Showing posts with label Iran. Show all posts
Showing posts with label Iran. Show all posts

Thursday, August 23, 2012

Obama faces delicate decisions as cyberattack fears rise

President Barack Ob, ... ] White House photo

At the height of the economic crisis in 2008, Saturday Night Live’s “Weekend Update” comedy news show rolled out the character Oscar Rogers as a faux financial commentator. His advice on how to restore the economy? “Fix it! It needs to be fixed! Now!”

Four years later, lawmakers are grappling with a cybercrisis, and despite rising concerns, legislative debates over how to secure U.S. networks and infrastructure have often resembled nothing so much as Oscar Rogers yelling “Fix it!”

Now, with Congress looking unlikely to act anytime soon to fix vulnerabilities in the nation’s computer systems that leave them open to cyberattacks, President Obama is weighing the pros and cons of using anexecutive order to do what Congress hasn’t.

Experts in government and industry alike report a tide of attacks aimed at stealing information from individuals, companies, and government agencies, potentially making a strong case for presidential action.

Further bolstering the case are warnings from top national-security officials that a catastrophic attack on a critical system like those that run energy grids or chemical plants could cause damage to the economy or even loss of life.

But Obama needs to consider his options carefully, because any unilateral steps could invite accusations from his critics of overstepping his authority. As the acrimonious debate over antipiracy legislation illustrated earlier this year, simmering Internet issues can easily explode.

In the final days before the August recess, the Senate hit an impasse on broad cybersecurity legislation that the White House and national-security and defense leaders support. The bill stalled after businesses and Republicans said the legislation would create burdensome regulations for industry without doing enough to shore up defenses against cyberattacks.

Top White House counterterrorism aide John Brennan said earlier this month that Obama was looking at the possibility of an executive order but that there is no decision yet.

Lee Hamilton, a Democratic former House member who sits on a board that advises the Homeland Security Department and who examined government security failures as cochair of the 9/11 Commission, said that Obama is right to consider moving forward on his own. He said the stalemate in Congress is a “serious breakdown” reminiscent of failures before the terrorist attacks on Sept. 11, 2001.

“The preference would be to work together with Congress, but the threat is serious enough that an executive order is in line,” he said. “There is certainly a lack of urgency in dealing with this, and it’s not a business-as-usual problem. Given the fact that Congress hasn’t acted, the president has the obligation to put together options to secure the country.”

While the debate in Congress largely broke down along party lines, some prominent Republicans support the cybersecurity standards backed by the White House.

Top national-security advisers for GOP presidential candidate Mitt Romney, such as former Homeland Security Secretary Michael Chertoff and former National Security Agency and Central Intelligence Agency chief Michal Hayden, differed with Republicans in Congress and publicly called for the Senate to pass provisions that have Obama’s support.

Romney campaign spokeswoman Andrea Saul declined to elaborate on the Republican candidate’s assertion that more needs to be done to secure American networks, or comment on whether he would favor using an executive order in the absence of legislation. But she reiterated Romney’s promise to make cybersecurity an early priority and didn’t rule out executive action. Romney's plan would require agencies to begin developing a new national cybersecurity strategy within the first 100 days of his administration. “Once the strategy is formulated he will determine how best it can be implemented,” Saul said in an e-mail.

Polls show that while Americans express concerns over cyberattacks, they, too, are divided over what should be done.

Separate surveys published by United Technologies/National Journal and The Washington Post over the summer found that a majority of Americans prefer that the government either not create standards for private companies, or keep any standards voluntary.

Backers of the White House’s proposals, however, say an executive order could add clarity to the debate and prove to skeptics that the government can play a greater role in protecting American networks without violating privacy or burdening private businesses.

“I think it’s hard to make things any messier than it was politically,” said James Lewis, an expert at the Center for Strategic and International Studies. “If done right, an executive order could help critics reconsider their arguments.”

That’s an analysis echoed by University of California (Berkeley) professor Steven Weber who said many people seem to be “sleepwalking” when it comes to the threat of cyberattacks. An executive order, he said, could reform cybersecurity policies before a catastrophic attack galvanizes public opinion.

An executive order could give Obama the chance to take a strong stand on a rising national-security concern while portraying Republicans in Congress as ditherers.

But an order is unlikely to accomplish all of the White House’s aims. It couldn’t hand DHS wider authority to ensure that certain private networks are secure. Nor could it entirely ease legal restrictions that prevent businesses from sharing threat information. Even policy changes for some federal network-security policies would likely need congressional action. Additionally, any action would need to avoid inciting privacy watchdogs who fear cybersecurity could be used as an excuse to undermine civil liberties.

And some analysts said the politics of an executive order could cut both ways for Obama. Presidents often win political debates that pit them against an unpopular Congress, especially one perceived as unable to do anything substantive, said Peter Feaver, a former National Security Council staffer during the Clinton and George W. Bush administrations. But if Obama were to take unilateral action, it would give his critics on the right an opening to paint him as an “imperial” president and to accuse him of saddling business with new regulations, Feaver said.

“In general, White Houses win in these fights with Congress, but this White House has played this card many times,” Feaver said. “This is an issue where there are bound to be unintended consequences and any cybersecurity measures will need a system to fix and update the provisions down the road. This administration has a hard sell assuring people to trust them to fix things later.”

Paul Rosenzweig, a consultant and visiting fellow at the conservative Heritage Foundation, said a cybersecurity executive order could play into both the “imperial presidency and do-nothing-Congress” narratives, but said he thinks there is a genuine possibility for a future compromise and unilateral action by Obama would do little to actually help secure private networks

http://m.nextgov.com/cio-briefing/2012/08/obama-faces-delicate-decisions-cybe...

Posted from DailyDDoSe

Sunday, July 1, 2012

TwitterGate Current Status of certifcate authorization

Richard Clarke: China's Cyberassault on ...
Reason: request error 403: Invalid AuthSub token. Invalid AuthSub token. Error 403
Next attempt in 3 minutes
2 minutes ago
Failed
The end result? Here you go. "Dead"
Reason: request error 403: Invalid AuthSub token. Invalid AuthSub token. Error 403
Next attempt in 6 minutes
11 minutes ago
Failed
"Just because it cracks me up" shitty de ...
Reason: request error 403: Invalid AuthSub token. Invalid AuthSub token. Error 403
Next attempt in 7 minutes
12 minutes ago
Failed
And here's JDenjgma w CHINA & Pakistan
Reason: request error 403: Invalid AuthSub token. Invalid AuthSub token. Error 403
Next attempt in 9 minutes
14 minutes ago
Failed
In case anyone cares? Here's China.
Reason: request error 403: Invalid AuthSub token. Invalid AuthSub token. Error 403
Next attempt in 10 minutes
15 minutes ago
Failed
Another one of his "friends"
Reason: request error 403: Invalid AuthSub token. Invalid AuthSub token. Error 403
Next attempt in 11 minutes
16 minutes ago
Failed
Look how much fun "we" are having
Reason: request error 403: Invalid AuthSub token. Invalid AuthSub token. Error 403
Next attempt in 13 minutes
18 minutes ago
Failed
Get off my network!
Reason: request error 403: Invalid AuthSub token. Invalid AuthSub token. Error 403
Next attempt in 16 minutes
21 minutes ago
Failed
Psychopath NOT hero! So who is crazy now ...
Reason: request error 403: Invalid AuthSub token. Invalid AuthSub token. Error 403
Next attempt in 22 minutes
27 minutes ago
Failed
This is NOT one of "those" stories!
Reason: request error 403: Invalid AuthSub token. Invalid AuthSub token. Error 403
Next attempt in 24 minutes
29 minutes ago
Failed
Another stalker. Two. Gross.
Reason: request error 403: Invalid AuthSub token. Invalid AuthSub token. Error 403
Next attempt in 30 minutes
35 minutes ago
Failed
Hacker by association? #CIA #Black&Berg ...
Reason: request error 403: Invalid AuthSub token. Invalid AuthSub token. Error 403
Next attempt in 33 minutes
38 minutes ago
Failed
Jewish Internet Defense Force
Reason: request error 403: Invalid AuthSub token. Invalid AuthSub token. Error 403
Next attempt in 36 minutes
41 minutes ago
Failed
Bigger Problems: Pakistan
Reason: request error 403: Invalid AuthSub token. Invalid AuthSub token. Error 403
Next attempt in 37 minutes
42 minutes ago
Failed
"he'll grow on you" Like a wart!
Reason: request error 403: Invalid AuthSub token. Invalid AuthSub token. Error 403
Next attempt in 38 minutes
43 minutes ago
Failed
From #stalking to #hacking
Reason: request error 403: Invalid AuthSub token. Invalid AuthSub token. Error 403
Next attempt in 41 minutes
about 1 hour ago
Failed
Too much traffic. #CyberStalking
Reason: request error 403: Invalid AuthSub token. Invalid AuthSub token. Error 403
Next attempt in about 1 hour
about 1 hour ago
Failed
I won't get daddy lawyer! I'll get mommy ...
Reason: request error 403: Invalid AuthSub token. Invalid AuthSub token. Error 403
Next attempt in about 1 hour
about 1 hour ago
Failed
Chat with Mike Firetown Sat, Mar 19, 201 ...
Reason: request error 403: Invalid AuthSub token. Invalid AuthSub token. Error 403
Next attempt in about 1 hour
about 1 hour ago
Failed
#GangStalking needs help to stalk me? Da ...
Reason: request error 403: Invalid AuthSub token. Invalid AuthSub token. Error 403
Next attempt in about 1 hour
about 1 hour ago
Failed
Chat with Mike Firetown Thu, Apr 14, 201 ...
Reason: request error 403: Invalid AuthSub token. Invalid AuthSub token. Error 403
Next attempt in about 1 hour
about 1 hour ago
Failed
Harassing my friends!
Reason: request error 403: Invalid AuthSub token. Invalid AuthSub token. Error 403
Next attempt in about 1 hour
about 1 hour ago
Failed
Chat with Mike Firetown Sat, Mar 19, 201 ...
Reason: request error 403: Invalid AuthSub token. Invalid AuthSub token. Error 403
Next attempt in about 1 hour
about 1 hour ago
Failed
Officially #GangStalking Jdenigma needs ...
Reason: request error 403: Invalid AuthSub token. Invalid AuthSub token. Error 403
Next attempt in about 1 hour
about 1 hour ago
Failed
Chat with Mike Firetown
Reason: request error 403: Invalid AuthSub token. Invalid AuthSub token. Error 403
Next attempt in about 1 hour
about 1 hour ago
Failed
Chat with Mike Firetown
Reason: request error 403: Invalid AuthSub token. Invalid AuthSub token. Error 403
Next attempt in about 1 hour
about 1 hour ago
Failed
Persistent little fucker! #CyberStalker
Reason: Not a valid private key.
Next attempt in about 1 hour
about 1 hour ago
Failed
"Crazy Bitch" or Crazy CyberStalker? You ...
Reason: request error 403: Invalid AuthSub token. Invalid AuthSub token. Error 403
Next attempt in about 1 hour
about 1 hour ago
Failed
CyberStalker at large
Reason: request error 403: Invalid AuthSub token. Invalid AuthSub token. Error 403
Next attempt in about 1 hour
about 1 hour ago
Failed
What Should I Do? || "Get me out of here ...
Reason: request error 403: Invalid AuthSub token. Invalid AuthSub token. Error 403
Next attempt in about 1 hour
about 1 hour ago
Posted

BITCH!

Posted from DailyDDoSe

Saturday, June 30, 2012

'Flame' Spread Via Rogue Microsoft Security Certificates

Analysis of the massive ‘Flame’ cyber attack code has revealed that rogue Microsoft security certificates were used to make the malware appear as if it was officially signed by Microsoft. Microsoft has issued a security advisory, revoked trust in the rogue certificates, and provided steps to help IT admins and users prevent attacks that rely on the spoofed Microsoft certificates.

A post on the Microsoft Security Response Center blog states plainly, “We have discovered through our analysis that some components of the malware have been signed by certificates that allow software to appear as if it was produced by Microsoft.”

Malware'Flame' slipped under network defenses by appearing as legitimate Microsoft code.Andrew Storms, director of security operations for nCircle, declares, “The discovery of a bug that’s been used to circumvent Microsoft’s secure code certificate hierarchy is a major breach of trust, and it’s a big deal for every Microsoft user. It also underscores the delicate and problematic nature of the trust models behind every Internet transaction.”

The Microsoft blog post explains that a vulnerability in an old cryptography algorithm is exploited by some elements of Flame to make them appear as if they originated from Microsoft. Most systems around the world accept officially-signed Microsoft code as safe by default, so the malware would enter unnoticed.

The weak algorithm is a function of the Terminal Server Licensing Service, which allowed IT admins to authorize Remote Desktop services on Windows-based networks. The algorithm in question was used to generate security certificates with the ability to sign code so that it is accepted as legitimate Microsoft code.

Microsoft is taking steps to deal with this issue. First, it released the security advisory which explains the issue in detail and provides steps IT admins can use to block software signed by the rogue security certificates. Microsoft also released an update, which automatically implements those same steps to make it easier for customers to prevent malware using the spoofed certificates from slipping through.

Microsoft adds that the Terminal Server Licensing Service is no longer capable of issuing certificates that can be used to sign code. With these steps in place, organizations can ensure that any malware that depends on the rogue security certificates will no longer be recognized as being from Microsoft.

Storms provides some further insight about the rogue Microsoft certificate revelation. He points out that the stealthy use of rogue Microsoft security certificates supports the theory that ‘Flame’ is part of a grander state-sponsored espionage effort. “A bug that can identify a piece of malware as legitimate is not something an average malware writer would have been able to sit on for long--it’s worth far too much on the black market.”

Storms adds, “The fact that this bug has been kept secret for at least 18 months, and quite possibly longer, is pretty clear evidence that there is a nation state behind Flame.”

Posted from DailyDDoSe

Flame Hijacks Microsoft Update to Spread Malware Disguised As Legit Code

It’s a scenario security researchers have long worried about, a man-in-the-middle attack that allows someone to impersonate Microsoft Update to deliver malware — disguised as legitimate Microsoft code — to unsuspecting users.

And that’s exactly what turns out to have occurred with the recent Flame cyberespionage tool that has been infecting machines primarily in the Middle East and is believed to have been crafted by a nation-state.

According to Microsoft, which has been analyzing Flame, along with numerous antivirus researchers since it was publicly exposed last Monday, researchers there discovered that a component of Flame was designed to spread from one infected computer to other machines on the same network using a rogue certificate obtained via such a man-in-the-middle attack. When uninfected computers update themselves, Flame intercepts the request to Microsoft Update server and instead delivers a malicious executable to the machine that is signed with a rogue, but technically valid, Microsoft certificate.

“We have discovered through our analysis that some components of the malware have been signed by certificates that allow software to appear as if it was produced by Microsoft,” Microsoft Security Response Center Senior Director Mike Reavey wrote in a blog post published Sunday.

To generate their fake certificate, the attackers exploited a vulnerability in a cryptography algorithm that Microsoft uses for enterprise customers to set up Remote Desktop service on machines. The Terminal Server Licensing Service provides certificates with the ability to sign code, which is what allowed the rogue code to be signed as if it came from Microsoft.

Microsoft has provided information to explain how the flaw occurred in its system.

Reavey notes that since Flame is a highly targeted piece of malware that is believed to have infected fewer than 1,000 machines, the immediate risk from Flame is not great. But other attackers could have been exploiting the vulnerability as well. And the fact that this vulnerability existed in the first place is what has security experts all aflame. Code that is officially signed by Microsoft is considered safe by millions of machines around the world, something that put them all at risk.

“The discovery of a bug that’s been used to circumvent Microsoft’s secure code certificate hierarchy is a major breach of trust, and it’s a big deal for every Microsoft user,” Andrew Storms, director of security operations for nCircle, told PC World. “It also underscores the delicate and problematic nature of the trust models behind every Internet transaction.”

According to Kaspersky Lab, which discovered the Flame malware about three weeks ago, the certificate is used by a component of Flame called “Gadget” to spread the malware from one infected machine to others on a network. It was the use of this rogue certificate that is believed to have allowed Flame to infect at least one fully patched Windows 7 machine, according to Alexander Gostev, chief security expert at the Lab.

Here’s how it works:

When a machine on a network attempts to connect to Microsoft’s Windows Update service, the connection gets redirected through an infected machine first, which sends a fake, malicious Windows Update to the requesting machine. The fake update claims to be code that will help display gadgets on a user’s desktop.

The fake update looks like this:

“update description=”Allows you to display gadgets on your desktop.”
displayName=”Desktop Gadget Platform” name=”WindowsGadgetPlatform”>

If the ruse works, a malicious file called WuSetupV.exe gets deposited on the machine. Since the file is signed with a fake Microsoft certificate, it appears to the user to be legitimate, and therefore the user’s machine allows the program to run on the machine without issuing a desktop warning.

The Gadget component was compiled by the attackers on Dec. 27, 2010, according to Gostev in a blog post, and was implemented in the malware about two weeks later.

The following is exactly how the process occurs: The infected machine sets up a fake server by the name “MSHOME-F3BE293C”, which hosts a script that serves a full body of the Flame malware to victim machines. This is done by the module called “Munch”.

When a victim updates itself via Windows Update, the query is intercepted and the fake update is pushed. The fake update proceeds to download the main body and infect the computer.

The interception of the query to the official Windows Update (the man-in-the-middle attack) is done by announcing the infected machine as a proxy for the domain. This is done via WPAD. To get infected, the machines do need however to have their System Proxy settings configured to “Auto”.

Microsoft has revoked the certificate and fixed the vulnerability via an update. Hopefully, the update will not be man-in-the-middled.

Homepage Photo: Marjan Krebelj/Flickr

Posted from DailyDDoSe

Meet 'Flame,' The Massive Spy Malware Infiltrating Iranian Computers

Map showing the number and geographical location of Flame infections detected by Kaspersky Lab on customer machines. Courtesy of Kaspersky

A massive, highly sophisticated piece of malware has been newly found infecting systems in Iran and elsewhere and is believed to be part of a well-coordinated, ongoing, state-run cyberespionage operation.

The malware, discovered by Russia-based antivirus firm Kaspersky Lab, is an espionage toolkit that has been infecting targeted systems in Iran, Lebanon, Syria, Sudan, the Israeli Occupied Territories and other countries in the Middle East and North Africa for at least two years.

Dubbed “Flame” by Kaspersky, the malicious code dwarfs Stuxnet in size — the groundbreaking infrastructure-sabotaging malware that is believed to have wreaked havoc on Iran’s nuclear program in 2009 and 2010. Although Flame has both a different purpose and composition than Stuxnet, and appears to have been written by different programmers, its complexity, the geographic scope of its infections and its behavior indicate strongly that a nation-state is behind Flame, rather than common cyber-criminals — marking it as yet another tool in the growing arsenal of cyberweaponry.

The researchers say that Flame may be part of a parallel project created by contractors who were hired by the same nation-state team that was behind Stuxnet and its sister malware, DuQu.

“Stuxnet and Duqu belonged to a single chain of attacks, which raised cyberwar-related concerns worldwide,” said Eugene Kaspersky, CEO and co-founder of Kaspersky Lab, in a statement. “The Flame malware looks to be another phase in this war, and it’s important to understand that such cyber weapons can easily be used against any country.”

Early analysis of Flame by the Lab indicates that it’s designed primarily to spy on the users of infected computers and steal data from them, including documents, recorded conversations and keystrokes. It also opens a backdoor to infected systems to allow the attackers to tweak the toolkit and add new functionality.

The malware, which is 20 megabytes when all of its modules are installed, contains multiple libraries, SQLite3 databases, various levels of encryption — some strong, some weak — and 20 plug-ins that can be swapped in and out to provide various functionality for the attackers. It even contains some code that is written in the LUA programming language — an uncommon choice for malware.

Kaspersky Lab is calling it “one of the most complex threats ever discovered.”

“It’s pretty fantastic and incredible in complexity,” said Alexander Gostev, chief security expert at Kaspersky Lab.

"Independent?" Iranian Hacker Claims Responsibility for Comodo Hack

The hack that resulted in Comodo creating certificates for popular e-mail providers including Google Gmail, Yahoo Mail, and Microsoft Hotmail has been claimed as the work of an independent Iranian patriot. A post made to data sharing site pastebin.com by a person going by the handle “comodohacker” claimed responsibility for the hack and described details of the attack. A second post provided source code apparently reverse-engineered as one of the parts of the attack.

Whether the postings are authentic and accurate is, at present at least, a matter of conjecture. The post specifies a number of details that appear authentic. The writer fingers Italian Registration Authority GlobalTrust.it/InstantSSL.it (the same company operating under multiple names) as the weak link. A Registration Authority (RA) is essentially a local reseller for a Certification Authority (CA); in principle, the RA performs the validation of identity that would be too difficult or expensive for the root CA to do, and then sends a request to the root CA to generate an appropriate certificate. Comodo’s systems trust that the RA has done its job appropriately, and issues the certificate. This is consistent with Comodo’s statement that it was a Southern European company that was compromised.

arstechnica

In addition to blaming a specific RA, the post includes other details: the username (“gtadmin”) and password (“globaltrust,” proving once again that security companies can pick really bad passwords) used by the RA to submit requests to Comodo’s system, the e-mail address of InstantSSL’s CEO (“mfpenco@mfpenco.com”), and the names of the databases used by GlobalTrust’s website. In practice, though, only Comodo can verify this information, and the company has no good reason to do so.

The alleged hacker also described some details of the hack itself. He claims to have broken into GlobalTrust’s server and found a DLL, TrustDLL.dll, used by that server to send the requests to Comodo and retrieve the generated certificates. The DLL was written in C#, so decompiling it to produce relatively clear C# was easy; within the DLL the hacker found hard-coded usernames and passwords corresponding to GlobalTrust’s account on Comodo’s system, and another account for the system of another CA, GeoTrust. The source code the hacker posted was part of this DLL, and certainly has the right form for decompiled source code. Again, though, only GlobalTrust could provide absolute confirmation of its authenticity.

Reasons for caution

So at least to some extent, the claim looks legitimate. They’re saying the right kind of things. There are, however, a few reasons to be cautious. The identity of the RA was already presumed to be InstantSSL.it, and the company is Comodo’s only listed reseller in the Southern Europe area. That listing also discloses mfpenco’s Comodo e-mail address, and from there it’s easy to find his full name, e-mail address, and position within the company. So someone uninvolved with the hack could provide this information. Even the DLL source code is not cast iron evidence: Comodo publishes the API that RAs use to integrate with its systems, so anybody could produce a similar DLL. Indeed, the only details not trivially discoverable with a bit of search engine leg-work are the ones that are also entirely unverifiable anyway.

The experience of 1,000 hackers

The claims are also infused with an almost unbelievable amount of BS in its purest form. Though initially describing him- or herself as “we,” the hacker then claims to be a 21-year-old programmer working alone, and to be unaffiliated with the Iranian Cyber Army (a group accused of hacking Twitter in 2009). So far, so good. He then goes rather off the rails, however, when he claims to have the hacking experience of 1,000 hackers, the programming experience of 1,000 programmers, and the project management experience of 1,000 project managers. Mmm-hmm.

He claims also that his original plan was to hack the RSA algorithm commonly used in SSL. RSA is a public key cryptography algorithm, and its security depends on one thing: that factorizing numbers into their prime factors (for example, converting 12 into 3×2×2) is computationally difficult. With numbers of the size used in RSA—typically 1024 bits, equivalent to about 309 decimal digits, or 2048 bits, equivalent to about 617 decimal digits—and the current best-known algorithms, literally thousands of years of CPU time are required to factorize the numbers involved, making it computationally intractable.

Though the hacker initially admits that he didn’t find a solution to the integer factorization problem—instead getting waylaid by the distraction of breaking into CAs—he later claims that “RSA certificates are broken,” and that “RSA 2048 was not able to resist in front of me.” He also directly threatens Comodo and other CAs, saying “never think you can rule the internet, ruling the world with a 256 digit [sic] number which nobody can find it’s [sic] 2 prime factors (you think so), I’ll show you how someone in my age can rule the digital world, how your assumptions are wrong.” So the implication is that an attack on RSA is forthcoming, but there’s no sign of it so far.

The decompilation of the DLL and subsequent generation of code that allowed the hacker to generate his own certificates is also ascribed to the hacker’s own brilliance. He claims that he had “no idea” of Comodo’s API or “how it works,” and that the DLL did not quite work properly due to being out of date and not providing all the information that Comodo’s systems needed. Nonetheless, he learned what to do and rewrote the code “very very fast,” with the result that Comodo will be “really shocked about my knowledge, my skill, my speed, my expertise and entire attack.” Skill and expertise are certainly one possibility, but looking at the documents that Comodo publishes is surely the easier approach—and surely the preferred approach of someone with the experience of 1,000 hackers.

The hacker’s manifesto

Nonetheless, the claims are probably authentic, at least insofar as they come from someone with some knowledge of, and involvement in, the Comodo attack. They tie together all the right pieces, and the DLL code, though by no means absolute evidence, is pretty compelling—though the grandiose claims about RSA are unlikely to amount to anything. In addition to claiming responsibility, the post includes something of a political manifesto—a series of “rules” that hint at the underlying reason for the attacks.

The nature of the targets chosen—mainly e-mail sites—enabled the perpetrator to relatively effectively eavesdrop on secure e-mail sent using Gmail, Yahoo! Mail, and Hotmail. This in turn implicated government agencies, as such an ability would allow them to more easily detect dissident communications. However, the hacker insists that he is independent and acting alone. He is, however, a staunch pro-government nationalist, and issues a warning to people within Iran such as the Green Movement and the MKO that they should be “afraid of [him] personally.” He continues, “I won’t let anyone inside Iran, harm people of Iran, harm my country’s Nuclear Scientists, harm my Leader (which nobody can), harm my President, as I live, you won’t be able to do so.” Those people “don’t have privacy in internet” and “don’t have security in digital world. [sic throughout]”

Are you inside Iran with problems? ph34r!

The hacker also criticizes Western governments, Western media, and Western corporations. He positions the fraudulent certificates as a means of giving himself equivalent powers to the US and Israel, stating that they can already read mail in Yahoo, Hotmail, Gmail, and so on “without any simple little problem,” since they can spy using Echelon. The certificates just let him do the same.

He criticizes the media in a number of ways. He regards it as unfair that Iranian ambassadors were quizzed by the media regarding the Comodo attack, and yet no equivalent scrutiny was given to US and Israeli officials over Stuxnet. Similarly, the Western media wrote about the Comodo attack, but ignores Echelon and HAARP—in other words, that the media swoops into action when it appears that Iranians might compromise the secrecy of Westerners, but doesn’t care about Westerners spying on the rest of the world.

And finally, he claims that Microsoft, Mozilla, and Google updated their software “as soon as instructions came from CIA.” He also claims that the reason Microsoft did not patch the Stuxnet vulnerabilities for so long is not because the company didn’t know about them, but rather because those vulnerabilities were required by Stuxnet—Redmond was again acting on the behalf of the CIA.

The hacker says that we should be scared and afraid, that he is immensely skilled, and that the security offered by SSL will soon come crashing down around our ears. This is highly unlikely. His claims are far-fetched, with more than a hint of conspiracy theory madness to them.

But in another sense, he’s right. The hack he describes was not particularly clever or advanced; we still don’t know all the details, but it appears that Comodo has done little to ensure that its RAs are secure, leaving it extremely prone to attack. It’s unlikely that Comodo is unique in this regard, too—the specifics will vary from CA to CA, RA to RA, but there are so many of these entities, all of them trusted by default, that further holes are inevitable. Such attacks don’t need large teams or state sponsorship to work; they’re well within the reach of a suitably well-motivated individual. With SSL we have built, and depend on, a large trust system—breaches of that trust are a genuine threat with the potential for enormous harm. It’s high time these trusted companies made sure they actually deserved that trust.

Top image: The alleged hacker’s claim of responsibility on pastebin.com

i think not.

Posted from DailyDDoSe

Fake Security Firms Will Be Exposed || CyberWarzone #404

Thursday, June 09, 2011


Boris Sverdlik

Ca292bdd9ad8d8228833ce1f1a44a052

UPDATE: BlackbergSecurity is NOT A DEFENSE CONTRACTOR according to E-VERIFY.

I’d like to preface this again by saying I don’t condone the activities of Lulzsec. I do fall into the crowd of security professionals who Patrick Gray described as secretly loving him. Patrick has written a great piece on the awareness the group has brought to the weaknesses in information security.

I suggest you go out and read it immediately and you’ll see why.

Attrition.org broke a story back in February on how Joe Black has used social media to create his “Security God” image. Needless to say, they debunked the entire image.

Unfortunately, real security guys are the only ones who actually read Attrition, and Joe Black was able to continue in his path to self proclaimed security god.

image

In his efforts to legitimize his site, he has built a reputation around certifications and misinformation. He has a very interesting career, that we can trace back to his days at Wright Printing in 2005 according to his LinkedIn Profile which is also about the time he was supposedly enrolled at ITT in his Bachelors degree program in Omaha.

Calls to ITT have not been returned as of this writing, but Joe did post his associates degree on his flickr page. While we are on the topic of education, his profile also states that he is expecting to complete his Masters in Security Management  at Bellevue University in 2013.

According to the registrar he has withdrawn from every single course he had enrolled in since January of 2009. Guess the worlds greatest hacker, didn’t realize information is public. Oh well.

With his reputation on the line he had called out our neighborhood Lulz maker with the following message on his website:

“Cybersecurity For The 21st Century, Hacking Challenge: Change this website’s homepage picture and win $10K and a position working with Senior Cybersecurity Advisor, Joe Black.”

Guess what happens next?

image

Again, not that I condone any of this, but you know me any chance to prove that security certifications are useless can’t be ignored. Wow, look at all of those interesting certifications on his website.

This guy must be a Security Megastar. Lets see what he has:

image

All can be seen thanks to our brainiac on his Flickr:

  • Project+ COM70010068307772 A+ 1/08
  • Remote Support COMP001006830772 1/09
  • Security+ COMP001006830772 1/08
  • Network+ COMP00100683C772 1/08
  • Linux+ COMP001006830772 2/08
  • CEH ECC926927 09/08CISSP 318010 12/08

What I don’t see is the ISACA CISM & CISA certifications.

Please Joe, if you have them send the numbers my way...

So are we still confident how certifications do not equate to competency? This is just another example of false advertising, and I’m glad it has been brought to light. Black has even used Facebook to advertise his services.

I love his About statement “At Black & Berg Cybersecurity Consulting we leverage our close relationship with the Federal Government to give our small business clients a Cybersecurity posture that equals or exceeds that of the NSA and Department of Defense.”

Wait speaking of his federal contacts he does have a CAGE# on his LinkedIn Profile. Wow, legit eh... EXPIRED.

In closing I’m sure you paper security guys would be more than happy to hire him, real security guys well we don’t find our vendors at bus stops.

image

Cross-posted from Jaded Security


Post Rating:

(Rate this Post)

Comments:


728dce02fbc900cb75609c4660de7bf6
Elyssa Durant The CyberSecurity business is a rapidly growing field.

Recruitment has been fast and furious since the United States became aware that we have a serious problem on our hands.

In that process, many firms are taking on interns to test the aptitude for those who are well suited for intelligence and counterintelligence work.

As Joe Black knows. This is a field where you need to prove your skills, and the only way to truly test them is in the field. From there, you either sink or swim.

In addition, that recruitment process has been untraditional; calling on experts from all walks of life.

As we all know, extraordinary times call for extraordinary measures. We live in extraordinary times and operate under extraordinary measures.

Black & Berg CyberSecurity Consulting, LLC is a new firm and failure is not an option.

I think Joe Black is handling the situation with real class responding to directed questions and placing his credentials out there for the world to see.

Joe Black has surrounded himself with a good team, and that is half the battle. This team will stand by him, until we hear otherwise. Our methods, background and training are diverse and atypical. Our dedication and commitment beyond reproach.

Nobody makes it in this business overnight, but Joe Black has, experienced excellent advisers to support him.

What exactly do we know about Lulzsec other than their desire to wreak havoc on the world wide web and their ability to to launch CyberWarfare on those who "dare" to challenge them?

I always get a chuckle when people make [want] to make the assumption that I attended Columbia Community College as opposed to my "real" alma matter, Columbia University in the City of New York.

If people are desperate to see Ivy League Credentials and a few advanced Masters degrees... just send them my way.

5 days ago
728dce02fbc900cb75609c4660de7bf6
Elyssa Durant megacommunities@blackbergsecurity.us
to elyssa.durant@gmail.com
date Wed, Jun 15, 2011 at 7:22 PM
subject Fwd: About your website defacement/compromise.
Important mainly because of the people in the conversation.

hide details 7:22 PM (1 hour ago)

via e-mail from Joseph Black:

Thought you should see this email that I received.

~Joe


---------- Original Message ----------
From: Victor Vennt
To: Megacommunities@blackbergsecurity.us
Date: June 8, 2011 at 8:44 PM
Subject: About your website defacement/compromise.

To whom it may concern:

I believe that "LulzSec" - The notorious hacking group responsible for recent Sony & FBI hacks may have given themselves away & identified themselves with their recent defacement and compromise of your site.

Last year cryptome.com was similarly compromised by a splinter group of "Anonymous" whom went by the name of "DIDITFORTHELULZ", one of that groups 'tag lines" was "We do it for the lulz", the members of that group were eventually exposed, see:

http://cryptome.org/0002/cryptome-hack4.htm

It is believed in certain circles of "Anonymous", that the ringleader of LulzSec is one Corey "Xyrix" Barnhill, further research may yet provide confirmation of this.

One friend of his, and "notable" member of this group has previously been charged with computer tampering, computer trespass, and criminal possession of computer material for an attack on AOL, see: http://www.infoworld.com/d/security-central/ny-teen-hacks-aol-infects-systems-818.

I hope this information is of some interest to you,

A concerned citizen.

48 minutes ago

Black and Berg Cybersecurity Consulting
Black and Berg Cybersecurity Consulting is an early 21st century response to the United States Senate's request for private sector intervention in order to raise our National security posture.

The US government, business, and civil sectors are working directly with Black & Berg to ensure the success of our aggressive campaign to combat Cyberterrorism. We cannot fail in our mission to secure American Cyberspace with the application of a Megacommunity. For if we do fail, then, we really have no choice but to recommend the hand over of complete control of privately owned systems to the Executive Branch of the United States Government.
0 Topics
0 Posts
No posts

The page you were looking for doesn't exist!

It may have been removed or you may have arrived here by using a bad URL

Try searching for the article you are looking for.
Visit the Homepage to see the most recent stories.
Browse categories and tags to find a related story.
Or try the forum at forum.cyberwarzone.com

blackbergsecurity 0 0 (-) 0 0 0 (-) 6000.

Top users
Rank User News Published Comments Total votes
1 CWZ 398 398 (100%) 4 406 399 (98%) 34403.00
2 Lovely 45 45 (100%) 0 45 45 (100%) 9701.00
3 cybercopsindia 10 10 (100%) 0 10 10 (100%) 7203.00
4 nigroeneveld 0 0 (-) 0 0 0 (-) 6000.00
4 blackbergsecurity 0 0 (-) 0 0 0 (-) 6000.00
6 mgd 3 3 (100%) 0 3 3 (100%) 1198.00
7 vagabondhuman35 1 1 (100%) 0 1 1 (100%) 66.00
7 ArnanRecruiter 1 1 (100%) 0 1 1 (100%) 66.00
9 dvlaho 0 0 (-) 0 0 0 (-) 1.00

http://www.forum.cyberwarzone.com/

http://www.network.cyberwarzone.com/404error.php

http://www.cyberwarzone.com/cyberwarfare/advertising

Posted from DailyDDoSe

Tuesday, July 19, 2011

Wikileaks Scam: A Mossad PsyOps Aimed at Iran?

Wikileaks Scam: A Mossad PsyOps Aimed at Iran?

by Gordon Duff

http://www.veteranstoday.com/2010/10/23/gordon-duff-ho-hum-more-wikileaks-chi...

Wikileaks Scam: A Mossad PsyOps Aimed at Iran?  October 23, 2010

 The new Wikileaks claims the US undereported by 15,000, the deaths of Iraqi "civilians." With the numbers listed by the military as little as 10% or less of the actual deaths, bumping up the numbers must be a joke.

More leaks about torture and killings, Iraqi torture and the US "looking away?" More idiocy. With the US sending "suspects" around the world on rendition flights, sent to secret prisons and obvious to anyone with a brain, to shallow graves, this Wikileak is simply another sideshow, more "chickenfeed."

Things have already come apart in Iraq. Why leak this now? Regular news stories are actually going much further than these "leaks." It doesn’t take a rocket scientist to see the agenda here, an agenda with absolutely nothing to do with enlightening the world.

What does it prove, any of it? For sure, we see one thing. Everything leaked is carefully screened to have nothing of real value.

With Mossad running around Mosul, operating out of Erbil, supplying and advising the terrorist PKK, not a word is mentioned.

Instead, poor Iranians are swimming the Euphrates with explosives strapped to their chests.

Get real.

Thousands of tons of explosives were "mislaid" in Iraq. The US failed to secure Saddam’s weapons depots which were looted. These stockpiles were vast. The idea that anyone would need to bring weapons into Iraq is insane, simply another Israeli ploy to pre-stage an attack on Iran. Any fool can see this in seconds.

In fact, there are more assault rifles in Iraq than people.

While trying to blame Iran, is Wikileaks reporting the hundreds of thousands of weapons bought by the US that simply disappeared in Iraq?

It is easier to buy an assault rifle or RPG in Iraq than to get potato chips. This need to blame Iran, the idea that "secret agents" are smuggling ordnance into Iraq, a country loaded with explosives, is insane. Who would believe it? The idiotic controlled press?

What will we see if we watch the stories coming out? Where will the press be told to manipulate the public to look?

THE LIES BEGIN...

"Iran's Training for Iraqi Militants Outlined in Leaked Pentagon Documents"

Bloomberg and The Guardian start the ball rolling. Imagine Iraq, a country with the 3rd largest military force in the world, needing "trainers" from Iran. Iraq with its elite Republican Guard and one million man army has more people with military training that Britain, a fact The Guardian seems oblivious to.

One minute, Iraq is building nuclear weapons and threatening the region with SCUD missiles, the next it is having to turn to "Iranian experts" to build pipe bombs. Has any nation ever suffered such a case of collective amnesia in the area of weapons technology before?

As the days pass, we can expect more and more fanciful accounts of Iranian spies, trainers, kidnappers and terrorists, each story more sensational and fictitious than the last.

There is a more insidious aspect to Wikleaks. Through representing itself as "anti-war" and "public spirited," it carries forward a globalist agenda, promoting war, promoting regional strife, coincidentally all directly tied to Israel's "hit list," the nations Israel openly advocates someone else destroys.

One could easily describe Wikileaks as a Mossad PsyOp.

Thus, Wikileaks is very effective in derailing genuine dialog and meaningful dissent.

ATTORNEY GENERAL GONZALES TOLD US TORTURE WAS GOOD FOR US

Americans proved long ago that they were immune to guilt about torture and killing. In fact, polls show that the more religious an American, the more willing they are to accept brutality, and few countries are as "religious" as America.

No other country in recent times as killed as many people as America, even overshadowing the ethnic cleansing in Rwanda and Bosnia or the "situation' in Israel.

As with the earlier "leak," Wikileaks has the ability to go through hundreds of thousands of pages of documents, carefully eliminating any blackmarket dealings, drug running or, as with Iraq, the massive corruption and theft of oil.

There are dozens of subjects that seem to be carefully screened from any Wikileak. Even the Department of Defense, not so secretly, thanks Wikileaks for holding back really embarrassing information.

"Held back" information is, of course, blackmail.

Who is Wikileaks? Is Wikileaks Israel?

Only Israel has the penetration of the Department of Defense that would allow this kind of spying. Not only can they do it, they also have so many spies in the American chain of command, they could easily prevent it. Who has the facilities to gather and filter this much data? Who would want to?

With the biggest story in Iraq the falsified intelligence on "weapons of mass destruction," why didn't Wikileaks get us documents on this? We know that the military had orders to try to falsify documents showing that they found fully operating nuclear, biological and chemical warfare facilities.

These would have made good reading along with the thousands of pages of reports about how these stories would be fabricated. Even the "controlled pres" wouldn’t touch them although they are still out there.

The lies.

Exposing this real Iraq scandal would so some good, except for one thing, friends of Israel inside the Pentagon were the creators of this program.

Is this why Wikileaks dodges the real issues? Is it because the trail for much of what happened in Iraq heads directly to Tel Aviv?

Who even cares about Iraq this many years later?

Look at the watered down reports about American support of Al Qaeda. The US is blamed for accidentally helping Al Qaeda by organizing the Sons of Iraq. In truth, the US actually reorganized the Baathists, something far worse than the imaginary construct "Al Qaeda." Not a word is said about this.

One of the biggest scams of the Iraq 'experience' was the looting of oil resources. Most easily verified is the theft of oil from the Kirkuk fields through the Kirkuk/Ceyhan pipeline, which goes to the Mediterranean through Turkey. Ships that load oil are shown on locator sights run by insurance companies and even the US Coast Guard. Their tonnage is available, how many ships, how long. When doing the math, how much oil is loaded compared to how much is paid for, billions and billions of dollars of oil is missing.

When Americans were paying $4 a gallon for gas, how many knew the oil that made the gasoline was "free' to the oil companies? Who spit the take on this? Who was paid? How much was stolen through Basra? Were the British involved?

Then we have Fallujah. We are told America “carpet bombed” civilians and "ethnically cleansed" the area, as we are now informed, for no reason. The version the Army told is being debunked along with the phony stories of the "embedded" press. Nothing on this hit Wikileaks either.

We are also noting high levels of radiation there and a health crisis that can only be described as shocking. Where is wikileaks on this REAL story?

There is little doubt that Wikileaks is a "sideshow" run by an intelligence agency with dozens of agents inside the Department of Defense. Only Israel has this capability, having penetrated Defense to such a degree they run it as their own. What is the agenda of Wikileaks? Is it revealing the truth?

If so, why is the truth censored and watered down to such a degree as to be "non-news" as the earlier leak had been. In fact, most stories about leaks are simply speculation and most "leaks" are little than "chickenfeed."

The last leak was an attack on Pakistan. Wikileaks tried to make a case for Pakistan running the Taliban in Afghanistan. However, the Taliban are Pashtun and don’t care much for Pakistan, they are 'blood enemies." Because of this, Israel and India have found them useful allies against Pakistan, the only Islamic nuclear power.

Aid of all kinds gets to the Taliban from the Mossad and RAW, something Wikileaks worked hard to keep secret.

Real leaks by former FBI translator Sibel Edmonds proved that documents exist showing that rendition flights were used to ferry terrorists around, move drugs and tons of cash. With bales of cash leaving Afghanistan every day, why is it that not one page, not one word of any of this, things we know are in American files, hit Wikileaks?

Why does Wikileaks spend more time hiding things than revealing them? When the story dies down, are the Julian Assange rape allegations going to be dragged out again to give the story more play?

Last time they 'double dipped' on that one, first charges, then no charges, then charges. It was like a badly written "soap opera." We have just received reports of Julian Assange fleeing Pentagon death squads. We are told he has virtually disappeared off the face of the planet. We also have a schedule of public appearances and interviews for Assange, who will mysteriously re-materialize when needed. Ah, to have powers such as those.

What about this new "leak?'

This one may be aimed at Iran.

Anyone surprised or shocked to find that Iraqi security forces killed or tortured people is living on their own private planet. These were Saddam's killers and torturers first. Then they became ours. What do killers and torturers do?

There was one reason for the invasion of Iraq with all the lies, all the killing, all the corruption. Israel wanted Iraq destroyed. Will Wikileaks ever get to something real?
 

http://www.whale.to/b/duff1.html

Posted via email from Whistleblower

Wednesday, June 22, 2011

21 year old Iranian hacker tagets CIA and Israel with stuxnet attack | Cyber Warzone #FAIRWARNING

21 year old Iranian hacker & think tank has avenged the stuxnet attack | Cyber Warzone

Media_httpcyberwarzon_cqggd

Submitted by Reza Rafati on Mon, 03/28/2011 - 14:48

1.Hello
2.
3.I'm writing this to the world, so you'll know more about me..
4.
5.At first I want to give some points, so you'll be sure I'm the hacker:
6.
7.I hacked Comodo from InstantSSL.it, their CEO's e-mail address mfpenco@mfpenco.com
8.Their Comodo username/password was: user: gtadmin password: [trimmed]
9.Their DB name was: globaltrust and instantsslcms
10.
11.GlobalTrust.it had a dll called TrustDLL.dll for handling Comodo requests, they had resellers and their url was:
12.http://www.globaltrust.it/reseller_admin/
13.
14.Enough said, huh? Yes, enough said, someone who should know already knows...Am I right Mr. Abdulhayoglu?
15.
16.Anyway, at first I should mention we have no relation to Iranian Cyber Army, we don't change DNSes, we
17.
18.just hack and own.
19.
20.I see Comodo CEO and others wrote that it was a managed attack, it was a planned attack, a group of
21.
22.cyber criminals did it, etc. etc. etc.
23.
24.Let me explain:
25.
26.a) I'm not a group of hacker, I'm single hacker with experience of 1000 hackers, I'm single programmer with
27.
28.experience of 1000 programmers, I'm single planner/project manager with experience of 1000 project
29.
30.managers, so you are right, it's managed by a group of hackers, but it was only I with experience of 1000
31.
32.hackers.
33.
34.b) It was not really a managed hack. At first I decided to hack RSA algorithm, I did too much
35.
36.investigation on SSL protocol, tried to find an algorithm for factoring integer, analyzed existing algorithms, for now I was not
37.
38.able to do so, at least not yet, but I know it's not impossible and I'll prove it, anyway... I saw
39.
40.that there is easier ways of doing it, like hacking a CA. I was looking to hack some CAs like Thawthe,
41.
42.Verisign, Comodo, etc. I found some small vulnerabilities in their servers, but it wasn't enough to
43.
44.gain access to server and sign my CSRs. During my search about InstantSSL of Comodo which signs CSRs immediately I found
45.
46.InstantSSL.it which was doing it's job under control of Comodo.
47.
48.After a little try, I analyzed their web server and easily (easy for me, so hard for others) I got FULL access on the server, after a little investigation on their
49.
50.server, I found out that TrustDll.dll takes care of signing. It was coded in C# (ASP.NET).
51.
52.I decompiled the DLL and I found username/password of their GeoTrust and Comodo reseller account.
53.
54.GeoTrust reseller URL was not working, it was in ADTP.cs. Then I found out their Comodo account works
55.
56.and Comodo URL is active. I logged into Comodo account and I saw I have right of signing using APIs. I
57.
58.had no idea of APIs and how it works. I wrote a code for signing my CSRs using POST request to those
59.
60.APIs, I learned their APIs so FAST and their TrustDLL.DLL was too old and was not working properly, it doesn't send all needed parameters,
61.
62.it wasn't enough for signing a CSR. As I said, I rewrote the code for !AutoApplySSL and !PickUpSSL
63.APIs, first API returns OrderID of placed Order and second API returns entire signed
64.
65.certificate if you pass OrderID from previous call. I learned all these stuff, re-wrote the code and
66.
67.generated CSR for those sites all in about 10-15 minutes. I wasn't ready for these type of APIs, these
68.
69.type of CSR generation, API calling, etc. But I did it very very fast.
70.
71.Anyway, I know you are really shocked about my knowledge, my skill, my speed, my expertise and entire attack.
72.
73.That's OK, all of it was so easy for me, I did more important things I can't talk about, so if you have to
74.
75.worry, you can worry... I should mention my age is 21
76.
77.Let's back to reason of posting this message.
78.
79.I'm talking to the world, so listen carefully:
80.
81.When USA and Israel creates Stuxnet, nobody talks about it, nobody blamed, nothing happened at all,
82.
83.so when I sign certificates nothing should happen, I say that, when I sign certificates nothing should
84.
85.happen. It's a simple deal.
86.
87.I heard that some stupids tried to ask about it from Iran's ambassador in UN, really? How smartass you are?
88.Where were you when Stuxnet created by Israel and USA with millions of dollar budget, with access to SCADA systems and Nuclear softwares? Why no one asked a question from Israel and USA ambassador to UN?
89.So you can't ask about SSL situtation from my ambassador, I answer your question about situtation: "Ask about Stuxnet from USA and Israel", this is your answer, so don't waste my Iran's ambassador's worthy time.
90.
91.When USA and Isrel can read my emails in Yahoo, Hotmail, Skype, Gmail, etc. without any simple
92.
93.little problem, when they can spy using Echelon, I can do anything I can. It's a simple rule. You do,
94.
95.I do, that's all. You stop, I don't stop. It's a rule, rule #1 (My Rules as I rule to internet, you should know it
96.
97.already...)
98.
99.Rule#2: So why all the world worried, internet shocked and all writers write about it, but nobody
100.
101.writes about Stuxnet anymore? Nobody writes about HAARP, nobody writes about Echelon... So nobody
102.
103.should write about SSL certificates.
104.
105.Rule#3: Anyone inside Iran with problems, from fake green movement to all MKO members and two faced
106.
107.terrorists, should afraid of me personally. I won't let anyone inside Iran, harm people of Iran, harm
108.
109.my country's Nuclear Scientists, harm my Leader (which nobody can), harm my President, as I live, you
110.
111.won't be able to do so. as I live, you don't have privacy in internet, you don't have security in
112.
113.digital world, just wait and see...By the way, you already have seen it or you are blind, is there any larger target than a CA in internet?
114.
115.Rule#4: Comodo and other CAs in the world: Never think you are safe, never think you can rule the
116.
117.internet, ruling the world with a 256 digit number which nobody can find it's 2 prime factors (you think so), I'll show
118.
119.you how someone in my age can rule the digital world, how your assumptions are wrong, you already understood it, huh?
120.
121.Rule#5: To microsoft, mozilla and chrome who updated their softwares as soon as instructions came from
122.
123.CIA. You are my targets too. Why Stuxnet's Printer vulnerability patched after 2 years? Because it was
124.
125.needed in Stuxnet? So you'll learn sometimes you have to close your eyes on some stuff in internet,
126.
127.you'll learn... You'll understand... I'll bring equality in internet. My orders will equal to CIA orders,
128.
129.lol
130.
131.Rule#6: I'm a GHOST
132.
133.Rule#7: I'm unstoppable, so afraid if you should afraid, worry if you should worry.
134.
135.My message to people who have problem with Islamic Republic of Iran, SSL and RSA certificates are broken, I did it one time, make sure I'll do it again, but this time nobody will notice it.
136.I see some people suggests using VPNs, some people suggests TOR, some other suggests UltraSurf, etc. Are you sure you are safe using those? RSA 2048 was not able to resist in front of me, do you think UltraSurf can?
137.
138.If you was doing a dirty business in internet inside Iran, I suggest you to quit your job, listen to sound of most of people of Iran, otherwise you'll be in a big trouble, also you can leave digital world
139.and return to using abacus.
140.
141.A message in Persian: Janam Fadaye Rahbar
142.
143.
144.[UPDATE 1]: Also check this: http://pastebin.com/DBDqm6Km

Trackback URL for this post:
http://www.cyberwarzone.com/trackback/464

THIS GUY HAS ADMIN RIGHTS FOR THE BLACK & BERG SITE AND HAS LAUNCHED A VICIOUS ATTACK ON ME WHEN I CALLED HIS BLUFF.

SO THERE YOU HAVE IT. I SAW THIS COMING, I PUT OUT FAIR WARNING, AND NOW I'M BEING BY EVERY HACKER IN THIS WHOLE MISERABLE PLANET.

I AM NOT THRILLED WITH THE UNITED STATES GOVERNMENT BY ANY STRETCH OF THE IMAGINATION. ESPECIALLY NOW THAT I AM UNDER ATTACK, AND I DON'T SEE ANYONE TRYING TO ASSIST ME IN GETTING DE-HACKED.

THE BOTTOM LINE IS THIS, I LIVE IN AMERICA, SO IF THIS COUNTRY GETS HIT, I DIE ALONG WITH MY ENTIRE FAMILY. IDGAF ABOUT MOST OF YOU, BUT THERE A FEW PEOPLE THAT DESERVE A FIGHTING CHANCE.

THAT IS ALL FOR NOW. I AM PHYSICALLY ILL OVER THIS, AND ALL MY COMMUNICATIONS ARE COMPROMISED. I DON;T DRIVE SO I CAN'T JUST "GO THE LIBRARY" AND EVEN IF I COULD, THEY ARE NOT ABOUT TO HELP ME SORT OUT THIS DISGUSTING MESS.

GOOD BYE FOR NOW. IF THIS SITE GOES DOWN, JUST KNOW THAT IT CONTAINS NOW ONLY MY PERSONAL PUBLICATIONS, BUT ALL OF MY WORK TRYING TO SORT OUT THIS UGLY MESS BEFORE IT IS TOO LATE.

JUST ME,

@ElyssaD

Posted via email from Whistleblower

Wednesday, June 15, 2011

Fake Security Firms Will Be Exposed || CyberWarzone #404

Thursday, June 09, 2011


Boris Sverdlik

Ca292bdd9ad8d8228833ce1f1a44a052

UPDATE: BlackbergSecurity is NOT A DEFENSE CONTRACTOR according to E-VERIFY.

I’d like to preface this again by saying I don’t condone the activities of Lulzsec. I do fall into the crowd of security professionals who Patrick Gray described as secretly loving him. Patrick has written a great piece on the awareness the group has brought to the weaknesses in information security.

I suggest you go out and read it immediately and you’ll see why.

Attrition.org broke a story back in February on how Joe Black has used social media to create his “Security God” image. Needless to say, they debunked the entire image.

Unfortunately, real security guys are the only ones who actually read Attrition, and Joe Black was able to continue in his path to self proclaimed security god.

image

In his efforts to legitimize his site, he has built a reputation around certifications and misinformation. He has a very interesting career, that we can trace back to his days at Wright Printing in 2005 according to his LinkedIn Profile which is also about the time he was supposedly enrolled at ITT in his Bachelors degree program in Omaha.

Calls to ITT have not been returned as of this writing, but Joe did post his associates degree on his flickr page. While we are on the topic of education, his profile also states that he is expecting to complete his Masters in Security Management  at Bellevue University in 2013.

According to the registrar he has withdrawn from every single course he had enrolled in since January of 2009. Guess the worlds greatest hacker, didn’t realize information is public. Oh well.

With his reputation on the line he had called out our neighborhood Lulz maker with the following message on his website:

“Cybersecurity For The 21st Century, Hacking Challenge: Change this website’s homepage picture and win $10K and a position working with Senior Cybersecurity Advisor, Joe Black.”

Guess what happens next?

image

Again, not that I condone any of this, but you know me any chance to prove that security certifications are useless can’t be ignored. Wow, look at all of those interesting certifications on his website.

This guy must be a Security Megastar. Lets see what he has:

image

All can be seen thanks to our brainiac on his Flickr:

  • Project+ COM70010068307772 A+ 1/08
  • Remote Support COMP001006830772 1/09
  • Security+ COMP001006830772 1/08
  • Network+ COMP00100683C772 1/08
  • Linux+ COMP001006830772 2/08
  • CEH ECC926927 09/08CISSP 318010 12/08

What I don’t see is the ISACA CISM & CISA certifications.

Please Joe, if you have them send the numbers my way...

So are we still confident how certifications do not equate to competency? This is just another example of false advertising, and I’m glad it has been brought to light. Black has even used Facebook to advertise his services.

I love his About statement “At Black & Berg Cybersecurity Consulting we leverage our close relationship with the Federal Government to give our small business clients a Cybersecurity posture that equals or exceeds that of the NSA and Department of Defense.”

Wait speaking of his federal contacts he does have a CAGE# on his LinkedIn Profile. Wow, legit eh... EXPIRED.

In closing I’m sure you paper security guys would be more than happy to hire him, real security guys well we don’t find our vendors at bus stops.

image

Cross-posted from Jaded Security


Post Rating:

(Rate this Post)

Comments:


728dce02fbc900cb75609c4660de7bf6
Elyssa Durant The CyberSecurity business is a rapidly growing field.

Recruitment has been fast and furious since the United States became aware that we have a serious problem on our hands.

In that process, many firms are taking on interns to test the aptitude for those who are well suited for intelligence and counterintelligence work.

As Joe Black knows. This is a field where you need to prove your skills, and the only way to truly test them is in the field. From there, you either sink or swim.

In addition, that recruitment process has been untraditional; calling on experts from all walks of life.

As we all know, extraordinary times call for extraordinary measures. We live in extraordinary times and operate under extraordinary measures.

Black & Berg CyberSecurity Consulting, LLC is a new firm and failure is not an option.

I think Joe Black is handling the situation with real class responding to directed questions and placing his credentials out there for the world to see.

Joe Black has surrounded himself with a good team, and that is half the battle. This team will stand by him, until we hear otherwise. Our methods, background and training are diverse and atypical. Our dedication and commitment beyond reproach.

Nobody makes it in this business overnight, but Joe Black has, experienced excellent advisers to support him.

What exactly do we know about Lulzsec other than their desire to wreak havoc on the world wide web and their ability to to launch CyberWarfare on those who "dare" to challenge them?

I always get a chuckle when people make [want] to make the assumption that I attended Columbia Community College as opposed to my "real" alma matter, Columbia University in the City of New York.

If people are desperate to see Ivy League Credentials and a few advanced Masters degrees... just send them my way.

5 days ago
728dce02fbc900cb75609c4660de7bf6
Elyssa Durant megacommunities@blackbergsecurity.us
to elyssa.durant@gmail.com
date Wed, Jun 15, 2011 at 7:22 PM
subject Fwd: About your website defacement/compromise.
Important mainly because of the people in the conversation.

hide details 7:22 PM (1 hour ago)

via e-mail from Joseph Black:

Thought you should see this email that I received.

~Joe


---------- Original Message ----------
From: Victor Vennt
To: Megacommunities@blackbergsecurity.us
Date: June 8, 2011 at 8:44 PM
Subject: About your website defacement/compromise.

To whom it may concern:

I believe that "LulzSec" - The notorious hacking group responsible for recent Sony & FBI hacks may have given themselves away & identified themselves with their recent defacement and compromise of your site.

Last year cryptome.com was similarly compromised by a splinter group of "Anonymous" whom went by the name of "DIDITFORTHELULZ", one of that groups 'tag lines" was "We do it for the lulz", the members of that group were eventually exposed, see:

http://cryptome.org/0002/cryptome-hack4.htm

It is believed in certain circles of "Anonymous", that the ringleader of LulzSec is one Corey "Xyrix" Barnhill, further research may yet provide confirmation of this.

One friend of his, and "notable" member of this group has previously been charged with computer tampering, computer trespass, and criminal possession of computer material for an attack on AOL, see: http://www.infoworld.com/d/security-central/ny-teen-hacks-aol-infects-systems-818.

I hope this information is of some interest to you,

A concerned citizen.

48 minutes ago

Black and Berg Cybersecurity Consulting
Black and Berg Cybersecurity Consulting is an early 21st century response to the United States Senate's request for private sector intervention in order to raise our National security posture.

The US government, business, and civil sectors are working directly with Black & Berg to ensure the success of our aggressive campaign to combat Cyberterrorism. We cannot fail in our mission to secure American Cyberspace with the application of a Megacommunity. For if we do fail, then, we really have no choice but to recommend the hand over of complete control of privately owned systems to the Executive Branch of the United States Government.
0 Topics
0 Posts
No posts

The page you were looking for doesn't exist!

It may have been removed or you may have arrived here by using a bad URL

Try searching for the article you are looking for.
Visit the Homepage to see the most recent stories.
Browse categories and tags to find a related story.
Or try the forum at forum.cyberwarzone.com

blackbergsecurity 0 0 (-) 0 0 0 (-) 6000.

Top users
Rank User News Published Comments Total votes
1 CWZ 398 398 (100%) 4 406 399 (98%) 34403.00
2 Lovely 45 45 (100%) 0 45 45 (100%) 9701.00
3 cybercopsindia 10 10 (100%) 0 10 10 (100%) 7203.00
4 nigroeneveld 0 0 (-) 0 0 0 (-) 6000.00
4 blackbergsecurity 0 0 (-) 0 0 0 (-) 6000.00
6 mgd 3 3 (100%) 0 3 3 (100%) 1198.00
7 vagabondhuman35 1 1 (100%) 0 1 1 (100%) 66.00
7 ArnanRecruiter 1 1 (100%) 0 1 1 (100%) 66.00
9 dvlaho 0 0 (-) 0 0 0 (-) 1.00

http://www.forum.cyberwarzone.com/

http://www.network.cyberwarzone.com/404error.php

http://www.cyberwarzone.com/cyberwarfare/advertising

Posted via email from Whistleblower