Internet Domain Registry

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Friday, 13 February 2009

Javeline Spins an Identity Theft Survey

Posted on 03:28 by Unknown
Kevin Poulsen at Wired Debunked Javeline's Identity Theft Report already, but I can't help myself from lending an outraged voice to the matter.

I'm not sure if I've ever seen such a blatant spinning of the facts to meet the desires of a research sponsor. Read this statement from Javelin's report, which was funded by Wells Fargo and Intersections, Inc., an online identity protection company:


Despite the hefty blame - largely perpetuated by the media - placed on the Internet and cyber-crime, online identity theft methods (phishing, hacking and malware) only accounted for 11% of fraud cases in 2008.


How did they reach that absolutely amazing and so absolutely inaccurate statement?

Let's look at the methodology. First, they did a survey of 4,784 people. Among them they found roughly 10% who called themselves a victim of identity fraud. 487 people.

Next they asked those 487 people if they knew where their fraud originated? 157 people said they did, and the other 330 people said they did not. Then they asked those 157 people how it occurred, and 11% of them said it had occurred "online" while another 11% said it had occurred via a "data breach".

According to the Pie Chart javeline then presents 43% of identity fraud victims had their wallet stolen while 19% had their data stolen during a transaction, and 13% of them had their data stolen through "friendly" identity theft - such as a family member using their knowledge of you to take out a loan using your credit.

What is their recommendation then?


Preventing theft of your information doesn't require spending money on security products or even a whole lot of effort. Practicing safe habits in your day-to-day activities can go far in reducing your risk of becoming a victim. Covering the keypad as you enter your PIN at the ATM, keeping sensitive documents in a locked drawer at home, or shredding old financial statements -- these are all considered basic precautionary measures that are easy and work to your benefit.


Really? Didn't you just say my three highest risks are having my wallet stolen, a transaction (which I would think of as a clerk or waiter stealing my credit card data) or a family member stealing my data? How does covering the ATM, and shredding old financial statements help with that? In fact NONE of the methods reported involved stealing my trash!

But let's get back to the big fallacy of the report -- the elephant in the room that Javelin chooses not to talk about.

HELLO! JAVELIN! YOUR DATA SAYS SIXTY-FIVE PERCENT OF IDENTITY FRAUD VICTIMS HAVE NO IDEA HOW THEIR DATA WAS STOLEN!!!



I can answer that one for you. It was stolen through Data breaches, Malware, Phishing, and Online. It was stolen by the waitress with the skimmer in her apron pocket, and it was stolen by the gas pump that silently reads your credit card data and sends it to the criminal. It was stolen by the website that you bought your kids Christmas present from, that used an insecure shopping cart and gave all its credit card and order data to criminals. It was stolen in the TJX Breach where more than 90 million credit cards were picked up, and it was stolen by the keylogger that is STILL on your computer that you can't find because no antivirus product can detect it.

According to Microsoft's Security Intelligence Report 5, which we coverend in this blog November 11th -- more than 11 million American computers had malicious trojans, backdoors, spyware, or password stealers on them in the first half of 2008!

Some security researchers are reporting that just ONE banking trojan -- Torpig -- stole the bank accounts of More than 300,000 people!. Since Torpig is almost impossible for the average computer user to detect and remove thanks to the "Mebroot" root kit, those people would all be examples of the folks who had no idea how their data was stolen.

WAKE UP, Javelin! Just because people notice their wallet is missing and don't notice the keylogger on their computer does not mean that there is not a risk online!

Although I'm sure your online identity protection survey sponsor had a big smile on their face as they handed you the check for your unbiased report.
Read More
Posted in | No comments

Thursday, 12 February 2009

New Trend: Stimulus Scammers

Posted on 09:03 by Unknown
With news of the President's Stimulus package dominating the media, it was only a matter of time before one of our long-time scammers decided to prey on the American public that way. Today we'll look at three "Stimulus Check" spam messages and show you how they are linked to a long-lived scam campaign.

Its been almost exactly a year since the Federal Trade Commission charged Member Source Media for deceptive advertising by email. In that case, A $200,000 Fine was levied against them for email advertisements claiming you could get "free" products and then requiring the consumer to jump through the hoops of completing multiple "offers" and likely never receiving any payment at all. You can read all the details of the case in the 18 page judgement for Civil Penalties and Permanent Injunctive Relief.

As you'll see below, the current case looks exactly like the previous one, which also included offers such as "Claim your $500 Target Gift Card Now". The current scammers seem to prefer WalMart and IKEA gift cards, but the sentiment is the same.

Here are three sets of Email, Web Entry Page, Personal Data Page . . . in each case the domain in the spam does not match the ultimate page to which you are rerouted.







While that certainly looks like they are asking where you want to send your stimulus check, they in fact have no intention of sending you any money.







Again, doesn't it look like they intend for you to receive a check? Be sure not to give them ANY of your personal information!







In whichever of these scams you choose to look at, the bottom line comes down to this. In order to receive any payment whatsoever, you have to complete their "rewards participation programs".

This isn't about getting a Stimulus check at all, and has nothing at all to do with the government. We can prove this to ourselves by looking at some of the other scams these hucksters offer.

For instance, if I choose "config=5421" on www.gifthouse.us.com, I'm being promised a $1,000 Visa Gift Card.
5420 = Free Pair of Fit Flops
5419 = Free Samsung Washer & Dryer
5418 = North Face Denali Jacket FREE!









So what's the scam?



Now that they have your email address, mailing address, telephone number, and in this case, estimated household income, its time for them to reveal their hand.

To get your check, you have to complete "2 Silver Offers, 2 Gold Offers, and 6 Platinum Offers" from their partners, all within the next 60 days, *AND* you have to personally recruit someone else who *ALSO* has to complete all the offers within 60 days. If you fail to complete all your offers, OR you fail to recruit a friend who completes all the offers, you don't get your check.

Some of the offers include . . .

Trying a Credit Reporting Service
Trying a Make-up Sample Kit
Trying Acai Berry Slim MD
Signing up for NetFlix
Signing up to learn about Government Grant Money
Signing up to learn how to make money on eBay
Signing up for Wrinkle Cream
Signing up for Silkies Hosiery
Taking a Video Professor computer lesson
Signing up for a Disney Movie Club
Trying the Cosmetique 5-Piece Sistina Collection
Signing up for a Disney Movie Library
Ordering Business Cards
Signing up to Learn a Language with OnLingo
Joining the Crafter's Book Club

and on, and on, and on . . .

Apparently the penalty of a $200,000 fine from the FTC is not enough of a threat to prevent this new group of scammers from continuing where Chris Sommer and friends left off last year.

If anyone in the FTC's Bureau of Consumer Protection would like many samples of such emails, just let me know. The UAB Spam Data Mine would be happy to provide!

We have many examples even just this year of
$500 Disney Gift Card
Victoria's Secret Gift Card
$1000 Wal-Mart Gift Cards
$1000 North Face Gift Card

Here are some of the "offers" you have to fulfill from "http://www1.freebotious.com" if you want to get your Free Jet Blue Airline Tickets:
Example Offers

If you don't like Jet Blue you can get Free SouthWest Tickets instead.

Of course there are still plenty of Free Laptops, like this one:
http://www.chooseyourskin.com/macbook/address.php
or this one:
from Simple Free Rewards
or get His and Hers Laptops

And we've still get SamSung Washers & Dryers.
Read More
Posted in | No comments

Wednesday, 11 February 2009

February 2009 Black Tuesday Report - Critical Exchange Server Patch

Posted on 03:58 by Unknown
We interrupt our regularly scheduled Valentine's Day Spam Countdown for an important message about Microsoft Black Tuesday. Yesterday's patches contain a special one for Exchange Server administrators.

The Patch, labeled MS09-003, addresses a vulnerability in "Transport Neutral Encapsulation", or TNEF attachments. These are the ones that non-Exchange users frequently see as a "winmail.dat" file. Basically, its possible for an attacker to create a Rich Text Format file (.RTF) or an X.400 attachment, and send it using TNEF in such a way that when your Exchange Server processes the message, it can corrupt memory on the server, allowing the attacker to remotely execute "arbitrary commands".

It is at least provable in theory that an email message can be crafted then, to execute any command it wants to on your Exchange Server.

The National Vulnerability Database labels this CVE-2009-0098 and gives this Overview:

Microsoft Exchange 2000 Server SP3, Exchange Server 2003 SP2, and Exchange Server 2007 SP1 do not properly interpret Transport Neutral Encapsulation (TNEF) properties, which allows remote attackers to execute arbitrary code via a crafted TNEF message, aka "Memory Corruption Vulnerability."

A second related bug allows an embedded MAPI command to be used to cause the Microsoft Exchange System Attendant service and other services that use EMSMDB32 to stop responding to messages, which would pretty much hang Exchange.

That sound pretty much like a Must Patch Now situation. Exploit code has not been seen in the wild yet, and Microsoft's Exploitability Index prediction is that "Inconsistent Exploit Code is Likely" with the most probable result leading to "Denial of Service". The "Remote Execution of Arbitrary Code" sounds like it would be much more challenging to pull off.

Bogdan Materna of VoIPShield Systems is thanked by Microsoft for reporting the underlying issue that lead to MS09-003.




The other big one this month is the standard Internet Explorer Security Roll-up patch. This one is MS09-002 and has two new ways for website authors to add code to their web pages to give them the ability to execute arbitrary code on your windows computer with the same rights as the logged in user.

The first vulnerability is called an "Uninitialized Memory Corruption Vulnerability" and deals with the security context for deleted items.

The second vulnerability is called a "CSS Memory Corruption Vulnerability" and is an attack based on how IE handles Cascading Style Sheets.

The recommended work-around is the same as it always has been for Internet Explorer. Create a "Trusted Sites" zone in your IE settings, and only allow programs to use ActiveX or Active Scripting if they are in your Trusted sites zone!

A special caution is given about surfing the web as Administrator as well . . .

"If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights."

This latter set of vulnerabilities was shared with Microsoft by Tipping Point and the Zero Day Initiative. Sam Thomas, who works with both, is credited with the CSS Memory Corruption.

We'll be back with more Valentine's Day Spam from the UAB Spam Data Mine tomorrow.
Read More
Posted in | No comments

Monday, 9 February 2009

Traveler Scams: Email Phishers Newest Scam

Posted on 06:20 by Unknown
Last Friday I had a phone call that sounded like an opportunity to look at a new scam from end-to-end. A retired school teacher in the Birmingham, Alabama area had received an email from a friend, claiming that she was stranded in London, and needed funds urgently to get home. The friend promised to repay the funds as soon as she arrived home safely.

The school teacher wondered if I was interested in the email from a computer forensics perspective. I asked her if her friend used Yahoo or Hotmail, because these are the main targets I've seen in Traveler Scams so far. She also told me that she had sent an email to her friend asking if she had really sent the strange email.

I told her that unfortunately her friend would not be able to reply, because she was almost certainly not in control of her email box. I laid out the normal course of a Traveler Scam for my new friend and asked her if she had a telephone number for her supposed traveler to see how many of our facts we could confirm.

In a normal Traveler Scam here is the layout:

Step One: The Traveler receives an email claiming that unless they reply to the email with their own email password their account will be closed. This is why we categorize this attack as an Email Phish. Someone sends an email, claiming to be a person in authority over your account, and claiming that unless you reply with a password something bad will happen.

Step Two: The Phisher then logs in to the Travelers account, using their real password. They then CHANGE the password, so that the Traveler can no longer access their email.

Step Three: The Phisher reads all the email in the Traveler's account, looking for people who might be "friends".

Step Four: All of the Traveler's Friends get an email, from the Traveler's normal email address, saying "I'm out of the country suddenly and (something bad has happened) and (I need you to send me money immediately to get home)"

Step Five: Because the email REALLY CAME from the Traveler's REAL EMAIL ADDRESS, the Friends are able to send replies, and receive answers, to convince them that this is a real email.

So, that's the theory. How did it play out in our particular example from last Friday?



Here is the email the Friend received from the Traveler, originating from an @hotmail.com address which the Friend regularly uses to correspond with the Traveler:


Sent: Saturday, February 07, 2009 3:45 AM
Subject: RE: URGENT RESPOND NEEDED‏

Hello,
I am sorry I didn't inform you about my traveling to Europe for a program called Empowering Youth to Fight Racism,HIV/AIDS,and Lack of Education,the program is taking place in three major countries in Europe which are Dublin,Scotland and England,I am persently in England,London.

I misplaced my wallet on my way to the hotel where my money,and other valuable things were kept.I will like you to assist me with a soft loan urgently with the sum of $2,800 US Dollars to sort-out my hotel bills and get myself back home.

I will appreciate whatever you can afford to send the money today.i'll pay you back as soon as i return,Let me know if you can assist. please use this information to send the money to me.I wait your quickly respond.




Of course there were many alarms that went off for the Friend. There are clear grammatical mistakes, in addition to the statement that "Dublin" is a "major country in Europe", which set off the alarms. So, what did the Friend do?

She emailed the Traveler to ask if this was really her. After she spoke to me, and then the Traveler, by telephone, she received an additional email reply from the hotmail account:


Sent: Saturday, February 07, 2009 3:45 AM
Subject: RE: URGENT RESPOND NEEDED‏

Please note the Email is legitimate,I am stranded in London now,I will appreciate whatever you can afford,I'll pay you back upon my return. dont deny me this help now, hence this happen to be The Greatest help you can render to me so far as a Friend I will feel honored if you dont ignore this request.


So, what was the experience like for the Traveler?

It was exactly as we had supposed it would be.

The Traveler received an email claiming to be from the Administrator of Hotmail.com, telling her that Hotmail was running out of space and was going to have to close any accounts which were not being used. In order to prove that it was really her using the account, she needed to reply to the email and give her name, email address, and password, so that they would know not to close her account.

The next time she tried to log in to Hotmail, she couldn't get in. Her password had been changed.

Note that this scam is NOT an original, but we have been hearing quite a few recent reports of it. A Google search on some of the phrases in the email will show that its been seen as early as May of 2008, with a big surge in September and October of 2008 as well, and that there is also an Asian version, which was seen as early as August 2008.

In this case, we also looked at the original headers on the email from the Traveler, who lives in Atlanta, Georgia. I wasn't too surprised to find that the Traveler's account was being logged into from Nigeria.

X-Originating-IP: [41.211.226.150]

inetnum: 41.211.192.0 - 41.211.255.255
netname: DOP1-20070404
descr: Wireless Broadband Internet service ,VSAT
descr: DIRECT ON PC LTD
country: NG
address: Direct-on-PC Limited
address: Plot B, Block 1
address: Illupeju Industrial avenue
address: Illupeju
address: Lagos
address: Nigeria
address: NG
phone: +234-1-2701700
fax-no: +234-1-2713554

It seems this scam is surging again . . . perhaps the "Yahoo Boys" have just rediscovered this scam...


I am in hurry writing you this message and am really sorry I didn't inform you about my traveling to Malaysia for a program called "Empowering Youth to Fight Racism, HIV/AIDS, Poverty and Lack of Education. The program is taking place in three major countries in Asia, which are Taiwan, Singapore and Malaysia. It has been a very sad and bad moment for me, the present condition that i found myself is very hard for me to explain.

I am really stranded in Malaysia because I forgot my little bag in the Taxi where my money, passport, documents, cell phone which i have all my contacts and other valuable things were kept on my way to the Hotel am staying, I am facing a hard time here because i have no money on me. I now owe a hotel bill of $1,400 and they wanted me to pay the bill soon or else they will have to seize my bag and hand me over to the Hotel Management. I need this help from you urgently to help me back home, I need you to help me with the hotel bill and i will also need $2,000 to feed and help myself back home. So please can you help me with a sum of $3,400 USD to sort out my problems here?


(the latter email included details on how to send a Western Union payment to their hotel)

Please let me know if you've received a Traveler Scam email. My research team is gathering samples to share with appropriate folks at email providers and law enforcement.

Gary Warner
Director of Research
UAB Computer Forensics
gar@cis.uab.edu
Read More
Posted in | No comments

Sunday, 25 January 2009

Dear Santa (or, the American Recovery and Reinvestment Act of 2009)

Posted on 13:26 by Unknown
Dear Santa,

We have been very good. Please send us $825 Billion worth of free stuff.

Sincerely Yours,

Congress


Turn on C-SPAN today and you can see that the above is the level of considered debate and opinion being given to the 625 page American Recovery and Reinvestment Act of 2009.

Still, if we're about to encumber $825 Billion of my children's funds, I thought it would be nice to see what Cyber, CyberCrime, and CyberSecurity Goodies might be waiting under the Christmas Tree.

For starters, we have the "Wireless and Broadband Deployment Grant Programs", established in section 6002 of division B of this Act, which will receive $2,825,000,000, of which $1,000,000,000 shall be for Wireless Deployment Grants and $1,825,000,000 shall be for Broadband Deployment Grants. I'd love to see the project plan and budget spreadsheets that came out to that nice round $1 Billion. (So, how much do we need to provide wireless access for everyone? Hmmm...when we add it all up it comes up to exactly $1 Billion. How convenient!)

Other things under Commerce Justice and Science that touch on technology:

Commerce


$650,000,000 for the Digital-to-Analog Converter Box Program

$100,000,000 for the National Institute of Standards and Technology for Scientific and Technical Research and Services.

$100,000,000 for "Industrial Technology Services", of which $30,000,000 shall be for Hollings Manufacturing Partnership.

$300,000,000 for "Construction of Research Facilities

$400,000,000 for the National Oceanic and Atmospheric Administration "for habitat restoration and mitigation activities"

$600,000,000 to NOAA for "accelerating satellite development and acquisition, acquiring climate sensors, and climate modeling capacity, and establishing climate data records."

Justice


$3,000,000,000 for the Edward Byrne Memorial Justice Assistance Grant Program.

$1,000,000,000 for Community Oriented Policing Services

State


$98,527,000 shall be available to State under the Comprehensive National Cybersecurity Initiative,

Health


$50,000,000 for "Public Health and Social Service Emergency Fund", to include Pandemic influenza preparedness, biomedical advanced research, Project BioShield, and Cyber Security.


Science


$400,000,000 to NASA, of which $250,000,000 shall be solely for accelerating the development of the tier 1 set of Earth science climate research missions.

$2,500,000,000 to the National Science Foundation for "Research and relate activities", with $200,000,000 earmarked for research facilities modification,

$400,000,000 more to NSF for "Major Research Equipment and Facilities Construction".

Energy


$18,500,000,000 for "Energy Efficiency and Renewable Energy" programs.

Social Security Administration


$400,000,000 for the contruction of a new National Computer Center

Testing of Health Information Technology


Section 4201. NIST - several new programs to develop more advanced health care technology.

Not much analysis here today, just thought these were some aspects of the Stimulus package that might be of interest to the readers here.

Oh - One other Cyber thing - throughout the bill, there is a requirement to document how funds are used by giving updates to the Internet website, "recovery.gov". I have to say that's a nice touch in the first legislation of the year -- here is the website where you MUST INFORM THE AMERICAN PEOPLE.
Read More
Posted in | No comments

Monday, 19 January 2009

Downadup / Conflicker Worm: 8? 9? 10 Million Infected?

Posted on 04:22 by Unknown
Its been quite a while since we've had a true run-away worm on the Internet, but if the claims of F-Secure are accurate, we've certainly got one on our hands now. At the end of this article are a list of the domain names ACTUALLY USED by the worm on January 13-16. The headlines have been ticking the number of infected machines forward for five days now, all based on F-Secure's successful monitoring of the worm via calculated domain names:

Jan 14 - Researcher: Worm infects 1.1 Million Windows PCs in 24 hours
Jan 15 - 2.5 million PCs infected with Conficker worm
Jan 15 - The Downadup Worm Hits 3.5 Million

Jan 19 - Fast spreading Windows virus already compromised 9 million computers
Jan 19 - Virus affects 10 million computers worldwide

The source for nearly every one of the thousands of media pieces about this worm has been F-Secure. In Friday's blog, they answered the many challenges about their methodology that they have received in their article Calculating the Size of the Downadup Outbreak. Briefly, each worm-infected computer has the ability to calculate a seemingly random domain name where it can receive new updates of the malware. There are as many as 250 possible domain names each day being calculated by the worm. As long as ANY of those domains are still live, the worm will be able to update itself to perform new functions. F-Secure has registered some of these domain names itself, and counts the number of infected computers which contact the domains it controls looking for an update. Each of the infected computers will show its IP address, as well as the number of computers which it claims to have infected itself. In a single day as many as 350,000 unique computers hit the domains controlled by F-Secure. Adding up the number of computers each of these computers claims to have infected -- and some are claiming more than 100 infections each -- is how F-Secure reaches its estimate, which they are calling conservative, knowing that many of the computers are choosing domain names other than their own with which to check in for an update.

The underlying vulnerability used to spread the Conficker worm was addressed by Microsoft with the patch MS08-067 back on October 23, 2008, the malware has only recently started a true run-away spread.

According to SC Magazine's Dan Kaplan, in his article No end in sight for massive Windows worm outbreak we haven't seen a worm this big since Nimda back in 2001.

Malware researchers report that the vast majority of the infected computers are on corporate networks, not home computers. There are two reasons for this:

As counter-intuitive as this sounds, many corporate networks have disabled the "automatic patching" that many home users have set as their default machine behavior. Because of a need for greater testing in corporate environments, many corporations believe it is acceptable to delay weeks or even months before applying recommended security patches from vendors. Any IT organization that willingly chose NOT to install this patch, after it was issued as a rare "emergency out of cycle patch" seriously needs to investigate whether their security staff needs training in Risk Management. HINT: If Microsoft breaks its Second Tuesday rule to issue a patch, they have performed the risk formla (Risk = Threats x Vulnerabilities x Value of Assets) and determined the Risk Is Very High!

Secondly, this is because the worm scans for a direct connection to the computer, rather than relying on human interaction. Most firewalls will actually block the worm, so the best way of catching it is to have an infected computer ON THE SAME SIDE OF THE FIREWALL as your machine. Because the other primary infection vector is an infected USB drive, employees who shuttle data back and forth to the house on a USB drive are often the Patient Zero for a corporate network outbreak. Once the worm arrives into an organization on an infected thumb drive, if the organization has not patched their machines, EVERY MACHINE IN THE CORPORATION is now an open target.

Because the worm can also spread by learning or guessing the Administrative password on network drives, organization that allow administrators to connect to every workstation machine on the network using the same administrative password share are especially vulnerable. As soon as the worm either guesses or learns via observation the Administrator password, every machine on the network can execute the worm code EVEN IF IT IS PATCHED! The Patch prevents the machine from being hacked via the Windows Server RPC Vulnerability. It does not prevent an Administrator from logging in to the machine and executing code, which is what the worm does if it correctly attempts a password. The Worst Case Scenario? A Domain Administrator visits an infected machine to try to disinfect it, sits down at the keyboard and logs in using his Domain Administrator password. As soon as that occurs, every machine on the network can be quickly compromised.

Computerworld's Gregg Keizer reported on January 15th that 1 in 3 Windows PCs remained vulnerable.

On the second Tuesday in January, the Microsoft Software Removal Tool was updated to be able to remove Conficker. You can follow the exploits of this worm and efforts to remove it at the Microsoft Malware Protection Center Blog and the F-Secure Blog.

A new Support article containing removal tips was released by Microsoft on January 15th: Virus alert about the Win32/Conficker.B worm.

The primary means for the virus to restart itself on an infected machine is the registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost

That key contains many critical Network Services which should be allowed to execute. If infected, the last entry on the list will be a key that was named with a random name generator. The example in Microsoft's article is "axyczbfsetg", but yours will be something different. There are many more steps to manual removal which can be found in the Microsoft support document above (KB 962007).

F-Secure has been posting lists of domain names which are being calculated by DownAdUp, their most recent list, for domains which would have been used over the weekend, contained exactly 1,000 domain names. 250 each for Jan 13, 14, 15, and 16. Rather than list all 1,000, I took the approach of running a WHOIS against each of the 1,000 domains on their list, and recording which ones were actually registered. So, here are the domains which ACTUALLY HAVE BEEN REGISTERED, out of the list of 1,000 potential names.

In all there were 57 domain names which had been registered out of the 1,000.

A tip of the hat to our friends at Georgia Tech, F-Secure, and Shadow Server, for reasons each will understand.

In what could be horrible news for certain domain name owners, five of the domains being automatically calculated on this list belong to actual domain owners. Apparently the malware's random domain calculator can randomly calculate some actual domains. Fortunately, of the domains thus affected only one is an actual company, (a German company, whose logs I would REALLY like to get my hands on!) while the other four seem to have been registered speculatively by domain investors. I've excluded all five from my results.

apleprodr.com
bbflvxif.info
cdmusnla.info
dxfvdadx.net
eonud.com
ezgcs.com
ezivhnbt.com
ffbnpzthj.info
ffvkwzear.org
fripjt.com
frwaqecvqk.info
fwotu.net
ggjdty.info
gkmwym.org
hhnvxjdms.info
hrypbb.info
hxgtuopbf.org
hxvyowd.info
ilklkc.net
jjydznuzxu.info
jrxgtdigb.info
jtpigznr.info
ktfadsqo.info
kxxqz.net
mirxdkbat.com
mkdjqosakje.net
mkfugrbowb.info
mrrdzwsz.biz
nmftyate.com
nsuzsjrp.info
pitoy.net
pvczx.info
qowte.com
qpqhcz.net
qqncaz.com
rofxb.net
ruvyhtdzdkm.info
rzowqlvco.com
tqreftcjgzm.info
vggdbocd.biz
vwmwpcs.info
wfivi.com
whtex.com
wshazbuck.cn
wvmsa.info
xhuwvozd.info
ybgcjpnzts.info
yeeollvintx.org
yykad.net
yzdmh.net
zbiqa.com
zullc.com
zwedpmoa.info

If any of those sites are in your logs for the past four days, Congratulations, and welcome to Conflicker.
Read More
Posted in | No comments

Thursday, 8 January 2009

US Army hacked as Gaza protest

Posted on 20:04 by Unknown
Today the anti-Israeli hackers for the first time brought their Cyber Propaganda War to Washington DC in the form of their attack against the United States Army's Military District of Washington website, www.mdw.army.mil

The defaced website can still be seen via Google's cache:





What is MDW?

MDW encompasses Fort Myer, Fort McNair, Fort Belvoir, Fort A.P. Hill, Fort Meade, Fort Holabird, Fort Ritchie, 12th Aviation Battalion at Davison Army Airfield, and Arlington National Cemetery.Mission is to respond to crisis, disaster, or security requirements in the National Capital Region (NCR), provide base operations support for Army and DoD organizations throughout the NCR, conduct official ceremonies, locally and worldwide, on behalf on the nation's civilian and military leaders.

According to Zone-H, websites that were hit by the group included:

soa.mdw.army.mil
mdw.army.mil
mdwweb.mdw.army.mil

They also hit the Italian UNICEF website, and the website www.nato-pa.int, the NATO Parliamentary Assembly website in Brussels, Belgium.

In recent months the group also defaced websites belonging to anti-virus vendors Eset and Nod32, as well as Microsoft's websites in Canada, Ireland, and China; Mercedes Benz, Subaru, Mitsubishi, Fiat, Aston Martin, and Shell; Harvard University, Goodyear, the NBA, and other high profile targets.

Although the group is now calling themselves "Peace Crew", the same membership was calling itself "Terrorist Crew" as recently as December.

In addition to the army.mil sites above, Agd_Scorp also defaced the website www.jfhqncr.northcom.mil. On a Turkish language website, the attack is claimed to be an SQL Injection attack against an ASP page on a Microsoft IIS 6.0 webserver.

This is the "Joint Force Headquarters, National Capital Region, of the Northern Command. Prior to the website being taken offline as a result of the hacking, the page read like this:

On Sept. 11, 2001 no one believed the National Capital Region would be a target for those who wish to do us harm. As a nation, we found that to be false. In direct response to the events of that fateful day, JFHQ-NCR was established as the responsible headquarters for land-based homeland defense, defense support to civil authorities and incident management in the national capital region. We have unique skills and are prepared to defend people, territory, critical infrastructures and sovereignty in a supporting role to a lead federal agency.

On a 24/7 basis JFHQ-NCR monitors security requirements; coordinating with the military services, the Department of Homeland Security and local first responders in identifying capabilities the military can provide in case of an emergency or National Special Security Event (NSSE). Once an event is designated, the command becomes a Joint Task Force-National Capital Region (JTF-NCR). JTF-NCR then directs military assistance to federal and civil authorities in safeguarding the nation’s capital.
Read More
Posted in | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Happy New Year! Here's a Virus! (New Year's Postcard malware)
    I've been busy this week looking at the various defacements (see ComputerWorld , and ABC News ) and other cyber attacks (see yesterday...
  • From Russia, With Love . . . new Postcard spam spies on your PC
    Isn't it nice to have friends who send you postcards? The UAB Spam Data Mine is especially fortunate in that way. Beginning the evenin...
  • Help stop the Osama bin Laden Videos on Facebook
    If you have teenage friends, or friends with poor security practices, you will probably notice that your wall has recently filled up with in...
  • Top Brands Imitated by Malicious Spam
    WebSense recently released an InfoGraphic titled "Top Five Subject Lines in Phishing Emails." for January 1, 2013 through Septemb...
  • A Dark and STORMy Night
    Just in time for the spookiest night of the year, the Storm botnet recruitment spam switched to a Halloween flavor. On the evening of Octobe...
  • TJX Update: The San Diego Indictments
    As promised, here is the update regarding the eight individuals charged in San Diego in connection with "the TJX bust". There wer...
  • Facebook Safety & Million Member Facebook Groups
    Two of my friends today invited me to join "Million User" facebook groups. Not that it matters really, but the two groups were: P...
  • Microsoft Security Intelligence Report 2H08
    The Microsoft Security Intelligence Report for the second half of 2008 has been released (the 184 PDF version, available from http://microso...
  • Operation Open Market: The Vendors
    When we wrote last week about Operation Open Market the court documents had not yet been released in a major multi-agency Identity Theft ca...
  • First 2008 Presidential Spam Campaign?
    Does Ron Paul suddenly have a strong support base among foreign computer owners with strange names and multiple personalities? or is it poss...

Categories

  • china
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • facebook
  • fake av
  • gumblar
  • koobface
  • law enforcement
  • malware
  • pharmaceuticals
  • phishing
  • public policy
  • spam
  • twitter
  • twitter malware
  • waledac
  • zbot

Blog Archive

  • ▼  2013 (21)
    • ▼  December (4)
      • Top Brands Imitated by Malicious Spam
      • 20 Million Chinese Hotel Guests have data leaked
      • Indian Banks targeted in multi-brand Phishing Attack
      • Paunch and the BlackHole/Cool Exploit Kit
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (92)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (6)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ►  2008 (101)
    • ►  December (7)
    • ►  November (17)
    • ►  October (11)
    • ►  September (10)
    • ►  August (22)
    • ►  July (12)
    • ►  June (3)
    • ►  May (7)
    • ►  April (5)
    • ►  March (2)
    • ►  February (1)
    • ►  January (4)
  • ►  2007 (31)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile