Saturday, June 30, 2012

Android Alert: Five Security Threats You Didn’t Know About

Your Android device is vulnerable to a host of security breaches. Here’s how to protect yourself.

When you think of viruses, spyware, and other security threats, you probably think of your PC. After all, that’s where the majority of these kinds of attacks take place. But malware on your mobile phone? Or even your tablet? Nah, that could never happen. Could it? Yes it could, especially if your mobile device runs the Android operating system. According to Juniper Networks, Android malware samples increased a whopping 472 percent in the period between July and November, 2011.

Hackers have declared war on Android devices, and you might get caught in the crossfire. Fortunately, as Sun Tzu famously noted in The Art of War, “If you know your enemies and know yourself, you can win a hundred battles without a single loss.” Here are the five biggest enemies you should know — and how to beat them at their own game.

1. SMS Trojans

According to that same Juniper Networks report, nearly half the malicious Android apps circulating today are SMS Trojans, which send text messages in the background (meaning without your knowledge) to premium-rate numbers owned by the hackers. The end result: a potentially huge surcharge on your monthly carrier bill.

By far the best way to stop an SMS Trojan is to avoid getting hit by one in the first place. For that, make sure to install an Android security suite designed to combat all kinds of threats, not just a few. Also, don’t install apps that look suspicious or sound too good to be true.

2. Carrier IQ

Late in 2011, a researcher discovered that a rootkit from software developer Carrier IQ was running on millions of mobile devices. Though not overtly nefarious, the code reportedly logs users’ locations and keystrokes (including passwords). Most troubling, all this happens without users’ knowledge and without the option to disable it.

To guard against this threat, get Carrier IQ Test, a free app that can detect and remove the unsanctioned software.

Adjusting the settings for additional security.

3. Preloaded apps

Your smartphone or tablet probably came with some “bonus” apps, software that’s not normally included with Android but was added by the manufacturer or carrier. Last December, researchers discovered that some of these preloaded apps contain serious security vulnerabilities, the kind that can be used to wipe a handset, steal private data, or even listen in on phone calls. Even worse, because many of these apps are “baked in” to the OS, they can’t be removed.

If you have Android 4.0 (a.k.a. Ice Cream Sandwich), you can at least hide and disable bloatware apps. Just venture into Settings, Device, Apps, tap All, tap the app you want to banish, and then tap Disable.

4. Fake Google Play stores

Earlier this year, Google transformed Android Market into Google Play, where it consolidated various services (apps, music, e-books, etc.). Shortly thereafter, cybercriminals began creating fake Google Play domains designed to trick users into installing malicious apps.

The way to fight this threat is to get smart. Don't attempt to install the Google Play app on your own by downloading it. Instead, follow the usual procedures to update your device's OS. Also, Android security software can detect and remove any rogue apps you might inadvertently install, so it’s a good idea to run anti-malware utilities on your mobile device.

5. Android/FakeToken.A

You get a text message from your bank: “Your account has been comprised! Tap here to sign in and update your password.” Tapping the link takes you to a realistic-looking site, complete with the bank’s logo. So you sign into your account — and, in the process, open the door to Android/FakeToken.A, a form of remote-control malware that can steal all kinds of personal data.

Never, ever tap a link contained in an email or text message, no matter how legitimate it looks. Instead, open your browser and connect to your financial institution directly, making sure the URL starts with https://. Even better, if the bank offers its own app, use that to access your account. And if you’re really concerned about a security breach, call the institution directly.

Posted from DailyDDoSe

@columbia FYI -- hack3d

jHAZbAau.DOC Download this file

 

SABU took over Lulz Whois domain July 1, 2011.

Registrant Name: Adrian Lamo
Admin Name: Adrian Lamo
Admin ID: CR25623848 
Admin Street1: 1 Police Plaza
Admin Street2: #Aspergers section
Admin City: New York
Admin Country: US

“The goberment of Portugal will not extradite me!”

Expires: January 17, 2012 

Fuck. That. Shit.

Category:
News & Politics

Tags:
Anonymous Fraud Lulz Aspergers Hackgate NY USA @ELyssaD Whois
License:
Standard YouTube License

504
Aspie
504-lulz
Columbia_transcript_ed_m_
Error83
Russian1
Elyssashirt
Blows

10columns

Posted from DailyDDoSe

Five Rules for Using Your Laptop On Public Wi-Fi Hotspots

Have laptop and planning to roam? Follow these tips and you won’t expose yourself to hardware or data theft while surfing wirelessly in public.

What’s the only thing better than a free Wi-Fi hotspot? Free coffee to go with it, of course. Alas, free, all-you-can-drink java is pretty rare, but free public Wi-Fi networks are easy to come by. You’ll find them in coffee shops, airports, food courts, and libraries, among other places.

But are they safe? As a matter of fact, no. An open network is, by definition, open, meaning hackers can more easily weasel into your system and steal your data — perhaps even your identity. Does that mean you should steer clear of your local Starbucks and other Wi-Fi-enhanced hangouts? Heck, no.

It simply means you should take a few precautions. With the right tools and by following five simple ground rules, you can keep your laptop secure on any network — and in any location.

1. Don’t connect to networks with strange names

Suppose you’ve plunked down at a coffee shop to get some work done. Your laptop detects two available Wi-Fi networks: “Joe’s Coffee” and “Free Public Wi-Fi.” The latter sounds harmless enough, but it could be a fake network set up by mischievous hackers. And by connecting to it, you run the risk of exposing every piece of data you send and receive.

To avoid these kinds of interceptions, bypass networks with plain-vanilla names. Instead, look for one that seems appropriate to the business or venue that’s hosting it. Better yet, look for the password-protected network that appears to be owned by the establishment you’re visiting. When in doubt, ask someone who works there what their network is called. If you’re a customer, they should be happy to tell you the network name and password so you can start surfing.

2. Dial ‘S’ for ‘security’

Want an easy way to foil hotspot hackers? Here’s a tip brought to you by the letter ‘S’: When you type a Web address into your browser, preface it with “https” instead of the usual “http.” The former activates something called Secure Socket Layer (SSL), which is a fancy term for encrypted browser traffic.

See, without SSL, hackers can sniff out the text you’re transmitting with your browser. That’s no big deal for, say, Google searches, but what if you’re typing in your Yahoo email password? Now we’re in big-deal territory.

Some sites default to https, but keep an eye on your address bar to make sure it’s there — and add the ‘S’ if it’s not. Fast, simple, effective.

3. Make like Fort Knox

A thief might be able to break into your house, but that safe you keep in the closet? No way he’s getting in there. You can apply the same principal to your laptop with a security suite that features an encrypted-storage solution, which is like a vault for your data.

Once enabled, this password-protected vault provides a hacker-proof haven for sensitive documents, photos, and the like. Thus, even if a hacker manages to break into your PC (or make off with it), your data will remain safe.

4. Flip the switch

Done checking email and hitting up your favorite websites? Then why not turn off Wi-Fi? That’s the best protection you can buy, and you’ll get the added bonus of longer battery life. Of course, you’ll still be able to use your word processor, watch movies, and so on — activities that don’t require Internet access.

Many laptops have a physical switch or keyboard function key that can toggle Wi-Fi on and off. Alternately, you can simply venture into the control panel or settings and deactivate Wi-Fi from there.

5. Lock it down

Data security is one thing, but don’t forget about securing your actual laptop. In the minute or two it takes you to go refill your coffee cup or answer the call of nature, a thief can easily walk off with your pricey property.

Kensington's Laptop Lock deters laptop theives.

Enlist some hardware help in the form of a lock, like the $25 Kensington Portable Combination Laptop Lock. It combines a compact, coiling cable with a four-digit combination-based T-bar lock, and it works with any laptop that has a security slot (most recent models do). Just wrap the cable around a bolted-down table leg or some other fixed point, and chances are good a thief won’t even bother trying to nab your notebook.

Finally, if you’re thinking about upgrading, make your next laptop an Ultrabook. Starting in June 2012, all Ultrabooks will pair hardware-based security features with smartphone-like anti-theft software, thus affording remote lock, remote data wipe, and location tracking. Maybe they should start calling them Smartbooks.

Posted from DailyDDoSe

'Flame' Spread Via Rogue Microsoft Security Certificates

Analysis of the massive ‘Flame’ cyber attack code has revealed that rogue Microsoft security certificates were used to make the malware appear as if it was officially signed by Microsoft. Microsoft has issued a security advisory, revoked trust in the rogue certificates, and provided steps to help IT admins and users prevent attacks that rely on the spoofed Microsoft certificates.

A post on the Microsoft Security Response Center blog states plainly, “We have discovered through our analysis that some components of the malware have been signed by certificates that allow software to appear as if it was produced by Microsoft.”

Malware'Flame' slipped under network defenses by appearing as legitimate Microsoft code.Andrew Storms, director of security operations for nCircle, declares, “The discovery of a bug that’s been used to circumvent Microsoft’s secure code certificate hierarchy is a major breach of trust, and it’s a big deal for every Microsoft user. It also underscores the delicate and problematic nature of the trust models behind every Internet transaction.”

The Microsoft blog post explains that a vulnerability in an old cryptography algorithm is exploited by some elements of Flame to make them appear as if they originated from Microsoft. Most systems around the world accept officially-signed Microsoft code as safe by default, so the malware would enter unnoticed.

The weak algorithm is a function of the Terminal Server Licensing Service, which allowed IT admins to authorize Remote Desktop services on Windows-based networks. The algorithm in question was used to generate security certificates with the ability to sign code so that it is accepted as legitimate Microsoft code.

Microsoft is taking steps to deal with this issue. First, it released the security advisory which explains the issue in detail and provides steps IT admins can use to block software signed by the rogue security certificates. Microsoft also released an update, which automatically implements those same steps to make it easier for customers to prevent malware using the spoofed certificates from slipping through.

Microsoft adds that the Terminal Server Licensing Service is no longer capable of issuing certificates that can be used to sign code. With these steps in place, organizations can ensure that any malware that depends on the rogue security certificates will no longer be recognized as being from Microsoft.

Storms provides some further insight about the rogue Microsoft certificate revelation. He points out that the stealthy use of rogue Microsoft security certificates supports the theory that ‘Flame’ is part of a grander state-sponsored espionage effort. “A bug that can identify a piece of malware as legitimate is not something an average malware writer would have been able to sit on for long--it’s worth far too much on the black market.”

Storms adds, “The fact that this bug has been kept secret for at least 18 months, and quite possibly longer, is pretty clear evidence that there is a nation state behind Flame.”

Posted from DailyDDoSe

Don't Get Burned By 'Flame' Malware Attack

Don't Get Burned By 'Flame' Malware Attack

Businesses and individuals need to be aware that other threats like 'Flame' may already be out there, and take steps to be more diligent in guarding against them.

Flame (or Skywiper) is a massive, complex threat. Weighing in at 20 megabytes, and somewhere around 750,000 lines of code, Flame is much closer to a commercial application like Microsoft Word, or Intuit’s Quicken than it is to the vast majority of malware attacks out there. The question is should you be concerned and what can you do about it?

At a conference in November 2011 Regina Dugan, director of the United States Department of Defense DARPA network, explained, “On average, the malicious code, viruses, bots, worms and exploits that try to penetrate [our networks] rely on 125 lines of code.” Flame is comprised of more than 7,000 times that.

When a security vendor gets a hold of a malware sample, it generally takes a matter of hours--or even minutes--to reverse-engineer it, figure out what it does and how it does it, and develop a signature to detect the threat and protect systems against it. Fully deconstructing and analyzing Flame could take months, or even years.

So far security researchers have discovered a wide variety of modules within Flame designed for different tasks. The quick analysis thus far suggests that modules like Flame, Weasel, Suicide, Euphoria, and Beetlejuice perform functions ranging from managing the Autorun infection routine, to interface and control of Bluetooth wireless devices, to self-terminating the malware itself.

The Flame malware itself may seem of little concern to most people. From what is known so far it seems to be a precision attack aimed at specific political and strategic targets in the Middle East. It seems at first glance to be a state-sponsored threat with military or national defense implications rather than run-of-the-mill malware that tries to steal your credit card information.

That’s true, and yet there is still much cause for concern. Even if Flame itself isn’t meant for you, the fact is that Flame was developed years ago, and it has been out there surreptitiously gathering data undetected. If one set of developers can create malware like Flame to use against specific targets, it’s possible that other similar threats are already out there and that we’re just not aware of them yet.

Thankfully, Flame didn’t reinvent malware. It’s impressive in its sheer size, but the underlying attacks are not all that unique. Malware toolkits like Zeus and SpyEye are also capable of many of the same underlying functions as Flame. Still, Flame has managed to fly under the radar for years.

Businesses and individuals should be more vigilant about monitoring network activity and identifying anomalous behavior. A layered defense should identify and block new threats from getting in, but should also contain elements that track behavior and watch outbound traffic to detect suspicious activity.

too late...

Posted from DailyDDoSe

Five Ways to Protect Your Children from Cyberbullying

Five Ways to Protect Your Children from Cyberbullying

Kids now face harassment on the Internet as well as on the playground. Here’s how you can help.

Cyberbullying is on the rise. According to a January 2012 Ipsos poll, a whopping 60 percent of children say they’ve experienced some form of cyberbullying. And 1 in 3 teens have encountered cyber-threats. If those stats seem surprising, consider that kids are exposed to technology at earlier and earlier ages, and spend more and more time connected to the Internet thanks to smartphones, tablets, and laptops.

The most alarming statistic of all: 90 percent of the victims of cyberbullying don’t inform a parent (or other trusted adult) of the abuse. And as evidenced by some heartbreaking recent headlines, cyberbullying can lead to depression or even suicide. It’s serious stuff.

So what’s a concerned parent to do? Communicate. Get involved. Set limits. You know — everyday parenting stuff, but with a focus on your kids’ online lives. Here are five ways you can help protect your children from the very real threats associated with cyberbullying.

1. Have a discussion

As in any healthy relationship, it’s crucial to have open, honest communication with your kids. So set aside a few minutes to talk about cyberbullying. Let them know you’re aware of it, you want to know if they’re experiencing it, and, if they are, you definitely want to help put a stop to it. Most importantly, tell them you won’t judge, even if there are photos, bad language, or other potentially embarrassing elements involved.

At the same time, make sure your kids know that it’s not okay to harass others — and that means explaining exactly what constitutes cyberbullying. The legal definition: “threats or other offensive behavior sent online to a victim or sent or posted online about the victim for others to see.” The kid-speak definition: “sending mean or hurtful text messages, instant messages, email, tweets, photos, and so on.”

In other words, just as you want to protect your kids from cyberbullying, you want to keep them from becoming cyberbullies, too.

2. Get involved

You pay attention to where your kids go after school, whom they hang out with, and all that, right? Extend that involvement and supervision, to their online activities. Find out which social networks they use (Facebook and Twitter are the most likely), create your own accounts on those networks, and friend/follow your kids. They’ll probably object, but tell them that’s the condition if they want to be online themselves.

Keep in mind that tech-savvy kids might know how to adjust their networks’ privacy settings to keep you from seeing their posts—even if you’re a friend or “follower.” For a more effective monitoring solution, install parental-control software on the computers your kids use.

And for younger kids, insist on knowing their passwords for any sites they use. That way you can conduct the occasional spot-check to make sure their communications stay tame.

If your child has a smartphone or tablet, consider installing an app that can remotely lock, wipe, and retreive data if the device is lost or stolen. Members of the peer-focused cyberbullying awareness group Teen Angels say a lost device is one of the most common ways that kids get cyberbullied.

3. Set limits

The vast majority of cyberbullying happens to kids in middle school (ages 9 to 14). The more unrestricted, unsupervised access these kids have to Internet-accessible devices (smartphones, tablets, etc.), the greater the chance of bullying. To lessen the chance your child will be a victim or perpetrator, set some limits. You might, for example, restrict laptop use to after-dinner hours, and make sure it happens out in the open, not sequestered away behind closed doors.

Likewise, consider setting up texting/instant-messaging filters so that kids can communicate only with family members and close friends. And use a shared account for email so you can keep an eye on what comes in and what goes out.

4. Work with the schools

Many schools teach kids about real-world bullies, but fewer focus on cyberbullying. Tell teachers and administrators that you’re concerned about it, and ask them to include the topic in their discussions and school policies. The more parents who speak up about cyberbullying, the more schools will make students aware that it’s just as unacceptable as “regular” bullying.

5. Learn the proper responses

How should a child deal with a cyberbully? According to Common Sense Media, the first rule of thumb is to avoid responding: “Engaging with a bully only fuels the fire. Plus, any response could be circulated immediately.”

Kids should also block the bully from future communication, change their contact information (especially if someone is pretending to be them), and save any bullying emails (to share with you, your Internet service provider, and, if necessary, the authorities).

how about adults?

Posted from DailyDDoSe

Flame Hijacks Microsoft Update to Spread Malware Disguised As Legit Code

It’s a scenario security researchers have long worried about, a man-in-the-middle attack that allows someone to impersonate Microsoft Update to deliver malware — disguised as legitimate Microsoft code — to unsuspecting users.

And that’s exactly what turns out to have occurred with the recent Flame cyberespionage tool that has been infecting machines primarily in the Middle East and is believed to have been crafted by a nation-state.

According to Microsoft, which has been analyzing Flame, along with numerous antivirus researchers since it was publicly exposed last Monday, researchers there discovered that a component of Flame was designed to spread from one infected computer to other machines on the same network using a rogue certificate obtained via such a man-in-the-middle attack. When uninfected computers update themselves, Flame intercepts the request to Microsoft Update server and instead delivers a malicious executable to the machine that is signed with a rogue, but technically valid, Microsoft certificate.

“We have discovered through our analysis that some components of the malware have been signed by certificates that allow software to appear as if it was produced by Microsoft,” Microsoft Security Response Center Senior Director Mike Reavey wrote in a blog post published Sunday.

To generate their fake certificate, the attackers exploited a vulnerability in a cryptography algorithm that Microsoft uses for enterprise customers to set up Remote Desktop service on machines. The Terminal Server Licensing Service provides certificates with the ability to sign code, which is what allowed the rogue code to be signed as if it came from Microsoft.

Microsoft has provided information to explain how the flaw occurred in its system.

Reavey notes that since Flame is a highly targeted piece of malware that is believed to have infected fewer than 1,000 machines, the immediate risk from Flame is not great. But other attackers could have been exploiting the vulnerability as well. And the fact that this vulnerability existed in the first place is what has security experts all aflame. Code that is officially signed by Microsoft is considered safe by millions of machines around the world, something that put them all at risk.

“The discovery of a bug that’s been used to circumvent Microsoft’s secure code certificate hierarchy is a major breach of trust, and it’s a big deal for every Microsoft user,” Andrew Storms, director of security operations for nCircle, told PC World. “It also underscores the delicate and problematic nature of the trust models behind every Internet transaction.”

According to Kaspersky Lab, which discovered the Flame malware about three weeks ago, the certificate is used by a component of Flame called “Gadget” to spread the malware from one infected machine to others on a network. It was the use of this rogue certificate that is believed to have allowed Flame to infect at least one fully patched Windows 7 machine, according to Alexander Gostev, chief security expert at the Lab.

Here’s how it works:

When a machine on a network attempts to connect to Microsoft’s Windows Update service, the connection gets redirected through an infected machine first, which sends a fake, malicious Windows Update to the requesting machine. The fake update claims to be code that will help display gadgets on a user’s desktop.

The fake update looks like this:

“update description=”Allows you to display gadgets on your desktop.”
displayName=”Desktop Gadget Platform” name=”WindowsGadgetPlatform”>

If the ruse works, a malicious file called WuSetupV.exe gets deposited on the machine. Since the file is signed with a fake Microsoft certificate, it appears to the user to be legitimate, and therefore the user’s machine allows the program to run on the machine without issuing a desktop warning.

The Gadget component was compiled by the attackers on Dec. 27, 2010, according to Gostev in a blog post, and was implemented in the malware about two weeks later.

The following is exactly how the process occurs: The infected machine sets up a fake server by the name “MSHOME-F3BE293C”, which hosts a script that serves a full body of the Flame malware to victim machines. This is done by the module called “Munch”.

When a victim updates itself via Windows Update, the query is intercepted and the fake update is pushed. The fake update proceeds to download the main body and infect the computer.

The interception of the query to the official Windows Update (the man-in-the-middle attack) is done by announcing the infected machine as a proxy for the domain. This is done via WPAD. To get infected, the machines do need however to have their System Proxy settings configured to “Auto”.

Microsoft has revoked the certificate and fixed the vulnerability via an update. Hopefully, the update will not be man-in-the-middled.

Homepage Photo: Marjan Krebelj/Flickr

Posted from DailyDDoSe

A Massive Web of Fake Identities and Websites Controlled Flame Warfare

Map showing the number and geographical location of Flame infections on Kaspersky customer machines. Courtesy of Kaspersky Lab

The attackers behind the complex Flame cyberespionage toolkit, believed to be a state-sponsored operation, used an extensive list of fake identities to register at least 86 domains, which they used as part of their command-and-control center, according to researchers at Russia-based antivirus firm Kaspersky Lab.

Kaspersky says the size of the command-and-control infrastructure, which appears to have been still partially active a few days ago even after the operation was publicly exposed, exceeds anything they’ve seen before.

“The huge amount of fake domains and fake identities used to run this infrastructure is pretty much unprecedented and unlike any other malware that we have seen before,” said Roel Schouwenberg, senior antivirus researcher at Kaspersky Lab. “In my opinion, it’s an indication of the huge resources which went into this project.”

Many of the domains, set up as early as 2008 in some cases and as late as April this year, were registered with the GoDaddy registrar service, and used fake addresses in Germany and Austria, with Vienna being a particularly popular choice for the attackers, according to research done by Kaspersky. A lot of the addresses tracked to places like hotels, medical offices, and shops. At least one address was for the British library in Paris and shops. Other addresses did not appear to exist at all.

The domains pointed to 24 IP addresses, at various times, that were located in Germany, Poland, Malaysia, Latvia, Switzerland, Turkey, the Netherlands, Hong Kong and other places.

The attackers used each identity only two or three times on average to register a domain, before choosing a new one. It’s not clear what they used to pay for the domains. Kaspersky referred the question to GoDaddy, but the registrar did not respond to a request for comment.

Cybercriminals often use stolen credit card numbers to pay for domains used in their operations, but since Flame is believed to be a state-run operation, the attackers likely used pre-paid cards issued under fake names to register the domains.

Although the domains went dark about an hour after news of the operation broke worldwide last Monday, suggesting the attackers were shutting down the mission, at least three infected machines in Iran, Iraq, and Lebanon were upgraded by the attackers with new versions of the malware after this occurred, Schouwenberg said, suggesting a certain boldness on their part.

Two of the machines went from having version 2.212 of Flame installed on them to suddenly having version 2.242.

“This means basically that this week, after the [news] announcement, the Flame command-and-control network was still operational and sending updates, possibly commands, to the victims,” Schouwenberg said. “Which, in my opinion, this is quite amazing, that despite all this noise and the story being everywhere, they’re still using the command-and-control infrastructure to send updates.”

Flame has a hardcoded password, 'LifeStyle2', that infected machines use to connect to command-and-control servers. Courtesy of Kaspersky

New findings also show that the attackers were particularly interested in stealing AutoCAD drawings from infected machines, according to the types of stolen files Kaspersky has seen infected machines trying to upload to the attackers’ domains.

AutoCAD is a popular software program that is used to render computerized models and schematics for architectural designs and consumer products, as well for the layout of machinery and networks at plants and factories, including critical infrastructure facilities.

The interest in AutoCAD documents is something Flame shares with DuQu, another espionage tool that was discovered on machines in various countries last year and is closely related to Stuxnet, the groundbreaking infrastructure-sabotaging malware that is believed to have wreaked havoc on Iran’s nuclear program in 2009 and 2010.

Flame is a 20MB malicious toolkit that consists of at least 20 known modules that can be swapped in and out to provide various functionality for the attackers – such as eavesdropping on conversations via the internal microphone on an infected computer, stealing documents or taking screenshots of email and instant message communications — depending on what the attackers want to do on a particular machine.

The toolkit is believed be part of a parallel project created by contractors who were hired by the same nation-state team that was behind Stuxnet and DuQu.

Flame appears to have been operating in the wild as early as March 2010, though there are clues that the malware may have been active as early as 2007. It was only discovered about three weeks ago by Kaspersky. It’s believed to have infected about 1,000 machines in the Middle East and elsewhere.

After news of Flame broke last Monday and the attackers shut down their domains, infected machines contacting the servers to report in and receive commands were met with 403/404 errors.

The researchers had already set up a sinkhole, however, and worked with GoDaddy and OpenDNS to divert traffic for about 30 of the domains to their sinkhole instead. This means that stolen files that would have landed in the hands of the attackers, are now being delivered to Kaspersky, though they’re encrypted by the malware before they’re sent out to Kaspersky.

The researchers got their first hit from an infected machine late that first evening after the redirect was completed, and have received communication from 118 infected systems from 18 countries and the Occupied West Bank since then.

Chart showing the domains the attackers registered for Flame and the registration dates. Courtesy of OpenDNS

Because antivirus firms distributed signatures and tools to detect and remove Flame quickly last week, the machines contacting the sinkhole are ones that either didn’t have antivirus installed on them, or don’t have updated signatures installed and are therefore still infected. These include 45 machines in Iran, 21 in Lebanon, 14 in Sudan, and 8 in the United States.

Each time an infected machine tries to contact the attack domains, they use a hardcoded password, LifeStyle2, to identify themselves as a Flame-infected machine. The password is coded into the malware’s configuration file, but can be changed.

Once a connection is established, the infected machine begins uploading compressed and encrypted packages of data, including an activity log that records everything the malware has done on the infected machine as well as a list of files it has sent to the attackers.

To avoid uploading entire documents from an infected machine to the attackers — which would mean collecting a lot of data in which they have no interest — the attackers designed their malware to just parse through PDFs, Excel and word-processing documents and extract a 1-kilobyte sample of the text. The malware then compresses and uploads the sample text to a command-and-control domain where, presumably, the attackers would pick through the contents and instruct the malware to then grab only specific documents that interested them.

Kaspersky still hasn’t figured out definitively if Flame is related to a piece of malware called “Wiper” that Iran reported had deleted files from machines at its Oil Ministry in April. The researchers have not found any module for Flame that wipes out files in the way that “Wiper” reportedly did, but have not ruled out that a wiper module may exist for Flame that they haven’t found yet.

One final new tidbit about Flame: the researchers previously reported that a kill module for Flame, called “browse32,” can be sent out by the attackers to wipe Flame off of systems. The kill module, they previously stated, searches for every trace of the malware on the system, including stored files full of screenshots and data stolen by the malware, and eliminates them, leaving nothing of the malware left behind.

The researchers now say that there is a mistake in the kill module and instead of deleting every trace of Flame, it leaves one file behind. The file is named “~DEB93D.tmp.” It’s the same file that Kaspersky has been instructing users to look for on their systems to determine if they are infected with Flame.

Posted from DailyDDoSe

Meet 'Flame,' The Massive Spy Malware Infiltrating Iranian Computers

Map showing the number and geographical location of Flame infections detected by Kaspersky Lab on customer machines. Courtesy of Kaspersky

A massive, highly sophisticated piece of malware has been newly found infecting systems in Iran and elsewhere and is believed to be part of a well-coordinated, ongoing, state-run cyberespionage operation.

The malware, discovered by Russia-based antivirus firm Kaspersky Lab, is an espionage toolkit that has been infecting targeted systems in Iran, Lebanon, Syria, Sudan, the Israeli Occupied Territories and other countries in the Middle East and North Africa for at least two years.

Dubbed “Flame” by Kaspersky, the malicious code dwarfs Stuxnet in size — the groundbreaking infrastructure-sabotaging malware that is believed to have wreaked havoc on Iran’s nuclear program in 2009 and 2010. Although Flame has both a different purpose and composition than Stuxnet, and appears to have been written by different programmers, its complexity, the geographic scope of its infections and its behavior indicate strongly that a nation-state is behind Flame, rather than common cyber-criminals — marking it as yet another tool in the growing arsenal of cyberweaponry.

The researchers say that Flame may be part of a parallel project created by contractors who were hired by the same nation-state team that was behind Stuxnet and its sister malware, DuQu.

“Stuxnet and Duqu belonged to a single chain of attacks, which raised cyberwar-related concerns worldwide,” said Eugene Kaspersky, CEO and co-founder of Kaspersky Lab, in a statement. “The Flame malware looks to be another phase in this war, and it’s important to understand that such cyber weapons can easily be used against any country.”

Early analysis of Flame by the Lab indicates that it’s designed primarily to spy on the users of infected computers and steal data from them, including documents, recorded conversations and keystrokes. It also opens a backdoor to infected systems to allow the attackers to tweak the toolkit and add new functionality.

The malware, which is 20 megabytes when all of its modules are installed, contains multiple libraries, SQLite3 databases, various levels of encryption — some strong, some weak — and 20 plug-ins that can be swapped in and out to provide various functionality for the attackers. It even contains some code that is written in the LUA programming language — an uncommon choice for malware.

Kaspersky Lab is calling it “one of the most complex threats ever discovered.”

“It’s pretty fantastic and incredible in complexity,” said Alexander Gostev, chief security expert at Kaspersky Lab.

"Independent?" Iranian Hacker Claims Responsibility for Comodo Hack

The hack that resulted in Comodo creating certificates for popular e-mail providers including Google Gmail, Yahoo Mail, and Microsoft Hotmail has been claimed as the work of an independent Iranian patriot. A post made to data sharing site pastebin.com by a person going by the handle “comodohacker” claimed responsibility for the hack and described details of the attack. A second post provided source code apparently reverse-engineered as one of the parts of the attack.

Whether the postings are authentic and accurate is, at present at least, a matter of conjecture. The post specifies a number of details that appear authentic. The writer fingers Italian Registration Authority GlobalTrust.it/InstantSSL.it (the same company operating under multiple names) as the weak link. A Registration Authority (RA) is essentially a local reseller for a Certification Authority (CA); in principle, the RA performs the validation of identity that would be too difficult or expensive for the root CA to do, and then sends a request to the root CA to generate an appropriate certificate. Comodo’s systems trust that the RA has done its job appropriately, and issues the certificate. This is consistent with Comodo’s statement that it was a Southern European company that was compromised.

arstechnica

In addition to blaming a specific RA, the post includes other details: the username (“gtadmin”) and password (“globaltrust,” proving once again that security companies can pick really bad passwords) used by the RA to submit requests to Comodo’s system, the e-mail address of InstantSSL’s CEO (“mfpenco@mfpenco.com”), and the names of the databases used by GlobalTrust’s website. In practice, though, only Comodo can verify this information, and the company has no good reason to do so.

The alleged hacker also described some details of the hack itself. He claims to have broken into GlobalTrust’s server and found a DLL, TrustDLL.dll, used by that server to send the requests to Comodo and retrieve the generated certificates. The DLL was written in C#, so decompiling it to produce relatively clear C# was easy; within the DLL the hacker found hard-coded usernames and passwords corresponding to GlobalTrust’s account on Comodo’s system, and another account for the system of another CA, GeoTrust. The source code the hacker posted was part of this DLL, and certainly has the right form for decompiled source code. Again, though, only GlobalTrust could provide absolute confirmation of its authenticity.

Reasons for caution

So at least to some extent, the claim looks legitimate. They’re saying the right kind of things. There are, however, a few reasons to be cautious. The identity of the RA was already presumed to be InstantSSL.it, and the company is Comodo’s only listed reseller in the Southern Europe area. That listing also discloses mfpenco’s Comodo e-mail address, and from there it’s easy to find his full name, e-mail address, and position within the company. So someone uninvolved with the hack could provide this information. Even the DLL source code is not cast iron evidence: Comodo publishes the API that RAs use to integrate with its systems, so anybody could produce a similar DLL. Indeed, the only details not trivially discoverable with a bit of search engine leg-work are the ones that are also entirely unverifiable anyway.

The experience of 1,000 hackers

The claims are also infused with an almost unbelievable amount of BS in its purest form. Though initially describing him- or herself as “we,” the hacker then claims to be a 21-year-old programmer working alone, and to be unaffiliated with the Iranian Cyber Army (a group accused of hacking Twitter in 2009). So far, so good. He then goes rather off the rails, however, when he claims to have the hacking experience of 1,000 hackers, the programming experience of 1,000 programmers, and the project management experience of 1,000 project managers. Mmm-hmm.

He claims also that his original plan was to hack the RSA algorithm commonly used in SSL. RSA is a public key cryptography algorithm, and its security depends on one thing: that factorizing numbers into their prime factors (for example, converting 12 into 3×2×2) is computationally difficult. With numbers of the size used in RSA—typically 1024 bits, equivalent to about 309 decimal digits, or 2048 bits, equivalent to about 617 decimal digits—and the current best-known algorithms, literally thousands of years of CPU time are required to factorize the numbers involved, making it computationally intractable.

Though the hacker initially admits that he didn’t find a solution to the integer factorization problem—instead getting waylaid by the distraction of breaking into CAs—he later claims that “RSA certificates are broken,” and that “RSA 2048 was not able to resist in front of me.” He also directly threatens Comodo and other CAs, saying “never think you can rule the internet, ruling the world with a 256 digit [sic] number which nobody can find it’s [sic] 2 prime factors (you think so), I’ll show you how someone in my age can rule the digital world, how your assumptions are wrong.” So the implication is that an attack on RSA is forthcoming, but there’s no sign of it so far.

The decompilation of the DLL and subsequent generation of code that allowed the hacker to generate his own certificates is also ascribed to the hacker’s own brilliance. He claims that he had “no idea” of Comodo’s API or “how it works,” and that the DLL did not quite work properly due to being out of date and not providing all the information that Comodo’s systems needed. Nonetheless, he learned what to do and rewrote the code “very very fast,” with the result that Comodo will be “really shocked about my knowledge, my skill, my speed, my expertise and entire attack.” Skill and expertise are certainly one possibility, but looking at the documents that Comodo publishes is surely the easier approach—and surely the preferred approach of someone with the experience of 1,000 hackers.

The hacker’s manifesto

Nonetheless, the claims are probably authentic, at least insofar as they come from someone with some knowledge of, and involvement in, the Comodo attack. They tie together all the right pieces, and the DLL code, though by no means absolute evidence, is pretty compelling—though the grandiose claims about RSA are unlikely to amount to anything. In addition to claiming responsibility, the post includes something of a political manifesto—a series of “rules” that hint at the underlying reason for the attacks.

The nature of the targets chosen—mainly e-mail sites—enabled the perpetrator to relatively effectively eavesdrop on secure e-mail sent using Gmail, Yahoo! Mail, and Hotmail. This in turn implicated government agencies, as such an ability would allow them to more easily detect dissident communications. However, the hacker insists that he is independent and acting alone. He is, however, a staunch pro-government nationalist, and issues a warning to people within Iran such as the Green Movement and the MKO that they should be “afraid of [him] personally.” He continues, “I won’t let anyone inside Iran, harm people of Iran, harm my country’s Nuclear Scientists, harm my Leader (which nobody can), harm my President, as I live, you won’t be able to do so.” Those people “don’t have privacy in internet” and “don’t have security in digital world. [sic throughout]”

Are you inside Iran with problems? ph34r!

The hacker also criticizes Western governments, Western media, and Western corporations. He positions the fraudulent certificates as a means of giving himself equivalent powers to the US and Israel, stating that they can already read mail in Yahoo, Hotmail, Gmail, and so on “without any simple little problem,” since they can spy using Echelon. The certificates just let him do the same.

He criticizes the media in a number of ways. He regards it as unfair that Iranian ambassadors were quizzed by the media regarding the Comodo attack, and yet no equivalent scrutiny was given to US and Israeli officials over Stuxnet. Similarly, the Western media wrote about the Comodo attack, but ignores Echelon and HAARP—in other words, that the media swoops into action when it appears that Iranians might compromise the secrecy of Westerners, but doesn’t care about Westerners spying on the rest of the world.

And finally, he claims that Microsoft, Mozilla, and Google updated their software “as soon as instructions came from CIA.” He also claims that the reason Microsoft did not patch the Stuxnet vulnerabilities for so long is not because the company didn’t know about them, but rather because those vulnerabilities were required by Stuxnet—Redmond was again acting on the behalf of the CIA.

The hacker says that we should be scared and afraid, that he is immensely skilled, and that the security offered by SSL will soon come crashing down around our ears. This is highly unlikely. His claims are far-fetched, with more than a hint of conspiracy theory madness to them.

But in another sense, he’s right. The hack he describes was not particularly clever or advanced; we still don’t know all the details, but it appears that Comodo has done little to ensure that its RAs are secure, leaving it extremely prone to attack. It’s unlikely that Comodo is unique in this regard, too—the specifics will vary from CA to CA, RA to RA, but there are so many of these entities, all of them trusted by default, that further holes are inevitable. Such attacks don’t need large teams or state sponsorship to work; they’re well within the reach of a suitably well-motivated individual. With SSL we have built, and depend on, a large trust system—breaches of that trust are a genuine threat with the potential for enormous harm. It’s high time these trusted companies made sure they actually deserved that trust.

Top image: The alleged hacker’s claim of responsibility on pastebin.com

i think not.

Posted from DailyDDoSe

Hacking Home Automation Systems Through Your Power Lines

LAS VEGAS – Hacking the grid took on new meaning at the DefCon hacker conference on Friday when two independent security researchers demonstrated two tools they designed to hack home and business automation and security systems that operate though power lines.

The automation systems let users control a multitude of devices, such as lights, electronic locks, heating and air conditioning systems, and security alarms and cameras. The systems operate on Ethernet networks that communicate over the existing power lines in a house or office building, sending signals back and forth to control devices.

The problem is that all of these signals are sent unencrypted, and the systems don’t require devices connected to them to be authenticated. This means that someone can connect a sniffer device to the broadband power network through an electrical outlet and sniff the signals to gather intelligence about what’s going on in a building where the systems are installed – such as monitor the movements of people in houses where security systems with motion sensors are enabled. They can also send commands through the network to control devices that are connected to it — for example, to turn lights on or off or to disable alarms and security cameras.

“None of the manufacturers have implemented really any security whatsoever on these devices,” said Dave Kennedy, one of the researchers. “It’s such an immature technology.”

Kennedy, aka Rel1k, and Rob Simon, aka Kc57, spent two months researching and designing their open-source tools to conduct the hacks. The tools focus on home-automation systems that are based on the X10 protocol, which doesn’t support encryption. They also looked at the ZWave protocol, which does support AES encryption, but the one device they found that was using it, implemented the encryption incorrectly – the key exchange was done in the clear so an attacker could intercept the keys and decrypt all of the communication.

The tools, which they’re releasing to the public, include the X10 Sniffer to determine what’s connected to the power network and monitor what the devices are doing, and the X10 Blackout, which can jam signals to interfere with the operation of lights, alarms, security cameras and other devices.

The researchers demonstrated the Sniffer and Blackout devices they designed that plug into a power socket inside or outside a house or even into an outlet in a house nextdoor, since signals can leak out from a house and carry for some distance. Kennedy said that while testing one of the devices from his house in Ohio, he picked up signals from home automation systems belonging to 15 neighbors.

The tools need to be preprogrammed with commands the hackers want to send. For example, the tools can be preprogrammed to send a jamming signal if a security system is triggered by someone opening a door or window. This would prevent an alarm from sounding and alerts being sent out to police and the property owner. The researchers are working on a GSM-enabled tool that would allow attackers to receive sniffed data remotely to their cell phones (currently the sniffed data is written to external storage) as well as send commands in real-time back to the tool via text messaging.

Thieves could monitor a house to determine when the occupants are generally gone based on signals indicating when lights are turned off, doors and windows are closed and the alarm system is enabled. Then they could send out jamming signals from the tool to disable motion sensors and alarms before breaking into the house. They could also completely fry the system by overloading it with rapidfire commands, though Kennedy acknowledged that this could potentially cause a fire.

The researchers said they hadn’t notified the makers of automation systems about the vulnerabilities in their systems, but said they are hoping their project will bring attention to the security problems.

Posted from DailyDDoSe

EVIDENCE: HACKS & ATTACKS: Lulz! Paste & Scrape? 501(c) FRAUD

HACKS & ATTACKS: Lulz! Paste & Scrape? HIPAA SSA and email my father sent from Munich, Germany

SUPPORT THE MENTALLY CHALLENGED. #JADED SECURITY WILL DONATE $1.00 for each shirt @ElyssaD Shirt Sold

 

I’m not really sure what her infatuation is with my piece on Joseph K Black or care enough to look at if there is any affiliation. She either has some serious problems or BlackBerg Security Sucks at background checks too.

The websites (not that I dug deep, cause I don’t care enough to)

www.thepowersthatbeat.blogspot.com/

http://posterous.com/people/5ewYgzxPVmnL

http://sanityforsuperheroes.blogspot.com/

http://information4sale.blogspot.com

From this photo ID posted on her Picasa, you would probably assume she might have some emotional problems. Why else would she post a photo id of herself with her social security number clearly on the front (Notice my Blur Skillz). As a Security Professional, I just can’t bring myself to post it on my site.

RECOVERED

Posted from DailyDDoSe

Manage My Account - TwitterGate paper trail - "Catch me if you can?" Exhibit B - Flickr

Failed
@earthspeakorg, 12/29/10 4:16 PM Retweet
Reason: Unknown Error. Please try to delete and re-add this autopost destination if this issue persists.
5 months ago
Failed
@srbijadanas, 12/29/10 3:00 PM me thinks ...
Reason: Unknown Error. Please try to delete and re-add this autopost destination if this issue persists.
5 months ago
Failed
@HeyJude408, 12/29/10 2:50 PM we saw too
Reason: Unknown Error. Please try to delete and re-add this autopost destination if this issue persists.
5 months ago
Failed
@rockingjude, 12/28/10 6:44 PM
Reason: Unknown Error. Please try to delete and re-add this autopost destination if this issue persists.
5 months ago
Failed
Conversation hiding the evidence ?
Reason: Unknown Error. Please try to delete and re-add this autopost destination if this issue persists.
5 months ago
Failed
@JasonBWhitman, 12/28/10 5:47 PM
Reason: Unknown Error. Please try to delete and re-add this autopost destination if this issue persists.
5 months ago

Posted from DailyDDoSe

Police Tried to Erase Evidence Lulz does it for them

I didn't do it! But I have a pretty good idea who is. SO on the eve of the day you Pwned my site and stole my identity, I hope you die! Thanks again, Jaded, Anthony, Niels, Lance, Niels, and of course, Joe Black. I hole you all know how much you fucked up my life. I hole you all get exact what you deserve. Some awful virus that makes your balks turn green and fall off! Thanks for the Lulz. And the T-shirts. I hope you die!

Photo

אל

Posted from DailyDDoSe

EVIDENCE: HACKS & ATTACKS: Lulz! Paste & Scrape? 501(c) FRAUD

HACKS & ATTACKS: Lulz! Paste & Scrape? HIPAA SSA and email my father sent from Munich, Germany

SUPPORT THE MENTALLY CHALLENGED. #JADED SECURITY WILL DONATE $1.00 for each shirt @ElyssaD Shirt Sold

 

I’m not really sure what her infatuation is with my piece on Joseph K Black or care enough to look at if there is any affiliation. She either has some serious problems or BlackBerg Security Sucks at background checks too.

The websites (not that I dug deep, cause I don’t care enough to)

www.thepowersthatbeat.blogspot.com/

http://posterous.com/people/5ewYgzxPVmnL

http://sanityforsuperheroes.blogspot.com/

http://information4sale.blogspot.com

From this photo ID posted on her Picasa, you would probably assume she might have some emotional problems. Why else would she post a photo id of herself with her social security number clearly on the front (Notice my Blur Skillz). As a Security Professional, I just can’t bring myself to post it on my site.

RECOVERED

Posted from DailyDDoSe

Twittergate 6/22/11 "please refrain from using my "identity" or "likeness"

 

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Begin forwarded message:

From: ED 
Date: June 22, 2011 
Subject:
Conversation

LilithVonSchtupp (@x25princess)
6/22/11 7:41 PM
@ElyssaD But thank you for your kindness today. Im sorry for the ka-fuffle, I hope you get it taken care of.
Elyssa Durant (@ElyssaD)
6/22/11 7:31 PM
@x25princess I can't get in. Maybe a redirect, I don't know. I get 404 on wordpress. http://twitpic.com/5feo8o
LilithVonSchtupp (@x25princess)
6/22/11 7:26 PM
@ElyssaD I just went to your link and its still there. I'm not interested in playing anymore. Keep it up, whatever. You 2 have issue, not me
Elyssa Durant (@ElyssaD)
6/22/11 7:14 PM
@x25princess @jadedsecurity I don't think it is a coincidence either. But I did try to remove the post you requested. http://t.co/rvovnsZ
LilithVonSchtupp (@x25princess)
6/22/11 3:43 PM
@ElyssaD @jadedsecurity LOL, as fun as that sounds (to be fucking a system today & not working) I imagine thats coincidence :)
Elyssa Durant (@ElyssaD)
6/22/11 3:38 PM
@jadedsecurity @x25princess you do realize my sites are #pwned yes? And what is wrong with my website? Did I miss something?
Jaded Security (@jadedsecurity)
6/22/11 2:55 PM
@x25princess @ElyssaD Just because @x25princess asked.. Needless to say they will be back up the next time i find an @ElyssaD site
LilithVonSchtupp (@x25princess)
6/22/11 2:51 PM
@ElyssaD Thats the joint podcast@ElyssaD , started by @jadedsecurity . And I just got confirmation the shirts will be removed on that end.
Elyssa Durant (@ElyssaD)
6/22/11 2:34 PM
@x25princess so #jadedexposure is your podcast? If so, please don't sell T-shirts using phrase "Do it for @ElyssaD" thank you.
LilithVonSchtupp (@x25princess)
6/22/11 2:20 PM
@ElyssaD Again, Im not @jadedsecurity but I will tell him.Ur likeness has not& never will be used 2 promote "my" podcast. Im Lilith, btw.
Elyssa Durant (@ElyssaD)
6/22/11 2:12 PM
@x25princess it's helluva story- but he is "bored" so please refrain from using my "identity" or "likeness" for #jadedexposure promos.Thanks
LilithVonSchtupp (@x25princess)
6/22/11 2:04 PM
@ElyssaD @vaxen_var Im not a twin. I just do a podcast w/ Jaded security hence the retweet. I thought it was our promo
Elyssa Durant (@ElyssaD)
6/22/11 1:59 PM "bored" that's one I've never heard before. Back to square one. At least we know I have "twin" which kinda makes sense given WHO

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted from DailyDDoSe

Another Fake Boutique Security Firm

Another Fake Boutique Security Firm

jadedsecurity.net

Thanks to @Highwick for pointing out friend here has opened up a new site…. http://www.blackandberg.com/

He is still a CyberSecurity Professional and still has his awesome paper listed.

At Black & Berg Cybersecurity we staff only the best in the world, our consultants Are Certified Private Cybersecurity Specialists and their qualifications include:

Bachelor of Applied Science, Information System Security

Associate of Applied Science, Computer Network Systems

Certified Information System Security Professional (CISSP) *

National Security Agency Certification INFOSEC Specialist NSA-4011

US Citizens with the ability to obtain Security Clearances

Certified Information Security Manager (CISM) *

Certified Ethical Hacker (C|EH) *

Security+ *

Network+ *

Project+

Linux+

A+ Remote Support Technician *

A+ IT Technician *

* Department of Defense (DoD) Directive 8570.01 Compliant

UPDATES: If anyone cares anymore…

Joe Claims he got his CISM

#Jadedexposure checks

June 11th 2011. Attrition.org had sent me another of his awesome sites.. http://www.securityofomaha.org/

UPDATE!!!!! BlackbergSecurity is NOT A DEFENSE CONTRACTOR according to E-VERIFY

I’d like to preface this again by saying I don’t condone the activities of Lulzsec. I do fall into the crowd of security professionals who Patrick Gray described as secretly loving him. Patrick has written a great piece on the awareness the group has brought to the weaknesses in information security.  I suggest you go out and read it immediately and you’ll see why.

Attrition.org broke a story back in February on how Joe Black has used social media to create his “Security God” image. Needless to say, they debunked the entire image. Unfortunately, real security guys are the only ones who actually read Attrition, and Joe Black was able to continue in his path to self proclaimed security god.

In his efforts to legitimize his site, he has built a reputation around certifications and misinformation. He has a very interesting career, that we can trace back to his days at Wright Printing in 2005 according to his LinkedIn Profile which is also about the time he was supposedly enrolled at ITT in his Bachelors degree program in Omaha. Calls to ITT have not been returned as of this writing, but Joe did post his associates degree on his flickr page.  While we are on the topic of education, his profile also states that he is expecting to complete his Masters in Security Management  at Bellevue University in 2013. According to the registrar he has withdrawn from every single course he had enrolled in since January of 2009. Guess the worlds greatest hacker, didn’t realize information is public. Oh well

With his reputation on the line he had called out our neighborhood Lulz maker with the following message on his website.

“Cybersecurity For The 21st Century, Hacking Challenge: Change this website’s homepage picture and win $10K and a position working with Senior Cybersecurity Advisor, Joe Black.”

Guess what happens next?

Again, not that I condone any of this, but you know me any chance to prove that security certifications are useless can’t be ignored. Wow, look at all of those interesting certifications on his website. This guy must be a Security Megastar. Lets see what he has

All can be seen thanks to our brainiac on his Flickr

  • Project+ COM70010068307772 A+ 1/08
  • Remote Support COMP001006830772 1/09
  • Security+ COMP001006830772 1/08
  • Network+ COMP00100683C772 1/08
  • Linux+ COMP001006830772 2/08
  • CEH ECC926927 09/08CISSP 318010 12/08

What I don’t see is the ISACA CISM & CISA certifications.

Please Joe, if you have them send the numbers my way

So are we still confident how certifications do not equate to competency? This is just another example of false advertising, and I’m glad it has been brought to light. Black has even Facebook to advertise his services

I love his About statement “At Black & Berg Cybersecurity Consulting we leverage our close relationship with the Federal Government to give our small business clients a Cybersecurity posture that equals or exceeds that of the NSA and Department of Defense.”

Wait speaking of his federal contacts he does have a CAGE# on his linkedin Profile. Wow, legit eh.. EXPIRED

In closing I’m sure you paper security guys would be more than happy to hire him, real security guys well we don’t find our vendors at bus stops.

Original Page: http://jadedsecurity.net/2011/06/08/another-fake-boutique-security-firm/

Shared from Read It Later

Elyssa Durant, Ed.M.

SHIELD • STRIKE  • ReMOVE
HATE Highest Anti Terror Effort

Forgive typos! iBLAME iPhone

Posted from DailyDDoSe