Category: I got hacked

  • Mitnick on Hiring Criminal Hackers; elam on hiring crackheads

    I basically look at it as… if the guy hacked into
    Citibank and stole millions of dollars, would I hire him to secure my
    bank? Maybe not!

    Kevin Mitnick

    I agree, Kevin. 

    Hiring a crimial hacker who has stolen millions from banks to guard
    your bank is like hiring a crack head to guard your CRACK.
    –Rob Elamb.


    Rufus Griffin.

  • My Honeypot server: Message from system to alert spam

    I plugged an unpatched Windows 2000 system on the Internet with no
    firewall, antivirus or even pop up blockers to sniff out the raw filth
    being pumped to the world. 

    What I was immediately spammed with was “Message from System to Alert messages” from various “security software” sites.   Here are the results:

    Message from System to Alert” Pop ups

    These messages claimed to be from Microsoft or from my system or from
    System32 saying my registry was corrupt and a bunch of other lies.

  • Surfing with an Admin account or How to Get Owned

    Martin McKeay over at mckeay.net is has good methods of securing his home network:

    I'm a strong believer in the 'rule of least privileges' as my wife and children well know; at least once a week I get called over to the kids computer to log in as administrator and install some program for them. The kids have gotten used to it, but my wife hasn't and she's forgotten that I gave her the adminstrator password.

    The reason it is a great idea to use the least priveleges possible and not go surfing the net with Admin priviledges is that if you (or anyone on your computer with admin priviledges) hit an exploit site that downloads something on your system, it will do so with your administrator permissions. 

    It is best to surf the web with an account that does not have permission to download anything from the web, with elevated security features on Internet Explorer (cookies and java scripts turned off).  In fact, just use and patched version of Firefox. 

    More Security on Internet Explorer

    You can increase security feature of IE by going to Tools | Internet Options | Security tab.  Adjust the trust you have for the Internet by adjusting the level on the slider in the “Security Level for this Zone Area.” 

    If you surf the web with an administrator account without a firewall not only will you more than likely get hit with a trojan and worms you will give the masters of these products elevated priviledges to your system as they will install code in the C:\Windows\System32 – also known as root. From root a criminal hacker can do practically anything they want with your computer (including install a keylogger that copies everything you type and send the data back to some IRC room on the Internet.)

    In layman's terms, they will OWN your ass.  

    If your really paranoid: 

    Customize your selected security levels by clicking the “Custom Level” button inthe “Security Level for this Zone Area.”  Disable Active X, and Java to completely destroy the ability of malicious mobile code to affect Internet Explorer (unless its already on your system).  This will impare your ability to expirience anything beyond text.

     

  • Hacked: Who Else Is Using Your Computer?

    A friend called me one day and asked if I would stop by to
    look at his computer. He said it was running abnormally slow
    and he had found something on his hard-drive he could not
    explain. I could almost guess what it was he found.
    Have I been hacked?

    You see, his computer had been hacked. Actually, in his
    case, his computer had been tagged. Similar to the image you
    see here.

    Tag, You're It!

    —————
    The file transfer protocol, commonly referred to as “FTP”,
    has been around for many years. In the early days of the
    Internet, it was one of the few ways to easily upload and
    download files from one computer to another. Many
    commercial operating systems come with an FTP server
    installed. In other cases, the option for FTP services is
    selected by a user when they are installing or updating
    their operating system. If this service is not setup
    properly, or you don't have an adequately configured
    software or hardware firewall, it is an open invitation for
    a hacker or intruder.

    FTP Tagging – The most common purpose for someone to
    compromise your FTP server is for the storage and
    distribution of illegally obtained software and files. This
    could include cracked software, stolen movies, audio files,
    and pornography. Removing this type of contraband from your
    computer can be difficult, particularly if you are using a
    Microsoft Windows platform. Hackers use sophisticated
    scripts to create a maze of directory structures to house
    their wares on your computer. They may use a combination of
    names with spaces in them, and in some cases use extended
    characters (characters outside the normal alpha-numeric
    range). Deleting these directories through normal means may
    be difficult, if not impossible, for the average user. Many
    people wind up wiping their system and re-installing it, and
    that is if they're lucky enough to find out their system has
    been compromised.

    The above is a perfect example of why the statement, “I'm
    not worried about being hacked. What do I have that a
    hacker would want?” is not a good position to take. The fact
    is, you do have something they want, your computers
    resources. Why should a hacker store tons of illegally
    obtained files on their systems when they can use yours.

    The Good, The Bad, And The Ugly

    ——————————-

    The Good

    ——–
    When I was young I use to spend hours upon hours on the
    Internet Relay Chat, also know as the IRC. The IRC is
    another method of Internet communication, which has been
    around for quite a long time. When I was a frequent user of
    the IRC, it was just plain fun. You would meet all kinds of
    people from all over the world. It was the instant messenger
    of the time.

    The Bad

    ——-
    Today, the IRC is a huge communications network. It is made
    up of thousands of channels, and can be accessed by pretty
    much any operating system platform. It is also a favorite
    means of communication for hackers. They can discuss new
    exploits, methods of compromise, and even send and receive
    files. Many hacker groups use a cryptic language to
    communicate with each other on the IRC channels. Unless you
    know the language constructs they use, their conversations
    can look like a bunch of nonsense.

    There are many exploits, backdoors, and Trojans that effect,
    or are contained in, the myriad of IRC clients on the
    Internet. Making sure you choose one that's relatively safe
    to use is not an easy task. As an example, take a look at
    this list of IRC safety and security info at
    irc.org.

    The Ugly

    ——–
    It's not just the exploits and security risks associated
    with using the IRC, which need to concern you. If a hacker
    is able to install an IRC relay agent on your computer, it
    can become a conduit through which they communicate and
    distribute information. In my line of work, I've identified
    many systems with IRC backdoors or relay agents installed.
    The only thing the end user typically experiences is a
    decrease in system performance and Internet access.

    Just Open The Door And Let Them In
    Peer-to-Peer File Sharing

    ———————————-
    If a total stranger were to knock on your door, and ask to
    come in to just hang out for awhile, would you let them in?;
    Most likely not. If you're using peer-to-peer file sharing
    software to locate and download files on the Internet,
    you're opening the door to destruction. Many of the file
    sharing services and software available on the Internet now
    tout themselves as being “safe” and “clean”. This is as far
    from the truth as you can get. If you're a regular user of
    these services, the chance of your computer being
    back-doored or hacked is significant.

    If you have anti-virus software installed (and up-to-date),
    you've undoubtedly received messages regarding viruses when
    downloading files from peer-to-peer services. These are not
    the only things you could be downloading. Many hackers imbed
    root-kits in files and distribute them using peer-to-peer
    file sharing. Root kits contain many types of tools used by
    hackers to gain control over computers. If the installation
    of the kit on your computer goes undetected and is
    successful, it's only a matter of time before your computer
    is completely compromised.

    I can't tell you how many times I've found company
    employees (and technical personnel) using peer-to-peer file
    sharing services. Any organization that permits this is
    putting itself at risk. And, the risk is much greater as
    compared to a single home computer because of the number of
    potential internal targets.

    Conclusion

    ———-
    Of course, the above is just a few examples of different
    methods and types of computer compromise. There are many
    ways your computer can be hacked. Your best defense is a
    good offense along with education and awareness.
    When you configure your computer make sure you enable only
    the software and services that you need. Many programs have
    known exploits and / or require additional steps be taken to
    adequately secure them.

    Don't make the assumption that you are not a target just
    because you don't think you have anything of interest on
    your computer.

    If our computer becomes unstable or dramatically decreases
    in performance, don't assume it's just a quirk or that it's
    time to upgrade.

    Make sure you have a software or hardware firewall in place
    to protect you from the Internet. Your firewall should be
    configured not to allow anonymous inbound access from the
    Internet. This is the default configuration for most
    firewalls, but you should make sure the one you are using is
    properly configured.

    Make sure you have adequate virus and spyware protection,
    and your pattern signatures are up-to-date. Many anti-virus
    applications work on a subscription basis. It's not uncommon
    to find out your subscription expired. If it is expired,
    your software may not protect you from new and emerging
    threats.

    And, do what ever you can to stay away from any type of
    Internet peer-to-peer file sharing service. No matter how
    safe the developer claims it is.

    About The Author

    —————-
    Darren Miller is an Information Security Consultant with
    over sixteen years experience. He has written many technology
    & security articles, some of which have been published in
    nationally circulated magazines & periodicals. Darren is a
    staff writer for http://www.defendingthenet.com and several other
    e-zines. If you would like to contact Darren you can e-mail
    him at Darren.Miller@ParaLogic.Net or
    DefendTheNet@ParaLogic.Net.

    If you would like to know
    more about computer security please visit us at our website. If someone you know has sent you
    this article, please take a moment to visit our site and
    register for the free newsletter at
    Newsletter Subscribe.

    Original URL

    ————
    http://www.defendingthenet.com/NewsLetters/HaveYouBeenHacked.htm

  • 40 Million credit card accounts practically given away.. not problem

    OLD NEWs:
    CardSystem lost 40 million credit cards and what is the result.

    Credit card companies don't have to notify customers their personal
    information has been stolen, a California Judge ruled today…

    …In June, CardSystems admitted intruders had compromised the
    confidentiality of 40 million credit card holders, and 200,000 records
    had left the network. CardSystems had refused to notify the card
    holders. The Rothken suit also requested that chargeback fees or
    penalties on hapless card holders who were the victims of ID theft
    should be waived.

    But a San Francisco Superior Court Judge, Richard Kramer, disagreed.
    “I don't see the emergency,” he said. “I don't think there is an
    immediate threat of irreparable injury” to consumers… [*]

    This company did not encrypt the credit card data! A gross violation of the Payment Card Industry Security Standard.

    My comment and Voice of the evil doers:

    It is amazing the kind of protection companies have.   
    From the begining that was the purpose of a corporate entity
    “indemnity.”  This allows the part owners ,shareholders, Legal
    protection from loss.  

    40 million credit cards is a lot of loss.  

    I think is half-haves should all form our own companies so we can have
    that kind of protection from loss, including the loss of our
    identities.  If fact, on paper we should not exist, but instead be
    employee Identification numbers subject to our own companies, owning
    nothing but controling every thing!  

    Nothing new about that idea.. this is one of the tactics of the wealthy.

  • Dvorak's Blog Spam Fix

    Dvorak gets no spam, now he gets no blog spam. 

    But my spam problems have just begun:
    I started getting nailed with casino, porn and commercial site spam.  They trackback promoting Disney Trips, penis enlargements or, my favorite, Texas Holdem.  I still get a few spam links about every few weeks or so.  And I'm currently getting and giving traffic to a casino site.. and I haven't figured out how that is happening.  I'm sure these bastards are usings some kind of software to locate vulnerable (anonymous accepting) blogs and nuke them.  I've had to terminate my anonymous comments and I'm thinking of shutting down my Trackbacks.  I also blocked a few repeat offenders.  For me, that is unfortunate because the interaction (free comments, links to and from relevant sites of many different oppinions) is the coolest thing about blogs.  Blog innocence has come and gone over night.

    Appearently, Marc Perkel at ctyme.com has found a way to get rid of all spam providing you are using apache and on word press.

    He does it with this code:

    < location /blog/wp-comments-newpost.php >
    RewriteEngine On
    RewriteCond %{HTTP_REFERER} !^.*dvorak.org/.*
    RewriteRule ^.* http://www.ctyme.com/comment-spam.html
    < /location >

    read more | digg story

  • Beer Can Padlock Shim aka "Masterlock Master Key"

    How to build a better padlock shim using a very special hacker tool… A beer can.

    This was picked from Deviant Ollam at Defcon 13.  This is yet
    another reason I love Defcon.   I've heard the arguement that
    we [security professionals] should NOT “promote” hacking or do anything to suggest that it is cool.

    But I think that is a pretty stupid thing to say… because hacking IS
    cool.  Its not always bad and definitely not always good.  As
    far as going to events like Defcon… The IT and Security Industry are
    so slow and firewalled with corporate BS that they will actually hide
    things the consumners need to know.  Just look at CiscoGate
    Or, do like a typical government, know that there is a problems but be
    so filled with overhead and beauracracy that they can not do any thing
    about it even if they cared enough to.

    You don't have that kind of big brother crap at the Defcon.  If
    its broke you fix it and if it is fixed you break it to see if its
    possible. 

    If
    the locks on the doors into your house are no good don't you want to
    know about it ASAP?

    Ollams Site:
    http://deviating.net/

    read more | digg story

  • First potential virus risk for Windows Vista found

    “Virus writers are targeting a new Microsoft tool that will be part
    of Windows and is set to ship as part of the next Exchange e-mail
    server release.” – C|Net

    F-Secure has already found a possible flaw in the Windows Vista
    (code named Longhorn) command Shell called Monad also know as MSH.

    Representatives of F-Secure stated that if Microsoft released Windows
    Vista with MSH enabled, it could cause and outbreak of scripting
    viruses.  Examples of Scripting viruses include Macrovirues, the
    ILOVEYou VB scripting virus and the Melissa virus.

    The exploit aiming at MSH is discussed here.

    Microsoft my chose to disable MSH by default or simply add it as a plugin. 

  • Home made Homemonkey: HoneySpider

    In my quest to find more viruses, trojans, and worms (which I find fastinating)  I started building my own HoneyMonkey server which I call a “HoneySpider.”

    What the hell is a HoneyMonkey?

    You've heard of HoneyPots, right?  A server that is set up to trick and track potential malicious hackers who think they have found the goods but have in fact been seduced by a decoy.  Brilliant defense however it is very passive as you must wait for the bastard hackers to come to your decoy system.  The HoneyMonkey is active in that it actively locates sites, pages and weblinks that seek to exploit systems.  The Microsoft's Strider HoneyMonkey Exploit Detection system is great evolutionary step for a proactive method of Internet security (something I've been waiting for a while).  It actually crawls the web to locate these evil boxes and maps out there location on the Web.

    I thought the concept seems pretty self explanatory:  set up a server that crawls the web specifically looking for offending sites.  This can be down with and old box you happen to have laying around and a web crawler like Zeus.

     

    I'm still working on it.  I'll keep you posted.

     

  • Why Corporations Need to Worry About Phishing

    Phishing is a relatively new form of online fraud that focuses on fooling the victim into providing sensitive financial or personal information to a bogus website that bears a significant resemblance to a tried and true online brand. Typically, the victim provides information into a form on the imposter site, which then relays the information to the fraudster.

    To view examples of phishing emails go to:

    * Citibank: www.ciphertrust.com/images/example_citibank.gif
    * US Bank: www.ciphertrust.com/images/example_usbank.gif

    Although this form of fraud is relatively new, its prevalence is exploding. From November 2003 to May 2004, Phishing attacks increased by 4000%. Compounding the issue of increasing volume, response rates for phishing attacks are disturbingly high, sometimes as high as 5%, and are most effective against new internet users who are less sophisticated about spotting potential fraud in their inbox.

    Corporations should be concerned with the following four issues:

    * Protecting employees from fraud
    * Reassuring and educating customers
    * Protecting their brand
    * Preventing network intrusions and dissemination of trade secrets

    A failure to succeed in any of these areas could be catastrophic to a company’s ability to function in the marketplace. If employees are not protected, the company could be held accountable for not putting protections in place to prevent fraud. If a hacker impersonates a company, then the company’s reputation and brand may be tarnished or ruined because customers feel that they can no longer trust the organization with their sensitive information. And finally, the latest trend in phishing has been to socially engineer employees or business partners to divulge sensitive trade secrets to hackers. The implications of employee login information getting into the wrong hands could result in grave consequences once hackers are able to “log in” to an employee’s network account using VPN or PC Anywhere software.

    Protecting Employees from Phishing

    One of the best ways to protect employees from Phishing is to prevent spam from ever getting to the user’s inbox. Since most phishing attacks proliferate through unsolicited e-mail, spam filtering technologies can be very effective at preventing the majority of phishing attempts.

    New technologies are also available to help prevent phishing. One such technology offered as a standard by Microsoft and supported by CipherTrust is the Sender ID Framework (SIDF), which prevents spammers from obfuscating their IP address by verifying the source of each email.

    Of course, spam filtering and SIDF cannot solve the problem entirely. Many phishing attacks are actually sent on an individual basis to users not protected by cutting edge spam detection technologies. Other attacks are distributed through online email accounts such as Yahoo! Mail, Gmail, MSN, and others. In short, technology alone cannot solve the phishing problem. Employees must be educated about phishing and how to spot fraudulent emails and websites.

    Reassuring and Educating Customers

    Once a consumer receives a fraudulent email that appears to come from a trusted company, he or she may never trust that company’s email communications again. That is damage that is not easily undone. It is essential that organizations communicate openly and frequently about how customers can identify legitimate email communications, and the need to report fraudulent ones. For those organizations that frequently process consumer credit card transactions, it is recommended that a special section of the site be devoted to helping customers avoid fraud.

    Companies that make efforts to educate their customers about phishing are much less attractive targets than those who make no efforts at all. Some examples of organizations that have developed extensive policies around this issue are:

    * USBank
    * Wells Fargo Bank
    * Ebay and PayPal
    * Citibank

    Protecting the Company Brand

    Each time a phishing attack is launched, a legitimate company’s trademark is tarnished and brand equity is eroded. The more attacks a company suffers, the less consumers feel they can trust the company’s legitimate email communications or websites. The value of this trust is difficult to quantify – at least until a company begins to lose customers. When customers no longer trust the company’s ability to protect their personal information, they often defect to competitors or opt to use more expensive commercial options such as telesales or retail locations.

    Clearly, the goal is to convince the fraudsters that your customers will not fall for the scam. This is why having an obvious anti-phishing program that is public for all to see can be very effective. The fraudsters tend to follow the path of least resistance. Seeing that customers are well informed of how to avoid phishing attacks, the perpetrators simply turn their attention to other “softer” targets.

    Preventing Network Intrusions and Dissemination of Trade Secrets Employees must be educated not only about phishing generally, but also about how fraudsters might use social engineering and other methods to entice employees to divulge sensitive information to hackers outside the organization.

    With little knowledge of an organization’s business methods, hackers can easily distribute hundreds or even thousands of spoofed messages to an organization’s employees. The messages may ask for network passwords and usernames, or may attempt to fool employees into providing sensitive information to competitors.

    It is important to properly train employees about what information is appropriate to share through email, and specifically what steps employees should take if they are unsure about the authenticity of a request for information.

    Information gleaned by fraudsters from corporate networks can be used in a variety of nefarious ways. In the financial services industry, criminals can use credit cards to deduct money straight from accounts of unsuspecting victims. Many other organizations hold private healthcare information, or personal financial information that could be used by criminals to extort payoffs from corporations wishing to avoid the bad publicity of a security breach becoming public knowledge.

    Though deflecting this attack does involve a significant amount of education, providing content filtering on outbound e-mail traffic can flag suspicious communications. Looking for these regular expressions, like social security numbers and account numbers, can prevent a simple deception from becoming a major liability issue.

    What to Do If You Are the Victim of a Phishing Scam If you become aware of fraudsters imitating your organization to commit phishing fraud, you should:

    * Immediately educate your customers on how they can correctly identify the phish

    * Notify the authorities of your situation. Phishing Fraudsters may have violated all or some of the following Federal Laws:

    — 18 U.S.C. 1028(a)(7) – Identity Theft
    — 18 U.S.C. 1343 – Wire Fraud
    — 18 U.S.C. 1029 – Credit-card Fraud
    — 18 U.S.C. 1344 – Bank Fraud
    — 18 U.S.C. 1030 (a)(4) – Computer Fraud
    — 18 U.S.C. 1037 – CAN-SPAM Act
    — 18 U.S.C. 1028(a)(5) – Damage to computer systems and files

    * Prosecute the criminals – when Spammers use your trademarks to commit fraud, they are violating U.S. Trademark laws as well as anti-fraud laws. Your organization has the right to defend its mark in court.

    If you find that you are personally the victim of a phishing scam, then you should identify what information was compromised and then:

    * If the fraudster obtained your Bank Account, Credit, ATM or Debit Card information:

    — Report the theft to your card issuer, and cancel the account

    — Check your statements for any unauthorized charges and follow up with your financial institution regarding their procedures for minimizing your liability to the charges

    * If the fraudster has obtained your personal identification information — Contact the credit reporting agencies:

    * Experian

    * Equifax

    * Trans Union — Request that a fraud alert be placed on your record

    — Request a copy of your credit report and follow up on any unauthorized credit inquiries

    — Request that unauthorized credit inquiries be erased from your record

    — Notify your bank of potential fraud

    — File a police report with your local police department

    — File a report with the Social Security Administration

    — Notify the Department of Motor Vehicles and determine if an unauthorized driver’s license number has been issued in your name

    — Notify the Federal Trade Commission (www.ftc.gov)

    — File a complaint with the Internet Fraud Complaint Center (www.ifccfbi.gov/index.asp). Additional Internet Fraud Sites:

    * www.cybercrime.gov

    * www.consumer.gov/idtheft/

    * www.identity-theft-help.us/

    * www.identitytheft.org/

    * www.usdoj.gov/criminal/fraud/idtheft.html

    * www.usdoj.gov/criminal/fraud/idquiz.html

    * www.ifccfbi.gov/index.asp

    Dr. Paul Judge is a noted scholar and entrepreneur. He is Chief Technology Officer at CipherTrust, the industry's largest provider of enterprise email security. The company’s flagship product, IronMail provides a best of breed defense against phishing attacks and other email-based threats. Learn more by visiting http://www.ciphertrust.com today.