Saturday, June 25, 2011

Sinister scams 'sextort' social networkers • The Register

Sinister scams 'sextort' social networkers

by Dan Goodin, theregister.co.uk
November 5th 2010 4:00 AM

A rash of cases in which men use their hacking skills to extort sexually explicit images from women and girls is bringing new attention to the risks of storing sensitive data on social networks and internet-connected devices.

The most recent “sextortion” plot to be detailed in a court of law is that of George Samuel Bronk, a 23-year-old California man accused of appropriating nude and sexually explicit images of at least 170 women, Sgt. Kelly Dixon of the California Highway Patrol's Computer Crimes Division told The Register. He was arraigned on Tuesday in California state court in Sacramento on more than 30 counts, including hacking, possession of child pornography and impersonation. He didn't enter a plea, Dixon said.

Investigators have identified more than 20 victims whose images are included in the cache of stolen pictures and videos. In some cases, Bronk allegedly contacted the women and threatened to make the images public unless they supplied him with more nude pictures. He was caught after a Connecticut woman told her state police department that sexually explicit photographs of her had been posted to her Facebook page. Police ultimately fingered Bronk by linking his IP address to the woman's hacked Facebook and email accounts.

A Canadian man, 30-year-old Daniel Lesiewicz, admitted to luring hundreds of girls aged 13 to 18 into a similar trap, according to news reports. At a sentencing hearing last month, prosecutors said he used compromised Facebook accounts to pose as some of the victims' friends and convinced the girls to undress in front of their webcams. He then threatened to publish the images unless they gave him more.

In some cases, he terrorized the girls by calling their cellphones from what appeared to be their own numbers. One victim, who was 17 at the time, testified that she was so humiliated that she quit her summer job and dropped out of advanced college classes. Another victim attempted suicide, The Montreal Gazette reported. Sentencing has been postponed until later this month.

Earlier this week, the FBI's field office in Los Angeles sought help from the public in identifying more victims of Luis Mijangos, 31, of Santa Ana, California, who in June was arrested and accused of using infected computers to capture nude pictures and videos of about 230 individuals, at least 44 of whom were juveniles.

According to prosecutors, Mijangos used peer-to-peer file-sharing networks to trick his victims into installing software that gave him complete control of their machines. He then rifled through the hard drives for intimate images and other incriminating data, which he would use to extort sexually explicit videos from the victims, court documents allege. He has pleaded not guilty to charges that include extortion.

Crimes like these may be unusually plentiful in the news right now, but they're hardly new. In 2006, Adrian Ringland, then 36, from Ilkeston, Derbyshire, admitted blackmailing teenage girls into sending him explicit pictures after infecting their PCs with malware. He was sentenced to 10 years in prison.

The list of similar offenses goes on and on and on.

That the reports only seem to be increasing suggests that many people still don't understand the risks of storing photos and information online. Many of the victims' accounts were compromised by by correctly guessing the security questions used when an account holder forgets her password. In other instances, racy photos were nicked from compromised email accounts or computers. Those who collect such images would do well to keep them on drives that aren't attached to the net at all. ®

Original Page: http://www.theregister.co.uk/2010/11/05/social_network_extortion_scams/

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

Hacker admits stealing $12m worth of chips from Zynga • The Register

Hacker admits stealing $12m worth of chips from Zynga

by Dan Goodin, theregister.co.uk
February 2nd 2011 8:48 PM

A UK-based IT expert has admitted hacking into the servers of game developer Zynga and stealing $12m worth of gaming chips, according to news reports.

Ashley Mitchell, 29, of Paignton, Devon, pleaded guilty to five charges on Wednesday in Exeter Crown Court. Judge Philip Wassall told him: “It is inevitable you are going to prison.” Mitchell, a former Torbay Council worker, was remanded into custody.

According to published news reports, Mitchell was able to gain unauthorized access Zynga's system by posing as one of the company's site administrators. He then transferred 400 billion gaming chips into fake Facebook accounts he set up. The price of the stolen booty would have come to $12m if Zynga had issued it, prosecutors said.

Mitchell proceeded to sell about a third of his take for about £53,000. If he had managed to sell the rest at the same discounted rate, his take would have come to about £184,000, a prosecutor told the court.

Mitchell's attorney said the crimes were committed when his client was “wrestling with a gambling addiction” that resulted in him spending £3,000 on online games. He said Mitchell was now drawing a six-figure salary from a Facebook application called Gambino Poker and asked the judge to consider allowing the defendant to repay the £184,000 over two years.

Mitchell was already given a 40-week suspended prison sentence for hacking into computers at Torbay Council. Sentencing is scheduled for next month.

More from The Herald Express and Small World News Service are here and here. ®

Original Page: http://www.theregister.co.uk/2011/02/02/zynga_chip_theft/

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

Fun-spoiling, DDoSing thieves farm virtual gold to sell for cold hard cash

Cybercrooks turn Eve Online into botnet battlefield

by John Leyden, theregister.co.uk
May 23rd 2011 1:08 PM

Crooks using online games to farm virtual currencies that they can sell for real money have turned internet spaceship game Eve Online into a battlefield for botnets.

Eve Online is home to various rival groups who generate in-game currency for gamers who want to join in without spending their time acquiring experience and resources by working their way up from the bottom. Rivals groups from eastern Europe are using botnets to DDoS opponents before taking over their territories. Regular gamers are often caught in the cross-fire of multi-pronged attacks that might occur in game, via DDoS attacks to forums, over VoIP communication systems and late night prank phone calls. Game servers have taken a hit in the process.

Gold farmers are known for using Trojans to gain control of compromised accounts. The Eve Online baddies have taken a different tack through attacks that swamp forums with junk traffic.

Chris Boyd, a senior threat researcher at GFI Software and gaming security experts, said that Eve Online's difficulties are a part of wider problems in virtual worlds.

"Gold farmers can cause the price of in-world items to rise, chat channels can be flooded by sale scams, endless bots and automated processes can cause significant server load," Boyd told El Reg. "That's before you get to the problems creating by phishing, hacking and scamming established and profitable accounts."

Boyd (AKA paperghost) agreed that the miscreants on Eve Online are taking it up to 11.

"The idea that there are effectively dead systems filled with nothing but spambots and hostile empires that are happy to do battle outside of their gaming realm by DDoS'ing websites and making prank phonecalls is a fascinating insight into the troubles plaguing virtual worlds, and real world currency having a marked impact on virtual trading makes this a few steps above dedicated DDoS botnets designed for nothing other than kicking console gamers out of Halo 3 sessions."

Various groups rumoured to be working out of Eastern Europe and Russia are said to be offering in-game currency for real money. "Investigations by the owners of the game have caused several leaders of these alliances to be banned in the past," explained Reg reader Patrick, who was the first to tell us of the hive of villainy within Eve Online.

More details on some of the DDoS attacks and other shenanigans on Eve Online can be found in blog posts on "Evenews" here, here and here. ®

Original Page: http://www.theregister.co.uk/2011/05/23/eve_online_botnet_mayhem/

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

Botnets claim 7-fold increase in victims • The Register

Bot attacks Linux and Mac but can't lock down its booty

by Dan Goodin, theregister.co.uk
January 19th 2011 11:12 PM

From the department of cosmic justice comes this gem, spotted by researchers from Symantec: a trojan that targets Windows, Mac, and Linux computers contains gaping security vulnerabilities that allow rival criminal gangs to commandeer the infected machines.

Known as Trojan.Jnanabot, or alternately as OSX/Koobface.A or trojan.osx.boonana.a, the bot made waves in October when researchers discovered its Java-based makeup allowed it to attack Mac and Linux machines, not just Windows PCs as is the case with most malware. Once installed, the trojan components are stored in an invisible folder and use strong encryption to keep communications private.

The bot can force its host to take instructions through internet relay chat, perform DDoS attacks, and post fraudulent messages to the victim's Facebook account, among other things.

Now, Symantec researchers have uncovered weaknesses in the bot's peer-to-peer functionality that allow rival criminals to remotely steal or plant files on the victim's hard drive. That means the unknown gang that took the trouble to spread the infection in the first place risks having their botnet stolen from under their noses.

“Even though it's encrypted and even though it was written in Java to make it cross-platform, it was still vulnerable to basically a directory transversal exploit,” Dean Turner, director of Symantec's Global Intelligence Network, told The Reg. “From a technical perspective, it goes to show that even if you have all those things where you're building in a secure platform, if you're not building application security into your malware, other bad guys will probably take advantage of it.”

Jnanabot's P2P feature is designed to make botnets harder to take down by providing multiple channels of communication. After sending an infected machine a single GET request, a website can discover all the information needed to upload any file to any location on the host's file system. Attackers can then install a simple backdoor on a user's machine by, for instance, writing a malicious program to a computer's startup directory.

Attackers can use the same vulnerability to steal files on infected machines.

Turner said the number of Jnanabot infections so far is “measured in the thousands,” rather than the hundreds of thousands for some of the better-known trojans. Still, infection statistics gathered by Symantec in December are surprising. They show that about 16 per cent of infections hit Macs. They didn't show any infections on Linux machines. Turner said that Jnanabot attacks on the open source platform weren't able to survive a reboot.

The bot was discovered spreading over Facebook posts that planted the following message on infected users' Facebook pages: “As you are on my friends list I thought I would let you know I have decided to end my life.” An included link leads recipients to a cross-platform JAR, or Java Archive file that can run on Windows, Mac, or Linux. Once the recipient is infected, his Facebook page carries the same dire warning.

It's not the first time that malware developers have built gaping vulnerabilities into their wares. In September, researcher Billy Rios disclosed a weakness in the Zeus crimeware kit that makes it easy to take over huge networks of infected PCs.

Symantec has more about the trojan here, here, and here. ®

Original Page: http://www.theregister.co.uk/2011/01/19/mac_linux_bot_vulnerabilities/

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

Advanced trojan development comes to the unwashed masses

Source code leaked for pricey ZeuS crimeware kit

by Dan Goodi, theregister.co.uk
May 10th 2011 11:03 PM

Source code for the latest version of the ZeuS crimeware kit has been leaked on the internet, giving anyone who knows where to look free access to a potent set of malware-generation tools that normally sell for as much as $10,000.

Complete source code is available in at least three different locations, ensuring that it is now permanently available to the masses, Peter Kruse, a researcher with Danish firm CSIS Security, told The Reg. While the release could erode the paid market for the DIY malware kit, it could also spawn entire new kits that clone the existing code and build new features or services on top of it.

“The source code has until now been shared in very closed communities or bought by criminals with significant funds,” Kruse wrote in an email. “With the release of the entire code it's obvious we will see new versions/rebrands or improvements in general. If this grows outside of the established underground ecosystem it could have a significant impact.”

Selling in the criminal underground for anywhere from $2,000 to $10,000, ZeuS is best known as a tool for developing customized trojans that send victims' banking credentials to servers under control of the attacker. Premium versions include technical support and advanced features, such as the ability to bypass two-factor authentication offered by some financial institutions. Although there are rival crimekits such as one dubbed Eleonore, ZeuS is considered one of the most powerful and widely used of them.

But over the past year, ZeuS has undergone a fair amount of upheaval. In September, security researcher Billy Rios disclosed a serious vulnerability in ZeuS that allows whitehats and blackhats alike to seize control of botnets built using the crimekit. Around the same time, authorities in the UK, US and Eastern Europe accused dozens of individuals of laundering millions of dollars siphoned out of ZeuS-compromised bank accounts.

More recently, researchers have found evidence that the ZeuS code base has been merged with a separate crimekit known as SpyEye. And in March, CSIS's Kruse discovered ZeuS source code for sale in underground forums.

The general release of the ZeuS source code makes it all but certain that no one will pay money for the standalone version of the program, at least until its creators add must-have features to it that aren't available now. It's not clear who released the code or why.

ZeuS's growing pains resemble in many ways the challenges legitimate software packages experience as they grow in popularity.

“I do like the fact that as these crimeware softwares become more mature, the developers and maintainer will start to face the same challenges as traditional software – security patches, piracy, protecting IP, feature requests, even PR,” said Rios, who is a former security researcher for Microsoft. “I find this funny having spent some of my life worrying about the same issues as a proper security/software engineer.” ®

Original Page: http://www.theregister.co.uk/2011/05/10/zeus_crimeware_kit_leaked/

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

Skype bug gives attackers access to Mac OS X machines • The Register

Skype bug gives attackers access to Mac OS X machines

by Dan Goodin, theregister.co.uk
May 6th 2011 7:40 PM

Mac users running Skype are vulnerable to self-propagating exploits that allow an attacker to gain unfettered system access by sending a specially manipulated attachment in an instant message, a hacker said.

“The long and the short of it is that an attacker needs only to send a victim a message and they can gain remote control of the victim's Mac,” Gordon Maddern of Australian security consultancy Pure Hacking blogged on Friday. “It is extremely wormable and dangerous.”

The vulnerability, which Maddern said isn't present in the Windows or Linux versions of the popular VoIP program, was confirmed by Skype spokeswoman Brianna Reynaud, who said a fix will be rolled out next week. Its disclosure comes the same week that researchers discovered a new crimekit that streamlines the production of Mac-based malware. It also comes as new malware surfaced for Apple's OS X that masquerades as a legitimate antivirus program.

Reynaud said there are no reports that the Skype vulnerability is being actively exploited.

Maddern said he stumbled on the critical flaw by accident.

“About a month ago I was chatting on skype to a colleague about a payload for one of our clients,” he wrote. “Completely by accident, my payload executed in my colleagues skype client. So I decided to test another mac and sent the payload to my girlfriend. She wasn't too happy with me as it also left the her skype unusable for several days.”

He then set out to write proof-of-concept attack code that used payloads borrowed from the Metasploit exploit framework. The result: a Skype exploit that allows him to remotely gain shell access on a targeted Mac. Because it's sent by instant messages, it might be possible to force each infected machines to send the malicious payload to a whole new set of Macs, causing the attack to grow exponentially.

Maddern didn't say what interaction is required on the part of the victim, and he didn't immediately respond to an email seeking clarification. His blog post says he notified Skype of the vulnerability more than a month ago, and that he will withhold specific details until a patch is released to prevent malicious attacks. ®

Update

According to a post on the Skype Security blog that was published a few hours after this story went live, a hotfix for the vulnerability was released in mid April.

“As there were no reports of this vulnerability being exploited in the wild, we did not prompt our users to install this update, as there is another update in the pipeline that will be sent out early next week,” Skype's Adrian Asher wrote.

He added:

This vulnerability, which they blogged about earlier today, is related to a situation when a malicious contact would send a specifically crafted message that could cause Skype for Mac to crash. Note, this message would have to come from someone already in your Skype Contact List, as Skype's default privacy settings will not let you receive messages from people that you have not already authorized, hence the term malicious contact.

The headline in this article was updated to correct the nature of the vulnerability. It remotely gives shell access.

Original Page: http://www.theregister.co.uk/2011/05/06/skype_for_mac_critical_vulnerability/

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

Write once, pwn anywhere

Java-based malware tries Mac-smacking cross-platform attack

by John Leyden, theregister.co.uk
May 6th 2011 11:19 AM

Malware-writers have developed a Java-based, equal-opportunity botnet Trojan in an apparent bid to infect more machines outside the Windows ecosystem.

IncognitoRAT uses source code and libraries that allow it to attack both Windows and Mac machines, at least in theory. Only the Windows version of the malicious downloader has been spotted actually spreading, McAfee reports.

"The original propagation vector of IncognitoRAT is a Windows executable, but apparently it was created using the tool JarToExe, which includes, among other features, the ability to convert .jar files into .exe files, to add program icons and version information, and protect and encrypt Java programs," explains McAfee researcher Carlos Castillo. "The victim's machine has to have the Java Runtime Environment installed and must be online. As soon as the file is executed, it starts downloading a ZIP file with a pack of Java-based libraries to perform several remote activities."

Once successfully executed, the malware establishes remote control of compromised systems, allowing criminal hackers to either control or extract and upload private information from compromised devices.

Cross-platform malware is rare but not unprecedented. The more widespread use of Mac machines is bound to make the platform a more attractive target for virus writers and other miscreants. Whether they will succeed is another question, but several vulnerabilities in Apple's software have been revealed through various editions of the annual CanSecWest Pwn2Own hacking competition, so it's certainly possible. ®

Original Page: http://www.theregister.co.uk/2011/05/06/java_based_malware/

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

iTune URLs and 380,000 other pages poisoned

LizaMoon mass-injection attack reaches epidemic proportions

by John Leyden, theregister.co.uk
March 31st 2011 10:35 AM

Malware writers are using website vulnerabilities to inject malicious scripts into thousands of websites as part of an ambitious attack ultimately designed to redirect surfers to a site pimping rogue anti-virus packages.

The so-called LizaMoon mass-injection attack uses SQL injection trickery to inject a line of malicious code into compromised pages, as explained in an advisory by net security firm Websense here. According to a Google Search, over 380,000 URLs have been compromised, including several web locations associated with iTunes URLs, as part of the attack.

The count only looks at unique URLs, not infected hosts, a more meaningful metric. Even so the assault still counts as among the most widespread mass-injection attacks on record. The assault, first spotted on Tuesday, started off using the domain lizamoon.com, but since then other domains have been deployed in the attack.

The domains linked to the attack host basic JavaScript code that redirects surfers towards a well-known rogue anti-virus site. This trick only worked in cases where surfers first visited a compromised site. Downloading podcasts or music via iTunes was never a risk thanks to the architecture of Apple's service.

Patrick Runald, of Websense Security Labs, explained: "iTunes downloads RSS/XML feeds from the publisher to update the podcast and list of available episodes. We believe these RSS/XML feeds have been compromised with the injected code. The good thing is that iTunes encodes the script tags, which means that the script doesn't execute on the user's computer." ®

Original Page: http://www.theregister.co.uk/2011/03/31/lizamoon_mass_injection_attack/

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

bypass two-factor authentication

ZeuS trojan attacks bank's 2-factor authentication

by Dan Goodin, theregister.co.uk
February 22nd 2011 6:02 AM

A variant of the ZeuS banking trojan is targeting mobile phone users who rely on their handsets to get enhanced, two-factor authentication from ING Bank Slaski in Poland, a security blogger said on Monday.

The ZeuS man-in-the-mobile attacks appear to similar to those that hit Spain in September, researchers from antivirus provider F-Secure said. Both attacks attempt to steal so-called mTANs, short for mobile transaction authentication numbers, which an increasing number of European banks are using to provide enhanced authentication to online customers. Financial institutions send the one-time passwords in text messages. The secondary passcodes are needed to login to online accounts.

The ZeuS Mitmo injects a fraudulent field into webpages that prompts users for their cellphone number and the type of handset they use. The criminals behind the operation then send the user an SMS message containing a link to malware that's customized to their Symbian or Blackberry phone. The malware automatically sends all mTANs sent to the handset to the ZeuS operators.

Security blogger Piotr Konieczny, who wrote about the attacks here, said the malware doesn't target iPhones. There was no mention of Android-based phones.

The attacks are a potent reminder of the cat-and-mouse game that's regularly played between criminal enterprises and the financial institutions they prey on. ING tuned to mTANs as a means to combat keyloggers ZeuS and other trojans use to compromise their customers' accounts. ZeuS is now attempting to strike back with a mobile version of the malware.

Google recently introduced one-time passwords that are similar to mTANs except they are used to provide two-factor authentication for Gmail account holders. ®

Original Page: http://www.theregister.co.uk/2011/02/22/zeus_2_factor_authentication_attack/

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

Skype sex cadets charged for misusing telco services • The Register

Skype sex cadets charged for misusing telco services

by Natalie Apostolou, theregister.co.uk
May 2nd 2011 5:38 AM

Police in Australia have finally worked out how to charge two Australian Defence Force Academy cadets at the center of the ‘Skype sex scandal’.

At the end of last week, the two were charged with “using a carriage service to cause offence" for their alleged role in broadcasting a fellow female cadet engaging in consensual sex.

The Australian Defence Force Academy has also indicated that the duo are also facing possible suspension and/or further action.

The accused cadets Daniel McDonald, 19, and Dylan De Blaquiere, 18, appeared before the ACT Magistrates Court on Friday to face the charge with McDonald facing an additional charge of committing an act of indecency.

McDonald allegedly bragged of his plan on Facebook to "root a girl n (sic) have a webcam setup" allowing fellow students of the Australian Defence Force Academy to watch via Skype. The unnamed female cadet was unaware of his plan to film the consensual sex.

"Now that the two officer cadets have been charged with criminal offences in the civilian criminal justice system, ADFA is now considering the possibility of taking further adverse administrative action against these cadets," the Defence spokesman told said.

The incident has incited an imbroglio between the DFA and the Defence Minister Stephen Smith, sparked a wide ranging cultural review of the DFA, six separate inquiries and a raft of unrelated claims of sexual misconduct and cover-up within the defence community.

The “cultural stocktake” currently underway focuses heavily on the use of social media and personal conduct at ADFA.

The Defence force has admitted that “the impact of social media has created new challenges for the ADF and the Defence organisation. Things which are conducted privately may be appropriate, but they are not appropriate if they are conducted in public, including through the use of social media.”

Federal Sex Discrimination Commissioner Elizabeth Broderick has also been charged with examining the treatment of women in the ADF. ®

Original Page: http://www.theregister.co.uk/2011/05/02/skypecadets_charged/

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

Woman with 15 IDs gets 7 years for multiple VAT fraud • The Register

Five jailed for £140m VAT scam

by John Oates, channelregister.co.uk
March 24th 2011 2:38 PM

Five men have been jailed for their roles in a huge missing-trader fraud which netted £140m.

The men were sentenced to 37 and a half years in prison in total.

HMRC said the five were motivated by pure greed. They were convicted of various counts of cheating the Revenue contrary to Common Law.

Andrew Hart (40) of Cricklewood, London, Mohammed Chaudhery (36) of Slough, Berkshire, Kevin Davis (46) of Kilburn, London, and Abdul Jabbar Butt (49) of Wembley, Middlesex set up their own limited companies, most of which traded for five weeks or less.

A fifth man, Tariq Sarwar, of Ryecroft Street, Gloucester acted as organiser. He pleaded guilty to five counts of cheating the Revenue and was sentenced to nine years in prison.

They imported mobile phones and computer chips VAT-free from other EU countries, then sold them on, with VAT added to UK customers. Each company owed the Revenue between £26.5m and £39.1m when it shut.

The money was never paid to the Rev but was laundered through various offshore firms.

The investigation began in October 2005 when Mohammed Chaudery was arrested. Information on his computer provided links to the other gang members and their companies.

The gang members got a flat fee of up to £30,000 for their work. HMRC is also seeking forfeiture of assets.

Click through to the next page for complete details of the fraudsters, and their companies, from HMRC. ®

1. Mohammed Tazib Chaudhery, (date of birth 19/1/1975) a UK national of 139 High Street, Slough, Berkshire, was the sole director of Greenview Electrical Supplies Ltd of Godolphin Road, Slough, Berkshire. He pleaded guilty to one count of Cheating the Revenue contrary Common Law and was sentenced to seven years' imprisonment on 22 March 2011.

2. Kevin Davis, (date of birth 10/2/1965) a UK national of 223 Ashmore Road, Kilburn, London, was the sole director of Intertec Trading Ltd. He pleaded guilty to one count of Cheating the Revenue contrary to Common Law and was sentenced to seven years' imprisonment on 22 March 2011.

3. Abdul Jabbar Butt, (date of birth 18/9/1961) of 47 Nettleden Ave, Wembley, Middlesex, was the sole director of Fone Rack Cellular Accessories Ltd. He pleaded guilty to one count of Cheating the Revenue contrary to Common Law and was sentenced to seven years' imprisonment on 22 March 2011.

4. Andrew Pierre Hart, (date of birth 18/11/1970) of 10a Lichfield Road, Cricklewood, London, was sole director of Shakedown Productions UK Ltd. He pleaded not guilty to one count of Cheating the Revenue contrary to Common Law. He was found guilty on 16 February 2011 and was sentenced to seven and a half years' imprisonment on 22 March 2011.

5. Tariq Sarwar, (date of birth 11/12/1966) of 35 Ryecroft St, Gloucester, (formerly of 56 Neville Close, Hounslow, Middlesex), pleaded not guilty to five counts of Cheating the Revenue contrary to Common Law and was sentenced to nine years' imprisonment on 22 March 2011. His role was as an organiser/coordinator of the fraud and he owned the laptop which contained information that was central to the fraud. He was found guilty on 16 February 2011 on each of the five counts of the fraud committed by the other five defendants.

Original Page: http://www.channelregister.co.uk/2011/03/24/hmrc_vat_fraud_sentence/

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

Five jailed for £140m VAT scam • Channel Register

Five jailed for £140m VAT scam

by John Oates, channelregister.co.uk
March 24th 2011 2:38 PM

Five men have been jailed for their roles in a huge missing-trader fraud which netted £140m.

The men were sentenced to 37 and a half years in prison in total.

HMRC said the five were motivated by pure greed. They were convicted of various counts of cheating the Revenue contrary to Common Law.

Andrew Hart (40) of Cricklewood, London, Mohammed Chaudhery (36) of Slough, Berkshire, Kevin Davis (46) of Kilburn, London, and Abdul Jabbar Butt (49) of Wembley, Middlesex set up their own limited companies, most of which traded for five weeks or less.

A fifth man, Tariq Sarwar, of Ryecroft Street, Gloucester acted as organiser. He pleaded guilty to five counts of cheating the Revenue and was sentenced to nine years in prison.

They imported mobile phones and computer chips VAT-free from other EU countries, then sold them on, with VAT added to UK customers. Each company owed the Revenue between £26.5m and £39.1m when it shut.

The money was never paid to the Rev but was laundered through various offshore firms.

The investigation began in October 2005 when Mohammed Chaudery was arrested. Information on his computer provided links to the other gang members and their companies.

The gang members got a flat fee of up to £30,000 for their work. HMRC is also seeking forfeiture of assets.

Click through to the next page for complete details of the fraudsters, and their companies, from HMRC. ®

1. Mohammed Tazib Chaudhery, (date of birth 19/1/1975) a UK national of 139 High Street, Slough, Berkshire, was the sole director of Greenview Electrical Supplies Ltd of Godolphin Road, Slough, Berkshire. He pleaded guilty to one count of Cheating the Revenue contrary Common Law and was sentenced to seven years' imprisonment on 22 March 2011.

2. Kevin Davis, (date of birth 10/2/1965) a UK national of 223 Ashmore Road, Kilburn, London, was the sole director of Intertec Trading Ltd. He pleaded guilty to one count of Cheating the Revenue contrary to Common Law and was sentenced to seven years' imprisonment on 22 March 2011.

3. Abdul Jabbar Butt, (date of birth 18/9/1961) of 47 Nettleden Ave, Wembley, Middlesex, was the sole director of Fone Rack Cellular Accessories Ltd. He pleaded guilty to one count of Cheating the Revenue contrary to Common Law and was sentenced to seven years' imprisonment on 22 March 2011.

4. Andrew Pierre Hart, (date of birth 18/11/1970) of 10a Lichfield Road, Cricklewood, London, was sole director of Shakedown Productions UK Ltd. He pleaded not guilty to one count of Cheating the Revenue contrary to Common Law. He was found guilty on 16 February 2011 and was sentenced to seven and a half years' imprisonment on 22 March 2011.

5. Tariq Sarwar, (date of birth 11/12/1966) of 35 Ryecroft St, Gloucester, (formerly of 56 Neville Close, Hounslow, Middlesex), pleaded not guilty to five counts of Cheating the Revenue contrary to Common Law and was sentenced to nine years' imprisonment on 22 March 2011. His role was as an organiser/coordinator of the fraud and he owned the laptop which contained information that was central to the fraud. He was found guilty on 16 February 2011 on each of the five counts of the fraud committed by the other five defendants.

Original Page: http://www.channelregister.co.uk/2011/03/24/hmrc_vat_fraud_sentence/

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

Russian pres fumes at mystery DDoS hack • The Register

Russian pres fumes at mystery DDoS hack

by John Leyden, theregister.co.uk
April 8th 2011 3:06 PM

Russian president Dmitry Medvedev has denounced online vandals who launched an attack against the site that hosts his blog.

The denial of service assault on the LiveJournal site on Wednesday was both "outrageous and illegal" the Russian politician fumed after the assault, the BBC reports. "What has occurred should be examined by LiveJournal's administration and law enforcement agencies," he wrote.*

Novaya Gazeta, a newspaper critical of official government policies, was also hit a day later, on Thursday, as part of a wave of website-jamming attacks directed around the Russian interwebs this week. The paper is running a project to create an "online parliament" in order to create a venue where issues ignored by vested government or corporate interests can be debated and discussed. Novaya Gazeta reckons that this effort to create a forum of free speech is behind the attacks.

Whether the two attacks are linked remains unclear.

LiveJournal addresses associated with a popular anti-corruption blogger, Alexey Navalny, were reportedly the first to be targeted by denial of service attacks that first began on 24 March, according to a post on Kaspersky Lab's SecureList blog. It reports the attacks are using the Optima/Darkness DDoS bot, currently all the rage on Russian language cybercrime forums. Who is being targeted – mostly political bloggers, although one furniture firm is on the list – is clear enough, as is how the attack took place. But why the attacks have been mounted, much less who exactly is behind them, remains unclear.

The other attacks might have been launched in order to draw attention away from the assault on the furniture firm, as Kaspersky analyst Maria Garnaeva notes. Alternatively, the attacks may have originated with anti-opposition cyber-militia, who then mistakenly attacked Medvedev's blog.

In possibly related news, surfers attempting to reach the website of Russian football club Zenit St Petersburg were redirected to a site hosting complaints against local politicians instead earlier this week. We suspect CSKA Moscow fans for this assault, blamed by the club on a DNS records hack. But that's just us. ®

Bootnote

*Sup Media, which runs LiveJournal, described Medvedev as an "enthusiastic blogger" who has maintained a blog on the site for the last two years. This, together with his quotes on the attack, evokes an unflattering image of him at his computer Wednesday – and frustrated at being unable to update his blog – while prime minister Vladamir "Dobby" Putin continues to run the country. Isn't it a bit odd that, as president of a country, Medvedev is writing that the police ought to investigate the attack rather than phoning them up and insisting they look into it. ®

Original Page: http://www.theregister.co.uk/2011/04/08/russian_ddos_assaults/

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

WordPress.com hack exposes confidential code • The Register

WordPress.com hack exposes confidential code

by Dan Goodin, theregister.co.uk
April 13th 2011 7:12 PM

The company that maintains the WordPress blogging platform said hackers gained root access to its servers and made off with sensitive code belonging to it and its partners.

Wednesday's advisory from Automattic is the latest to detail a breach on a company entrusted to keep customer information private. The company, which serves about 18 million publishers, said employees are still determining exactly what data was stolen, but the initial assessment didn't look good.

“Automattic had a low-level (root) break-in to several of our servers, and potentially anything on those servers could have been revealed,” the company's founder, Matt Mullenweg, wrote. “We presume our source code was exposed and copied. While much of our code is open source, there are sensitive bits of our and our partner's code. Beyond that, however, it appears information disclosed was limited.”

In the comments section to his post, Mullenweg said there's no evidence that passwords were exposed, “and even if they had they'd be difficult to crack.” He advised users to change their passwords anyway, especially if the same one is used in two or more places. WordPress passwords are hashed and salted using the Portable PHP password hashing framework, he added.

Mullenweg didn't say how hackers were able to root multiple servers belonging to his company but said it has “taken comprehensive steps to prevent an incident like this from occurring again.”

WordPress joins companies including RSA Security, Epsilon, and an unnamed reseller of SSL certificate authority Comodo in admitting to breaches that put its customers at risk. So far, there's little public evidence about who is responsible for the hacks.

With about 12 percent of websites running WordPress, the platform has long been a target of hacks. In 2009, a spam-friendly worm attacked older installations of the program, including that of tech blogger Robert Scoble, who lost two months of blog entries as a result. It was the second time that year that his blogging software had been exploited.

More recently, WordPress came under a massive denial-of-service attack that made it impossible for many of its users to publish their content.

Source code stored on Automattic's servers includes API keys and Twitter and Facebook passwords that can used to gain access to sensitive information, TechCrunch said.

Original Page: http://www.theregister.co.uk/2011/04/13/wordpress_hack_attack/

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

Malicious software downloads invade WordPress • The Register

WordPress bug resets admin password

by Dan Goodi, theregister.co.uk
August 12th 2009 1:29 AM

This story was updated to correct details of the bug. It allows attackers to reset passwords, but not take over accounts.

Developers of the widely used WordPress blogging software have released an update that fixes a vulnerability that let attackers reset the administrator password.

The bug in version 2.8.3 is trivial to exploit remotely using nothing more than a web browser and a specially manipulated link. Using the special URL, the old password is removed and a new one generated in its place with no confirmation required, according to this alert published on the Full-Disclosure mailing list.

The flaw lurks in some of the PHP code that fails to properly scrutinize user input when the password reset feature is invoked. Exploiting it is as easy is directing a web browser to a link that looks something like:

http://domain_name.tld/wp-login.php?action=rp&key[]=

According to WordPress documentation here, the bug has been fixed by changing a single line of code so the program checks to make sure the input supplied for the new password isn't an array. If it is, the user gets an error message and must try again. After this article was first published, version 2.8.4 was released.

That would appear to be the end of it, but security researchers Rafal Los and Mike Bailey wonder aloud here whether it would have made more sense to check instead whether the input is a string.

"Hasty coding?" he asks. "Why take the blacklist vs. whitelist approach?"

After this article was first published, WordPress documentation showed the suggestion from Los and Bailey was being formally adopted.

The bigger point he and other observers seem to make is that PHP is the coding equivalent of an everyman's jet pack. It allows him to quickly soar into the sky with a minimal amount of training but doesn't necessarily provide the means to check for buildings, planes or other hazards that may greet the user once he gets there.

Of course, all languages are only as good as the person using them. But it's worth posing such questions to anything that's standing between your website and the people out to get it.

Additional details and analysis from Sans and Heise here and here. ®

Original Page: http://www.theregister.co.uk/2009/08/12/wordpress_password_reset_bug/

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

Social engineering put on notice

Google Chrome to warn of malicious Windows executables

by Dan Goodi, theregister.co.uk
April 5th 2011 9:21 PM

Google says it's expanding its blacklist of malicious websites to include those that use deceptive claims to push harmful Windows programs.

The addition to Google's Safe Browsing API will warn people when they are about to visit websites that offer Windows-based trojans that are disguised as screen savers or other innocuous applications. The search behemoth introduced the service five years ago to alert users when they try to browse sites that perform drive-by downloads that exploit security vulnerabilities in the operating system or browsing software.

The underlying programming interface is already being used by browsers including Google Chrome, Mozilla Firefox, and Apple Safari. It's also available to any webmaster who wants to use the wealth of information available from Google to prevent malicious links from being posted to their sites.

“Safe Browsing has done a lot of good for the web, yet the internet remains rife with deceptive and harmful content,” Moheeb Abu Rajab, a member of Google's security team, blogged on Tuesday. “It's easy to find sites hosting free downloads that promise one thing but actually behave quite differently.”

Keyloggers, botnet software and adware are just three examples.

The new feature will initially be available only for Chrome users who subscribe to the browser's development release channel. The company plans to integrate it into the next stable release of Chrome. There is no mention of it being made available to browser providers outside of Google.

The warning will be displayed whenever users encounter a download from a URL that matches the latest list of malicious websites published by the Google API. ®

Original Page: http://www.theregister.co.uk/2011/04/05/google_malicious_executables_warning/

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

Cybercrooks turn the table on researchers with fake interface

ZeuS miscreants offer up honeypot

by John Leyden, theregister.co.uk
November 5th 2010 1:31 PM

Cybercrooks are attempting to turn the tables on security researchers by setting up fake interfaces on their botnets in a bid to confuse and confound analysis.

The fake honeypot tactic was brought into play by a group using a variant of the infamous Zeus crimeware toolkit. The unknown miscreants targeted quarterly federal taxpayers with fake emails that sought to trick prospective marks into visiting a website loaded with exploits on the pretext that there had been a problem with their tax returns. If successful, the attack resulted in the infection of PCs with variants of ZeuS primarily designed to capture and extract bank login details.

In between waiting for the drop of confidential IDs from compromised machines, the crackers set up a trap for researchers. A bogus administrative panel hands out counterfeit statistics on the number of ZeuS-infected machines, as well as the ability to upload new bot malware, a feature designed to hoodwink security researchers or rival botnet operators.

A write-up of the ZeuS decoy admin console can be found in a post on the Last Line of Defense blog here.

"This admin interface acts as a 'hacker honeypot' that records detailed information about who attempted to access the admin console, as well as who attempted to hack into it," the post explains.

In a nice touch, the phoney login accepts default or easily guessed login credentials. Just for good measure, the interface is also also vulnerable to a simple SQL-injection vulnerability.

The deployment of the fake honeypot tactic in ZeuS-related malware operations is unlikely to be coincidental. The discovery of genuine ZeuS interfaces over recent months has been a major source of raw intelligence for security researchers. Although we can't say for sure at this point it's even possible that this data led to the recent run of arrests of ZeuS crimeware suspects in the UK, US and the Ukraine.

Crooks who use ZeuS as the weapon of choice for snaffling online banking credentials would doubtless be interested in frustrating this kind of researcher through the use of decoys. Viewed from this perspective, spying on what their opponents are up to would be a bonus for cybercrooks. And since ZeuS is highly customisable adding in the additional honeypot hooks would have been no great chore. ®

Original Page: http://www.theregister.co.uk/2010/11/05/zeus_fake_interface_ruse/

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

Stuxnet code leak to cause CYBER-APOCALYPSE NOW! • The Register

Stuxnet code leak to cause CYBER-APOCALYPSE NOW!

by John Leyden, theregister.co.uk
November 26th 2010 10:11 AM

Source code for the sophisticated Stuxnet worm has reportedly made it onto underground forums where it is been offered up for sale at some unspecified price.

This not entirely unexpected development, first reported by Sky News, has prompted the satellite TV channel to get for broke with a loosely substantiated story sensationally headlined "Super Virus A Target For Cyber Terrorists". Sky quotes unnamed senior IT security sources sources to report the "virus is in the hands of bad guys".

The malware could now be adapted and used to shut down power stations, "the transport network across the UK" and the 999 system, according to Will Gilpin, an IT security consultant to the UK government. Gilpin goes on to conclude, at the end of an accompanying video report, that we're a generation behind and have already lost the war in cyberspace.

These dire warnings of doom are nothing more than alarmist claptrap, according to Paul Ducklin of Sophos, who criticises the report for stating assumptions as fact as well as for sensationalism.

Ducklin is far more worried about the very real problem posed by cybercrooks raiding bank accounts and subverting payment systems, a concern we wholeheartedly share.

"The problem with inaccurate, inflammatory and irresponsible stories about Stuxnet - good though they may be for page impressions and video views - is that they make cybercriminality sound like a second-rate problem when it is positioned against a news backdrop alleging cyberwar," Ducklin writes.

Stuxnet is highly sophisticated worm that selectively targets industrial control systems from Siemens. The most well-publicised incident of infection was at the Bushehr nuclear power plant in Iran but it's far from clear if the worm sabotaged systems carrying out uranium enrichment at Natanz or at Iran's controversial Bushehr nuclear power plant, which has been subject to delays. It's even less clear who developed the malware.

Whoever created the code used four Windows zero-day vulnerabilities, now exposed, and must have done a great deal of testing on industrial control systems. Adapting the worm for another target would take a almost equivalent level of expertise.

The idea that "cyberterrorists" are poised to unleash variants of this malware at 999 systems or the UK transport network belongs in the same category as claims that Iraq might be able to deploy biological weapons within 45 minutes in discredited documents published by the UK government prior to the start of the disastrous invasion of the country.

It really is that bad.

Stuxnet is a complex threat, and the Iranian nuclear angle certainly adds spice, so it's a bit easy for the general media to get a bit carried away. For a very good – non-sensationalist – info on the Stuxnet worm we can offer no better resource than F-Secure's well-written redux here. ®

Original Page: http://www.theregister.co.uk/2010/11/26/stuxnet_leak_hype_rot/

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

HBGary gets the ACS:Law treatment

Anonymous pwns security firm that probed its membership

by John Leyden, theregister.co.uk
February 7th 2011 10:15 AM

The Anonymous hacking collective took revenge on a security firm that had investigated its membership on Sunday.

HBGary Federal has been seeking to uncloak the identities of senior members of Anonymous involved in attacks against financial services firms, such as PayPal and Mastercard, that had suspended accounts run by WikiLeaks. The security consultancy had infiltrated IRC chat sessions and Facebook groups used by core members of the Anonymous collective. HBGary Federal wanted to present its research at an upcoming security conference.

In response, Anonymous did a number on HBGary by hacking into its email system and uploading 60,000 emails onto file-sharing networks. Anonymous also defaced HBGary's website with an image explaining their motives as well as taking over the Twitter feed of HBGary's chief exec, Aaron Barr, to tweet abuse as well as supposed details of his home address and social security number. LinkedIn accounts of other senior HBGary execs were also targeted for attack.

Anonymous also posted HBGary's research of the hacking collective, claiming that the names and addresses of Anonymous members gleaned by the firm are largely bogus. The techniques and methods employed during the attack remain unclear.

The assault is far more sophisticated than than usual denial of service attacks deployed by Anonymous volunteers against organisations the earn its displeasure, such as entertainment industry firm-hassling file-sharing sites and the Church of Scientology as well as as those refusing to cash WikiLeaks' cheques.

The assault on HBGary follows the same pattern as a previous assault against ACS:Law, a controversial legal firm that ran a business sending threatening letters to alleged file-sharers.

HBGary's website had been replaced by an "under construction" holding page at the time of writing. Rootkit.com, a research site maintained by HBGary, and also hit by the attack remains unavailable. ®

Original Page: http://www.theregister.co.uk/2011/02/07/anon_pwns_hbgary/

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

Fun-spoiling, DDoSing thieves farm virtual gold to sell for cold hard cash

Cybercrooks turn Eve Online into botnet battlefield

by John Leyden, theregister.co.uk
May 23rd 2011 1:08 PM

Crooks using online games to farm virtual currencies that they can sell for real money have turned internet spaceship game Eve Online into a battlefield for botnets.

Eve Online is home to various rival groups who generate in-game currency for gamers who want to join in without spending their time acquiring experience and resources by working their way up from the bottom. Rivals groups from eastern Europe are using botnets to DDoS opponents before taking over their territories. Regular gamers are often caught in the cross-fire of multi-pronged attacks that might occur in game, via DDoS attacks to forums, over VoIP communication systems and late night prank phone calls. Game servers have taken a hit in the process.

Gold farmers are known for using Trojans to gain control of compromised accounts. The Eve Online baddies have taken a different tack through attacks that swamp forums with junk traffic.

Chris Boyd, a senior threat researcher at GFI Software and gaming security experts, said that Eve Online's difficulties are a part of wider problems in virtual worlds.

"Gold farmers can cause the price of in-world items to rise, chat channels can be flooded by sale scams, endless bots and automated processes can cause significant server load," Boyd told El Reg. "That's before you get to the problems creating by phishing, hacking and scamming established and profitable accounts."

Boyd (AKA paperghost) agreed that the miscreants on Eve Online are taking it up to 11.

"The idea that there are effectively dead systems filled with nothing but spambots and hostile empires that are happy to do battle outside of their gaming realm by DDoS'ing websites and making prank phonecalls is a fascinating insight into the troubles plaguing virtual worlds, and real world currency having a marked impact on virtual trading makes this a few steps above dedicated DDoS botnets designed for nothing other than kicking console gamers out of Halo 3 sessions."

Various groups rumoured to be working out of Eastern Europe and Russia are said to be offering in-game currency for real money. "Investigations by the owners of the game have caused several leaders of these alliances to be banned in the past," explained Reg reader Patrick, who was the first to tell us of the hive of villainy within Eve Online.

More details on some of the DDoS attacks and other shenanigans on Eve Online can be found in blog posts on "Evenews" here, here and here. ®

Original Page: http://www.theregister.co.uk/2011/05/23/eve_online_botnet_mayhem/

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower