Mostrar mensagens com a etiqueta Criminal Hackers. Mostrar todas as mensagens
Mostrar mensagens com a etiqueta Criminal Hackers. Mostrar todas as mensagens

terça-feira, 27 de setembro de 2011

Microsoft halts another botnet: Kelihos


This image from the complaint illustrates how a bot herder uses a command-and-control server to communicate with infected computers via routers.

Microsoft has put a halt to the Kelihos botnet and is accusing a Czech resident of hosting the botnet and using it to deliver spam and steal data, the company said today.
Kelihos, also known as "Waledac 2.0" after a previous botnet that Microsoft shut down last year, comprised about 41,000 infected computers worldwide and was capable of sending 3.8 billion spam e-mails per day, according to Microsoft.
The complaint filed last week in the U.S. District Court for the Eastern District of Virginia accuses Dominique Alexander Piatti, Dotfree Group SRO and John Does 1-22 of infecting victim computers with malware to create the Kelihos botnet, using it to send unregulated pharmaceutical and other spam, harvest e-mails and passwords, conduct fraudulent stock scams and, in some cases, promote sites dealing with sexual exploitation of children.
Meanwhile, subdomains were allegedly used to infect Mac computers with MacDefender scareware, according to the complaint. Piatti could not immediately be reached for comment.
In addition to filing complaints, Microsoft also is using a relatively new tactic of filing restraining orders to get court permission to sever the connections between the botnets and the individual infected computers, known as "zombies." This stops the botnet from continuing to operate and grow.
Microsoft also plans to work with ISPs and Community Emergency Response Teams (CERTs) to help clean up computers that were infected and used in the botnet. As part of that process, the Microsoft Malware Protection Center will add the Win/32 Kelihos family in a second release of theMalicious Software Removal Tool later today.
"Without a domain infrastructure like the one allegedly hosted by Mr. Piatti and his company, botnet operators and other purveyors of scams and malware would find it much harder to operate anonymously and out of sight. By taking down the botnet infrastructure, we hope that this will help deter and raise the cost of committing cybercrime," Richard Domingues Boscovich, senior attorney with the Microsoft Digital Crimes Unit, wrote in a blog post today.
The case also highlights an industry-wide problem related to the stealth use of subdomains, he said. "Under U.S. law, even pawn brokers are more effectively regulated to prevent the resale of stolen property than domain owners are to prevent the use of their digital properties for cybercrime. For example, pawn shop operators must require a name, address and proper identification from customers, while by contrast there are currently no requirements necessitating domain hosts to know anything about the people using their subdomains--making it easy for domain owners to look the other way."
This is the third botnet--following Waledac, and Rustock earlier this year--that Microsoft has taken down using these same legal and technical measures, but it's the first time a defendant has been named in one of the company's civil cases involving a botnet.

quinta-feira, 22 de setembro de 2011

Alleged LulzSec member arrested in Sony breach




The FBI arrested a 23-year-old Arizona man today on charges of stealing data from Sony Pictures Entertainment earlier this year.
Cody Andrew Kretsinger of Phoenix was indicted September 2 by a federal grand jury on charges of conspiracy and unauthorized impairment of a protected computer, the FBI said in a statement. Kretsinger could not be reached for comment.
~

Meanwhile, Fox News reported that a hacker who is believed to be homeless was arrested in San Francisco on charges of participating in attacks allegedly carried out by activist group Anonymous on Santa Cruz County government Web sites, and that search warrants were being executed in New Jersey, Minnesota, and Montana. An FBI spokesman told CNET that the agency does not typically comment on search warrants. FBI officials in San Francisco did not immediately return a call seeking comment.
Kretsinger is accused of using proxy services via the hidemyass.com site, designed to offer anonymous Internet access, to probe Sony Pictures Entertainment's computer systems in May, according to the indictment, which was unsealed in U.S. District Court in Los Angeles today.
He and others co-conspirators looked for vulnerabilities and exploited them by means of a SQL injection attack between May 27 and June 2, the indictment says. They then allegedly compromised the Sony system, making "tens of thousands of requests for confidential data," and released the information from Sony on a public Web site and on Twitter.
Kretsinger permanently erased the hard drive of the computer he used to conduct the attack, the indictment alleges. He is due to make an initial appearance in federal court in Phoenix today. The U.S. government will request that he be transferred to Los Angeles to face prosecution. He faces up to 15 years in prison if convicted.
He is alleged to have used the hacker handle "recursion" and is believed to be a member of the LulzSec hacker group.
The LulzSec group, believed to be a spin-off of the Anonymous group of online activists, had bragged about breaking into Sony Pictures' system, posting a statement on the Pastebin on June 2 and proof of their attack. "We recently broke into SonyPictures.com and compromised over 1,000,000 users' personal information, including passwords, email addresses, home addresses, dates of birth, and all Sony opt-in data associated with their accounts," the statement said. "Among other things, we also compromised all admin details of Sony Pictures (including passwords) along with 75,000 'music codes' and 3.5 million 'music coupons.'"
A week later, Sony said that actually personally identifable information of 37,500 customers had been exposed in the breach. The breach was one of a series of attacks targeting Sony and its affiliate sites globally that started in May following a legal spat Sony had with a hacker who had modified his Sony PlayStation 3.
Arrests of people accused of being part of Anonymous or LulzSec have taken place globally, including 16 in the U.S. in July, as well as in the United Kingdom and Spain.

sábado, 10 de setembro de 2011

NBC News Twitter account hacked


This screenshot shows the fake news tweets posted from a hacked NBC News Twitter account.
This screenshot shows the fake news tweets posted from a hacked NBC News Twitter account.
(Credit: Twitter)
Hackers compromised the NBC News Twitter account today and sent several fake tweets from the account about an attack on Ground Zero reminiscent of the attacks of September 11, 2001.
"Breaking News! Ground Zero has just been attacked. Flight 5736 has crashed into the site, suspected hijacking. More as the story develops," was the first tweet this afternoon. It was followed by two others, including one that started "This is not a joke."
The fourth tweet said "NBCNEWS hacked by The Script Kiddies."
An e-mailed NBC News statement said: "The NBC News twitter account was hacked late this afternoon and as a result, false reports of a plane attack on ground zero were sent to @NBCNews followers. We are working with Twitter to correct the situation and sincerely apologize for the scare that could have been caused by such a reckless and irresponsible act."
NBC News also used the Twitter account of its chief digital officer, Vivian Schiller, to alert followers to the problem. "Ignore tweets from @nbcnews till further notice. We've been hacked. Do not retweet," her account tweeted shortly early on.
A search for the NBC News Twitter profile shortly thereafter displayed the message "This user does not exist."
It's unclear who the Script Kiddies are. The profile for the Script Kiddies--a term used to describe novice hackers--also appeared to have been removed from Twitter.
Updates on the hack were tweeted from the account of NBC News Chief Digital Officer Vivian Schiller after the official NBC News account was disabled.
Updates on the hack were tweeted from the account of NBC News Chief Digital Officer Vivian Schiller after the official NBC News account was disabled.
(Credit: Twitter)
The hacking comes on the heels of a similar problem with Apple co-founder Steve Wozniak's Twitter account, which was used to tweet blatant spam yesterday. Wozniak told CNET that he wasn't aware of his account being hacked but that he would change his password. "I really don't use my Twitter account," he wrote in an e-mail. "I should. It's a good thing. But it's down on my priority list and I'm too short of time."
Twitter spokeswoman Lynn Fox, contacted in regards to the Wozniak incident, said the company does not comment on individual accounts.
Graham Cluley of security firm Sophos predicted that account hijinks of this sort would continue to happen until Twitter offered extra security measures for popular profiles.
"Twitter should be applauded for taking such quick action (in suspending the accounts), but isn't it time that there was better security available to accounts which have a large number of followers, or who (like media organizations) may cause public panics if someone breaks in and starts tweeting false news stories about terrorist attacks?" he wrote in a blog post today. "I, for one, would like to see Twitter and other social media sites offer an additional level of authentication for those who want to better defend their accounts. I fear that, unless that happens, we will continue to see high-profile accounts hacked and brands damaged as hackers run rings around them."


Read more: http://news.cnet.com/8301-27080_3-20104165-245/nbc-news-twitter-account-hacked/#ixzz1XYpZ7VrG