Hackers have released an application designed to thwart a Microsoft-packaged forensic toolkit used by law enforcement agencies to examine a suspect’s hard drive during a raid.
The hacker tool, dubbed DECAF, is designed to counteract the Computer Online Forensic Evidence Extractor, aka COFEE. The latter is a suite of 150 bundled, off-the-shelf forensic tools that run from a script. Microsoft combined the programs into a portable tool that can be used by law enforcement agents in the field before they bring a computer back to their forensic lab. The script runs on a USB stick that agents plug into the machine.
The tools scan files and gather information about activities performed on the machine, such as where the user surfed on the internet or what files were downloaded.
Someone submitted the COFEE suite to the whistleblower site Cryptome last month, prompting Microsoft lawyers to issue a take-down notice to the site. The tool was also being distributed through the Bit Torrent file sharing network.
This week two unnamed hackers released DECAF, an application that monitors a computer for any signs that COFEE is operating on the machine.
According to the Register, the program deletes temporary files or processes associated with COFEE, erases all COFEE logs, disables USB drives, and contaminates or spoofs a variety of MAC addresses to muddy forensic tracks.
The hackers say that later releases of the program will allow computer owners to remotely lock down their machine once they detect that it has fallen into law enforcement hands. The hackers, however, have not released source code for the program, which would make it easy for anyone to see if the program contains malware that might also harm a computer or allow the attackers to take control of it.
Update: The developers of DECAF have taken issue with Threat Level referring to them as hackers. “We’re just two developers who support the free flow of information and privacy,” one of them wrote Threat Level in an anonymous e-mail. “You could say we’re just average joes.”
Showing posts with label Hackers. Show all posts
Showing posts with label Hackers. Show all posts
Tuesday, December 15, 2009
Wednesday, August 5, 2009
Rejoice! Latvian ISP linked to online criminal activity booted out of Internet
IDG News Service — A Latvian ISP linked to online criminal activity has been cut off from the Internet, following complaints from Internet security researchers.Real Host, based in Riga, Latvia was thought to control command-and-control servers for infected botnet PCs, and had been linked to phishing sites, Web sites that launched attack code at visitors and were also home to malicious "rogue" antivirus products, according to a researcher using the pseudonym Jart Armin, who works on the Hostexploit.com Web site.
"This is maybe one of the top European centers of crap," he said in an e-mail interview.
"It was a cesspool of criminal activity," said Paul Ferguson a researcher with Trend Micro.
The ISP was disconnected from the Internet by its upstream provider, Junik, on Monday, after its provider, TeliaSonera told it to stop servicing Real Host or face sanctions Armin said.
Real Host was considered a "bullet proof" hosting provider, that would allow customers to remain online even after they had been linked to malicious activity. It had been linked to the Zeus botnet-making software.
This isn't the first time this type of hosting provider has been knocked offline. In the past year, at least three U.S. ISPs: Atrivo, McColo and 3FN have been unplugged after security researchers built cases against them. Atrivo and McColo were also taken offline by their upstream providers. 3FN was shut down by the U.S. Federal Trade Commission.
But according to Armin, this may be the "first time an international group has achieved this across borders and in Eastern Europe."
In the past, these takedowns have had a serious affect on spam. And while some observers reported a noticeable drop in spam over the weekend, security experts say that this was probably not attributable to the Real Host takedown.
Observers expect to see the criminal activity linked to Real Host resume soon, but they say that the takedown puts some pressure on the bad guys and the networks that provide service to them. "The precedent that's being set right now is that you need to take some responsibility for your network," said Lawrence Baldwin, owner of security research firm Mynetwatchman.
"There actually are some consequences now for allowing an obviously heavy concentration of criminal activity on your networks. It's just not going to be accepted anymore."
Labels:
botnets,
cyber attacks,
Cyberthieves,
Hackers,
security
Tuesday, August 4, 2009
Conficker Worm - Still Ice Cold at DefCon Conference
All talk of the Conficker Worm was sanitised at the Black Hat conference to protect the current investigation.The criminal ring is very savvy and might have infiltrated the group hunting it down, one investigator says.
The international security team tracking down Conficker thought that the masterminds behind it would have been apprehended by now, according to one of the leaders of the effort to stamp out the resilient worm but that’s not the way it has worked out.
Investigators cautious
A meeting and presentation talk at Black Hat yesterday had to be scaled back because it contained information about Conficker that might tip the investigators’ hand and send the perpetrators further underground, says Mikko Hypponen, chief research officer at F-Secure and a member of the Conficker Working Group.
A Forensic Look
When Hypponen submitted the abstract for his Black Hat briefing more than six months ago, he thought he’d be presenting a forensic look at a dead worm and that the team who had written and managed it would be out of action. “I had hoped that by the end of July we would be in a totally different situation, the case would be closed and the group would be in jail,” Hypponen said in an interview after his talk.
Critical Information
His official line was that he was asked last week not to reveal critical information that might help prolong Conficker’s reign over millions of computers and inhibit the ongoing criminal investigation. “So I will end my presentation here,” Hypponen said at the conclusion of his Black Hat session. “Thank you very much. I will not be taking any questions.”
Holding Back
Hypponen said afterwards that he wasn’t forced to curtail his remarks (Black Hat has been the site of numerous speech-blockings and speech-blocking attempts, including that of a researcher Cisco sued because he was to reveal a flaw in the company's IOS code). Rather, Hypponen had already realised that it made sense to hold back some of what the working group has found out. “It’s better to keep them in the dark about what is known,” he says.
Agility and Precision
Given the agility and precision with which Conficker alters its tactics, Hypponen doesn’t rule out that the Conficker Working Group itself might have been infiltrated by Conficker operatives.
He wouldn’t say how close he thinks authorities are to bringing down the group, but did say there is an indication that it is based in the Ukraine. Some techniques used in Conficker match those used in an earlier worm, which might mean the same people were behind both.
Ukrainian Police
That earlier worm avoided propagating to machines in the Ukraine, which might mean that the group is based there and was trying to avoid committing a local crime to keep Ukrainian police off their backs, Hypponen says.
Technical Sophistication
During his talk Hypponen outlined some of Confickter’s technical sophistication. In one version change – the worm has gone through five major revisions – the worm adopted the MD-6 cryptographic hash algorithm. Investigators estimate that MD-6 was only a month or so old when it was incorporated in Conficker, making the worm one of the earliest implementations of MD-6, he says.
Buffer Overflow
The next major revision of Conficker patched an MD-6 buffer-overflow vulnerability that was publicly announced about six weeks earlier, which means the criminals keep themselves in the loop with the latest advances, he says. (The patch they used was identical to the one issued by MD-6 creators.)
Disables Infected Machines
The worm avoids sending itself to domains owned by members of the Conficker Working Group, and it disables infected machines so they can’t reach sites where they might seek help.
F-Secure Help Site
Hypponen’s company set up a help site with a different domain name from its regular business site that included the term F-secure, and the next version of Conficker blocked it. The company changed the term to Fsecure with no hyphen, and the next revision blocked that, too, he says.
The worm had been propagating to eight top level Internet domains and the working group mustered enough cooperation to shut it down in all those domains, Hypponen says. The next version propagated to 116 domains, he says.
Strategy Weak
“These guys are very good in cryptography and code development,” he says, but maybe not so good about strategy, given the attention they drew to themselves. “They didn’t know better than to infect 10 million computers in a couple of days.” The goal of any botnet ought to be to remain hidden, not draw attention to itself, he says.
“They might have experience in another crime business but hadn’t run a botnet before. If they were more experienced, they’d know better.”
The Malady Lingers on
It would make sense, Hypponen says, for the Conficker gang to abandon its current botnet and build a new one that doesn’t get too big too fast and doesn’t draw a team of experts to fight it. “Maybe they already have,” he says.
Subscribe to:
Posts (Atom)