• How We Do It

    How We Do It

    Lorem ipsum dolor sit amet, consectetur adipiscing elit. Mauris sit amet nisl lectus, id sagittis metus.

  • Easy to Customize

    Easy to Customize

    Nunc sapien risus, molestie sit amet pretium a, rutrum a velit. Duis non mattis velit. In tempus suscipit sem, et consectetur.

  • Clean Design

    Clean Design

    Class aptent taciti sociosqu ad litora torquent per conubia nostra, per inceptos himenaeos. Nam consequat risus et lectus aliquet egestas.

  • Works Everywhere

    Works Everywhere

    Nullam a massa ac arcu accumsan posuere. Donec vel nibh sit amet metus blandit rhoncus et vitae ipsum.

  • Web Development

    Web Development

    Suspendisse eleifend nulla in est euismod scelerisque. Etiam lacinia fermentum nunc id imperdiet.

  • Color Picker

    Color Picker

    Nullam tortor tellus, iaculis eu hendrerit ut, tincidunt et lorem. Etiam eleifend blandit orci.

Showing posts with label Internet Crimes. Show all posts
Showing posts with label Internet Crimes. Show all posts

Saturday, June 16, 2012

LulzSec 'hacker' Ryan Cleary indicted over attacks on television networks

0 comments

Ryan Cleary, the 20-year-old Briton arrested over attacks on Fox and PBS television networks, has been indicted by a federal grand jury in Los Angeles.

LulzSec 'hacker' Ryan Cleary

 

Cleary, who is already jailed in the United Kingdom where he faces prosecution over similar charges, is accused of joining other members of LulzSec in harnessing compromised computers, known as a "botnet," to steal confidential information, deface websites or attack servers. He was indicted on Tuesday.
"Cleary is a skilled hacker. He controlled his own botnet, employed sophisticated methods and his broad geographic scope affected a large number of businesses and individuals," FBI spokeswoman Laura Eimiller said.
LulzSec, an offshoot of the international hacking group Anonymous, has taken credit for hacking attacks on government and private sector websites.
Anonymous and its offshoots, including LulzSec and AntiSec, initially focused on fighting attempts at internet regulation and the blocking of free illegal downloads, but have since taken on such targets as Scientology and the global banking system.
The charges come just over two months after accused LulzSec hacker Cody Kretsinger pleaded guilty in US District Court in Los Angeles to taking part in an extensive computer breach of Sony Corp's Sony Pictures Entertainment.
In March, court documents revealed that Anonymous leader "Sabu," whose real name is Hector Xavier Monsegur, had pleaded guilty to hacking-related charges and provided the FBI with information on fellow hackers.
According to the indictment released by the FBI, Cleary and his unnamed co-conspirators hacked into the computer systems of News Corp's Fox Entertainment Group and Sony Pictures Entertainment and stole confidential user information.
The indictment also charges Cleary and his co-conspirators of defacing the PBS website and launching "denial of service" attacks against an online gaming website and Britain's Serious Organized Crime Agency.
Cleary is charged with one count of conspiracy and two counts of unauthorised impairment of a protected computer. He faces a maximum sentence of 25 years in prison if convicted.
Eimiller said federal authorities would "allow the prosecution to take its course" against Cleary overseas before deciding whether to seek his extradition to the United States. He is next scheduled to be in court in the UK on June 25.
Anonymous, and LulzSec in particular, became notorious in late 2010 when they launched what they called the "first cyber war" in retaliation for attempts to shut down the WikiLeaks website.
They attacked websites including those of MasterCard Inc, which had tried to block payments to WikiLeaks after apparent pressure from the US government following the release of thousands of diplomatic cables.
Source: agencies

 



Read more

Thursday, May 31, 2012

Iran claims to have beaten 'Flame' computer virus

0 comments

Iran claims it has defeated a powerful computer virus that has boasted unprecedented data-snatching capabilities and could eavesdrop on computer users, a senior official said. 

Iran's government-run Computer Emergency Response Team Coordination Center has said the Flame virus was focused on espionage

 

Ali Hakim Javadi, Iran's deputy Minister of Communications and Information Technology, told the official IRNA news agency that Iranian experts have already produced an antivirus capable of identifying and removing "Flame" from computers.
Iran's government-run Computer Emergency Response Team Coordination Center has said the Flame virus was focused on espionage.
Javadi did not say whether any Iranian government bodies or industries were affected by the virus.
"This is no longer about stealing card data or passwords, the stakes are so much higher, and security procedures must follow suit," said James Todd, an expert in virus attacks at specialist firm, FireEye.
"The next big trend in IT security was always going to be cyber-espionage, given the potentially huge rewards for the taking. This is particularly true if hackers can infiltrate information relating to policy, patents, intellectual property and R&D plans."
Iran did not release any details of the tool to combat the most complex cyber attack. Its computer emergency response and co-ordination centre said the programme had identified and removed the malicious software.
Since Iran's nuclear facilities and oil ministry have been the target of past virus attacks, Tehran has accused the US and Israel of trying to sabotage its technological progress.


Read more

Tuesday, May 29, 2012

Flame: anatomy of a super-virus

0 comments

The Flame espionage virus, believed to target Iran, among others, has been identified as the most complex malicious software ever discovered. 

Flame : most complex malicious virus.

 

Security experts are still dissecting the Flame code, which is many times longer than any other computer virus, but some facts are clear:
Basics
Up to 20MB file (by comparison Stuxnet, which dmaage Iranian uranium centrifuges, is around 500KB)
Infects Windows XP, Windows Vista and Windows 7 systems
Detected in Iran, Russia, Egypt, the West Bank, Lebanon, Syria, Sudan
Espionage capabilities
Taking screenshots
Covert sound recording
Intercepting keyboard strokes
Monitoring network activity
Detects 100 types anti-virus software and conceals its presence
Creates a database to store stolen information
Communicates with command and control servers over encrypted channels
Propagation
Via USB sticks
On local networks via printers
As a self-spreading internet “worm” when directed by its controllers

source : Telegraph.co.uk


Read more

Monday, April 9, 2012

Downing Street website also taken down by Anonymous

0 comments

The Downing Street website was also disrupted by computer hackers who targeted the Home Office in protest at the Government’s extradition policies. 

The Anonymous hacking network uses as a logo the mask from the comic V For Vendetta
The Anonymous collective has vowed to target British Government sites every week, bringing them offline by overloading them with traffic.
So-called “hacktivists” were able to launch their cyber attack on Saturday night despite announcing it days in advance, raising questions about the effectiveness of Whitehall internet security.
The British branch of Anonymous – a loose global collective of computer hackers who often target law-enforcement websites – first advertised “#OpTrialAtHome” last Monday.
A poster featured the photos of three British citizens who have been sent to the US to face trial – Gary McKinnon, Richard O’Dwyer and Christopher Tappin – together with the slogan “Fight extradition”.
It included the address of the Home Office website and the direction to “charge ya lazers” on Saturday at 9pm GMT.
Supporters would understand this to be an order to join in a “distributed denial-of-service attack” on the website, in which thousands of computers are used to send a flood of requests to visit the victim’s homepage, causing its servers to buckle under the demand.
At the appointed hour, Anonymous Twitter feeds ordered followers to “fire your Laz0rs”, and soon reported “Tango Down” as the target was hit.
Screenshots showed that the Home Office website was inaccessible from 9pm and service was reportedly patchy until Sunday morning.
A Home Office spokesman said: “The Home Office website was the subject of on online protest last night.
“This is a public-facing website and no sensitive information is held on it. There is no indication that the site was hacked and other Home Office systems were not affected.
“Measures put in place to protect the website meant that members of the public were unable to access the site intermittently.
“We will continue to monitor the situation and take measures accordingly.”
The activists also brought down the Downing Street website at about 10.30pm, but a spokesman for the Prime Minister said it only lasted for a “couple of minutes” and there was no suggestion of it being hacked into. The Ministry of Justice denied the hackers’ claims that its website had also been taken offline.
Anonymous explained on Twitter: “It’s a digital protest which is different [from] hacking. UK want their government to listen. We can do it as long as it takes.
“Selling your citizens to foreigners is not acceptable! We are Anonymous, we do not forget, we do not forgive.”
Another message from the group said: “EXPECT a DDOS (Distributed Denial of Service) every Saturday on the UK Government sites.”

 



Read more

Tuesday, April 3, 2012

Lulzsec suspect Ryan Cleary jailed

0 comments

Ryan Cleary, the British teenager arrested for allegedly hacking with the LulzSec group has been sent back to jail for breaching his bail conditions. 

The Lulzsec logo. The hacker group has been implicated in several security breaches in recent months

 

Cleary, 19, is said to have contacted LulzSec leader Hector Xavier Monsegur (alias "Sabu"), who was himself revealed to have betrayed LulzSec members, despite his bail terms banning web use.
Cleary has been charged with launching distributed denial-of-service attacks against organisations including the Serious Organised Crime Agency, the International Federation of the Phonographic Industry (IFPI) and the BPI. He is said to have breached his bail conditions over Christmas and is now being held in Chelmsford jail after being arrested on 5 March.
Cleary’s lawyer Karen Todner said that he had sent a handful of electronic messages to Monsegur.
Cleary, who suffers from Asperger’s Syndrome, is now due to reappear before a judge in May.
He was originally detained in a "pre-planned intelligence-led operation” in cooperation with the FBI, the Metropolitan Police said in June.
He was questioned at a central London police station on suspicion of Computer Misuse Act and Fraud Act offences. Computer forensics specialists were also examining a "significant amount of material" seized from his address.
LulzSec's victims have included Sony, the US Senate, the NHS and security companies linked to the FBI.
The group splintered from Anonymous, a digital activism collective best known for its cyber attacks last year against corporations such as PayPal that withdrew online services from WikiLeaks. Anonymous has been under investigation for several months by British and American authorities. More than 80 alleged members have been targeted worldwide.


Read more

Friday, January 13, 2012

How to tackle the risks of cyber attacks

0 comments

It's impossible to be completely secure online, especially as more and more devices are connected. Lee Howell of the World Economic Forum suggests four ways to minimise the risks. 

Viruses such as Stuxnet hint at what may become possible

 

Any device with software-defined behaviour can be tricked into doing things its creators did not intend. Any device connected to a network of any sort, in any way, might be compromised by an external party – there are no provably secure systems, only systems whose faults have not yet been discovered.
These two axioms for the cyber age are proposed in the World Economic Forum’s Global Risks 2012 report, published today. Experts who were asked to nominate the risks the world’s leaders should be addressing over the next decade focused heavily on the possibility that the dark side of connectivity could become increasingly apparent, just as over the last decade the Internet’s power for good has been amply demonstrated in realms from business and personal relationships to popular protest.
Viruses such as Stuxnet hint at what may become possible given a 10-year time horizon. Stuxnet is a malicious code, which in 2010 attacked a specific piece of IT equipment — the Siemens controllers used in nuclear facilities in Iran. Its impacts are disputed, but it shows how a virus could conceivably trigger a meltdown in a functioning nuclear power plant, turn off oil and gas pipelines or change the chemical composition of tapwater.
As more and more of our daily lives come to depend on interconnected systems, the axioms for the cyber age become ever more relevant. Consider the growing trend for “smart” electricity meters to be installed in homes, allowing energy use to be managed more efficiently at the network level. The benefits are obvious. But, might a hacker be able to gain access to the electricity network via a domestic meter?
Such things are impossible to rule out with certainty, but it is also easy to be alarmist. Experts point out that viruses as sophisticated as Stuxnet require a team of software developers and intimate knowledge of the target’s security measures. For skilled individuals bearing a grudge, the havoc that can be wreaked online is currently limited to the embarrassing rather than the life-threatening. Nonetheless, the barriers to entry in cybercrime and cyberterrorism are falling all the time.

How do we minimize the risks from the dark side of connectivity? There are four main challenges.
First, online security is a public good: costs are borne privately, but benefits are shared. When an individual weighs the cost of investing in antivirus software, he or she does not account for the benefits of protecting other users from spam and APT attacks if his or her computer is infected with malware. Firms have an incentive to invest in cybersecurity measures that protect their own interests, rather than contributing to the health of the critical information infrastructure that constitutes the systemic whole. In addressing this challenge, we need to find new ways to support collaboration.
Second, we do not yet fully understand how social norms are shaped in the virtual world. Why is it that many people who would be ashamed to admit stealing a DVD from a shop will happily discuss illegally downloading a movie? What are the rules of acceptable engagement for corporate and industrial espionage, especially where the line between private and public enterprise is blurred? To what extent can “hacktivist” movements be accommodated as a virtual expression of legitimate civil disobedience?
Only by understanding and working with human motives can challenges be defined and solutions explored. The key to meeting this second challenge is more research and a greater willingness to engage in frank discussions.
Third, the information we have is sometimes skewed. Vendors of online security products have an interest in talking up the threats of cybercrime, while victims of cybercrime often have an interest in remaining silent. It is therefore very difficult for firms and organizations to get a clear picture of the true levels of the risk and needs for investment. We need better access to information to form policies which will improve global cybersecurity and create efficient markets.
Finally, incentives are misaligned. Lacking legitimate outlets for their talents that are comparably lucrative, hackers are drawn to the thriving black market in “zero-day exploits”, where pieces of code that take advantage of vulnerabilities in software applications can sell for hundreds of thousands of US dollars.
The axioms for the cyber age remind us that there will always be holes in new software. We need to develop better mechanisms to incentivize the well-intentioned to find them first.



Read more

Saturday, October 29, 2011

Hackers go after Facebook sites 600,000 times every day

1 comments

Hackers are breaking into hundreds of thousands of Facebook accounts every day, the social network has admitted. 

Facebook is ramping up security measures.

 

Out of more than a billion logins to the website every 24 hours, 600,000 are impostors attempting to access users’ messages, photos and other personal information Facebook said.
The figure is the first time that Facebook has revealed how it is bombarded by hackers on a daily basis.
It was revealed as part of a Facebook blog post announcing a couple of new security measures being implemented across the site over the coming weeks to tackle these sorts of breaches.
Security experts have said the figure is a “big concern” and that people need to be more careful when choosing their passwords and responding to offers supposedly from friends on Facebook.
Graham Cluley, a senior technology consultant at Sophos, a computer security organisation, said: “When a Facebook login is compromised, it means that someone else, the hacker, has taken control of that account.

“When a hacker takes over a user’s Facebook account, they can post images, send messages and access all of that person’s private information in one fail swoop. Facebook has had a lot of security issues which it is now trying to address.”
The most common reason for hackers to breach Facebook users’ accounts is so that they can spread scams and send false offers to the member’s friends in an attempt to sell counterfeit goods and benefit financially.
Cluley said it was becoming easier to hack into more users’ Facebook accounts as thirty per cent of people online are using the same passwords across all of their digital accounts – making it simpler for hackers to control a person’s entire web identity.
He also warned that growing numbers of teenagers are hacking into the Facebook accounts of their school rivals in order to post malicious messages and photos on their behalf.
Facebook declined to comment.
Increasingly more people are also duped into sharing their login details on fake sites, a process called phishing, which gives hackers access to passwords and email accounts.
Security experts have advised people to choose complicated passwords in order to avoid any of their personal online accounts being hacked and to have different ones for every single digital service they use.
It is understood that out of the approximate 600,000 ‘compromised Facebook logins’ a day, not all of them are successful as Facebook is able in certain circumstances to block some pre-emptively using location technology.
The social network is rolling out two new features in an attempt to further protect Facebook users’ security. ‘Trusted Friends’ is a tool which will allow users to nominate three to five ‘trusted friends’ to be sent login codes if a person is locked out of their account, having had their password changed by a hacker.
The site is also introducing passwords for apps, meaning members do not have to use the same logins for different third party services they access via Facebook – such as Spotify.
Facebook is the largest social network in the world with more than 800 million members who spend more than a total of 700 billion minutes on the site per month. Half of the UK now have accounts on the site which was created and still run by Mark Zuckerberg, a 27 year-old technology entrepreneur. The average user has 130 friends on the service.


Read more

Monday, September 26, 2011

Most burglars using Facebook and Twitter to target victims, survey suggests

0 comments

The majority of burglars use social media such as the websites Facebook and Twitter to target their victims, a survey suggests. 

The results were based on the answers of offenders who were convicted of burglary this year. Photo: PSL Images / Alamy

 

With many users posting constant updates, the sites can unwittingly provide the thieves with information about recent high-value purchases such as televisions as well as the dates and times when they are out.
Other websites, such as Google Street View, show photographs of individual houses from which the would-be burglars can gauge security and ease of access by looking for alarms and side entrances.
The results were based on the answers of offenders who were convicted of burglary this year.
Four out of five of the criminals said social media websites were being used by burglars.
However, the same number said a simple home alarm would have deterred them from targeting the property in the first place.

According to the survey, a thief steals an average of £487 from a home on a single visit.
One of the convicted burglars interviewed, Richard Taylor, said: “We’re living in the age of the digital criminal and people are taking advantage of social media to access information about would-be victims.
“We’ll tell them even when we're going away on holidays. We will let them know that we’re not in. We’re inviting them round to our house.”
Jonathan Lim, an expert at Friedland, the security firm behind the research, said: “Taking simple measures, including cutting back trees and shrubs to remove potential hiding places and installing simple alarm systems are all good, cost-effective deterrents that all homeowners can implement to remove their home from the target list.”


Read more