Monday, July 11, 2011

Lessons from LIGATT

Lessons from LIGATT


Monday, July 11, 2011



Ben Rothke

D9d968536525db2cf6ac805403260d61

I have been writing book reviews on information security and technology books for quite a while.  Topics such as authentication, security design, operational resilience, biometrics and security policy are rather tame and most of the reviews don’t generate a huge amount of controversy.

In fact, before June 2010, no book review I wrote ever lead to being interviewed by a major network for an expose of theirs, or a personal attack by the author (including being called a racist and a stock basher) against myself, Chris John Riley, Sam Bowne and others.  These critiques by aforementioned and others were never a personal issue, and this article is simply a record of lessons learned.

Writing book reviews is something I do as a pastime, and with that, I generally refrain from writing negative book reviews.  But occasionally, some books are so problematic that one can’t remain silent. 

That is what lead to my June 2010 review of How to be the World’s #1 Hacker, written by Gregory D. Evans of LIGATT Security International (and SPOOFEM.COM and High Tech Crime Solutions Inc.). I demonstrated (as did Brian Baskin) that significant amounts of the book were plagiarized. This was based on the use of the iThenticate service.  iThenticate is one of the leading plagiarism detection services that provides impartial content analysis.  I published the book review and thought that was the end of it. 

For those who need a briefing on the LIGATT saga, Attrition notes that Evans describes himself as a hi-tech hustler, The World’s No. 1 Hacker and a convicted felon. Attrition further writes that Evans has invented himself as some form of hacker with the ability to break into anything and spin that supposed knowledge into advising companies on security.

It is the common opinion of industry experts that Evans and his company have little real knowledge beyond pedestrian hacking techniques found in plagiarized books and beginner hacking texts. LIGATT offers products that are simply bloated version of common tools such as ping and nmap.

Due to a variety of unexpected events that took place, my book review did not simply end there. I ultimately learned a considerable amount about a number of topics, from fair use to securities law and more, and met a lot of smart people along the way.  I would like to share those lessons with you.

Twitter is a powerhouse for action

Details

From as early as 2009, the use of Twitter for organized student protests significantly changed the dynamics of mass communications.  In 2011, we saw the use of Twitter to overthrow the corrupt Tunisian government and fight the oppressive Syrian regime.  Twitter is indeed a powerhouse for action. 

Twitter and other social media outlets are changing the way business and marketing are done.

Lesson

While Fox, Bloomberg and other media outlets had Evans on their show, Twitter was often the medium for those that did not view Evans as the number 1 security expert to get the word out via the #Ligatt hash tag.  People and organizations such as Attrition, 0ph3lia, Sam Bowne, Marcus Carey, Chris John Riley and krypt3ia used the #LIGATT hashtag to get their message across.

Self-publishing

Details

Indie movies came about due to the frequent inability for smaller movie producers to get the attention of the major studios. When it comes to books, self-publishing is often a great way to bypass traditional publishers and quickly get a book into print.

But with that ability, many authors will self-publish; bypassing the editing, fact checking and rigorous plagiarism checking that a traditional publishing house will typically perform.

Rich O’Hanley, publisher at Auerbach Publications and CRC Press, notes that plagiarism continues to plague both his firm and the entire industry, thanks to the self-publishing and the web, and its ethos that information should be free. The reality is that it is far too easy for authors to use whatever is available.

O’Hanley is not sure if the motivation to plagiarize is driven by ignorance of copyright rules, or simply the perception that they won’t be caught.  Even authors whose careers predate the web, fall victim to this and use material they can cut-and-paste that they likely wouldn’t use if they had to retype it.  CRC Press has tightened the whole permissions process, but it’s still a matter of trusting the author and his or her attestations. 

Lesson

Had How to be the World’s #1 Hacker been sent to a traditional publisher, it likely would have been flagged immediately and never allowed into print.

Evans has claimed in interviews and self-made YouTube videos to have had permission from the sources he used.  But as of July 2011, he has yet to show a single document, email or contract that entitled him to re-publish the works of others.

Fair use

Details

The US judicial system (see 17 U.S.C. § 106 and 17 U.S.C. § 106A) allows for the fair use of copyrighted content. While there is no definitive level of where fair use ends and plagiarism begins, How to be the World’s #1 Hacker crosses the line according to a reasonable assessment of what fair use is.

In An Independent Plagiarism Review of How to Become the World's No. 1 Hacker, Brian Baskin noted that you will find that many of the references are from NMRC; a site run by Simple Nomad. Simple Nomad developed the basic structure that Evans used to plan his table of contents, as well as originally developed the material used by Evans in his book. This was excellently written material, but is dated originally from 2000.

What Evans also did was modify some of the text that Simple Nomad wrote, to make it look like he was in fact the true author.

Ron Coleman, Partner, Head of Intellectual Property Department at Goetz Fitzpatrick LLP and general counsel of the Media Bloggers Association, notes that even seasoned attorneys are often at sea about where a quotation crosses the line from fair use to copyright infringement. 

Coleman observed that “fair use is a very fact-specific inquiry, where courts are often asked to weigh a lot of factors at the same time.  The tricky part is that while judges are making very subjective decisions about liability, the copyright statute is designed -- with mandatory awards of attorneys’ fees and in some cases of statutory damages -- to punish every infringer as if he knew in advance how that equation would come out.  In the close cases, that's simply impossible.”

Lesson:

Before I wrote my review, I was not aware of the fine details of fair use With How to be the World’s #1 Hacker, objective analysis demonstrated that there was lot of use, and very little of it fair.

Copyrights

Details

A copyright is a set of exclusive rights granted by a state to the creator of an original work or their assignee for a limited period of time in exchange for public disclosure of the work. This includes the right to copy, distribute and adapt the work. 

Without copyright protection, most artists and authors would not create music or books, if their works could not be protected.  With that, copyright owners have the exclusive statutory right to exercise control over copying and other exploitation of the works for a specific period of time, after which the work is said to enter the public domain. Uses covered under limitations and exceptions to copyright, such as fair use, do not require permission from the copyright owner. All other uses require permission.

The notion of a copyright has its roots in the United States Constitution; where it states in Article I, Section 8, Clause 8 (known as the Copyright Clause) that empowers the United States Congress to “promote the Progress of Science and useful Arts, by securing for limited Times to Authors and Inventors the exclusive Right to their respective Writings and Discoveries”.

Lesson

As detailed in Gregory D. Evans, Copyright Violations for Over a Year, Evans has been plagiarizing content for his Twitter feed and associated web sites, here and here  

The copyright violations are that the LIGATT sites scrape entire news articles, including the graphics, without permission. While LIGATT ultimately gave give credit to the original source at the end of the article; that does not justify what he is doing or make it legal. Reproducing an entire piece of work without permission is a copyright violation.

One site LIGATT scraped a significant amount of content from is the Krypt3ia blog.  Note that the following statement on the blog site leaves little room for ambiguity:  All content of this site is copyright of Krypt3ia (Scot A. Terban) and not to be copied unless express consent is given in writing by its author.  LIGATT never received permission to use the content.

Blog owner Scot Terban observed that “it seems to be the standard of practice on the LIGATT sites that no original content is ever posted by Mr. Evans.  There are quite a few PR pieces and links to interviews he has done in the past.  But as far as his own original content, there is none.   Instead, there is an overabundance of scraped content from well-known information security web sites and noted authors; many of whom likely don’t know that their content has been copied”.

Penny stocks

Much of the spam you get is around weight loss and various schemes to make money.  Rarely will a day go by that you won’t receive numerous spam emails touting a hot stock tip.

Often these emails are used in pump-and-dump schemes (P&D).  The US Securities and Exchange Commission (SEC) define P&D as “the touting of a company's stock (typically microcap companies) through false and misleading statements to the marketplace. After pumping the stock, fraudsters make huge profits by selling their cheap stock into the market”.

Since most of these companies being pumped are listed on the Pink Sheet (an unregulated market), a stock moving up just one cent (since these companies have as many as 5 billion shares of stock or more) can bring significant money to those pumping it, when they finally dump it.

How to Identify a Pump and Dump Stock Scam notes that if the stock trades on the OTC (Over The Counter) or Pink Sheet Exchanges, it is often an indicator of a scam. Stocks traded on these exchanges do not fulfill the rigorous requirements of the NYSE, NASDAQ, or American Stock Exchanges.

In Tips To Identify Pump And Dump Schemes at Motley Fool, a few quick tips to help identify P&D schemes are to:

  • look at the structure of the company
  • examine the trading and price history
  • take a close look at the founders of the company (previous experience, background, etc.)
  • look at the percentage ownership of the company (insider, retail, institutional)
  • look at any VC investors that have made investments in the company

Harry Domash writes in Beware of pump-and-dump stocks that promoters pump the stock by issuing copious media releases announcing the firm’s entry into a variety of promising businesses.

Domash notes that in truth, it is relatively easy to spot these risky stocks and lists six checks you can use to quickly rule out dangerous stocks, whether pump-and-dumpers or just bad ideas. He suggests ruling out any stock that fails to meet the following:

  1. Last price above 50 cents
  2. Last-quarter sales at least $10 million
  3. Market capitalization at least $50 million.
  4. Institutional ownership at least 15%
  5. Debt/equity ratio less than 3
  6. Maximum price/book ratio of 30

Ryk Edelstein, veteran entrepreneur and CEO at Cicada Security Technology has seen the dark side of P&D, having observed a well-intentioned business owner partner with less well intentioned partners who offered a promise of riches and success by simply letting them take the company public. To those in the high tech sector, there is no shortage of charlatans who will approach unsuspecting business owners, stoking their egos, and appealing to greed.

Consequently, as in the case of the well intentioned business owner, at the end of his partner’s cycle of P&D, he was left sucked dry holding a valueless corporate shell, debt, and facing the prospect of serious legal repercussions.

Lesson

Like many companies listed on the pink sheets, LIGATT (while not necessarily a P&D stock) seemed to consistently use myriad press releases as a method of garnering attention to the company, which would ostensibly serve to increase the perceived value of the company.

LIGATT press releases are somewhat unique in that many of them are unidirectional; in that the other party does not issue a corresponding press release.

One of countless examples of bidirectional press releases is the June 2011 strategic partnership of Juniper Networks and OnLive under which Juniper will be the exclusive networking provider for OnLive's network infrastructure.  This was announced on both Juniper’s web site and correspondingly on OnLive’s web site.

When it comes to LIGATT, I could not find a company or organization mentioned in their press releases that has reciprocated with a similar press release.

 Notice the following:

Regulation has its limits

Details

Even with SOX, GLBA and other regulations, the consumer and investor ultimately can’t be fully protected. The finance system and financial markets in this country are so complex, with so many layers and with so many interrelated parts, that it is ripe for abuse.

Even with the SEC in place to regulate such entities, publicly traded companies on the Pink OTC Markets (Pink Sheets) are lower priority for investigations, for many reasons. 

Even the Food and Drug Administration (FDA) often finds itself limited, even with its regulatory powers.  As I wrote in New York News Radio, the Voice Of Bad Science, for the consumer, whenever they hear the following mandated FDA disclaimer, they should immediately be suspicious:  These statements have not been evaluated by the Food and Drug Administration. This product is not intended to diagnose, treat, cure or prevent any disease.  After such a disclaimer, an able person should ask himself or herself, if the product is not intended to diagnose, treat, cure or prevent any disease, why use it?  Nonetheless, even such regulatory disclaimers seem to go in one ear and out the other of most consumers.

Part of the reason regulation won’t work is that an investor with an insatiable appetite for profits, often finds that their ability to reason is occluded.  Combine this with the flash of mega-gains that the P&D maker’s supply and people will invariably find themselves on the losing end of the deal, with no recourse in which to recoup their losses. 

Corresponding to what Ryk Edelstein observed earlier about the well-intentioned business owner; there are many entities required to make a P&D work; from lawyers, securities underwriters, transfer agents and much more.  Any regulation that would encompass all of the myriad entities would have to be so draconian as to stop all market activities.  And such a thing will never happen.

Lesson:

Even with the many LIGATT lawsuits, including many frivolous cases filed by Evans, the most recent case on April 11, 2011,the legal case LIGATT filed was thrown out of court and the firm ordered to pay over $29,000 in legal costs to the other party. 

With all of this, as of July 2011, the SEC has not announced any sort of investigation against LIGATT.  Nor have any securities lawyers I consulted said they expect any investigation against the firm any time soon. 

Pink sheets are not for girls’ beds

While there is the NYSE, NASDAQ and other reputable exchanges, it should be noted that the Pink Sheets is not a stock exchange. In fact, firms have very little requirements in order to be quoted in the Pink Sheets.  Since many of these firms do not submit timely financial statements, nor perform third-party audits, it makes it difficult for the investor to really understand what they are getting into.

It is questionable why any novice investor would want to invest in a firm that can’t afford or won’t submit an audited financial statement. It is for these reasons and more, that Pink Sheet firms are extremely risky. Read: a place where naïve investors can lose their entire investment quickly and effortlessly.

This does not mean to imply that all Pink Sheet stocks should be avoided, as there are certainly many legitimate Pink Sheet companies.  Many are smaller firms with legitimate intentions of starting small and growing big.  But given there are so many that are not like that, the novice investor in the Pink Sheet market is going down a road fraught with financial risk.

Much of the hype of some of these Pink Sheet companies is often based on the charisma and hyperbole of the financial people and executives at the companies. Uneducated and unsophisticated investors, who lack the most basic financial wherewithal and fail to perform due diligence, become victims to these charlatans.

As noted in the previous paragraph, the very nature of Pink Sheets means they can never be fully and properly regulated. With that lack of common financial sense of basic investors, and Barnum’s observations, those people are for the most part doomed to losing their investment. 

Investors who are not comfortable with the underlying mechanics of how the financial markets operate should consider the pink sheet market just like a Vegas Casino; where the odds are stacked against them from the start. 

A market maker who works in the pink sheet world succinctly told me that “these stocks are garbage.  You buy a stock for a half a cent and hope if goes to a penny”.

Lesson:

LIGATT (LGTT.PK) is a pink sheet stock, better known as a penny stock. As to LIGATT and Pink Sheets, the following screen shot says it all:

Rothke-Ligatt 1

On any given day, hundreds of media outlets need content to fill their airwaves.  Radio stations, newspapers, periodicals and a never ending supply of cable channels need people they can interview on the air to use for external expertise.

Over the last year, LIGATT PR solicited numerous media outlets, who in turn had Evans appear as an expert and provide commentary.  Just a few weeks ago, their PR department sent the following email to many media outlets (click image to enlarge):

Rothke-Ligatt 2

Lesson

Numerous media outlets had Evans on air, irrespective of his false associations (Atlanta Hawks, Atlanta Thrashers, Los Angeles Clippers, Phillips Arena and more), false certifications, and authorship of plagiarized books to make him seem like he was indeed the “worlds #1 hacker”.

With that, one can pose the question – if the  major media outlets such as Fox, CNN, Bloomberg, et al, can’t get it right with a guest on technology, what does that say about their approach for foreign policy, investment news and more pressing concerns.

While the major media players ignored Evan’s qualifications, it is worth noting that the smaller media outlets such as The Register, Tech Herald  and CBS Atlanta affiliate did run exposes about the firm and its titular #1 hacker.

Racism in the USA

Not a Miley Cyrus song, but racism is a serious transgression.  It wasn’t that long ago that an African American couldn’t use a public restroom or drinking fountain in this country.  These racist inequalities were the driving force behind the establishment of the NAACP and other such organizations. 

In the 100 years since the founding of the NAACP, a lot has changed.  Take a look at the former Secretary of State, the current President and Attorney General; it is clear that state-sponsored racism is no longer an issue.

Perhaps fighting racism is no longer the raison d'être of the NAACP.  To a degree, the organization has been reduced to a business that produces the NAACP Image Awards.

The irony is that in March of this year, the NAACP had its image tarnished, as it found itself on the receiving end of a boycott, since Kid Rock received the NAACP Great Expectations award at the Detroit NAACP gala.

This award caused a dispute by some who believe that he should not have received the award.  Their opinion is that he is an inappropriate choice given his affiliation with the Civil War-era Confederate Army flag, which has been adopted by white supremacists, and have irked many civil rights activists. In fact, some supporters of the civil rights organization boycotted the annual fundraiser on May 1 because of the issue.

The singer has argued that the flag stands as a symbol of southern rock and roll, but many protesters don’t quite see it that way.  Dr. Boyce Watkins, Professor at Syracuse University writes that if anyone ever wants to understand why so many in the black community have lost faith in certain elements of the NAACP, you need to look no further than this incident.  He notes that It’s one thing for the NAACP to remain quiet about Kid Rock’s use of one of the most traumatic symbols in American history, but quite another for them to step up and give him an award for it.

Lesson

The NAACP presented Evans with its NAACP humanitarian award in 2002.

But LIGATT used press releases to accuse respected professionals who did deeper investigations and analysis into its activities of having a racist agenda and being some of the world’s worst cyberbullies.  Some examples include a blog posting in June 2010, How Can Computer Nerds Be Racist, where LIGATT accused this author and Chris John Riley of being racist, and emphasized the claims that criticism leveled at Evans' and LIGATT are all racially motivated.  

For a full account, see Security firm fights racism in InfoSec while apparently profiting from it and World's No. 1 hacker' tome rocks security world - Plagiarism, racism, and fake Mitnickism alleged.

LIGATT even accused CBS Atlanta of having a racist agenda when they ran an expose against the firm.  While CBS Atlanta posted the response from LIGATT, it was somewhat ironic that portions of the response had to be redacted because of racially offensive language from LIGATT themselves.

Yet when his charges of racism where brought to the attention of the NAACP, they did not seem receptive to the issue, nor did they revoke the award.  Furthermore, despites our attempts to contact them they never return a phone call or replied to email.

Despite numerous emails, phone calls, conversations with the executive assistant to the president of the NAACP, or messages directly to the President of the organization would be invoke even the gesture of a courtesy reply. 

But big organizations have politics and bureaucracies like the best of them.  As for the NAACP, I was disappointed to see the organization ignore a complaint about one of their award winners making baseless accusations of racism.

Conclusion

I am currently writing a review on a book about cloud computing.  Something tells me (and I certainly hope) that it won’t be as much as an adventure as this review was. On the upside, I learned a lot more by writing the review than by reading Evans’ book. 
 
 

Ben Rothke CISSP, CISA (@benrothke) works in the information security field, writes the Security Reading Room blog and is the author of Computer Security: 20 Things Every Employee Should Know (McGraw-Hill).

https://www.infosecisland.com/blogview/15064-Lessons-from-LIGATT.html

Posted via email from Whistleblower

How to Log In to Windows Without the Password 127.0.0.1

How to Log In to Windows Without the Password


Saturday, July 09, 2011



Dan Dieterle

B64e021126c832bb29ec9fa988155eaf

I covered this topic last year (Windows Backdoor: System Level Access via Hot Keys) but just ran into this again recently. How do you gain access to a Windows system that you have legitimately lost the password to?

Well, there seems to be a couple utilities out there that claim to allow you to do this. We tried a Linux Live-CD based, one that was supposed to allow you to change any Windows password. But it didn’t work.

I even tried Kon-Boot, both the CD based and USB flash drive variety. Kon-boot sounds very cool, and comes highly recommended. You boot Kon-Boot first, then after it is booted, it loads your OS.

Then you can put in any password, or hit enter and it bypasses the login and allows you into the users account. It is supposed to work on Windows and Linux systems. But unfortunately it also did not work on my systems.

What to do? Well, I figured I would give my article from last year a shot to see if it still worked.

(Okay, just a quick disclaimer. Do not do this on a system that you do not own, or have permission to modify. And messing with system files could leave your system in an unstable state, if you chose to continue, you do so at your own risk.)

So I booted into Ubuntu, went to the Windows System 32 directory, renamed utilman.exe to utilman.old, copied cmd.com to utilman.exe and rebooted.  At the Windows log in prompt I hit the “Windows”+”U” key and open pops a system level command prompt. From here you can type any windows command, add users, etc.

The funny part is you can type “explorer.exe”, hit enter and a you get a System level desktop. From here you can open Internet Explorer, and surf the web. And while you are doing all this, the Windows login screen dutifully stays in the background  protecting(?) your system.

image

I found the Utilman modification solution on Microsoft’s Technet site, but it is not the only one that works. A comment on last year’s post pointed me to another trick on Adam’s Technical Journal

Modifying the “Sethc.exe” command in the same way also allows you to bypass the Windows login screen. The “sethc” file is for the Windows Sticky Keys function. Under normal operation, if you hit the Shift key something like 5 times in a row, the sticky key dialog box will pop up.

Doing so when the sethc file has been replaced with a copy of command.com, opens up a system command prompt at the login screen, just like the utilman modification above.

This process still works on a fully patched and updated Windows 7 system. When I checked it last year, it also worked on all of Windows server products. Windows protects these system files from being modified when Windows is booted, but booting in Linux to alter them just takes a couple minutes at most.

These techniques can be a life saver if you have lost the password to an important system, but it also goes to show that strong physical security is also needed when securing your systems.

Cross-posted from Cyber Arms

https://www.infosecisland.com/blogview/15031-How-to-Log-In-to-Windows-Without...

Posted via email from Whistleblower

Google is Your Friend - If You're a Lulzer

Google is Your Friend - If You're a Lulzer


Wednesday, June 29, 2011



Kevin McAleavey

Ba829a6cb97f554ffb0272cd3d6c18a7

While the digital paparazzi were lined up waiting to snap photos of the Lulzboat crew getting vanned, some of us focused on how this collection of low tech script kiddies were able to knock over SONY, AT&T, the CIA, Arizona's DPS and numerous other sites and make off with highly confidential contents again and again.

It turns out that they had an accomplice, Google. Now before the good townspeople grab their torches and pitchforks and beat a hasty path to Mountain View, let it be known that Google's part in these massive hacks isn't actually Google's fault.

Or perhaps it can be if the public still wants to blame them anyway and question why this information is there on Google for the taking in the first place. But that's not really the issue at all.

The blame in my opinion lies once again with the administrators of the sites which were attacked. Google merely indexed the available booty for the lulzers and others and left the cardboard box on the curb where it could be picked up by anyone who drove by.

After all, page crawls weren't considered privileged information - they're all part of the "public internet" available to anyone who drops by.

How could this be? How could Google allow these kids to troll the internet and easily locate SQLi vulnerabilities or remote logins, passwords or even entire databases for the taking without any real effort at all? Simple.

A little thing known as SEO, sitemaps and the little spiders that go bump in the night. Let's look at the problem, along with a few specifics since the bad guys have been doing this for years and years and it's not a secret at all. Then I will explain what site admins can do to see to it that this information is not left at the curb any longer.

The problem:

Copy and paste the following into a Google searches in a new window. I'll wait:

filetype:sql hotmail gmail password

or

inurl:"login.(asp|php) inurl:"id=1"

You can try the above and substitute any of these too:

    * userid=
    * index=
    * form=
    * username=

You might even see some major security companies and governments turn up in there. For extra credit, use the "site:your website url here" and see what comes up on yours!

THIS is what the script kiddies do when they do their Google drive-bys. The victims of lulzsec and others fell because of such simple Google searches, and they're made even easier when you have a target URL in mind to play "anybody home?"

As long as Google has it in their indexes, and you know the keywords to search for sites, then it certainly isn't "nuclear brain science" when an injectable site is found.

There's plenty of tools to automate the attacks on the database behind the site once you know how to POST or GET to it. I've seen apologists claim "we don't use MYSQL."

Rest assured that there are exploit GUI's readily available for PostgreSQL, MSSQL and Oracle as well as lesser and older databases. If it's there, and they can find it, and they can talk to it, and you're not properly filtering what can get to it, your site could very well be the next breaking news story.

The Solution

Search results on Google come from two primary methods. The first one is web-crawlers which may or may not respect your "robots.txt" file in your website's root. Most webmasters are well aware of the rules for "robots" but can't always be expected to be aware of what dynamic web pages could contain from other parts of their site's backend.

Therefore, some dynamic content might end up not being in the "robots.txt" file to be skipped in the first place. It is essential that those responsible for web sites ensure that the golden rule of "if you don't want people to see it, don't put it on the site in the first place" is properly enforced.

Some more "l33t" hackers have written their OWN webcrawlers and you cannot count on these critters to obey your "robots.txt" file in the first place. Google does usually, but don't count on it EVER. There's plenty more spiders in that basement and Google is but one of them.

The biggest risk of all though is SEO ("Search Engine Optimization" for my pointy-haired readers). It involves the creation of sitemaps using either Google's own sitemapping tool, or risking using a third party SEO tool which will truly map everything it can find and then wrap it all up into a nice little XML file that the webmaster uploads to all the search engines.

Incredibly, a lot of not-so-experienced webmasters will run the SEO tool and never look at the final output file before sending it! If the XML indexes your databases or scripts, they're all part of your sitemap ready for lulzing. PLEASE check your sitemap information before sending it, please?

Your Homework

Yes, there WILL be a test. And it will go down on your "permanent record." Some useful reading on how your databases can be hit can be found here:

Google even has some nifty tools with which you can test your injectability quotient:

Bottom line: If you don't want pirates on your poopdeck, remember the golden rule. If it's ON your website, it's there for the pickings. Do NOT toss your company's wallet on the sidewalk and expect it to be there intact the following morning.

Know what's on your website, know what's being indexed and be certain that anything you don't want anybody else to own isn't there in the first place. Kinda depressing to even have to say any of this. May the lulz be your own, and not some idiot children with no leet in them at all.

About the author: Kevin McAleavey is the architect of the KNOS secure operating system ( http://www.knosproject.com ) and has been in antimalware research and security product development since 1996.

https://www.infosecisland.com/blogview/14829-Google-is-Your-Friend-If-Youre-a...

Posted via email from Whistleblower

LulzSec Spree Sparks DHS Response

LulzSec Spree Sparks DHS Response


Wednesday, June 29, 2011



Ron Baklarz

91648658a3e987ddb81913b06dbdc57a

 

In the wake of the recent LulzSec 50 day hacking spree that left many high profile companies and organizations scrambling, DHS announced on Monday June 27, 2011, "detailed guidance" on the top 25 software vulnerabilities. 

The "Common Weakness Enumeration" list was developed in collaboration among DHS, Mitre, and SANS as well as numerous other private sector organizations. 

In addition to the list, there is also a scoring system and risk analysis framework that can be used to prioritize risk mitigation activities.

Not surprising, SQL Injection flaws top the DHS list which is closely aligned with the vulnerabilities identified in the OWASP Top 10.

Common flaws between the two lists include injection, cross-site scripting (XSS), authentication flaws, and cross-site request forgery (CSRF).

While the generation of these lists is laudable, it is quite another thing for companies and organizations to actually continuously test their environments for these flaws and implement sound security controls.  

While there are the proverbial "low hanging fruit" types of fixes there are no quick fixes for changing corporate cultures. 

A clear example of this is Sony one of the most high profile victims of the LulzSec breaches.

Sony has 1,000 subsidiaries and employs approximately 168,000 people and for some unknown reason has never had a CISO function!  

Until now.

Posted via email from Whistleblower

Anonymous Releases "Super Secret Security Handbook"

Anonymous Releases "Super Secret Security Handbook"


Thursday, June 30, 2011



Headlines

69dafe8b58066478aea48f3d0f384820

The rogue hacker movement Anonymous has released the "OpNewBlood Super Secret Security Handbook" (pdf) in an effort to recruit more would-be hacktivist types to further the Internet anarchy cause.

The tutorial-style guide instructs users on multiple subjects, particularly how to set up secure Internet Relay Chat (IRC) access for group discussion participation.

"If you have not gone through the IRC chat client setup for your operating system, we recommend you go back and get started there," the guide states.

/uploads/remoteimg/645fb5627bfdb1925e2773b1442b82d7.jpg

The publication will edify aspiring armchair hackers on methods used to obscure one's identity while conducting operations online and avoid exposing one's identity to rival hackers and law enforcement.

The guide is replete with step-by-step instructions and peppered with tips on how to avoid missteps in the process, as well as warnings for those who might me getting in over their head from a technical standpoint:

"Always be cautious when tinkering with systems you don't fully understand, as this may lead to undesirable results, detection, and in extreme cases system failure or legal trouble... While this guide does attempt to put it simply and in laymans terms, you the user are ultimatly [sic] responsible for the security of your own systems," the publication warns.

The publication is more evidence that hacktivist groups like Anonymous and the now supposedly defunct LulzSec are shifting tactics by moving away from conducting offensive operations themselves, and instead may be seeking to educate and enable others take up the cause.

Recently we have also seen the emergence of the Anonymous-backed School4lulz, a resource for hi-tech hooligans to learn the finer art of hacking, cross-site scripting, SQL injections, botnet herding, doxing, and tools of the trade.

By concentrating on instruction and inspiration, the core leadership of these hacker collectives can effectively remove themselves as primary targets for law enforcement and anti-AntiSec hackers like The Jester (th3j35t3r), The A-Team, and the Web Ninjas, and instead encourage their less-savvy teen minions to commit the attacks and take the heat.

https://www.infosecisland.com/blogview/14854-Anonymous-Releases-Super-Secret-...

Posted via email from Whistleblower

Scriptkiddies Claim Fox News Twitter Account Hack

Scriptkiddies Claim Fox News Twitter Account Hack


Tuesday, July 05, 2011



Headlines

69dafe8b58066478aea48f3d0f384820

One of the Twitter accounts maintained by the Fox News organization was hijacked over the holiday weekend and used to post false messages claiming that President Barack Obama was assassinated.

The disturbing messages remained for several hours before being removed. The incident has been reported to the Secret Service and an investigation is underway.

The hack was claimed by a group calling themselves the "Scriptkiddies".

"We are looking to find information about corporations to assist with antisec [a concerted hacker attack on corporate and government security]. Fox News was selected because we figured their security would be just as much of a joke as their reporting," a purported member of the Scriptkiddies told Think Magazine.

A Fox News Twitter feed was hacked and used to publish false items that President Barack Obama had been killed.

Representatives of Fox News have requested Twitter present them with the details of the event and have asked to be provided with guidance on how to prevent further incidents.

"We will be requesting a detailed investigation from Twitter about how this occurred and measures to prevent future unauthorized access into FoxNews.com accounts," said Jeff Misenti, Fox News Digital's vice president and general manager.

Twitter representatives released the following statement regarding the Fox News account hijacking:

While Twitter does monitor accounts for brute-force login attempts and similar methods of attack, we're unable to anticipate compromises that take place due to offsite behavior.

Generally speaking, we suggest using an e-mail address associated with your domain or, if you do not have one, using two-factor authentication or being aware of best practices around password security in order to prevent attacks.

We've heard from Fox News that they have identified the offsite vector that led to the compromise, and would encourage follow-up with them about the details of how that compromise took place.

The Scriptkiddies claim to be loosely associated with the rogue movement Anonymous who previously gained attention for DDoS attacks against PayPal, Visa, MasterCard, PostFinance Bank, Amazon, Bank of America, the U.S. Chamber of Commerce website, and for having breached the systems of security consultants HBGary Federal.

"I would consider us to be close in relation [to Anonymous], two of the members of our group were members of Anonymous... I was a member of Anonymous. We hope to be working with them soon," the alleged hacking group member said.

Anonymous last week released the "OpNewBlood Super Secret Security Handbook" (pdf) in an effort to recruit more would-be hacktivist types to further the Internet anarchy cause.

The tutorial-style guide instructs users on multiple subjects, particularly how to set up secure Internet Relay Chat (IRC) access for group discussion participation.

The publication is more evidence that hacktivist groups like Anonymous and the now supposedly defunct LulzSec are shifting tactics by moving away from conducting offensive operations themselves, and instead may be seeking to educate and enable others take up the cause.

Recently we have also seen the emergence of the Anonymous-backed School4lulz, a resource for hi-tech hooligans to learn the finer art of hacking, cross-site scripting, SQL injections, botnet herding, doxing, and tools of the trade.

https://www.infosecisland.com/blogview/14971-Scriptkiddies-Claim-Fox-News-Twi...

Posted via email from Whistleblower

Innocence Blog: Friday Roundup: The Stories of Innocence Before and After Exoneration

Friday Roundup: The Stories of Innocence, Before and After Exoneration (7/8/2011)

innocenceproject.org | Jul 8th 2011 1:55 PM

Friday Roundup: The Stories of Innocence, Before and After Exoneration

Tavis Smiley sat down recently for a two-part PBS invterview with four men exonerated in Illinois after years in prison for crimes they didn’t commit.

A review by the Mid-Atlantic Innocence Project is exposing doubts about the police investigation of a Washington D.C. murder.

A Florida State Attorney recused himself after four new suspects were revealed in a case for which William Dillon was wrongfully convicted.

NPR reported this week on reforms in Dallas to make eyewitness identification procedures more reliable.

A Florida Today editorial calls on the state legislature to address reforms in eyewitness identification procedures.

A DNA mix-up caused by human error that led to a wrongful conviction of a Las Vegas man has prompted police to reanalyze more than 200 cases handled by a forensic scientist.

Two Canadian men who say they falsely confessed to a murder are seeking to overturn their convictions in Washington state with the help of the Idaho Innocence Project, an Innocence Network member.

Original Page: http://www.innocenceproject.org/Content/Friday_Roundup_The_Stories_of_Innocence_Before_and_After_Exoneration.php

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

Innocence Blog: Supreme Court Ruling Means Lab Tech Should Testify

Supreme Court Ruling Means Lab Tech Should Testify (7/11/2011)

innocenceproject.org | Jul 11th 2011 5:16 PM

Supreme Court Ruling Means Lab Tech Should Testify

Last month, the U.S. Supreme Court ruled that the prosecution must call the actual lab analyst who performed the testing – or at least an analyst who was present during the testing – in criminal prosecutions.

Although this is a pretty clear requirement of the Constitution’s confrontation clause, , lab officials in New Mexico are worried that they will have to add up to 20 analysts to manage the work load, reported the Daily Times.

The Supreme Court’s finding stems from a 2005 drunk driving case where the public defender for the defense moved to exclude the testimony of the blood analyst since it wasn’t the analyst who performed the actual test.

The overburdened Scientific Laboratory Division is the only lab in the state and it has to be determined how it will handle the increased demands of analysts.

"The initial response is we are going to need more analysts, but if we don't have more, then we may be asking the analysts there to work more hours," said Elizabeth Trickey, general counsel for the state health department. "The implications could be very broad."

Read the full article.

Original Page: http://www.innocenceproject.org/Content/Supreme_Court_Ruling_Means_Lab_Tech_Should_Testify.php

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

Innocence Blog: Reforms Pending In Connecticut

Reforms Pending In Connecticut

innocenceproject.org | Jun 15th 2011 5:16 PM

After a decade of attempts by Connecticut lawmakers to mandate the recording of interrogations, a bill is finally awaiting the governor’s signature, reports the Hartford Courant.

The bill, which cleared the Senate last week, requires police to make an electronic recording of every custodial interrogation on a felony case that is substantially accurate and not intentionally altered. If the bill is signed, any custodial interrogations that are not electronically recorded will be inadmissible in court.

Interrogations won’t be recorded until January 2014, to give law enforcement ample time to familiarize themselves with the procedure.

Recording interrogations can prevent disputes about how a suspect was treated, create a clear record of a suspect’s statements and increase public confidence in the criminal justice system. Recording interrogations can also deter officers from using illegal tactics to secure a confession.

In addition to mandatory recording of interrogations, the Connecticut legislature also passed a bill aiming to reduce wrongful convictions by creating an Eyewitness Identification Task Force to study issues surrounding eyewitness misidentification.

Read the full article.

Read the full text of the proposed bills: Interrogations / Identification

Read more about false confessions and the benefit of recording interrogations.


Tags: Connecticut, False Confessions, Eyewitness Identification

Original Page: http://www.innocenceproject.org/Content/3106.php

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

The Innocence Project - As More States Weigh Improving Lineups, New Innocence Project Report Shows Extent of the Problem and Effectiveness of Reform

As More States Weigh Improving Lineups, New Innocence Project Report Shows Extent of the Problem and Effectiveness of Reform

innocenceproject.org | Jun 15th 2011

75% of wrongful convictions overturned with DNA testing involve eyewitness misidentification; 17 states in last two years have considered reforms

(New York, NY; July 16, 2009) —A report released today by the Innocence Project shows that while eyewitness identification is among the most prevalent and persuasive evidence used in courtrooms, it is not error-proof and is the leading cause of wrongful convictions that have been overturned with DNA testing.

The report comes as 17 states have considered legislation in the last two years to improve lineups. So far, nine states have taken action to prevent eyewitness misidentification, and the Innocence Project said it will focus on implementing reforms over the next year in 10 states, including New York, Texas, Kentucky, New Mexico, Ohio, Michigan and Rhode Island.

Titled “Reevaluating Lineups: Why Witnesses Make Mistakes and How to Reduce the Chance of a Misidentification,” the report lays out the overview of eyewitness misidentification and problems with traditional eyewitness identification procedures. It explains how to minimize the possibility of misidentification and outlines criminal justice reforms that are proven to reduce inaccurate eyewitness identifications.

“There is a growing understanding nationwide that eyewitness identification is often unreliable, and that simple reforms can reduce misidentifications,” said Stephen Saloom, Policy Director at the Innocence Project, which is affiliated with Cardozo School of Law. “This reports shows the extent of the problem, explains why eyewitnesses sometimes identify the wrong person, and outlines how police practices can be improved to result in more reliable evidence. The consequences of not improving lineups are stark: Investigations get derailed early in the process, and true perpetrators of crime remain free to commit additional violent crimes while innocent people are incarcerated.”

A series of reforms that are proven to reduce misidentifications have been developed by leading social scientists, endorsed by criminal justice organizations and successfully implemented in the field. The reforms include: double-blind presentation (photos or lineup members are presented by an administrator who does not know who the suspect is); lineup composition (the non-suspects included in a lineup resemble the eyewitness’s description of the perpetrator and the suspect should not stand out); witness instructions (the person viewing a lineup is told that the perpetrator may not be in the lineup but the investigation will continue regardless); confidence statements (at the time of identification, the eyewitness provides a statement in her own words indicating a level of confidence in the identification); recording of identification procedures (the identification is videotaped entirely); and sequential presentation (lineup members are presented one-by-one instead of side-by-side; because research is ongoing on this reform, the Innocence Project recommends it as an optional addition to the reforms above).

“Several states, cities and towns have already adopted the reforms and found them to be cost-effective and easily implemented,” the report found. “The benefits are extensive and include reinforcing the integrity of reliable identifications as well as reducing the rate of misidentifications.”

States that have taken steps to improve eyewitness identification through legislation include: New Jersey and North Carolina, which mandate blind-sequential policies; Georgia, which has statewide training; West Virginia, which mandates the use of certain reforms proven to increase the accuracy of eyewitness identifications; Vermont, which established a task force to explore and recommend enhanced eyewitness identification protocols; Maryland and Wisconsin, which require all jurisdictions statewide to enact written policies regarding the use of eyewitness identification procedures; Connecticut, which directed its Advisory Commission on Wrongful Convictions to monitor and evaluate implementation of double-blind administration of lineup procedures; and Virginia, where the Crime Commission studied misidentification cases and recommended improvements to eyewitness identification procedures including training and sequential presentation.

Disappointingly, there are no consistent standards for identification procedures from state to state or even from one police department to the next. Many police departments don’t even have a written policy, which often leads to inconsistency within a single station.

“We know from social science research and real-world experience that these reforms work. We’re looking forward to working with police and policymakers in several key states over the next year to help them understand the need to improve lineups and the benefits of these reforms,” Saloom said. “Victims are denied justice, innocent defendants are sent to prison and the public’s safety is at risk when real perpetrators go undetected.”

The findings in “Reevaluating Lineups: Why Witnesses Make Mistakes and How to Reduce the Chance of a Misidentification,” released today, include:

• 240 people, serving an average of 12 years in prison, have been exonerated through DNA testing in the United States, and 75% of those wrongful convictions (179 individual cases as of this report) involved eyewitness misidentification.

• In 38% of the misidentification cases, multiple eyewitnesses misidentified the same innocent person.

• Over 250 witnesses misidentified innocent suspects.

• 53% percent of the misidentification cases (among those where race is known) involved cross-racial misidentifications.

• In 50% of the misidentifications cases, eyewitness testimony was the central evidence used against the defendant (without other corroborating evidence like confessions, forensic science or informant testimony).

• In 36% of the misidentification cases, the real perpetrator was identified through DNA evidence.

• In at least 48% of the misidentification cases where a real perpetrator was later identified though DNA testing, that perpetrator went on to commit (and was convicted of) additional violent crimes (rape, murder, attempted murder, etc.) after an innocent person was serving time in prison for his previous crime.

Read the executive summary here.

Download the full report here. (PDF)

Original Page: http://www.innocenceproject.org/Content/2079.php

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

Eyewitness Identification: "Reevaluating Lineups: Why Witnesses Make Mistakes and How to Reduce the Chance of a Misidentification

Reevaluating Lineups: Why Witnesses Make Mistakes and How to Reduce the Chance of a Misidentification

innocenceproject.org

Executive Summary

Eyewitness identification is among the most prevalent and persuasive evidence used in courtrooms. Eyewitness testimony that directly implicates the defendant is compelling evidence in any trial, but it is not error-proof. Jurors may not realize that confident, trustworthy witnesses can be mistaken. A single witness’s identification can be enough to obtain a conviction.

Eyewitness identification also plays a key role in shaping investigations. In the immediate aftermath of a crime, an erroneous identification can derail police investigations by putting focus on an innocent person while the actual perpetrator is still on the streets. Once a witness identifies the suspect to police, whether or not that person actually committed the crime, investigators may stop looking for other suspects.

Over 175 people have been wrongfully convicted based, in part, on eyewitness misidentification and later proven innocent through DNA testing. The total number of wrongful convictions involving eyewitness misidentifications exceeds this figure, given the widespread use of eyewitness testimony and the limited number of cases in which DNA evidence is available for post-conviction testing.

Experts estimate that physical evidence that can be subjected to DNA testing exists in just 5-10% of all criminal cases.1 Even among that small fraction of cases, many will never have the benefit of DNA testing because the evidence has been lost or destroyed. DNA exonerations don’t just show a piece of the problem – they are a microcosm of the criminal justice system.

Decades of empirical, peer-reviewed social science research reaffirms what DNA exonerations have proven to be true: human memory is fallible. Memory is not fixed, it can be influenced and altered. After the crime and throughout the criminal investigation, the witness attempts to piece together what happened. His memory is evidence and must be handled as carefully as the crime scene itself to avoid forever altering it.

The Innocence Project identifies the common causes of wrongful convictions across DNA exoneration cases and has found eyewitness misidentification to be the leading cause.

Innocence Project research shows:

• Over 230 people, serving an average of 12 years in prison, have been exonerated through DNA testing in the United States, and 75% of those wrongful convictions (179 individual cases as of this writing) involved eyewitness misidentification.

• In 38% of the misidentification cases, multiple eyewitnesses misidentified the same innocent person.

• Over 250 witnesses misidentified innocent suspects.

• Fifty-three percent of the misidentification cases, where race is known, involved crossracial misidentifications.

• In 50% of the misidentification cases, eyewitness testimony was the central evidence used against the defendant (without other corroborating evidence like confessions, forensic science or informant testimony).

• In 36% of the misidentification cases, the real perpetrator was identified through DNA evidence.

• In at least 48% of the misidentification cases where a real perpetrator was later identified through DNA testing, that perpetrator went on to commit (and was convicted of) additional violent crimes (rape, murder, attempted murder, etc.), after an innocent person was serving time in prison for his previous crime.

Many of these misidentifications could have been prevented, many wrongful convictions averted, and many additional crimes avoided if police had used more reliable lineup procedures. In recognition of this, procedural reforms have been developed by leading eyewitness psychologists and successfully implemented by criminal justice professionals. These reforms have a strong scientific foundation and have been embraced by leading national justice organizations including the National Institute of Justice and the American Bar Association.They include:

• Double-blind presentation: photos or lineup members should be presented by an administrator who does not know who the suspect is.

• Lineup composition: “Fillers” (the non-suspects included in a lineup) should resemble the eyewitness’s description of the perpetrator and the suspect should not stand out. Also, a lineup should not contain more than one suspect.

• Witness instructions: The person viewing a lineup should be told that the perpetrator may not be in the lineup and that the investigation will continue regardless of whether an identification is made.

• Confidence statements: At the time of the identification, the eyewitness should provide a statement in her own words indicating her level of confidence in the identification.

• Recording: Identification procedures should be videotaped.

• Sequential presentation (optional): Lineup members are presented one-by-one (by a “blind” administrator) instead of side by side.

Several states, cities and towns have already adopted the reforms and found them to be cost-effective and easily implemented. The benefits are extensive and include reinforcing the integrity of reliable identifications as well as reducing the rate of misidentifications. Despite positive feedback from police departments where the reforms have been implemented and mounting evidence of the reforms’ effectiveness, the majority of jurisdictions have maintained the status quo. There are no consistent standards for identification procedures from state to state or even from one police department to the next. In fact, many police departments do not have written procedures for conducting identifications, so there is often inconsistency even within individual police departments. Now is the time for change. Misidentifications benefit no one: not the innocent defendants who face incarceration for crimes they didn’t commit, not the victims who are denied justice, not the police officers working to catch the real perpetrator, and not the public whose safety is jeopardized when real perpetrators remain at large.

This report provides a historical overview of how eyewitness misidentification came to be recognized as a leading cause of wrongful conviction, it examines the shortcomings of traditional eyewitness identification procedures, and it describes how simple improvements to procedures can alleviate the problem, with examples of cities and states across the country that have successfully implemented procedural reforms.

Download the full report here. (PDF)

Original Page: http://www.innocenceproject.org/Content/Reevaluating_Lineups_Why_Witnesses_Make_Mistakes_and_How_to_Reduce_the_Chance_of_a_Misidentification.php

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

Confidential Informants, Questionable Convictions (7/6/2011)

Confidential Informants, Questionable Convictions (7/6/2011)

innocenceproject.org | Jul 6th 2011 5:54 PM

Confidential Informants, Questionable Convictions

An editorial in yesterday’s Newark Star-Ledger points to the murky role played by confidential informants in countless criminal cases across the state and the country. New Jersey has few rules governing the use of confidential informants in police investigations or in court. And while informants can help investigations, secret incentives like reduced sentences – or even cash – can lead to false testimony. At least 15 percent of the 272 wrongful convictions overturned through DNA testing to date involved informant testimony at the trial level.

A report released last month by the New Jersey ACLU calls on the New Jersey Attorney General to “issue specific, detailed and mandatory policies” governing use of informants by all law enforcement agencies in the state.
From the Star-Ledger editorial:

Each year, thousands of offenders provide all levels of law enforcement with information in order to save themselves. Sometimes, the information is reliable. Often, it’s not.

And while the ACLU report details how police can abuse informants, who often create fiction to get the deal they want or just to get cops off their backs, the real victims are the courts. Sometimes, innocent people get railroaded, and bad guys, because of shady witnesses, go free.


Read the full editorial.

Original Page: http://www.innocenceproject.org/Content/Confidential_Informants_Questionable_Convictions.php

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

Bit of a phone phreak

Accused Pentagon Hacker's Online Life

by Kevin Poulse, theregister.co.uk
November 19th 2002 9:57 PM

Usenet posts show Gary McKinnon was a bit of a phone phreak, knew where to buy lock picks, and had an early interest in defense computers. A former employer says he was bored at work.

The British man accused of the most ambitious hack attacks against Defense Department computers in years was also a fine network administrator, according to a former co-worker.

A manager at the London-based telecom equipment seller Corporate Business Technology Ltd. recalls Gary McKinnon as a friendly -- if unremarkable -- presence at the company, where he provided IT support for an office of about 50 people. "He was personable, relatively happy around the office," says the manager, who declined to give his name. "You wouldn't have realized that he could do what he did."

McKinnon, now 36, worked for CBT for approximately ten months ending in late 1999, the company says. He left on good terms. "As I remember it, he decided to leave because he was bored working here," says the manager. "But at the time that he left, he didn't have any place to go to."

On Tuesday (Nov 12, 2002), U.S. officials in Virginia charged McKinnon with seven felony counts of computer fraud for allegedly penetrating 92 different systems belonging to the Army, Navy, Air Force, the Pentagon, and NASA, as well as six computers owned by private companies and organizations, in a year-long hacking spree that ended last March.

A related indictment unsealed the same day in New Jersey charges the Londoner with a September, 2001 attack against U.S. Navy systems at the Earle Naval Weapons Station that allegedly resulted in the network of 300 computers being shut down for a week.

The private computers listed in the Virginia indictment are mostly at traditional easy targets, like public libraries and universities, and may have been used as cut-outs to cover the hacker's tracks. Gregg Cannon, IT director at victim-company Tobin International in Texas, says federal investigators contacted and subpoenaed his company early this year after a test system outside the company firewall was compromised and used to attack government computers. "All the government would tell us is that it was overseas," says Cannon. "He didn't do any damage."

Diverse Interests

The U.S. is seeking McKinnon's extradition, which McKinnon is fighting in the U.K.

McKinnon's former co-worker said Wednesday that there was nothing about the network admin to hint at a future as a civilian infowarrior, "assuming it was him that did it."

A trail of Usenet messages posted by McKinnon in the late 1990's to public Internet newsgroups suggests McKinnon had an early interest in esoteric technological subjects.

Postings in 1997 to the U.K. phone hacking newsgroup alt.ph.uk show McKinnon, or someone with the same name, offering advice on purchasing lock picks in the U.K., tips on encrypting files, and hints on changing the electronic serial numbers in cellular telephones.

A flurry of less subversive posts in December, 1999 from an email address at Corporate Business Technologies have McKinnon advising colleagues in Windows-administration newsgroups on a variety of topics -- most of them security related.

One post from that period hints at an earlier start to McKinnon's interest in U.S. defense systems than the government has acknowledged. The message finds McKinnon advising someone on what brand of intrusion detection system to buy. He recommends ISS's RealSecure, because "The US Navy use[s] that and only that ..."

"[B]ut then," McKinnon adds without explanation, "they really need it."

© 2002 Security Focus. All rights reserved.

Original Page: http://www.theregister.co.uk/2002/11/19/accused_pentagon_hackers_online_life/

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

Thursday, July 7, 2011

Conversation "The Freak Show" LoL

Heather (@Lebonbon22)
7/7/11 6:50 PM
@ElyssaD @RockTique Is that the freak show?
Elyssa Durant (@ElyssaD)
7/7/11 6:50 PM
@RockTique I knew it wouldn't be long. Give him a swift where it counts.
Meredith Allison (@RockTique)
7/7/11 6:41 PM
@JDenigma @ElyssaD Oooh, so we meet!
Josh (@JDenigma)
7/7/11 4:35 PM
@ElyssaD lol & you also make up crap about me...why don't u tell her the whole story? ;-) u have me blocked yet troll my TL too @RockTique
Elyssa Durant (@ElyssaD)
7/7/11 12:56 PM
@RockTique @lebonbon22 I refollowed but if some troll Jdenigma bugs you just block him. He's relentless and pathetic. Sorry.
Meredith Allison (@RockTique)
7/7/11 12:52 PM
@Lebonbon22 Yep! I meant to ask if you too but I guess not. I tweeted her when I noticed & no reply. @ElyssaD ..WHY?! Something I said? Lol
Heather (@Lebonbon22)
7/7/11 9:16 AM
@RockTique she deleted u? Really?
Meredith Allison (@RockTique)
7/7/11 8:01 AM
So late!! (@ Starbucks) http://4sq.com/qynAUt

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

Conversation

freethetweet (@freethetweet)
7/7/11 1:55 AM
@JDenigma no you've just rustled the right feather@silentsoeur @_cromcruach @snkscoyote @elyssad @mantis8585 @_deadreckoning_ @awesomejon37
Josh (@JDenigma)
7/7/11 1:52 AM
@silentsoeur @freethetweet @_cromcruach @snkscoyote @elyssad @mantis8585 @_deadreckoning_ @awesomejon37 I've created a storm here lol
liz a (@silentsoeur)
7/7/11 1:50 AM
@JDenigma @freethetweet @_cromcruach @snkscoyote @elyssad @mantis8585 @_deadreckoning_ holy shit I'm lost here and I read all the tweets :P
Josh (@JDenigma)
7/7/11 1:48 AM
@freethetweet @_CromCruach @silentsoeur @snkscoyote @elyssad @mantis8585 @_deadreckoning_ I never said you are lol
freethetweet (@freethetweet)
7/7/11 1:48 AM
@freethetweet @JDenigma @_CromCruach @silentsoeur @snkscoyote @elyssad if you think I am "elyssa", you are all fucking sorts of SAD.
freethetweet (@freethetweet)
7/7/11 1:46 AM
@JDenigma @_CromCruach @silentsoeur @snkscoyote @elyssad why keep contacting ppl u have bocked and hated upon? Makes no sense. (elyssa)
Josh (@JDenigma)
7/7/11 1:42 AM
@_CromCruach @freethetweet @silentsoeur @snkscoyote lol S.O.S. to @elyssad Hello Elyssa "cease and desist"
Donnchadh (@_CromCruach)
7/7/11 1:42 AM
@freethetweet @silentsoeur @jdenigma @snkscoyote informants? Me? Lmao you're drunker than all of us bahahahahahaha
freethetweet (@freethetweet)
7/7/11 1:38 AM
@freethetweet btw crom, u suck, they should "hire" informants better than you.@_CromCruach @silentsoeur @jdenigma @snkscoyote
freethetweet (@freethetweet)
7/7/11 1:35 AM
@_CromCruach just study the play book. @silentsoeur @jdenigma @snkscoyote @jessidarko @awesomejon37 @mantis8585
Donnchadh (@_CromCruach)
7/7/11 1:32 AM
@silentsoeur @freethetweet @jdenigma @snkscoyote @jessidarko @awesomejon37 @mantis8585 fall? Weebles wobble but never fall down!!!
liz a (@silentsoeur)
7/7/11 1:26 AM
@freethetweet @jdenigma @snkscoyote @_cromcruach @jessidarko @awesomejon37 @mantis8585 we all fall down in the end then :(
freethetweet (@freethetweet)
7/7/11 1:25 AM
@JDenigma @silentsoeur @snkscoyote @_cromcruach @jessidarko @awesomejon37 @mantis8585 we can play ring round the rosie till cows come home.
Josh (@JDenigma)
7/7/11 1:20 AM
@silentsoeur @snkscoyote @_cromcruach @jessidarko @awesomejon37 @mantis8585 It's in good fun here snks ;-)
liz a (@silentsoeur)
7/7/11 1:19 AM
@JDenigma not workin but still amusing ;P @snkscoyote @_cromcruach @jessidarko @awesomejon37 @mantis8585
Josh (@JDenigma)
7/7/11 1:17 AM
@silentsoeur Oh,you're baiting snks now I see ;-) @snkscoyote @_cromcruach @jessidarko @awesomejon37 @mantis8585
liz a (@silentsoeur)
7/7/11 1:16 AM
@jdenigma @snkscoyote ur raped & tortured &then proven innocent but its ok I got a badge @_cromcruach @jessidarko @awesomejon37 @mantis8585

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

Monday, July 4, 2011

@JosephKBlack GET ON THIS ACCOUNT nyan-my-ass

Joe Black ✔ Genuine (@JosephKBlack)
7/3/11 9:28 PM
I HAVE NYANED FOR 9554.0 SECONDS! http://t.co/G1pdxGl via @nyannyancat

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

@JosephKBlack, 7/3/11 10:07 PM re: CIA.gov

Joe Black ✔ Genuine (@JosephKBlack)
7/3/11 10:07 PM
@xSSLZx You cant be this dumb? Im doing my job you fuck stick. cia.gov received my resume in '08 and brought me on as an Agency asset in '10

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

And the CIA got hacked in 11. So did Blackandbergsecurity.us 

Joe claims to be with Lulzsec. 

Get me the fuck out of here! NOW!

Posted via email from Whistleblower

@JosephKBlack, 7/4/11 1:36 PM

Joe Black ✔ Genuine (@JosephKBlack)
7/4/11 1:36 PM
Thank you for the Mentions, @not2fear @JosephDeSanko @c4i @ElyssaD @jadedsecurity @Abhaxas @Donotgiveintoev You're all ROCKSTARS! Much love

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

What the what???? 

Posted via email from Whistleblower

Conversation

✔mate (@xSSLZx)
7/4/11 5:50 AM
@itinsecurity @attritionorg @caks2257 @ElyssaD regardless @JosephKBlack is fucked http://t.co/ZUOfsyC http://t.co/HARXy7X
Anders Reed-Mohn (@itinsecurity)
7/4/11 3:26 AM
RT @attritionorg: and it seems @caks2257 is Greg Evans' sockpuppet of the day #LIGATT < And @ElyssaD is @JosephKBlack 's perhaps?

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

Friday, July 1, 2011

Conversation #Exploitation

Tom (@d0rkh0rs3)
7/1/11 7:04 PM
@jadedsecurity @grostad @isdpodcast @ElyssaD Sounds like winning to me. Wait, #winning is so 2 months ago.
Jaded Security (@jadedsecurity)
7/1/11 7:00 PM
@d0rkh0rs3 @grostad @isdpodcast :) The @ElyssaD shirts will be here next week...
Tom (@d0rkh0rs3)
7/1/11 7:00 PM
@jadedsecurity @grostad @isdpodcast Awesome. Where's my shirt? ;)
Jaded Security (@jadedsecurity)
7/1/11 6:59 PM
@d0rkh0rs3 @grostad @isdpodcast LOL... i saw it.. I'm converting the 2 episodes so far..
Tom (@d0rkh0rs3)
7/1/11 6:58 PM
Hey @grostad, since you're always pimping the iTunes rating for @isdpodcast you should tell @jadedsecurity how to get on iTunes

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower