malicious Spam
      • 20 Million Chinese Hotel Guests have data leaked
      • Indian Banks targeted in multi-brand Phishing Attack
      • Paunch and the BlackHole/Cool Exploit Kit
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (92)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (6)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ►  2008 (101)
    • ►  December (7)
    • ►  November (17)
    • ►  October (11)
    • ►  September (10)
    • ►  August (22)
    • ►  July (12)
    • ►  June (3)
    • ►  May (7)
    • ►  April (5)
    • ►  March (2)
    • ►  February (1)
    • ►  January (4)
  • ►  2007 (31)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile