My Quote

“Cyber criminals are real.Never let them into your network.As long as they believe in absurdities they will continue to commit atrocities” Beware!!!!

Thursday, July 28, 2011

“Cyber Attacks, Real or Imagined, and Cyber War”


Excerpt: 
“Assorted “cyber attacks” have attracted much attention in the past few months. One headline in this genre recently proclaimed “Anonymous Declares War on Orlando.” This is wrong on so many levels that it almost defies analysis. A more precise accounting would show that there have been no cyber wars and perhaps two or three cyber attacks since the Internet first appeared.

The most ironic example of hyperbole catching itself involves the new Department of Defense Cyber Strategy, which says that the United States reserves the right to use military force in response to a cyber attack. Since many reports call everything—pranks, embarrassing leaks, fraud, bank robbery, and espionage—a cyber attack, the strategy led to expressions of concern that the United States would be shooting missiles at annoying teenage hackers or starting wars over Wikileaks. In fact, the strategy sets a very high threshold that is derived from the laws of armed conflict for defining a cyber attack. Nothing we have seen this year would qualify as an attack using this threshold.

Only by adopting an exceptionally elastic definition of cyber attack can we say they are frequent. There have been many annoyances, much crime, and rampant spying, but the only incidents that have caused physical damage or disruption to critical services are the alleged Israeli use of cyber attack to disrupt Syrian air defenses and the Stuxnet attacks against Iran’s nuclear facilities. An extortion attempt in Brazil against a public utility may have backfired and temporarily disrupted electrical service. A better way to identify an attack is to rely on “equivalence,” where we judge whether a cyber exploit is an attack by asking if it led to physical damage or casualties. No damage, no casualties, means no attack.

Many militaries are developing attack capabilities, but this is not some revolutionary and immensely destructive new form of warfare that any random citizen or hacker can engage in at will. Nations are afraid of cyber war and are careful to stay below the threshold of what could be considered under international law the use of force or an act of war. Crime, even if state sponsored, does not justify a military response. Countries do not go to war over espionage. There is intense hostile activity in cyberspace, but it stays below the threshold of attack.

The denial-of-service efforts against Estonian and Georgian websites in 2007 and 2008 were not attacks. The Estonian incident had a clear coercive purpose, and it is worth considering whether the denial-of-service exploit against Estonia could have become the equivalent of an attack if it had been extended in scope and duration. The exploits against Georgia, while undertaken with coercive intent and closely coordinated with Russian military activities (and a useful indicator of how Russia will use cyber warfare), did no damage other than to deface government websites…”

Friday, July 22, 2011

Anonymous, LulzSec Vow to Hack on


 By Jaikumar Vijayan
In a defiant statement addressed largely at FBI director Steve Chabinsky, members of the Anonymous and LulzSec hacktivist groups vowed to continue with their hacking campaigns and dared law enforcement to try and stop them.
The statement comes just two days after the FBI arrested 14 alleged members of Anonymous in connection with a series of distributed denial of service (DDoS) attacks against PayPal last year.
The immediate provocation appears to have been some comments made by Chabinsky in a NPR report following the recent arrests.
In it, Chabinsky is quoted as saying that chaos on the Internet is unacceptable. "[Even if] hackers can be believed to have social causes, it's entirely unacceptable to break into websites and commit unlawful acts."
In their response, posted on Pastebin.com , Anonymous and LulzSec members claimed their hactivist campaigns were motivated by a desire to expose what they described as lying governments, corrupt corporations and powerful lobbyists.
"We will continue to fight them, with all methods we have at our disposal, and that certainly includes breaking into their websites and exposing their lies," the letter said.
"We are not scared any more. Your threats to arrest us are meaningless to us as you cannot arrest an idea," the groups claimed. The two groups claimed they were acting like bandits only because they were forced to. "The Anonymous bitchslap rings through your ears like hacktivism movements of the 90s. We're back -- and we're not going anywhere."
Given the highly decentralized and loosely organized nature of the two groups it's hard to say how much of the content in the letter is bluster, how much is real or even how much it represents the true sentiment among members.
Certainly both Anonymous and LulzSec have demonstrated their ability to strike at what appears to be pretty much at will and pretty much against any target.
Just today for instance, Anonymous released a 36-page restricted document that is claimed to have obtained by breaking into a Web server at North Atlantic Treaty Organization (NATO) .
In a Twitter message, the group said that it has 1GB of material from NATO which it would not release because it would be irresponsible.
Over the last week, both groups have claimed credit for breaking into Rupert Murdoch's media sites. In one attack LulzSec compromised DNS servers at News International so that visitors to the group's Sun tabloid site were redirected to a fake story proclaiming Murdoch's death.
And in recent weeks and months both Anonymous and LulzSec have claimed responsibility for breaks-in at military contractor Booz Allen Hamilton, Sony and several other high-profile organizations.

The attacks have been mostly designed to embarrass and to provoke rather than to create any real damage. In most instances, the groups have cited some political or social cause for their attacks.
Recently for instance, when Anonymous attacked police union sites in Arizona , it claimed it was doing so because of the state's tough immigration laws.
However, law enforcement has made some important gains as well. Last weeks raids for instance, netted a total of 14 individuals who are allegedly members of Anonymous. Several arrests have been made overseas as well. Last month U.K police arrested Ryan Cleary, a 19-year old who is believed to be connected to both LulzSec and Anonymous.
Computers seized from last week's arrests and from Cleary's arrests are likely to lead authorities to more people connected with the two groups.
Whether such arrests will dampen their enthusiasm or only spur more attacks remains to be seen.

Thursday, July 21, 2011

US federal government to close 800 data centers, walk into the cloud


 
Sure, it's been just a few months since the National Security Agency asked for a $900 million supercomputing complex – you know, to help out with all that internet wiretapping. But concern about deficit spending will mean shuttering 800 other federal data centers in the US, or 40 percent of total government capacity. The closures are part of a larger push toward greater efficiency and consolidation, with an estimated savings of $3 billion a year; moving services to the cloud will mean more savings in licensing fees and infrastructure. Single-digit savings might sound like chump change when you realize the federal information technology budget runs around $80 billion a year, but hey, it's a start, right?

FBI Raids New York Homes in Hunt for Anonymous Hackers


 By John E Dunn

The FBI is reported to have raided homes in New York and California in connection with DDoS attacks carried out earlier this year by the hacktivist group, Anonymous.
Fox News has reported that the agency arrived to search two homes in Long Island and one in Brooklyn, removing papers and some computer equipment. The FBI is said to have followed up with search warrants at one or more addresses in California later in the day.
It is not yet clear whether anyone will be arrested as part of the investigation, but all the suspects were described by Fox News sources as being in their late teens or early twenties. Only one individual said to live at one of the addresses in New York has been named but his association has not been confirmed.
Getting on top of Anonymous has proved remarkably difficult for such a high-profile group, despite arrests by UK and US in January, further arrests in Spain, and an even larger raid in Turkey last month. It could be that Anonymous is simply too loose, dispersed and evolving to be stopped quickly by law enforcement.
Also in June, teen Ryan Cleary was arrested for being involved in DDoS attacks launched by LulzSec, a separate entity loosely associated with Anonymous.
Coincidentally, after a month out of the news, LulzSec yesterday launched a web redirection attack on websites run by British newspapers controlled by News International, owners of Fox News.
Not coincidentally, but perhaps ironically, thousands of miles away the head of News International, Rupert Murdoch, faced a committee of British parliamentarians to account for phone phreaking attacks allegedly carried out by journalists working for his company.

The Sun Hacked: How it Happened


By Leo King

A fake 'Murdoch dead' news report, placed on newspaper The Sun's website during a hacking attack last night by Lulz Security, has prompted a massive IT security crackdown at parent company News International. Computerworld UK.com has learned that the hackers injected a preformatted HTML file into an old internal server at News International, which is used to serve a text entry window on screen in the company's content management system. The window appears within pages hosted by the paper's main Amazon Cloud-delivered site, though sources close to News International said the Amazon Cloud data centre was not hacked.
Rupert Murdoch and his son James, as well as former editor Rebekah Brooks, are due to appear at 2.30pm today in front of the Commons Culture, Media and Sport Committee. They will be asked tough questions on allegations that journalists at the company hacked into the voicemail accounts of 9/11 victims, murdered teenager Milly Dowler, and a raft of celebrities, in a bid to find stories.
The spoof story placed last night on thesun.co.uk claimed that Rupert Murdoch had been found dead in his garden. Readers clicking on the hoax story were redirected to new-times.co.uk, where the story was placed, headlined 'Media mogul's body discovered'. The spoof story claimed Murdoch had taken palladium, a radioactive substance.
The news has prompted an aggressive IT security clampdown at News International this morning.
Sources told Computerworld UK.com that News International's staff have been issued with new login and password details, following the hacking attack, and that the company has also shut off remote access to its systems.
News International operates a Citrix virtual desktop system, which allows staff to 'hotdesk' and access their desktop on any PC in the firm's offices. Access codes for the virtual desktop, as well as News International's content management system, are said to have been changed.
The Sun and The Times websites are back online, but the News International website was offline at the time of writing. News International declined to comment on how it was hacked, what was happening with its corporate website, or how it is tackling IT security concerns. It gave confirmation only that its newspaper sites were back online.
The news comes as The Guardian newspaper reported that police are examining a laptop dumped near former News of the World and Sun editor Rebekah Brooks' flat in Chelsea. Brooks' husband, Charlie, has claimed it is his and that it was in a bag accidentally thrown out by a cleaner, but this remains unconfirmed. Rebekah Brooks was arrested on Sunday on suspicion of conspiring to intercept communications, and she was bailed the next day.
Rupert Murdoch, who is accustomed to his journalists writing stories on celebrities and other public figures, has in recent weeks found himself at the centre of the news as the hacking scandal grows.
Another of Scotland Yard's most senior police officers, John Yates, resigned yesterday. Yates decided in 2009 that there was no need to reopen investigations into alleged phone hacking by journalists on the now-shuttered News of the World newspaper. Yates was about to be suspended.
Sean Hoare, a former News of the World journalist and the first reporter to expose hacking at the paper, has been found dead.