Tuesday, August 4, 2009

Nine very scarey things about Botnets

In a shrinking universe, the Botnet world is expanding.

Let me warn you that this article will paint a scarey picture of botnets taking over all PCs, both the ones on corporate networks as well as the ones at home.


I am sure you have long wondered just how widespread the botnet problem is. What you will learn is enough to make you want to return to the days of stand-alone computing. The reality is worse than most people suspect.

Here is a list of nine known things about botnets that will scare you but perhaps this article will help you to increase your effort to keep your PCs off the illicit botnets.


1. The process of developing software that creates and controls botnets has reached a professional level. Forget the amateur script kiddies that are out for kicks; developers are in it to make a lot of money. The techniques they use to create malware or command and control software are as sophisticated as those used by any commercial software company.

What's more, this underground development community is very cooperative, like a quasi-legitimate open source community. Software is shrink-wrapped, packaged and sold or passed around. The developers add their "personal touches" to create many variants of the malware. Finjan reports that the Golden Cash network operated by cybercriminals provides an exploit toolkit as well as an attack toolkit to distribute malware.

2. Once a PC is captured by a botnet, the use of that PC can be bought and sold many times e.g. the Golden Cash network is a vast botnet exchange. Cyberthieves purchase malware-infected PCs from anyone in the underground market, and then like bond traders, they bundle them and resell them to criminals who want to rent the use of a botnet. This provides a great incentive for criminals to create even larger botnets.

3. Botnets use multiple automated propagation vectors to spread, including spam, worms, viruses and drive-by download attacks e.g. legitimate Web sites are often compromised with HTML tags that force a victim's browser to download JavaScript code from a server that's controlled by the attacker.

That code can launch a number of exploits against the unsuspecting PC. If any of the exploits is successful, the PC can become the next zombie on the botnet, making it easier than ever for the attacker to collect new nodes on his illicit network.

4. The malware that turns the PC into a bot can hide as a rootkit, making it exceptionally hard to detect and eradicate the malware. The Torpig botnet, as an example, implants Mebroot on the victim PC. Mebroot is a rootkit that replaces the system's Master Boot Record. Therefore, the PC is under the attacker's control even before the operating system loads.

5. Once installed, the malware can attack and nullify the very software that is supposed to prevent or at least detect the malware infection. Intel researchers report that botnet developers have begun to target the antivirus, local firewall and intrusion prevention/detection software and services.

The researchers identified at least two ways that a botnet blocked the security software from getting updates:
  • A botnet changed the local DNS settings of the affected system to disable the antivirus software from reaching its update site.
  • A botnet was actively detecting connection attempts to the update site and blocking them.
6. Botnet malware code is often polymorphic; that is, it changes with every new infection. This means that signature-based antivirus software is useless against it. What's more, the Intel researchers have discovered the use of techniques such as code obfuscation, encryption and encoding that further hide the true nature of the code, making it hard for antivirus software to detect it.

7. Botnets can be reprogrammed, allowing their missions to change. One day the botnet can be sending out spam, and the next day it can be told to collect credit card information from the infected PCs.

8. It used to be that bots generated a lot of "noise," making it easier to spot a compromised PC on a network. These days, some bots transmit little traffic, helping them to fly under the radar of log management systems. What's more, botnet traffic can masquerade as legitimate network traffic, making it hard to detect.

9. Legitimate applications such as Web browsers or office productivity tools can be compromised as part of the botnet's malware infection. For instance, the Torpig botnet injects malevolent DLLs into browsers, popular applications, e-mail clients, instant messengers and system programs. After the injection, Torpig can peruse and steal any data that is handled by these applications, including logon IDs and passwords.

If you were under the impression that botnets are no big deal, it's time to realise that they are a big threat and that they are to legitimate businesses and organisations. Now all you have to do is find ways to detect botnet infestations on your network.

The Unwritten Laws of Luddite Technology

What are the Basic Luddite PC Tech Laws?

Let's start with the so-called 'Brains of the Outfit', the 'Nerve Centre' - The PC, Laptop, Mac or 'computer'

  • Law 1: For every fix that a Windows Update patch fixes, the update will break two other things on your PC
  • Law 2: The risk that Windows will need to automatically install time-sucking critical updates on your PC, is directly proportional to your need to get your PC started
  • Law 3: The hard drive always fails just before you were going to back it up.
  • Law 4: Your data will get corrupted just before you plug in your new backup external drive or will be corrupted when plugging in your backup device..
  • Law 5: Your backup plan is only as good as your last successful restore.
  • Law 6: The number of USB ports on your PC or Mac will always be one less than you need at any given time.
  • Law 7: Feeling the time pressure on you to fix a computer quickly, will cause you to take longer.
  • Law 8: If you close the PC case and tighten all the screws before testing it, it won't work; If you test it before closing the case, it will be OK.
What are The Luddite Tech Support Rules?
Now that you've mastered the basic technology traps, you think you're ready to move on to Tech Support.
  • Law 1: If you fix a computer for a friend or family member, you'll be their tech support for life.
  • Law 2: If you Build a computer for someone else, then he/she also owns you for life!
  • Law 3: Recommend a product that you've used with no problems, and the friend/family member who buys it will immediately descend into some sort of product return hellhole of retribution.
  • Law 4: Show any smart or handy IT skills at work, and your company's IT department will start referring all their difficult coworkers to you, the Mr Fixit Guru Guy!
  • Law 5: If it's broken and you call tech support, it will immediately fix itself while you're on hold or are still trying to press the correct buttons to get through the responding call centre's phone system.
What are The Luddite Internet Ordinances?
You can find a world of trouble online.
  • Law 1: Within a month of agreeing to be "friends" with your boss on Facebook you will regret it, big time.
  • Law 2: The crappier the Web site, the sleazier and sketchier the ads.
  • Law 3: When entering "Captcha" verification codes on a Web site, you'll always type in the numeral 1 when the site wants a lowercase L, and a capital O when the site wants the number 0.
  • Law 4: Just before taking out the boss in a WoW raid, your Internet connection will die.
  • Law 5: The difficulty involved in redeeming a rebate is directly proportional to the monetary value of the rebate.
  • Law 6: The safe draft of a nasty e-mail, will always somehow find its way to the (unintended) recipient.
What are The Luddite Precepts of Mobile Tech?
Desktop technology isn't the only source of inevitable woe in your life. All those shiny mobile devices can cause pain, too, since the freedom of untethered technology doesn't extend to immunity from rank on rank of frustrating unalterable laws.

We report 10 master Luddite Mobile Laws here.
  • Law 1: The charger for your current cell phone will not work with the next cell phone you buy.
  • Law 2: Your laptop's charger weighs half of what your laptop weighs and doesn't fit easily into the laptop carry bag.
  • Law 3: A laptop battery will drain at twice its normal rate whenever you leave home without your power cord.
  • Corollary: Your laptop's battery life is inversely proportional to the amount of work you need to get done on a single charge.
  • Law 4: Your iPod or iPhone will be on its last burst of power just as the plane door shuts.
  • Law 5: A replacement battery charger will cost 70 percent of the original purchase price of the whole device, including the laptop bag. For phones, the figure is 140 percent!
  • Law 6: Your cell phone will inevitably break before your two-year contract is up, forcing you to overpay for a new, less-cool model.
  • Law 7: The proprietary charging plug (cost to produce: 50 cents) for your device will disappear within two weeks and will cost you $40 to replace.
  • Law 8: On any vacation, a) the memory card for your digital camera will be safely lodged in the card reader on your desk at home. b) The camera's proprietary re-chargeable battery will be dead, with the charger sitting next to the card reader.
  • Law 9: A cup of coffee or fizzing drink on your desk, is guaranteed to render your laptop utterly useless.
  • Law 10: Your MagSafe adapter will always come unplugged precisely when you need to charge your Mac laptop's battery.
What are The Luddite Software Statutes?
Finally, if entanglements with hardware principles don't leave you bound and gagged, there are always software standards to render you helpless.
  • Law 1: Your software provider's online support pages contain explicit instructions for troubleshooting every conceivable problem, except yours.
  • Law 2: Nine times out of ten, tinkering with your Registry to fix a system issue will create a new and more severe problem. Did you back it up before you started? Unlikely!
  • Law 3: Ten times out of ten, downloading a spyware product will create hidden processes/services more insidious than the original malware/adware encroachment you set out to stop.
  • Law 4: The performance increase you can expect from running a Registry cleaner can be calculated as z(n + y), where n is the number of Registry entries cleaned, y is your system CPU's clock speed in gigahertz, and z = 0, or near to it.
  • Law 5: The larger the number of people who want your attractive iPhone app, the likelier Apple is to reject it.
  • Law 6: iTunes will crash. That's it. No, really.

Conficker Worm - Still Ice Cold at DefCon Conference

All talk of the Conficker Worm was sanitised at the Black Hat conference to protect the current investigation.

The criminal ring is very savvy and might have infiltrated the group hunting it down, one investigator says.


The international security team tracking down Conficker thought that the masterminds behind it would have been apprehended by now, according to one of the leaders of the effort to stamp out the resilient worm but that’s not the way it has worked out.

Investigators cautious
A meeting and presentation talk at Black Hat yesterday had to be scaled back because it contained information about Conficker that might tip the investigators’ hand and send the perpetrators further underground, says Mikko Hypponen, chief research officer at F-Secure and a member of the Conficker Working Group.

A Forensic Look
When Hypponen submitted the abstract for his Black Hat briefing more than six months ago, he thought he’d be presenting a forensic look at a dead worm and that the team who had written and managed it would be out of action. “I had hoped that by the end of July we would be in a totally different situation, the case would be closed and the group would be in jail,” Hypponen said in an interview after his talk.

Critical Information

His official line was that he was asked last week not to reveal critical information that might help prolong Conficker’s reign over millions of computers and inhibit the ongoing criminal investigation. “So I will end my presentation here,” Hypponen said at the conclusion of his Black Hat session. “Thank you very much. I will not be taking any questions.”

Holding Back
Hypponen said afterwards that he wasn’t forced to curtail his remarks (Black Hat has been the site of numerous speech-blockings and speech-blocking attempts, including that of a researcher Cisco sued because he was to reveal a flaw in the company's IOS code). Rather, Hypponen had already realised that it made sense to hold back some of what the working group has found out. “It’s better to keep them in the dark about what is known,” he says.

Agility and Precision
Given the agility and precision with which Conficker alters its tactics, Hypponen doesn’t rule out that the Conficker Working Group itself might have been infiltrated by Conficker operatives.
He wouldn’t say how close he thinks authorities are to bringing down the group, but did say there is an indication that it is based in the Ukraine. Some techniques used in Conficker match those used in an earlier worm, which might mean the same people were behind both.

Ukrainian Police
That earlier worm avoided propagating to machines in the Ukraine, which might mean that the group is based there and was trying to avoid committing a local crime to keep Ukrainian police off their backs, Hypponen says.

Technical Sophistication
During his talk Hypponen outlined some of Confickter’s technical sophistication. In one version change – the worm has gone through five major revisions – the worm adopted the MD-6 cryptographic hash algorithm. Investigators estimate that MD-6 was only a month or so old when it was incorporated in Conficker, making the worm one of the earliest implementations of MD-6, he says.

Buffer Overflow

The next major revision of Conficker patched an MD-6 buffer-overflow vulnerability that was publicly announced about six weeks earlier, which means the criminals keep themselves in the loop with the latest advances, he says. (The patch they used was identical to the one issued by MD-6 creators.)

Disables Infected Machines
The worm avoids sending itself to domains owned by members of the Conficker Working Group, and it disables infected machines so they can’t reach sites where they might seek help.

F-Secure Help Site
Hypponen’s company set up a help site with a different domain name from its regular business site that included the term F-secure, and the next version of Conficker blocked it. The company changed the term to Fsecure with no hyphen, and the next revision blocked that, too, he says.

The worm had been propagating to eight top level Internet domains and the working group mustered enough cooperation to shut it down in all those domains, Hypponen says. The next version propagated to 116 domains, he says.

Strategy Weak
“These guys are very good in cryptography and code development,” he says, but maybe not so good about strategy, given the attention they drew to themselves. “They didn’t know better than to infect 10 million computers in a couple of days.” The goal of any botnet ought to be to remain hidden, not draw attention to itself, he says.

“They might have experience in another crime business but hadn’t run a botnet before. If they were more experienced, they’d know better.”

The Malady Lingers on
It would make sense, Hypponen says, for the Conficker gang to abandon its current botnet and build a new one that doesn’t get too big too fast and doesn’t draw a team of experts to fight it. “Maybe they already have,” he says.

The Ups, Downs and Wonders of Living in a Parallel Universe

In recent months economists, and even economics as a discipline, have received an unprecedented amount of negative publicity. They have been attacked by governments, bankers, unions, industrial corporations, and the press.

They have even been attacked by their own peers from the world of academia, possibly to divert attention from them. Economists have been accused of ineptitude for not predicting the current crisis and its magnitude.


Forecasting
Some have, of course, suggested that the dismal science was never intended to help predict where the economy was going to go in the future and that in fact it was established to help manage economies in a more efficient manner but, of course, those who have spent anything more than a few seconds with anyone considering themselves to be an economist would have experienced that the first thing they would do to prove their knowledge would be to make a prediction about some economic variable.

Predictions
The problem is that given the magnitude of information necessary to make any kind of prediction about anything that needs aggregate economic data it is literally impossible to make guess-timates that are even remotely accurate.

The recent bad economic news in the U.K. and the U.S. was a perfect example of that. Not only had the economists missed the first stages of the crisis they also misread or misinterpreted how the economy was recovering but, of course, it never stopped any of them from predicting that we have turned the corner as soon as we had all got used to the fact that the economy is in a bad state.

The Property Market
The same seems to be happening in the property market. Economists at major U.K. building societies have started suggesting the many people were sitting on mountains of cash waiting for a sign that the economy has turned a corner before starting their buying spree. Hence, they suggest cautiously that there is a chance that house prices in the U.K. could end 2009 in the positive territory.

Waiting for a Sign
The problem is that even if it was true that these investors were simply waiting for a sign of economic recovery before they started buying why have they started buying now? After all, the latest signs are that the economy is doing much worse than expected. Consequently, if anything, they should have delayed their purchases even further.

Mass Re-possessions
It seems that since building societies need house prices to rise in order to avert the risk of mass repossessions their economists somehow arrive at more than positive data. If prices do rise they can also reduce the amount of capital they need to keep against bad debts and hopefully increase the amount of mortgages they issue.

Unfortunately, the reality is that most people find it very hard to get mortgages, especially since few can afford the 20% or 25% deposits that most lenders demand. Add to that the ever increasing numbers of unemployed and you can get an idea of just how far from reality these predictions are.

A Parallel Universe
Based on the recent experience with economists, and those working for building societies in specific, it seems that they somehow live in a parallel universe to the rest of the world. Looking at useless data seems to give either a false sense of doom or growth.

It somehow seems as if they never actually have human contact with those who buy homes or spend money shopping. It is a wonderful cocoon to live in, completely oblivious to the rest of the world or they are trying to maintain the charade.

Published Reports
The only problem is that their outlandish predictions are actually published by leading news agencies. If the press stopped giving such predictions the amount of attention that they are, I am sure that they would also not feel compelled to publish data that while newsworthy are in no way related to what is happening in the real economy.

Perhaps it is time that the press also learn to ignore such predictions, like the rest of us have done for years.

Sunday, August 2, 2009

China makes Internet Filtering Software Mandatory

China’s Ministry of Industry and Information Technology (MIIT) mandated that everyone must install filtering software known as Green Dam Youth Escort. More of a chaperone or minder than an escort. The Filtering Bully is content-control software.

The decree ensures that, depending on your interpretation, it is provided or installed on every computer sold in China. This applies to all global computer manufacturers and suppliers supplying China with equipment.

The wide spread use of Internet Censorship is an obvious indication of the Chinese government's determined efforts to suppress the
growth and freedom of the Chinese people and to prevent the free exchange of news and views with other peoples, countries and cultures.

'Net Users Outraged
The ensuing outrage by Chinese netizens has created a slight back peddling by MIIT on their determined stance and a slight softening of the tone of their mandate. The netizens see it as another barrier to censor and restrict their access to the global village, via the internet.

Government links to software
Whether or not the mandate or the program survives the outcry, is currently a heated subject of debate. However, it is not surprising that the companies involved in producing the software are known to have close government and military ties.

Site License
The government has already paid the equivalent of $6M for the software. This covers a site license for the entire country, a user base that is potentially 4 times the size of the US population.

US Computer Makers Reluctant
US computer manufacturers are dragging their feet on this emotive issue due to moral grounds thinly disguised as ' copyright concerns.'

Sony Capitulates
Japanese manufacturer Sony has reportedly already started to comply, for fear of sanctions against the company and a reduction in revenues from its largest and most aggressive neighbour.

Do Not Neglect Your Workforce: Your Future Depends on it

IT executives are constantly challenged to retain skilled IT employees and attract new talent whilst, keeping the budget square and the cost of labour in line with recession-related staff cuts.

In the midst of all this brinkmanship, juggling and balancing, they have to remember that neglecting the IT workforce will definitely damage the long term prospects of the company and themselves.

Do not cut your staff out of your IT budget:
It is clear that the majority of organisations do not plan to add staff in the coming months. Nearly two-thirds of those asked say that IT hiring has been put on hold until the 1st Quarter 2010, and the rest said they expect to increase head count modestly, in the same timeframe and only to replace shrinkage.


The problem is that despite the need to contain costs, the greatest priority in IT departments is the need to maintain and update skills, whilst at the same time adding enough staff to help support their companies' business. This is clearly more important in times of rapid growth and expansion but needs to be taken into account.

The Biggest Piece
Consider that the HR budget is the largest part of the IT budget, one of the primary challenges for executives and HR leaders, will be finding ways to better control those labour costs while engaging and retaining the workforce, effectively.

Morale
In addition, the current trend to restrict and reduce compensation and potential benefits coupled with additional workload will continue to stress and de-moralise the current IT workforce at many companies, and IT leaders need to be aware of retaining their key talent to ensure a potential for recovery from the current recession.


It will take time for the economy to stabalise and re-establish a new normal, the impact of this recession will continue to affect the organisation's bottom line, as well as on the overall job market. This will tempt companies to consider making further cuts in workforce-related spending.

Key Skills

Additional cuts, despite the budgetary need, could be false economy or at worst, a very big mistake. Certain IT skills remain in demand despite numerous IT professionals looking for work during the downturn. Key skills areas such as Oracle, SAP (All Flavours but particularly HR), Java EE, Microsoft .Net, SOA, Java and PeopleSoft (SAP-HR) continue to be sought after.


IT managers find it difficult to fill positions for enterprise architect, database administrator, project managers, ERP programmer/analysts, Internet/Web architects and Web application programmer positions. The issue isn't about the number of candidates available for hire, but rather their quality and skill profiles.It is ironic, because these are the very skills needed to implement the efficiency driven ERP system suites that are being put forward as essential to transform organisations in a crisis.

Dilemma

Here is the dilemma for IT executives. First you need to invest in powerful ERP Systems to transform, and re-shape an inefficient organisation but you don't have the skills on board to manage it, you do not have the skills to maintain it and your budget is so restricted that it does not allow for a quantum leap in demand for re-training. Even if you did re-train everyone, once they were trained they would be snapped up by other organisations!

IT Consultants

The good news is that the ERP System are being introduced and implemented by willing outsourced IT Consultancy group allied to the company, which is great in the beginning but unless your people can quickly gain the knowledge and skills required to manage the systems, then the consultants will be with you for a very long time ,at a huge cost to the organisation.


You have to ask yourself, "Where are the savings and benefits now?" and "What's my position and prospects for the future in all this?" Discuss!

Saturday, August 1, 2009

Avoiding Identity Theft: What to be aware of

Look out! Look out! There's a thief about! You would be amazed how little information a criminal needs to steal your identity.

Social Engineering is the real threat

Even a piece of direct mail that you've carelessly thrown away, can be enough for a fraudster to pose as you, borrow money or acquire sweets and goodies and then vanish. What do you get? Debts in your name and your credit status in tatters.

The information they use varies but the personal information that an ID thief is typically interested in is your full name, date of birth, current addres, account numbers and, if possible, passwords and PINs.

It sounds a lot but a little work can deliver a surprisingly large amount of data. The idea is to do a bit of cherry picking, and the internet and social networks are a big help.

Here are the ID fraudster's 10 most wanted items.

1. A bank statement
If they're really lucky, a statement might indicate your overdraft limit as well as your full name, address and account number. Shred, burn or rip em up, before binning them

2. A credit card statement
This won't contain your PIN, so they can't use the card account in a British retailer, but it could be enough information to enable the fraudster to purchase from foreign websites. Shred, burn, rip..

3. Access to your social networking pages
It may seem innocent enough, but many people innocently reveal enough information on Facebook, My Space or other social networking sites for a fraudster to guess their PIN and passwords. Don't make it too easy. Change them regularly.

4. Direct mail
Fraudsters are always on the lookout for direct mail containing an offer of a credit card or loan, with your details filled in that they can intercept. Once a crook has one fake account in your name, it's easier to open others. Shred, burn, rip...

5. Your driving licence or passport
These documents provide vital photographic ID that can be amended by an expert and used to prove that he or she is actually you. Secure them securely....they are worth 50,000 GBPs

6. Replies to phishing e-mail
Phishing e-mails are messages that appear to be sent from your bank or other trusted authority and are designed to capture your personal or financial information. Always remember that banks never ask for your PIN or internet banking details. Don't respond to scam stuff...

7. Your PINs and passwords
These are essential if a criminal wants access to any of your accounts or to use your payment cards. Guard them securely and change them regularly

8. A catalogue
Mail-order catalogues may appear innocuous enough, but if they're stamped with your name, address and account number, a thief could claim you've moved home and hijack your spending limit. Shred, burn, rip up anything with your name and address on it before binning

9. Your CV
Most CVs had a lot of personal information, such as your name, address, date of birth, employment history and marital status. Your CV contains so much information that could be used to impersonate you that some online job search services are advising people to be careful before uploading them to to their sites Be selective and question people who want your details.

I agree that it is difficult if you are looking for work and broadcasting lots of CVs in an uncontrolled manner. Keep a spreadsheet of who you have contacted (Company, Contact person, phone number) and when, also which CV version they have but 'be aware' that not all e-mails asking for CVs or CV updates are genuine.

Question them! and do some research on THEIR contact details and website credentials. We all know how easy it is to create a believable or viable website!

If in doubt, don't do it! or severely restrict the amount of personal information on the CV provided. Think of it like this; someone (an attractive stranger) has just stopped you in the street and asked for your contact details; name, address, phone number, e-mail address, etc. In return, you get a moment's 'hope'; hope of a job, hope of money, hope of a future. It is a very attractive offer!

Would you do it? Consider under what circumstances you would do it and why? Consider also how you could replicate those 'conditions' online, when responding to requests for personal details?

10. Online banking information
A prime target for credit-hungry fraudsters, who often set up fake websites to con genuine account holders into parting with their access data. Never click a link in an e-mail directing you to a supposed banking site - it could be a trap. Watch out for scam e-mails and don't click on anything from anyone you don't know

How thieves get your details

The snail mail post and mailing lists, is the most likely way that ID fraudsters would get hold of some of your personal details. The crooks' top choice of method is to forward your mail to a collection address. This was the cause of 36% of identity frauds during 2007. Check with the Post Office if your mail suddenly stops arriving

In second place, with 30% of cases, comes present address fraud, in which someone living at the same address - often flats with communal postal delivery areas - steals your mail. Previous address frauds, when the criminal uses your name and a previous address to take over your ID, account for 24 per cent of cases. Make sure your Postie knows you (I am Spartacus) and make sure your post box is secure - change the lock if you are suspicious or paranoid

Other popular cons to steal your personal details include:

  • Stealing your stuff /belongings
  • Tenancy fraud, where the tenant uses the landlord's details to borrow money
  • Jackal fraud, when the criminal uses personal details of a dead person
  • Card not present fraud, which occurs when someone has your credit or debit card details, but not the card, uses it on the internet or over the phone
Social Networking is the next best tactic for stealing people's identity and it is closely related to this article. The thief simply uses his /her personality to trick the target into divulging information about people, places or companies. Click Here for More Details