Showing posts with label Offences - Unauthorised 'modification' (and co). Show all posts
Showing posts with label Offences - Unauthorised 'modification' (and co). Show all posts

Friday, 7 May 2010

Security review by Symantec and other issues of web security

Symantec published its report analysing cyber-issues in 2009. Most of the attacks continue to come from the US (19%), followed by China (8%) and a new comer, Brazil (6%). The bulk of the attacks (37%) focuses on acquiring data, then it is accessing structural tools of companies (26%) and piracy (15%). Fraud represents only 2%. It confirms that the new value or currency today is data, rather than money itself as a direct target. In other words, data is worth more than currencies.
The recent story about a Twitter user confirms that data is gold. He was able, after numerous tweets to different users including to a Twitter employee, to find the ID and password of that employee and conduct himself as an Twitter administrator (JDN, 6 May 2010). He has been arrested in France in the Massif Central, after collaboration with the FBI (Obama's account was hacked).

A lot of those attacks are performed by users dowloading PDF documents and believing that their banks would send them e-mails requesting for their information (74% of phishing). It confirms that users are "culprits" as much as the perpetrators. If people were a bit more careful in what they download and read, there would be less succesful attacks. It is certainly the message of Remy Fevrier from the French Gendarmerie Nationale (the French police under the military umbrella) at the FIC or Forum International sur la Cybercriminalite held in Lille from the 31 March to 1st April 2010. He explained that some firms went bankrupt because precious data was stolent by a competitor which was then able to offer the product at a lesser price because it did not have the costs of research and development.

Coming back to the Symantec report, to control other computers, attackers continue to use keystroke softwares, uploading users' details and zombies/botnets I suppose.
Firefox and Safari are the most vulnerable browsers on the web currently. IE and Chrome being stable and quite below (50 instead of around 100).

See the summary in French on JDN "Les menaces IT n'ont pas connu la crise en 2009" (6 May 2010)

Tuesday, 8 December 2009

Virtual worlds and theft

Apparently, somebody has been arrested for theft for hacking into accounts, use avatars and steal the virtual possessions. "Real-world arrest for man who stole RuneScape virtual characters" (Times, 30 November 2009)
For disapproval, "If You Gain Unauthorized Access To A Character In A Virtual World, Is It Theft?" (TechDirt, 01 December 2009)
Contra: "Is virtual boom our industrial revolution?" (TheGuardian, 10 September 2009)
http://www.guardian.co.uk/technology/2009/sep/09/victor-keegan-virtual-world-revolution

Different issues on fraud and malware and a few arrests/suspicions

Well, I would have thought they were an obvious target? "Online bank fraud targeting corporate accounts" (ZDnet.co.uk, 04 November 2009)

"Facebook denies mass hijack was down to flaw" (ZDnet.co.uk, 11 November 2009) but a few weeks later, decides to change its approach to security as company policy! "Facebook forms safety advisory board" (07 December 2009)

I think here Google is over optimistic. Actually data security and privacy is the very reason why I choose not to use the different services available, despite the fact that it would have made my life much easier. "Google: Data is more secure in the cloud" (ZDnet.co.uk, 03 November 2009)

"UK police make Zeus Trojan arrests" (ZDnet. co.uk, 19 November 2009)
"Former YouSendIt chief accused of DoS attack" (ZDnet.co.uk, 02 November 2009)

Smartphones and malwares

Not a surprise that smartphones start to be the target of viruses and other malwares. They are powerful computers when one think of their size.

"iPhone worm could be used to create botnets" (ZDnet.co.uk, 23 November 2009)
"Un nouveau virus s'attaque à l'iPhone" (JDN. 24 November 2009)

which in turn, means good jobs for technicians and ex-hackers/malware writers "Rickroll virus author hired by iPhone app company" (ZDnet.co.uk, 27 November 2009)

Monday, 26 October 2009

hacking in the US

Three indicted in largest-ever US hacking prosecution (ZDnet.co.uk, 18 August 2009)

with one of them pleading guilty to ID theft

Hacker pleads guilty to ID thefts worth millions (ZDnet.co.uk, 2009)

DoS attack - Australia

Australian gov't calls on experts over DDoS attack (ZDnet.co.uk, 10 September 2009)

and Australian police probe government cyberattack (ZDnet.co.uk, 09 september 2009)

Twitter, Facebook and DoS: security and hactivism

Facts of 1st attack: a Georgian account in Twitter, Facebook and Google' blogger, was targeted by multiple attacks. It caused Twitter to shut down, Facebook had problems. And the suspicion is on Russia, obviously (although it remained to be proved).
Apart from the costs of it all, what is interesting is the fact that the attack against one person/entity triggered problems for everybody else using the services of Twitter, Facebook and Google. The collateral effects are damning.

Blogger targeted in Twitter, Facebook DoS (ZDnet.co.uk, 7 August 2009) and Cyberattack That Brought Down Twitter & Facebook Only Highlighted The Guy It Hoped To Silence (TechDirt, 10 August 2009)

French version: Twitter rendu indisponible par une attaque visant un internaute (JDN, 7 August 2009)


Facts of 2nd attacks:

Twitter suffers outage following fresh attack (ZDnet.co.uk, 12 August 2009)

To which extend the botnet was part of the 2 attacks, it remains to be seen: Security firms reveal botnet on Twitter (ZDnet. co.uk, 17 August 2009)

Thursday, 25 June 2009

Spam, fraud and mobile phones

"Proud, Bragging Spammer Alan Ralsky Pleads Guilty" (TechDirt, 24 June 2009) - the US spammer was finally caught ... for fraud and spam!!

For new areas of fraud coming up soon given the huge development of mobile phone banking:
Le m-paiement atteindrait 250 milliards de dollars d'ici 2012 (JDN, 23 June 2009)

Wednesday, 3 June 2009

Thursday, 7 May 2009

Cyberthreats - importance of botnets or virus?

It is obviously silly to leave computers infected whatever the reasons. The regulation applied here should simply be modified. The article is however interesting for another reason: the scale of the use of internet to connect medical devices and the threat to health this can create. Apparently, nobody has quantified the risk, which is scary when one thinks of the threat to the electric grid that happened a few weeks ago. It actually made me think of Beck's argument in the Risk Society (our use of inadequate criteria to assess risks because the type and scale of risks have changed since the 19th century)
"US red tape leaves Conficker on medical devices " (ZDNet.co.uk, 5 May 2009)

The Conficker worm also reveals that the real and most dangerous threat is invisible. This is particularly stressed in the French article where it is explained that the purpose of botnets is not be noticed, to be as invisible as possible even though the damages can be enormous for the person infected or for others not related.
"Forget Conficker — focus on the real threats" (ZDnet.co.uk, 29 April 2009)
Frédéric Guy (Trend Micro)"Nous identifions 800 à 1300 nouveaux virus par heure" (JDN, 20 April 2009)
"Un botnet ciblant les ordinateurs Mac" (JDN, 17 April 2009) with the scale of the threat being minimum given the few users of Apple
"Le zapping de la sécurité (avril 2009)" (JDN, April 2009)

Wednesday, 29 April 2009

Sunday, 25 January 2009

UK institutions victims of viruses

Hospitals first, with hopefully only a few appointments cancelled as damage.
"Downadup virus hits PCs at five Sheffield hospitals " (ZDnet.co.uk, 22 January 2009)
More serious in terms of national security, and certainly more worrying, is the MoD's system victim of viruses. "Virus causes Ministry of Defence outages " (ZDnet.co.uk, 16 January 2009)

Thursday, 20 November 2008

DDOS and amended CMA

At last the amended version of CMA by Police and Justice Act 2006 comes into force on 1st October 2008. The delay is inadmissible when considering the threats and the potential for a different outcome than in the Lennon case.
DoS and distributed hacking tools finally criminalised (14 November 2008)
For the official text, http://www.opsi.gov.uk/si/si2008/uksi_20082503_en_1

Monday, 23 June 2008

Botnets - DDOS

on the phenomenon of botnets, describing its key feature (the difficulty to track down who did what and with or without a criminal intention), see FBI cyber division's sparse comments http://www.crime-research.org/news/16.04.2008/3312/ (16 April 2008)

Thursday, 20 December 2007

Trojan and new victims: ISPs

Usually trojans victimise the lot of us, private users who are not careful about what we download or where we go; but this time, ironically, the victim is Google itself who is loosing money, exactly what it should not!

Google 'powerless' to stop AdSense theft (20 December 2007) http://news.zdnet.co.uk/security/0,1000000189,39291643,00.htm

Unintended DDOS!

How efforts to fight corruption in China ended it up with the equivalent of a DDOS attack, although quite unvoluntarily (well, let's hope)
'Too many hits' crash Chinese anti-corruption website (19 December 2007)
http://news.zdnet.co.uk/internet/0,1000000097,39291622,00.htm