Showing posts with label Hackers. Show all posts
Showing posts with label Hackers. Show all posts

Tuesday, October 12, 2010

Tips and Tricks to help protect yourself from malicious hackers.

“Their intention is to infect your computer so that you don’t even know you’ve been infected.”
Hardly reassuring words for computer users or business owners. Cybercrime continues to flourish for one simple reason: it’s profitable.
Hackers use two broad approaches: Either they sneakily install malicious software on your computer to control it or steal your information, or they trick you into giving up your information voluntarily.
The malicious software can enter your system when you visit a shady website, or open an e-mail attachment carrying a virus. If it infects your machine, it might hand control of your computer over to networks that will rent it out to spammers, who will use it as a junk-mail-sending machine.
Or worse, it might install “key-logger” software that takes careful note of every word you type – usernames, passwords and all – and sends it back to hackers, who can co-opt your online accounts, take your money, and even represent themselves as you to your friends.
None of these things bode well for small businesses, which are often focused on the job at hand more than they are on information security. But there are new responses to these threats. In increasingly perilous seas, how do you stay on course without giving in to paranoia?
Here are some suggestions:
1. Don’t open unexpected attachments, even if they come from friends.
E-mail attachments are a great source of malware. But nowadays, they don’t just come from dodgy strangers, they can come from your best friends.
When certain malware infects computers, it will scan e-mail address books and send malicious messages to every contact, making it appear that the message comes from a friend. Oftentimes, they’ll contain messages such as “Here’s the PDF I said I’d send,” but they’re getting more clever and more subtle all the time.
If someone you know sends you an e-mail with attached files that you weren’t expecting, or that seem strangely generic (“Hey, check out these pictures!”), make contact with the sender first to make sure it’s genuine.
“If it sounds unbelievable, it totally is,” says David Mirza Ahmad, a cyber-security veteran and one of the founders of Subgraph, a Montreal-based security start-up. “Look for cues in the e-mail: Is the e-mail worded a little differently? Is it normal to receive random files from this person? If there’s a file, there should be context.”
In fact, any unexpected behaviour from friends on social networks should be taken with a grain of salt. Social networks are the latest frontier for hackers because they engender so much trust. If a Facebook friend starts posting items they wouldn’t normally post, be careful: their account might have been compromised, and the items might be a trap.
2. Update, update, update.
Even if you never opened another attachment in your life, you can still let viruses in, even by doing something as simple as visiting the wrong website at the wrong time.
The software that runs modern computers is enormous and labyrinthine, and hackers are always finding new holes that they can use to sneak malicious software onto computers – usually by injecting. And software makers such as Microsoft, Apple, and anti-virus makers, are constantly rushing to patch those holes. It’s a never-ending game of cat-and-mouse.
This is why it’s essential to keep your software up-to-date, and up to the minute. You need to update three things: First, your operating system (such as Windows or Mac OS), which receive updates to plug security holes as they’re found. By default, these will install automatic updates – it’s important to let them. Second, your web browser (Internet Explorer, Firefox, Chrome) needs to be up-to-date for the same reason. New versions are free to download. This goes expecially for users of Internet Explorer 6, an older version of the popular browser that was well-known as a security nightmare.
Finally, your virus-checking software needs constant updates to know which malware to look for today.
3. Be very careful about following login links from e-mails.
The next trick is to keep from getting tricked. Increasingly, scammers will try to convince you to give away your login and password for a phony web page that’s set up to look like a real one.
It’s called “phishing” – as in, going fishing for victims. You’ve probably already received some that use banks as bait: An e-mail arrives, prompting you to visit your bank’s website to “verify your login information.” It will direct you to a page that looks like your bank’s website, but it is really a false front that passes your login information on to hackers.
So far, these have been fairly easy to spot. But scammers are getting smarter: they’re now sending e-mails that look like new-friend or message-waiting notices from social networks such as Facebook or LinkedIn.
Always be cautious. Watch out for vague-seeming notifications. Pay careful attention to the URL at the top of the web page. If there’s any doubt, don’t follow the link from the e-mail, but visit the social network’s page directly and log in there.
4. Use different passwords.
Password safety isn’t the be-all and end-all of security, but it’s an important rudiment. You’ve probably been regularly warned not to use simple or easy-to-guess passwords. But it’s probably even more important (and, yes, more annoying) not to use the same password for every online service you use.
The reason is simple: If, by installing a key-logger, or tricking you with a phishing trick, a hacker gets the username and password for one site, you can bet he’ll turn around and try it on every other service you’re signed up with. You could wind up being locked out of everything at once.
If remembering a dozen different passwords is unwieldy (and it is), consider using at least two groups of passwords – one for not-so-important sites, and different ones for the really sensitive logins. Or, Mr. Mizra suggests using desktop software that uses one master password to access all the individual passwords - software such as the Mac OS Keychain or PasswordSafe for Windows.
5. Don’t think you’re smarter than the criminals.
So you know the ropes on the Internet. You know a malicious e-mail when you see one. Still, sometimes curiosity gets the best of you, and you click, thinking that you’re not going to divulge any personal information or download any suspicious files. Surprise: the bad guys have anticipated that, too.
“People believe that the operating system will protect them from everything they want to do; that by clicking on this link they’re smarter than the criminal,” Mr. Masiello says. “The criminals have got smart to this kind of thing.”
Tricks such as interstitial pages, pop-ups, and unpatched browser exploits can infect a computer before the user has clicked a single button or typed a word on a malicious web page.
And if you’re reading this on a Mac – don’t get too smug. For all of Apple’s marketing, Macs aren’t actually more secure, they’re just targeted less because fewer people own them. Malware comes for everyone, and – unfortunately - the only real solution is diligence.

Thursday, October 7, 2010

Secret-Spilling Sources at Risk Following Cryptome Breach

Secret-spilling site Cryptome was hacked over the weekend, possibly exposing the identities of whistleblowers and other confidential sources, according to a hacker who contacted Wired.com and claimed responsibility for the breach.
The hacker said two intruders from the group Kryogeniks breached the long-running site, where they gained access to a repository of secret files and correspondence. Among them, the hacker claimed, were the records of self-proclaimed WikiLeaks insiders who have been the source of several unconfirmed tips supposedly detailing internal WikiLeaks matters.
Wired.com could not confirm the identity of the hacker, who asked to be identified as “Ruxpin” or “Xyrix.” To verify his claims, the hacker showed Wired.com screenshots of Cryptome founder John Young’s Earthlink account inbox and Cryptome’s directory. The latter showed two WikiLeaks file paths. The hacker also provided a list of about 30 names and e-mail addresses of sources who communicated with Cryptome and the contents of at least one e-mail between Young and a Wired.com contributor from 2008. The Wired.com contributor and Young have authenticated the e-mail.
The hacker said they broke into Cryptome using a stolen e-mail password for the Earthlink account belonging to Young. They then used the e-mail account to reset the password for his site’s hosting account. The hacker claims they copied 6.8 terabytes of data from Cryptome, though “no files were deleted or altered.”
“Everything was copied for analysis,” one of the hackers wrote Wired.com in an e-mail interview. “Cryptome is an interesting read indeed.” He added that “only data that had relatively new time stamps is being given thought. There is simply too much to sift through.”
Young, reached by phone, confirmed some of the information provided by the hacker but disputed other assertions.
He didn’t know how the hackers got into his site or if data was deleted but said that “all the files were inaccessible,” and that Network Solutions had to restore content from a backup. He disputed the amount of data the hackers say they obtained.
“We had a little over 7 gigabytes, but not terabytes,” he said. “We’ve never had that much.”
Regarding the WikiLeaks insiders, although he acknowledged that some of them communicated with what appear to be e-mail addresses that could identify them, he doesn’t believe they’re actual WikiLeaks insiders and says he’s never done anything to verify their identities, and that the e-mail addresses could have easily been spoofed.
“I’ve not verified any of those and don’t know how one would,” he said. “I’ve been quite skeptical of anyone claiming to be a WikiLeaks insider.”
The hack of Cryptome would seem to illustrate the real value that a site like WikiLeaks offers. Cryptome, a proto-WikiLeaks, has published many important leaks since it was launched in 1996, exposing government secrets and gaffes.
The site, however, doesn’t provide the kind of secure, anonymized submission process that WikiLeaks boasts. Instead, it uses e-mail addresses controlled by Young, raising the risk that sensitive sources could be exposed by this and other hacks. Despite many controversies surrounding WikiLeaks and its founder, that site has never had a security breach, as far as anyone knows. But now Cryptome has.

The WikiLeaks Connection

According to the hacker, Cryptome’s WikiLeaks files contain ample communication between Young and about half-a-dozen supposed WikiLeaks insiders who, out of purported discontent with WikiLeaks founder Julian Assange and his management of the organization, have sent Cryptome unverified tips about supposed malfeasance and other activities inside WikiLeaks.
Young, who has long been suspicious of WikiLeaks’ motives, began publishing the tips this spring, despite expressing doubts publicly about their veracity. The tips prompted the ire of WikiLeaks, which referred to them as a “smear campaign” and has disputed that the sources are insiders.
Cryptome’s hacker claims that although some of the “insiders” initially communicated anonymously with Cryptome using a PGPBoard drop box, they later used personal e-mail addresses for ongoing correspondence, thus potentially exposing their identities to anyone with access to Cryptome’s files.
“Six [WikiLeaks insiders] are on familiar terms with John Young,” he told Wired.com. “Their real names are exposed in their signatures and in their messages. They are using familiar, personal accounts to communicate with Young.”
The hacker noted that “someone@wikileaks.org writes about problems with their leader and problems with money. He sends a PDF (was published to the site recently), some chat logs, and information about the encryption process for submits that he thinks is suspicious. This is from one of the regulars.”
He declined to identify the WikiLeaks correspondents or the e-mail addresses they used.
“Their privacy is to be respected, and they will not be exposed or compromised,” he wrote. “We believe in preserving the system of transparency that Cryptome and other websites represent.”
The hacker claimed that Young demanded proof from the insiders to verify their connection to WikiLeaks and that “he gets it with ease” from them.
“They are legitimate,” the hacker wrote. “Those who are not, appear to get trolled (John Young is absolutely hilarious) and moved to a different folder.”
Asked if the identities of other anonymous sources of Cryptome were also exposed, he replied, “Yes, all of them are. [Young’s] address books were compromised, and many of the messages were not sent from anonymous emails … there are over hundreds. Too many to easily quantify.”

How They Got In

The whois record for Cryptome, which is hosted by Network Solutions, listed the site contact address as jya@pipeline.com, one of Young’s accounts.
The hackers got the password for the e-mail account through Earthlink’s customer service center. Earthlink handles customer service for Pipeline accounts and uses a system, called MIDAS, that stores customer passwords unencrypted, in the clear, according to the hacker.
“Any Earthlink employee using MIDAS can do this without effort,” he wrote. “MIDAS is a legacy ssh application that many of the employees do not use, preferring a web interface called Spirtle instead.”
Earthlink did not return a call for comment.
The hacker said Earthlink’s system was breached about a month ago, at which time Cryptome’s login credentials were seized.
Armed with that password, according to a Network Solutions spokesman, the hackers then initiated a password reset for Cryptome’s hosting account using an online form. Network Solutions sent an automated e-mail to Young’s Pipeline account with a link to reset the password. The hackers, who had control of the e-mail account, then used the link to reset the Network Solutions Cryptome password twice — to passw0rd1 and then letmein1 — locking Young out of his account while they rummaged through Cryptome’s content.
The hackers said they decided to breach Cryptome primarily to harass a fellow hacker named Josh Holly, aka “TrainReq,” by posting a message identifying Holly as Cryptome’s hacker. Holly is best known for allegedly hacking into Miley Cyrus’s Gmail account and stealing provocative photos she purportedly sent of herself to singer Nick Jonas.
“Cryptome is a popular website,” the hacker wrote Wired.com. “Many people would have seen the joke (defacement), and the person (Trainreq) would have been subsequently bombarded with inquires about that to which he was clueless.”


The message included a shout-out to fellow Kryogeniks members EBK and Defiant — Christopher Allen Lewis and James Robert Black, Jr. — who were recently sentenced to 18 months and 4 months in prison respectively for a stunt in which they replaced Comcast’s homepage with a shout-out to fellow hackers.
The Cryptome hackers deleted the shout-out to Holly before many people saw it, however. “It did not have the intended effect,” the hacker wrote. “Josh Holly was sleeping and unavailable for trolling.”
They replaced it with another one identifying “Ruxpin” as Cryptome’s hacker. It’s not known if Ruxpin is one of the hackers behind the hack, since the hackers acknowledged they initially intended to point blame for the hack at someone else. It’s also not known if Ruxpin is the real handle for the hacker who communicated with Wired.com.
In addition to the shout-outs, the hackers left a note for Young: “Dear John. Rest assured that the integrity of the data hosted here has not been altered. We like Cryptome and needed your site because it was popular. Sorry. Godspeed.”
Young was not amused and says he’s determined to hunt down the intruders.
“One of the things I’m interested in is how much prowling they did beyond Cryptome,” he said. “Any rummaging in our e-mail is different than rummaging in Cryptome. We’re going to burn his or her ass with that.”

source
long post is loooong.
i'm sure we all remember xyrix. still attention whoring it seems.

Wednesday, October 6, 2010

Hackers Hijack Cryptome and Delete Everything

The longstanding whistleblower website Cryptome.org has been hacked during the weekend and all of the 54,000 files hosted on it have been deleted.

Cryptome publishes sensitive leaked documents and is ran by a long-time civil liberties activist named John Young, who co-founded the site in 1996.

The attack began during the early hours of October 2nd with the hacking of an Earthlink email address associated with the domain name.

The hackers then contacted the site's hosting provider, Network Solutions, from the compromised mailbox and requested information about the Cryptome's accounts.

There is no information to suggest that Network Solutions gave hackers control over the site's management panel, but they did somehow manage to get in.

They proceeded to delete all of the 54,000 files (around 7 GB) hosted in the account, changed the password and replaced the index page.

Theere were two separate versions of rogue home pages uploaded. One credited a hacker named "Trainreq" for the attack and the other one calling himself "RuxPin".

The pages reference "EBK" and "Defiant," two of the hackers convicted for hijacking the Comcast.net domain back in May 2008.

Kryogeniks, the group of defacers "EBK" and "Defiant" were members of, is also mentioned and so is Bradley Manning, the Army intelligence analyst suspected of leaking classified data to Wikileaks.

"A person wrote claiming to know who did the hack. No way to know if this claim is true. Hackers, like spies, often blame one another to cover their tracks.
"Blocking attacks is nearly impossible due to the purposefully weak security of the Internet. Nearly all security methods are bogus.

"A competent hacker or spy, or the two working together, can penetrate easily. We monitor and keep back-ups ready. And do not trust our ISP, email provider and officials to tell the truth or protect us," a statement from Cryptome reads.

This is the second successful Cryptome.org hack in fourteen years. The previous incident occurred in 2003 and also involved all files being deleted.

Back in February, the site was temporarily suspended by Network Solutions due to a DMCA notice from Microsoft regarding the company's "Global Criminal Compliance Handbook," which Cryptome published.

Then in March, PayPal suspended the account used by the site to receive donations from users, forcing John Young to refund $5,300.



source 

IMO i highly doubt it was trainreq who did this, and if they did they aren't true hackers. merely puppets being employed by somebody to do their dirty work. no hacker in their right mind would delete all the files off a whistleblower website unless their was incriminating evidence against them. They usually back up the files and either hold it for ransom or simply give it back after they have gained some notoriety.

prepare for the new generation of hackers, hacking against we the people. they will make sure our internets are policed and profit from it.