Sunday, August 9, 2009

US Marines Ban Facebook and Twitter: Use of Social Network Sites

The U.S. Marine Corps made it official this week: Social networking sites such as Facebook and Twitter are banned from military networks.

This new administrative directive doesn't change very much but clarifies the use of social networks from a security perspective.

Marines have never been allowed to access non-official sites like Facebook, MySpace or Twitter from military networks because it is classed as improper use of government property.

In this new or revised directive, the Marines have simply put an official stamp on the ban. At the same time, they are also laying out the process to be followed by any Marine who wants to officially access such a site, as part of his or her job.


A Haven and Conduit for Adversaries
"These Internet sites in general are a proven haven for malicious actors and content and are particularly high risk due to information exposure, user generated content and targeting by adversaries," the directive noted.

Increased Threat
"The very nature of social networking sites, creates a larger threat, attack and exploitation window, exposes unnecessary information to adversaries and provides an easy conduit for information leakage."

Improper use of US equipment
The ban, however, is only for people using Marines' equipment and networks while they are working. Marines may still Twitter or post to Facebook on their own time and on their own computers but they should do so with a raised level of awareness.

The military isn't against using sites like Facebook and Twitter, said 1st Lt. Craig Thomas, a Pentagon-based spokesman for the Marine Corps.

Facebook, YouTube and Twitter
The U.S. Central Command has a Facebook page, a channel on YouTube and a Twitter account to get out information regarding operations news. The Army is using MySpace to recruit new soldiers and the U.S. Forces Afghanistan page on Facebook has more than 24,000 fans.
A Balanced Approach
"The Marine Corps has got to find a balance between security and letting Marines capitalise on the technology," Thomas said in a recent interview. "We don't want information leaks. We want to keep Marines focused on their mission at work and we also wanted to save critical bandwidth. We're trying to find the fine line."
Measured Progress
Thomas noted that 30 years ago, soldiers were warned about revealing too much information in letters home. Then 10 years ago, they were warned about how they used e-mail. Today, the focus is on social networks.

Tight Lips
"You can't have someone posting, 'Hey, we're leaving on this date and at this time,'" he added. "Believe me, the enemy is checking out what you guys are reporting and what service men and women are saying online.

The Marine Corps instills tight operational security. They need to be cognizant of what they're saying, whether verbally or what they're saying on social networking sites."

Saturday, August 8, 2009

Child dies of Meningitis after Swine Flu wrongfully diagnosed by 16 year old responder

Girl's meningitis death probed after swine flu diagnosis
pa.press.net
Health bosses are investigating whether a two-year-old girl who died from suspected Meningitis was wrongly diagnosed with swine flu by medical responders, one of which was under age.

16 Year Old Responders
News of her death comes after it emerged at least one call centre for the Government's National Flu Pandemic Service for England was employing 16-year-olds, sparking concern about the inexperience of staff.

Remote or Off-Hand Diagnosis
The parents of Georgia Keeling from Norwich claim paramedics "diagnosed her before even looking at her" and gave Tamiflu before her condition worsened and she died in hospital.

The parents of Georgia, who died at the Norfolk and Norwich University Hospital on Tuesday, said they were twice told her symptoms sounded like swine flu before she was finally taken to hospital, in a state of emergency and in the last throws of Meningitis.

Didn't Fit the H1N1 Profile
Their local health centre first said, Georgia 'probably' had swine flu and advised them to call the swine flu helpline. They told them that Georgia had only one of the symptoms and suggested that they should call NHS Direct.

NHS Direct; Dangerously poor advice
NHS Direct then advised them to take the little girl to hospital only if her temperature rose above an astounding 40 degrees C, enough to cause hallucinations and fits in a young child. An hour later, Georgia's condition worsened and her distraught mother called an ambulance.

Paramedic Turned Ambulance away
A paramedic who arrived first said it sounded to him like Georgia had swine flu (H1N1). Having decided that it was a 'False Alarm', and nothing but another 'Hysterical Mother', he advised the ambulance despatchers not to send an ambulance.

Calpol and Tamiflu
Georgia's mother Tasha Keeling was given Calpol and Tamiflu and told to put Georgia to bed, the girl's father said.

An hour later, her near hysterical mother again called for an ambulance again, this tie it came but far too late. Georgia was taken to hospital where she died soon after.

Meningitis; Wrongly Diagnosed
A hospital spokesman said the suspected cause of death was meningitis. Sources said the investigation into the little girl's death would look into all aspects of her care - including the possibility that she may have been wrongly diagnosed as having swine flu.

A Tragedy of Errors
A horrendous story of incompetence and lack of support for the public. The NHS panic about Swine Flu has blinded them to the greater risk of more prevalent and more deadly diseases e.g. Meningitis, Clostridium difficile (C Diff), etc. C Diff kills more people every week in hospital than Swine Flu will ever do.


Friday, August 7, 2009

Cyber criminals can empty business accounts in minutes

Modern Methods to move and transfer Money, ensure that it moves fast and it can be equally fast going from your account with Automated Clearing House (ACH) fraud.

These criminals are not stupid. They knew what they were doing when they hit the US Western Beaver County School District and they knew when to strike.

They waited until school administrators were away on holiday, and then during a four-day period between Dec. 29 and Jan. 2, siphoned US$704,610.35 out of two of the school district's bank accounts. Western Beaver's financial institution, ESB Bank, managed to reverse some of the transfers, but the Pennsylvania school district was out more than $441,000.


On July 9, Western Beaver sued ESB to try and recover the money, but security experts say that it's just one of many organisations that have been hit in recent months by a disturbing new type of financial fraud that can often leave the victim holding the empty bag.

Fraudsters are taking advantage of the widely used but obscure Automated Clearing House (ACH) Network in order to pull off their attacks. This financial network is used by financial institutions to handle direct deposits, checks, bill payments and cash transfers between businesses and individuals.
In April, ACH fraudsters moved $1.2 million out of a Sugar Land, Texas, importer called Unique Industrial Products, according to a report in the Houston Chronicle. They did this by hacking into the company's computers and then authorising 39 transfers to move the money out of Unique Industrial's account. Although the bulk of the money was recovered, scammers made $150,000 from the attack -- not bad for 30 minutes of work.

Thursday, August 6, 2009

Facebook and Twitter both Hit by Targetted Denial of Service (DoS) Attack

On an otherwise normal and happy Thursday morning, Facebook and Twitter both became the most recent high profile sites to be the target of a denial of service attack (DoS).

A Georgian blogger with accounts on Twitter, Facebook, LiveJournal and Google's Blogger and YouTube was targeted in a denial of service attack that led to the site-wide outage at Twitter and problems at the other sites on Thursday, according to a Facebook executive.

The blogger, who uses the account name "Cyxymu", the name of a town in the Republic of Georgia, had accounts on all of the different sites that were attacked at the same time, Max Kelly, chief security officer at Facebook said.

Attacks such as this are malicious efforts orchestrated to disrupt and make unavailable services such as online banks, credit card payment gateways, and the usual online services provided to customers.

Twitter. 'We are defending against this attack now and will continue to update our status blog as we continue to defend and later investigate.'

Facebook:
"We have restored full access for most people," the company reported. "We’ll keep monitoring the situation to make sure you have the reliable experience you expect from us.

Chinese Teenager Killed At Internet Addict Boot Camp

An innocent 15-year-old boy has reportedly been beaten to death by Chinese 'Tutors' hours after arriving at a boot camp for internet addicts in China.

The teenager was declared dead after arriving at hospital in the nearby town of Wuxu. This incident happens only weeks after 'Electirc Shock' treatment is banned.


Deng Senshan was sent to the camp for a month to 'cure' him of his 'addiction'. Police are investigating the incident after Deng Senshan was found with multiple injuries over his body.


They have arrested four trainers from the camp, which attempts to 'cure' youngsters of their web 'addiction' by forcing them to replace hours in front of the computer with gruelling military-style drills.

The boy's father Deng Fei told how he paid 7,000 yuan (£600) to send his son to Guangxi Qihang Survival Training Camp for a month.

He said his son was put in solitary confinement within hours of his arrival and was then beaten to death by staff after they "scolded" him for running too slowly.

"My son was very healthy and was not a criminal. He just had an internet addiction when I left him at the camp," he said. "The police informed us that our child had died. We can't believe our only son was beaten to death."

Our methods are tough but do not include torture or other methods that might damage a child's health. - Guangxi Qihang Survival Training Camp's Mission Statement

Wednesday, August 5, 2009

Rejoice! Latvian ISP linked to online criminal activity booted out of Internet

IDG News Service — A Latvian ISP linked to online criminal activity has been cut off from the Internet, following complaints from Internet security researchers.

Real Host, based in Riga, Latvia was thought to control command-and-control servers for infected botnet PCs, and had been linked to phishing sites, Web sites that launched attack code at visitors and were also home to malicious "rogue" antivirus products, according to a researcher using the pseudonym Jart Armin, who works on the Hostexploit.com Web site.

"This is maybe one of the top European centers of crap," he said in an e-mail interview.

"It was a cesspool of criminal activity," said Paul Ferguson a researcher with Trend Micro.

The ISP was disconnected from the Internet by its upstream provider, Junik, on Monday, after its provider, TeliaSonera told it to stop servicing Real Host or face sanctions Armin said.

Real Host was considered a "bullet proof" hosting provider, that would allow customers to remain online even after they had been linked to malicious activity. It had been linked to the Zeus botnet-making software.

This isn't the first time this type of hosting provider has been knocked offline. In the past year, at least three U.S. ISPs: Atrivo, McColo and 3FN have been unplugged after security researchers built cases against them. Atrivo and McColo were also taken offline by their upstream providers. 3FN was shut down by the U.S. Federal Trade Commission.

But according to Armin, this may be the "first time an international group has achieved this across borders and in Eastern Europe."

In the past, these takedowns have had a serious affect on spam. And while some observers reported a noticeable drop in spam over the weekend, security experts say that this was probably not attributable to the Real Host takedown.

Observers expect to see the criminal activity linked to Real Host resume soon, but they say that the takedown puts some pressure on the bad guys and the networks that provide service to them. "The precedent that's being set right now is that you need to take some responsibility for your network," said Lawrence Baldwin, owner of security research firm Mynetwatchman.

"There actually are some consequences now for allowing an obviously heavy concentration of criminal activity on your networks. It's just not going to be accepted anymore."

Tuesday, August 4, 2009

Be Aware! Voice and Data Can Be Spied on

Attackers seeking to do harm or mischief to your networks work with an ever expanding arsenal of tools that sometimes seem to be the stuff of spy fiction, but they are all too real.

Here are 10 Spy style cloak-and-dagger ways, legal and illegal, to secretly tap into networks and computers to capture data and conversations.

1. Wireless keyboard eavesdropping: Remote-exploit.org has released an open source hardware design and accompanying software for a device that captures then decrypts signals from wireless keyboards. The device uses a wireless receiver that can be concealed in clothing or disguised as a common object that could be left on a desk near a PC to pick up signals.

Called Keykeriki, the technology targets 27MHz wireless keyboards to exploit insecurities that remote-expoit.org discovered earlier. The company plans to build and sell the hardware.

2. Wired keyboard eavesdropping: Electromagnetic pulses that keyboards make to signal what key is being hit travel through the grounding system of the keyboard and the computer itself as well as the ground for the electrical wiring in the building where the computer is plugged in.

Probes placed on the ground for the electric wiring can pick up these electromagnetic fluctuations, and they can be captured and translated into characters. The potential for this type of eavesdropping has been known for decades, and many experts believe spy agencies have refined techniques that make it practical. Andrea Barisani and Daniele Bianco, researchers for network security consultancy Inverse Path, are presenting their quick-and-dirty research on the topic at this year's Black Hat USA conference in the hopes of sparking more public research of these techniques.

3. Laptop eavesdropping via lasers: Bouncing lasers off laptops and capturing the vibrations made as keys are struck give attackers enough data to deduce what is being typed. Each key makes a unique set of vibrations different from any other. The space bar makes an even more unique set, Barisani and Bianco say.

Language analysis software can help determine which set of vibrations correspond to which key, and if the attacker knows the language being used, the message can be exposed, they say.

4. Commercial keyloggers: Early keyloggers were devices attached in-line with keyboards, but they advanced to software tools that grab keystrokes and store or send them to an attack server. Commercial versions have the software loaded on memory sticks that can dump the software on a computer and then be reinserted later to download the collected data.

5. Cell phones as remotely activated bugs: Software loaded onto certain models of cell phones can silence the ringers and cut off the light displays that would normally be triggered when calls are made to them. The caller can then listen in on conversations in the room where the phone is located.

According to press reports, the FBI received court permission to use this technique to spy on suspected Mafia members in New York.

6. Cell phone SIM card compromise: If attackers can get possession of a cell phone briefly, they can use commercially available software to download and read SIM cards and their store of phone numbers, call logs, SMS messages, photos and so on.

For instance PhoneFile Pro is software on a USB stick that claims to enable both the download and the display of the data.

7. Law enforcement wiretapping based on voice print: Phone company voice switches include software that can search all conversations going through it for voices that match sets of voiceprints. Whenever the switch makes a match, it can trigger a recording of the conversation and alert law enforcement officials, says James Atkinson, an expert in technical surveillance countermeasures.

The feature is designed to support communications assistance for law enforcement (CALEA) -- the law that requires phone companies to provide wiretapping access under court order to specific communications traffic.

8. Remote capture of computer data: Under a sketchy technique called Computer and Internet Protocol Address Verifier (CIPAV), the FBI has remotely tracked down data about individual computers.

Details of the technology have never been publicly revealed, but they were used to track down high-school students who sent e-mail bomb threats. CIPAV grabs IP and MAC addresses, running processes, visited Web sites, versions of operating systems, registered owner and logging of computers the target computers connect to. It is believed the software that does this is dropped in via exploiting instant messaging.

9. Cable TV as an exploitable network: Because most cable TV networks are essentially hubbed, any node can monitor any other node's traffic, says James Atkinson, an expert in technical surveillance countermeasures. By and large security is rudimentary and the encryption used could be hacked by someone with basic technical skills and readily available decryption tools, he says.

10. Cell phone monitoring: Commercially available software claims to capture cell phone conversations and texting. Attackers need to get physical access to the phone to upload the software that enables this.

There are several commercial brands on the market, but there are also online complaints that the software doesn't work as advertised or is more complicated to use than the vendors let on.