<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CounterMeasures -  A Security Blog » cybercrime</title>
	<atom:link href="http://countermeasures.trendmicro.eu/tag/cybercrime/feed/" rel="self" type="application/rss+xml" />
	<link>http://countermeasures.trendmicro.eu</link>
	<description>Trend Microâ€™s Rik Ferguson blogs about current security issues.</description>
	<lastBuildDate>Wed, 01 Feb 2012 14:48:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>The best form of defence?</title>
		<link>http://countermeasures.trendmicro.eu/the-best-form-of-defence/</link>
		<comments>http://countermeasures.trendmicro.eu/the-best-form-of-defence/#comments</comments>
		<pubDate>Tue, 03 Jan 2012 16:19:41 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[countermeasures]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Opinion]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[compromise]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[Denial of Service]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[malicious code]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=3223</guid>
		<description><![CDATA[&#160; A report in the Daily Yomiuri suggests that the Japanese government have commissioned Fujitsu Ltd to create a &#8220;defensive virus&#8221; and that after 3 years of work and a budget of $2.3 million, the project is nearing completion. &#160; Technical details in the article are necessarilyÂ thin on the ground but it appears that the [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/the-best-form-of-defence/' addthis:title='The best form of defence? '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p><div id="attachment_3225" class="wp-caption alignleft" style="width: 510px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2012/01/782926958_d73f5c1300.jpg"><img src="http://countermeasures.trendmicro.eu/wp-content/uploads/2012/01/782926958_d73f5c1300.jpg" alt="" title="Mutation by woodleywonderworks" width="500" height="333" class="size-full wp-image-3225" /></a><p class="wp-caption-text">Mutation by woodleywonderworks</p></div><br />
&nbsp;<br />
A <a href="http://www.yomiuri.co.jp/dy/national/T120102002799.htm" title="Govt working on defensive cyberweapon / Virus can trace, disable sources of cyber-attacks" target="_blank">report in the Daily Yomiuri</a> suggests that the Japanese government have commissioned Fujitsu Ltd to create a &#8220;defensive virus&#8221; and that after 3 years of work and a budget of $2.3 million, the project is nearing completion.<br />
&nbsp;<br />
Technical details in the article are necessarilyÂ thin on the ground but it appears that the &#8220;cyberweapon&#8221; is designed to &#8220;springboard&#8221; from oneÂ compromised computer to another, tracing back to the original source of the attack and shutting down malicious processes en route.<br />
&nbsp;<br />
Whilst I can see the attractiveness of the principle and have some sympathy for the thinly veiled claims in the article that &#8220;everyone else is doing it&#8221;, the concept of the &#8220;good&#8221; computer virus has been the subject of debate for many years and it has never gained widespread support.<br />
&nbsp;<br />
Even a &#8220;good&#8221; virus or worm must execute on a machine without the permission of the owner of that machine. If that &#8220;good&#8221; virus has the objective of terminating malicious processes and/or patching security holes then, by definition it must modify or delete critical processes, memory content or files. If its design is to spread autonomouslyÂ  then system owners will have no opportunity to test whether its supposedly altruistic activities will have any negative impact on a running system. It will also consume bandwidth, disk space, memory and processor cycles, allÂ adding to the load, just as a malicious worm does effectively creating a Denial of Service condition.<br />
&nbsp;<br />
The &#8220;good&#8221; virus may also be hindered by effective security software, many of the actions it will be carrying out, such as modifying systemÂ components and terminating process,Â will be precisely those which are designed to be recognised andÂ stopped by security programs.<br />
&nbsp;<br />
Finally it really wouldn&#8217;t take much effort for criminal groups to take these white-hat tools and modify them for more malicious use, blurring the line even more between the &#8220;good&#8221; and the bad and putting professional grade carrier mechanisms in the hands of criminals.<br />
&nbsp;<br />
The Japanese government seem less than coordinated right now on the actual use such a technology would be put to, the article reports them as saying that they are &#8220;<em>not considering outside applications for the program as it was developed for more defensive uses, such as identifying which terminal within the Self-Defense Forces was initially targeted in a cyber-attack</em>&#8220;. This is hardly surprising, as the creation of malware is currently a violation of Japan&#8217;s criminal code.<br />
&nbsp;<br />
You have to wonder though, even in that limited scenario, wouldn&#8217;t such an automated &#8220;sprinkler system&#8221; pose a huge risk of destroying valuable forensic evidence in the case of a breach? Wouldn&#8217;t effective real-time monitoring of computers and networks, reporting to a centralised SIEM console provide as much intelligence in a less inherently risky way?<br />
&nbsp;<br />
<strong>Post Script:</strong><br />
&nbsp;<br />
In 2004Â Cyrus PeikariÂ  made a seemingly good case for <a title="Fighting Fire with Fire: Designing a &quot;Good&quot; Computer Virus" href="http://www.informit.com/articles/printerfriendly.aspx?p=337309" target="_blank">Fighting Fire with Fire</a>, but I feel that the medical analogy breaks down completely under close examination.Â In the digital case we are talking about releasing a self-replicating virus into the wild, whereas in the medical case we talk about manual and controlled introduction of an attenuated virus on an individual (and voluntary) basis.</p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/the-best-form-of-defence/' addthis:title='The best form of defence? '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/the-best-form-of-defence/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>&#8217;tis the season to be squatting</title>
		<link>http://countermeasures.trendmicro.eu/tis-the-season-to-be-squatting/</link>
		<comments>http://countermeasures.trendmicro.eu/tis-the-season-to-be-squatting/#comments</comments>
		<pubDate>Wed, 14 Dec 2011 16:06:36 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[data protection]]></category>
		<category><![CDATA[Family Safety]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[christmas]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[online shopping]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=3206</guid>
		<description><![CDATA[In the run up to Christmas criminals are abusing the opportunity to prey on online shoppers with tired eyes and weary fingers. Many thousands of misspelled versions of popular retail destinations have been registered by criminals in the hope that the unwary consumer will land there by accident. Customers of popular online retailers such as [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/tis-the-season-to-be-squatting/' addthis:title='&#8217;tis the season to be squatting '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p>In the run up to Christmas criminals are abusing the opportunity to prey on online shoppers with tired eyes and weary fingers. Many thousands of misspelled versions of popular retail destinations have been registered by criminals in the hope that the unwary consumer will land there by accident. Customers of popular online retailers such as John Lewis, Debenhams and Argos have all been targeted.<br />
&nbsp;<br />
<div id="attachment_2047" class="wp-caption alignleft" style="width: 386px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/06/whackamole.jpg"><img src="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/06/whackamole.jpg" alt="" title="Animal Kingdom" width="376" height="500" class="size-full wp-image-2047" /></a><p class="wp-caption-text">Image from Joe Shlabotnik&#039;s Flickr stream under creative commons</p></div><br />
&nbsp;<br />
The criminal websites are often copies of the legitimate website, copies that aim to pass off counterfeit goods, redirect the visitor through money-spinning advertising links or to harvest personal and financial information if a â€śpurchaseâ€ť is made. In other instances the misspelled domain names can lead to objectionable content or even to websites loaded with exploits that aim to infect the victim machine with information stealing malware or to recruit it into a botnet, a network of compromised machines under the remote control of a criminal.<br />
&nbsp;<br />
Typosquatting has been around almost as long as the world-wide web, in fact US legislation dating back to 1999, the <a href="http://en.wikipedia.org/wiki/Anticybersquatting_Consumer_Protection_Act">Anticybersquatting Consumer Protection Act</a>, contains a specific clause (Section 3a) aimed at combatting this phenomenon. In the past individual companies have been known to spend large amounts of money in bringing cybersquatters to justice. Lego, for example, have previously spent more than half a million US dollars pursuing cybersquatters through the <a href="http://www.icann.org/en/udrp/udrp.htm">Uniform Domain-Name Dispute-Resolution Policy (UDRP)</a> going after such domain names as <em>legoworskhop.com</em> in and effort to protect their brand.</span><br />
&nbsp;<br />
However in this most recent outbreak of typosquatting, we are not talking about domain names which simply include the names of well-known brands, rather those that prey on our lack of attention to detail. In the rush to get the online Christmas shopping done, how sure can you really be that you were shopping at the legitimate debenhams.com rather than the typosquatted debanhams.com, or marksandspencer.com rather than marsandspencer.com or markandspencer.com (I would recommend <strong>*not*</strong> visiting these by the way.<br />
&nbsp;<br />
<a href="http://www.theregister.co.uk/2011/11/21/uk_cybercops_fraud_site_takedown/">This year</a> and <a href="http://countermeasures.trendmicro.eu/british-police-remove-drop-from-ocean/">last</a>, British law enforcement have been doing their best to crack down on dodgy online shopfronts, however efforts to suspend illegitimate domain names can only ever represent a game of whac-a-mole in the fight against evil online traders. Criminals can register vast reserves of domain names in advance and, when one gets shut down,Â  simply activate another as required.<br />
&nbsp;<br />
And that is the real issue, far too many DNS domains, including .co.uk and those of many other countries, are operated as â€śopenâ€ť domains and <a href="http://www.nominet.org.uk/registrants/aboutdomainnames/rules/">in the words of Nominet</a><br />
&nbsp;<br />
&#8220;<em>We do not impose restrictions on your status as applicant for the registration of a Domain Name in the following SLDs (&#8220;Open SLDs&#8221;):</em><br />
&nbsp;<br />
<em>Â 1. 4.4.1 .co.uk; or</em><br />
&nbsp;<br />
<em>2. 4.4.2 .org.uk.</em><br />
&nbsp;<br />
<em>In the SLD Charter of the SLD Rules for the Open SLDs we do set out certain intentions regarding the class of applicant or use of registrations of the Domain Name which we assume you will comply with when applying for a registration of a Domain Name within an Open SLD. <strong>However, we do not forbid applications, and will take no action in respect of registrations that do not comply with the SLD Charters</strong></em>&#8221;<br />
&nbsp;<br />
Until regulation is tightened and international cooperation is improved then well-intentioned law-enforcement initiatives will only be treating the symptom not addressing the cause.<br />
&nbsp;<br />
In the meantime, be careful where you click and if you are planning on some serious online shopping sessions you may be wise to create yourself some bookmarks to popular online shopping sites rather than relying on your typing skills standing up to the Christmas rush.<br />
&nbsp;<br />
On that note here are <a href="http://uk.trendmicro.com/uk/about/infographics/safety-tips-for-online-shopping/">5 great tips for shopping safely online</a> from Trend Labs.<br />
&nbsp;</p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/tis-the-season-to-be-squatting/' addthis:title='&#8217;tis the season to be squatting '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/tis-the-season-to-be-squatting/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Conficker, Duqu, Stuxnet, Aliens, Confuxnet!</title>
		<link>http://countermeasures.trendmicro.eu/conficker-duqu-stuxnet-aliens-confuxnet/</link>
		<comments>http://countermeasures.trendmicro.eu/conficker-duqu-stuxnet-aliens-confuxnet/#comments</comments>
		<pubDate>Fri, 02 Dec 2011 14:37:21 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[malware]]></category>
		<category><![CDATA[Opinion]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[compromise]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[hacktivism]]></category>
		<category><![CDATA[malicious code]]></category>
		<category><![CDATA[Rogue AV]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[worm_downad]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=3186</guid>
		<description><![CDATA[I have just read a Reuters news story where respected &#8220;cyber warfare expert&#8221; John Bumgarner is reported to claim that Conficker was devised and released to act as a global smokescreen for the surgical attack, using Stuxnet on nuclear facilities in Iran. &#160; Bumgarner claims that initial reconnaissance work was carried out using Duqu in [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/conficker-duqu-stuxnet-aliens-confuxnet/' addthis:title='Conficker, Duqu, Stuxnet, Aliens, Confuxnet! '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p>I have just read a <a title="Insight: Did Conficker help sabotage Iran's nuke program?" href="http://ca.reuters.com/article/topNews/idCATRE7B10AP20111202?pageNumber=1&amp;virtualBrandChannel=0&amp;sp=true" target="_blank">Reuters news story</a> where respected &#8220;cyber warfare expert&#8221; John Bumgarner is reported to claim that Conficker was devised and released to act as a global smokescreen for the surgical attack, using Stuxnet on nuclear facilities in Iran.<br />
&nbsp;<br />
Bumgarner claims that initial reconnaissance work was carried out using Duqu in 2007 to identify targets relevant to a later attack by Stuxnet. In November 2008 Conficker was released globally to infect as many machines as possible. When a Conficker infection phoned home, if the victim machine was found to be in a apposite location (Iran) it was flagged as a later target for Stuxnet. He further states that Conficker did no damage to machines outside Iran and that on the infamous April 1st &#8220;activation date&#8221; (of the third variant from March 2009) it was used to pull down Stuxnet to those machines located in interesting locations in Iran.<br />
&nbsp;<br />
Here is the evidence, all of it unsubstantiated as far as I can ascertain, that Bumgarner presents to support his claim:<br />
&nbsp;<br />
1- Both Stuxnet and Conficker show evidence of &#8220;<em>unprecedented sophistication</em>&#8221; leading him to believe that they are related.<br />
&nbsp;<br />
2- Both Stuxnet and Conficker use the same vulnerability to infect machines (<a href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx">MS08-67</a>)<br />
&nbsp;<br />
3 &#8211; Unspecified &#8220;<em>key dates</em>&#8221; in timestamps of unspecified &#8220;<em>different versions</em>&#8221; of Conficker and Stuxnet overlap and also &#8220;<em>helped him to identify April 1 2009 as the launch date for the attack</em>&#8220;.<br />
&nbsp;<br />
4 &#8211; April 1st 2009 was the 30th anniversary of the declaration of an Islamic Republic in Iran. Other unspecified dates also corresponded with days when &#8220;<em>Iranian President Mahmoud Ahmadinejad said his nation would pursue its nuclear program despite international objections, and another with the day that he made a highly controversial appearance at Columbia University in New York</em>&#8220;.<br />
&nbsp;<br />
As regards the end-game, the eventual infection of machines physically located in the right place inside nuclear facilities, Bumgarner concedes that at this point the malware wasn&#8217;t yet &#8220;<em>in the target</em>&#8220;. So to make that final crucial leap, Stuxnet was designed to infect USB drives, in the hope that someone would later take the same USB drive from a Conficker/Stuxnet infected machine and plug it into a machine located in an air-gapped network in nuclear facility. At that point, Bumgarner states, &#8220;<em>it was checkmate</em>&#8220;.<br />
&nbsp;<br />
Phew, what a ride! You&#8217;ll forgive me I hope if I say that this account stretches my credulity to breaking point. Let me list a few reasons why.<br />
&nbsp;<br />
1 &#8211; If targets outside of IranÂ were surplus to requirements, why did the first iteration of Conficker only exclude computers based in the Ukraine? Why was that restriction later removed? Why not only infect machines in Iran in the first place?Â It is also not true to say that machines infected with Conficker were all unharmed, <a title="Downad/Conficker, whoâ€™s the April Fool?" href="http://countermeasures.trendmicro.eu/downadconficker-whos-the-april-fool/" target="_blank">Conficker was used to deliver Fake AV </a>and had a <a title="New Downad/Conficker variant spreading over P2P" href="http://countermeasures.trendmicro.eu/new-downadconficker-variant-spreading-over-p2p/" target="_blank">functional relationship with Waledac botnet C&amp;C</a><br />
&nbsp;<br />
2 &#8211; The levels of sophistication in Conficker and Stuxnet are in different leagues. The original version of Conficker used a single already patched Windows vulnerability to spread, the second variant added the capability to spread via removable drives and by brute forcing passwords against a list of common password variants, neither method sophisticated. There was a level of sophistication in the scale of pseudo-random domains that were generated by the malware as potential C&amp;C locations, but nothing that wasn&#8217;t quickly reverse engineered and understood. In the third variant of Conficker the propagation methods were actually removed, only to reappear again in the fourth significant variant. Stuxnet was a far more sophisticated animal, taking advantage of zero-day vulnerabilities and requiring specialist knowledge of SCADA systems and nuclear facilities.<br />
&nbsp;<br />
3 &#8211; I would theorise that the creators of Stuxnet chose to also use the MS08-67 vulnerability because its effectiveness is demonstrated by the fact that Conficker is still one of the most prevalent infections in enterprise networks, three years after its initial appearance. Why would you make two pieces of malware that propagate using the same vulnerability and yet rely on one to download the other?<br />
&nbsp;<br />
4 &#8211; The &#8220;activation date&#8221; of April 1 was <strong>coded into</strong> the third variant of Conficker. You don&#8217;t need unspecified time-stamps on unspecified files to tell you that.<br />
&nbsp;<br />
5 &#8211; April 1st is also April Fool&#8217;s day in many countries around the world, it&#8217;s also the anniversary of the founding of Apple Inc., the founding of the Serious Organised Crime Agency (SOCA) in the UK, the birth of the Republic of Ireland and the land blockade of West Berlin by the East German military. Get my point? As regards President Mahmoud Ahmadinejad saying that his country would continue to pursue it&#8217;s nuclear program, well surely, pick a day, pick any day&#8230;<br />
&nbsp;<br />
Then of course there&#8217;s the difficult conclusion, relying on persons unknown to plug a USB device into a Confuxnet infected machine, then unknowingly taking that same USB drive and plugging it into a PLC in a nuclear facility. Given the &#8220;unprecedented sophistication&#8221; of everything that has gone before, it&#8217;s this one just a tiny bit of a shot in the dark? A little bit &#8220;hit and hope&#8221;?<br />
&nbsp;<br />
Sorry Mr. Bumgarner, it could be true, of course it could, and it could be that you have been misreported, but on the evidence you present so far, I just don&#8217;t buy it.<br />
&nbsp;<br />
If I were a government with this kind of resource at my disposal, wouldn&#8217;t it make sense for one of my operatives in the target facility to simply take the USB containing Stuxnet right there for me?<br />
&nbsp;<br />
I know, there weren&#8217;t any aliens.<br />
&nbsp;</p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/conficker-duqu-stuxnet-aliens-confuxnet/' addthis:title='Conficker, Duqu, Stuxnet, Aliens, Confuxnet! '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/conficker-duqu-stuxnet-aliens-confuxnet/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Verified by Visa?</title>
		<link>http://countermeasures.trendmicro.eu/verified-by-visa/</link>
		<comments>http://countermeasures.trendmicro.eu/verified-by-visa/#comments</comments>
		<pubDate>Thu, 01 Dec 2011 15:18:43 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[countermeasures]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Underground Economy]]></category>
		<category><![CDATA[banking]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=3166</guid>
		<description><![CDATA[&#160; In 2001 Visa introduced a security protocol they called 3DS, short for 3 Domain Secure in an attempt to reduce the incidence of credit card fraud in online purchases. 3DS is better known by the names used by the various card issuers when they implement the system &#8220;Verified by Visa&#8220;, &#8220;MasterCard Secure Code&#8220;, &#8220;J/Secure&#8221; [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/verified-by-visa/' addthis:title='Verified by Visa? '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p><div id="attachment_3178" class="wp-caption alignleft" style="width: 407px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2011/12/monkeys.jpg"><img src="http://countermeasures.trendmicro.eu/wp-content/uploads/2011/12/monkeys.jpg" alt="" title="monkeys" width="397" height="226" class="size-full wp-image-3178" /></a><p class="wp-caption-text">used under creative commons from johnsnape&#039;s Flickr</p></div><br />
&nbsp;<br />
In 2001 Visa introduced a <a href="http://en.wikipedia.org/wiki/Verified_by_Visa">security protocol they called 3DS</a>, short for 3 Domain Secure in an attempt to reduce the incidence of credit card fraud in online purchases. 3DS is better known by the names used by the various card issuers when they implement the system &#8220;<em>Verified by Visa</em>&#8220;, &#8220;<em>MasterCard Secure Code</em>&#8220;, &#8220;<em>J/Secure</em>&#8221; (JCB International) and &#8220;<em>SafeKey</em>&#8221; (American Express). the trouble is that 3DS doesn&#8217;t really present any barrier at all, to even the average fraudster, at least in the way that is is implemented by card issuers that I tested.<br />
&nbsp;<br />
In the <a href="http://www.visaeurope.com/en/cardholders/verified_by_visa/faqs.aspx" target="_blank">FAQ</a> published by Visa they say &#8220;<em>Verified by Visa protects your card against unauthorised transactions, giving you complete confidence when shopping online</em>&#8220;. Later in the same FAQ they also state &#8220;<em>If you forget your password you can easily reset it</em>&#8221; and therein lies the problem. The following relates to implementations by the credit card issuers I was able to test, not necessarily to the entire 3DS system.<br />
&nbsp;<br />
The problem stems from a very basic design flaw. If you are making a purchase through a merchant that is subscribed to the program, you will be redirected, during the payment phase, to a 3DS verification page. On this page you confirm the details of the transaction, enter your password and hey presto, the transaction is complete. So far so good, the merchant never sees my password, no transaction with that merchant can be completed without it and I&#8217;m protected, but&#8230;<br />
&nbsp;<br />
What would a criminal do if they access to your card details but not your password? Of course, there&#8217;s that handy &#8220;I forgot my password&#8221; link. Let&#8217;s see how well protected that is.<br />
&nbsp;<br />
The first step in the password reset procedure is to enter your card number, obviously to ensure you are resetting the password for the correct account. Once that number is entered the system now requires some corroborating data to be sure that you are the legitmate account holder, let&#8217;s have a look at that &#8220;<em>Identification</em>&#8221; phase.<br />
&nbsp;<br />
<div id="attachment_3167" class="wp-caption alignleft" style="width: 414px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2011/12/step-2.png"><img class="size-full wp-image-3167" title="Second step in password reset" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2011/12/step-2.png" alt="" width="404" height="428" /></a><p class="wp-caption-text">Second step in password reset</p></div><br />
&nbsp;<br />
Oh noes, this doesn&#8217;t look good at all! Three out of four of the items of information used to verify my identity are <strong>all contained in the credit card data itself</strong>, embossed or printed on the card and contained in the magnetic stripe data. Wouldn&#8217;t the criminal already have access to this? So what remains? One piece of information that is not included on the card. Trouble is, it&#8217;s information that is not only widely shared on social networks, surveys, sign-up forms and a myriad of other places, but alsoÂ freely available in public records. We cannot and should not consider our date of birth to be a secret.<br />
&nbsp;<br />
Having entered the required information all that remains is to enter a new password of your choosing and your transaction is authorised. Worse still,Â no email notification is sent to alert the cardholder that their account has been accessed or modified. The cardholder need never know until they check their statements.<br />
&nbsp;<br />
So what should be improved? There&#8217;s nothing new or amazing here, just some really basic steps that need to be incorporated into the process.<br />
&nbsp;</p>
<ul>
<li>Upon enrolling in the system, cardholders should be requested to set a &#8220;Secret question&#8221; which will later serve as authentication data for a passsword change.</li>
<p>&nbsp;</p>
<li>Instead of simply clicking through to the reset screen, a one time password reset URL should be delivered to a registered email address.</li>
<p>&nbsp;
<li>Whever a change to the account details is requested, or is succesful, the registered email address should receive a notification message.</li>
<p>&nbsp;
</ul>
<p>&nbsp;<br />
Oh, one more thing, it would be really great if I could use special characters in my password, please.<br />
&nbsp;</p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/verified-by-visa/' addthis:title='Verified by Visa? '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/verified-by-visa/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
		<item>
		<title>The mobile threat: FUD or MUD</title>
		<link>http://countermeasures.trendmicro.eu/the-mobile-threat-fud-or-mud/</link>
		<comments>http://countermeasures.trendmicro.eu/the-mobile-threat-fud-or-mud/#comments</comments>
		<pubDate>Mon, 21 Nov 2011 13:38:21 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[countermeasures]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[Family Safety]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Mobile threats]]></category>
		<category><![CDATA[Opinion]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[malicious code]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=3150</guid>
		<description><![CDATA[Preface: This blog is not about open source vs closed, it&#8217;s also not about Android vs iOS or any other mobile operating system. It&#8217;s about criminals vs people, it&#8217;s about hype and reality and it&#8217;s about knee-jerk self-preservation vs openness and consideration. &#160; Last Wednesday, Chris DiBona (Open Source Programs Manager at Google Inc.) made [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/the-mobile-threat-fud-or-mud/' addthis:title='The mobile threat: FUD or MUD '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p><strong>Preface</strong>: This blog is not about open source vs closed, it&#8217;s also not about Android vs iOS or any other mobile operating system. It&#8217;s about criminals vs people, it&#8217;s about hype and reality and it&#8217;s about knee-jerk self-preservation vs openness and consideration.<br />
&nbsp;<br />
Last Wednesday, Chris DiBona (Open Source Programs Manager at Google Inc.) made <a title="Chris DiBona Google+" href="https://plus.google.com/u/0/114765095157367281222/posts/ZqPvFwdDLPv" target="_blank">a post on his Google+ profile</a> hitting out at claims about &#8220;<em>open source being inherently insecure&#8217; and that android is festooned with viruses because of that and because we do not exert apple like controls over the app market</em>&#8220;.<br />
&nbsp;<br />
While Chris does make some reasonable points regarding the comparative resilience and security of open source code, I can&#8217;t help but feel that he is wilfully missing the point when it comes to the current threat landscape that confronts smartphone users today. I&#8217;ll deal with the points I disagree with in the same sequence that Chris raises them:<br />
&nbsp;<br />
1 &#8211; &#8220;<em>All the major vendors have app markets, and all the major vendors have apps that do bad things, are discovered, and are dropped from the markets</em>.&#8221;<br />
&nbsp;<br />
Yes Chris, the major vendors all distribute apps based on the Marketplace or App Store model. One or more rogue or plain malicious apps have been discovered in most of those distribution channels and some of them get removed. Some of them even get removed in a timely fashion. Perhaps this is where some of the criticism based on &#8220;<em>openness</em>&#8221; has been misunderstood. As far as I am concerned, the problem pertinent to Android is not that the OS itself is open source, like I said you made some valid points about that, but that the app <strong>distribution mechanism</strong> is entirely open. Android embraces the concept of multiple third party marketplaces in addition to the &#8220;official&#8221; marketplace, even in the &#8220;official&#8221; marketplace there is no upfront vetting of code or functionality. Couple that with the undeniable and deserved popularity of the platform, it is no surprise that criminals are already actively exploiting an opportunity here. It&#8217;s not the open source, it&#8217;s the openness of the source.<br />
&nbsp;<br />
2 &#8211; &#8220;<em>Yes, virus companies are playing on your fears to try to sell you bs protection software for Android, RIM and IOS. They are charlatans and scammers. IF you work for a company selling virus protection for android, rim or IOS you should be ashamed of yourself.&#8221;</em><br />
&nbsp;<br />
Well now, this seems to be plainly stating that there is no malware problem for the popular mobile platforms. The weight of evidence (not to mention criminal intent) would seem to be heavily against you here Chris and Android itself seems to be the target of choice. TrendLabs for example have <a title="A snapshot of Android threats" href="http://blog.trendmicro.com/a-snapshot-of-android-threats-infographic/" target="_blank">documented a 1410% increase</a> in Android malware in the period January to July 2011. Let me be very clear. I am well aware that this rate of increase is starting from a low base, those four figure increases are not as shocking as they may at first appear. In raw numbers the total amount of malware is of course orders of magnitude lower than for example the Wintel platform. However the more important figure is not the total number of malware, but the <em>rate of increase</em> of that malware quarter on quarter and year on year. That demonstrates current, active and sustained criminal interest in the mobile platform. It&#8217;s not complicated, criminals follow consumers; always have, always will.<br />
&nbsp;<br />
3 &#8211; &#8220;<em>If you read an analyst report about &#8216;viruses&#8217; infecting ios, android orÂ  rim, you now know that analyst firm is not honest and is staffed withÂ  charlatans. There is probably an exception, but extraordinary claims need extraordinary evidence. If you read a report from a vendor that trys to sell you something based on protecting android, rim or ios from viruses they are also likely as not to be scammers and charlatans</em>. &#8221;<br />
&nbsp;<br />
I think the figures referenced above and <a title="Mobile - TrendLabs" href="http://blog.trendmicro.com/category/mobile/" target="_blank">the litany of mobile woe researched and documented by TrendLabs here</a> speak for themselves. This clinging desperately to the term &#8220;<strong>virus</strong>&#8221; in a last ditch attempt to demonstrate that a platform is free of <strong>malware </strong>is exactly the same language I have heard from MacOS enthusiasts (I am one before you flame me) who have been historically unwilling to admit that now the criminals are after them as well. It may well be that there are no viruses in the strictest definition of the term Chris, where do you stand on criminal malware for mobile devices?<br />
&nbsp;<br />
4 &#8211; &#8220;<em>Please note: Policy engines, and those tools that manage devices from an Â corporate IT department are not the same thing at all, but sometimes marketers in companies that sell such things sometimes tack on &#8216;virus&#8217; protection. That part is a lie, tell your vendor to cut it out.</em>&#8221;<br />
&nbsp;<br />
So we agree that security of mobile devices extends far beyond the threat from malware. Of course there is loss, theft, inappropriate access, device tracking, web-based threats through social networking or phishing for exampleÂ and many other areas to consider (by the way this is important for the consumer too) but advising your users to request that vendors remove functionality designed to detect malicious software? Well I guess that&#8217;s one way to make a platform appear malware free&#8230;</p>
<p>&nbsp;</p>
<p>Am I ashamed of myself? Not at all. I&#8217;d prefer to offer protection against a growing threat to personal and business security than to bury my head in the sand and defend my stance with wild accusation.<br />
&nbsp;<br />
Your post very much accuses security vendors of FUD, sowing Fear, Uncertainty and Doubt. I hope I have demonstrated that is very much not the case. Maybe your outburst was more a case of MUD? Myopic Unalloyed Denial.<br />
&nbsp;</p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/the-mobile-threat-fud-or-mud/' addthis:title='The mobile threat: FUD or MUD '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/the-mobile-threat-fud-or-mud/feed/</wfw:commentRss>
		<slash:comments>17</slash:comments>
		</item>
		<item>
		<title>How to check if you are a victim of Ghost Click</title>
		<link>http://countermeasures.trendmicro.eu/how-to-check-if-you-are-a-victim-of-operation-ghost-click/</link>
		<comments>http://countermeasures.trendmicro.eu/how-to-check-if-you-are-a-victim-of-operation-ghost-click/#comments</comments>
		<pubDate>Wed, 09 Nov 2011 22:27:22 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[Bad guys always lose]]></category>
		<category><![CDATA[countermeasures]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[Family Safety]]></category>
		<category><![CDATA[Mac OS]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Underground Economy]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[compromise]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[Fake AV]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[malicious code]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[Rogue AV]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=3130</guid>
		<description><![CDATA[&#160; Trend Micro and the FBI are very pleased to announce today the dismantling of a criminal botnet, in what is the biggest cybercriminal takedown in history. &#160; This concerted action against an entrenched criminal gang is highly significant and represents the biggest cybercriminal takedown in history. Six people have been arrested through multinational law [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/how-to-check-if-you-are-a-victim-of-operation-ghost-click/' addthis:title='How to check if you are a victim of Ghost Click '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p><div id="attachment_3131" class="wp-caption alignleft" style="width: 510px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2011/11/265838484_c6c4980b55.jpg"><img src="http://countermeasures.trendmicro.eu/wp-content/uploads/2011/11/265838484_c6c4980b55.jpg" alt="Ghost in the Machine" title="Ghost in the Machine" width="500" height="460" class="size-full wp-image-3131" /></a><p class="wp-caption-text">used by permission from flattop341 Flickr photostream</p></div><br />
&nbsp;</p>
<p>Trend Micro and the <a href="http://www.fbi.gov/news/stories/2011/november/malware_110911/malware_110911" target="_blank">FBI</a> are very pleased to announce today the dismantling of a criminal botnet, in what is <a title="Esthost Taken Down â€“ Biggest Cybercriminal Takedown in History" href="http://blog.trendmicro.com/esthost-taken-down-%e2%80%93-biggest-cybercriminal-takedown-in-history/" target="_blank">the biggest cybercriminal takedown in history</a>.<br />
&nbsp;<br />
This concerted action against an entrenched criminal gang is highly significant and represents the biggest cybercriminal takedown in history. Six people have been arrested through multinational law enforcement cooperation based on solid intelligence supplied by Trend Micro and other industry partners. more than 4 million victims in over 100 countries have been rescued from the malign influence of this botnet and an infrastructure of over 100 criminal servers has been dismantled with minimal disruption to the innocent victims.<br />
&nbsp;<br />
If you are worried that you might have been a victim of this criminal activity, the FBI have made an online tool available which will allow you to check if your DNS server settings have been tampered with.<br />
&nbsp;<br />
First you will need to discover what your current DNS server settings are:<br />
&nbsp;<br />
On a PC, open the <strong>Start</strong> menu by clicking the Start button or the Windows icon in the lower left of your screen, in theÂ  <strong>Search</strong> box type &#8220;<strong>cmd</strong>&#8221; and hit return (for Windows 95 users, select &#8220;<strong>Start</strong>&#8220;, then &#8220;<strong>Run</strong>&#8220;).This should open a black window with white text. In this window type &#8220;<strong>ipconfig /all</strong>&#8221; and hit return. Look for the entry that reads &#8220;DNS Servers&#8221; and note down the numeric addresses that are listed there.<br />
&nbsp;<br />
On a Mac (yes they can be victims too), click on the <strong>Apple</strong> icon in the top left of your screen and select &#8220;<strong>System Preferences</strong>&#8220;, from the Preferences panel select the &#8220;<strong>Network</strong>&#8221; icon. Once this window opens, select the currently active network connection on the left column and over on the right select the <strong>DNS</strong> tab. note down the addresses of the DNS servers that your computer is configured to use.<br />
&nbsp;<br />
You can check to see if these addresses correspond to servers used by the criminals behind Operation Ghost Click by using <a href="https://forms.fbi.gov/check-to-see-if-your-computer-is-using-rogue-DNS" target="_blank">this online tool provided by the FBI</a>, simply enter the IP addreses, one by one and click the &#8220;check ip&#8221; button.<br />
&nbsp;<br />
If you feel that you computer may have been infected, you can visit <a href="http://housecall.trendmicro.com/" target="_blank">Trend Micro&#8217;s HouseCall </a>for a free scan and clean-up and <a href="https://forms.fbi.gov/dnsmalware" target="_blank">notify the FBI by submitting this form</a>. You should also contact your Internet Service Provider for advice on restoring your legitimate DNS settings.<br />
&nbsp;<br />
Ongoing updates on this threat can be found on our <a href="http://us.trendmicro.com/us/trendwatch/current-threat-activity/operation-ghost-click/index.html"> Operation Ghost Click landing page</a>.<br />
&nbsp;</p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/how-to-check-if-you-are-a-victim-of-operation-ghost-click/' addthis:title='How to check if you are a victim of Ghost Click '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/how-to-check-if-you-are-a-victim-of-operation-ghost-click/feed/</wfw:commentRss>
		<slash:comments>30</slash:comments>
		</item>
		<item>
		<title>The mystery of the &#8220;hacked&#8221; Facebook accounts</title>
		<link>http://countermeasures.trendmicro.eu/the-mystery-of-the-hacked-facebook-accounts/</link>
		<comments>http://countermeasures.trendmicro.eu/the-mystery-of-the-hacked-facebook-accounts/#comments</comments>
		<pubDate>Wed, 19 Oct 2011 14:30:36 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[data leakage]]></category>
		<category><![CDATA[Family Safety]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Site Compromise]]></category>
		<category><![CDATA[Underground Economy]]></category>
		<category><![CDATA[Web 2.0]]></category>
		<category><![CDATA[compromise]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[hacktivism]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=3095</guid>
		<description><![CDATA[After a day of investigation it seems that &#8220;Team SwaStika&#8221; may be attempting to take credit for compromising account details that they really had nothing to do with. &#160; The two lists of hacked accounts (Part 1 and Part 2) have both been circulated online before the Pastebin posts were made by Team SwaStika. The [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/the-mystery-of-the-hacked-facebook-accounts/' addthis:title='The mystery of the &#8220;hacked&#8221; Facebook accounts '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p>After a day of investigation it seems that &#8220;Team SwaStika&#8221; may be attempting to take credit for compromising account details that they really had nothing to do with.<br />
&nbsp;<br />
The two lists of hacked accounts (Part 1 and Part 2) have both been circulated online before the Pastebin posts were made by Team SwaStika. The list entitled Part 1 appears to have been doing the rounds on various underground forums for the better part of a year. The second list entitled Part 2 by Team SwaStika is much more recent. The first evidence I can find of the accounts listed in Part 2 is only 19 days old.<br />
&nbsp;<br />
A list with content exactly matching this second Pastebin post by Team SwaStika was uploaded to a compromised website by the better known group of hackers Group Hp-Hack. Group Hp-Hack is a Saudi Arabian hacker group that has previously gained notoriety in August of this year for <a href="http://thehackernews.com/2011/08/joomla-canada-website-defaced-by-group.html">defacing the websites of Joomla Canada and ethicalhackingcourses.com</a> (which remains defaced to this day).<br />
&nbsp;<br />
The html list of alleged Facebook logins uploaded to a compromised web server was created in Microsoft Word and has a creation date of 1st October 2011 but was posted with the claim (in Arabic) that the list only represents 10% of the 7 million accounts that were breached by Group Hp-Hack.<br />
&nbsp;<div id="attachment_3096" class="wp-caption alignleft" style="width: 529px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2011/10/19-10-2011-15-06-11.png"><img src="http://countermeasures.trendmicro.eu/wp-content/uploads/2011/10/19-10-2011-15-06-11.png" alt="Group Hp-Hack defacement" title="Group Hp-Hack defacement" width="519" height="447" class="size-full wp-image-3096" /></a><p class="wp-caption-text">Group Hp-Hack defacement</p></div><br />
&nbsp;<br />
I have informed the owners of the compromised server and advised them to remove the content and once again passed this information to Facebook&#8217;s security team<br />
&nbsp;</p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/the-mystery-of-the-hacked-facebook-accounts/' addthis:title='The mystery of the &#8220;hacked&#8221; Facebook accounts '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/the-mystery-of-the-hacked-facebook-accounts/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Over 10,000 Facebook account details hacked and published</title>
		<link>http://countermeasures.trendmicro.eu/over-10000-facebook-account-details-hacked-and-published/</link>
		<comments>http://countermeasures.trendmicro.eu/over-10000-facebook-account-details-hacked-and-published/#comments</comments>
		<pubDate>Tue, 18 Oct 2011 12:02:51 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[data leakage]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[Family Safety]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Underground Economy]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[Web 2.0]]></category>
		<category><![CDATA[compromise]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[hacktivism]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=3085</guid>
		<description><![CDATA[An update to this investigation is available here. _____________________________________________________________________________________________________ A hacking group calling themselves &#8220;Team Swastika&#8221; have published what they claim to be the usernames and passwords for over ten thousand Facebook accounts on Pastebin, an online service for sharing large quantities of text data online. It should be noted that the PR agency for [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/over-10000-facebook-account-details-hacked-and-published/' addthis:title='Over 10,000 Facebook account details hacked and published '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p>An update to this investigation is available <a href="http://countermeasures.trendmicro.eu/the-mystery-of-the-hacked-facebook-accounts/">here</a>.<br />
_____________________________________________________________________________________________________<br />
A hacking group calling themselves &#8220;Team Swastika&#8221; have published what they claim to be the usernames and passwords for over ten thousand Facebook accounts on Pastebin, an online service for sharing large quantities of text data online. It should be noted that the PR agency for Facebook in the UK gave me the following statement, &#8220;<em>This does not represent a hack of Facebook or anyoneâ€™s Facebook profiles. Our security experts have reviewed this data and found it to be a set of e-mail and password combinations that are not associated with any live Facebook accounts</em>&#8220;.<br />
&nbsp;<br />
Team Swastika are a new arrival on the hacking scene, having <a href="http://pastebin.com/2ZnNPUym">announced their &#8220;launch&#8221;</a> only six days ago. although they have only <a href="https://twitter.com/#!/TeamSwastika/status/125482598272204801">one tweet</a> to their name they have already caused concern by <a href="http://pastebin.com/u/TeamSwastika">publishing</a> database tables and user credentials stolen from the websites of the Indian Embassy in Nepal and the Government of Bhutan, apparently by SQL injection attack.<br />
&nbsp;<br />
This latest publication of what they claim to be more than ten thousand Facebook user credentials is without context and with no indication of the means by which they were stolen. The posts themselves have already been removed by Pastebin but I managed to get a look at them before this happened&#8230;<br />
&nbsp;<br />
<div id="attachment_3086" class="wp-caption alignleft" style="width: 503px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2011/10/18-10-2011-13-50-37.png"><img class="size-full wp-image-3086" title="Stolen credentials for Facebook accounts" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2011/10/18-10-2011-13-50-37.png" alt="Stolen credentials for Facebook accounts" width="493" height="265" /></a><p class="wp-caption-text">Stolen credentials for Facebook accounts</p></div><br />
&nbsp;<br />
The compromised user accounts come from all over the globe, and a quick glance through the list of associated passwords shows that the majority of affected users are not using complex passwords, with many being simply a derivation of the user name, a favourite football club or a short numerical password.<br />
&nbsp;<br />
The ongoing effect of such a large scale compromise can be disastrous for affected users, particularly if the password is shared for multiple accounts. It can lead to compromise of the victim&#8217;s email account which can act as the skeleton key for many other online services, as any password reset procedure will normally pass through the account owner&#8217;s email inbox for verification. regaining control of a compromised account can be a costly and time consuming process, <a title="How an email hacker ruined my life and then tried to sell it back to me" href="http://www.guardian.co.uk/technology/2011/oct/16/email-hacker-identity-rowenna-davis" target="_blank">as this recent victim explains</a>.<br />
&nbsp;<br />
It is never a good idea to use the same password across multiple web sites, so try to have a unique one for every site you use. While this may sound complex and impossible to remember there is simple way to achieve this. Create a complex password using upper and lower case letters, numbers and special characters such as $%&amp;!. Devise a way to differentiate your password for each site you use, for example putting the first and last letters of the web site name at the beginning and end of your initial complex password, making it unique yet easy to remember<br />
&nbsp;<br />
As for those security or password reset questions, this is also one of the most common ways to break into an account. If you are asked to provide answers to â€śSecurity questionsâ€ť consider whether the answers are really secure. Secure means that you are the only person who can answer the question. If the possibility exists to create your own questions, use it. If you are obliged to answer more standard questions such as â€śFirst schoolâ€ťor â€śFirst petâ€ť remember the answer doesn&#8217;t have to be the truth, it only has to be something you can remember.<br />
&nbsp;<br />
I have not verified if the credentials as posted are legitimate, for reasons of privacy, but have passed the full list of affected accounts on to Facebook security so that they can warn and protect their users.<br />
&nbsp;</p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/over-10000-facebook-account-details-hacked-and-published/' addthis:title='Over 10,000 Facebook account details hacked and published '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/over-10000-facebook-account-details-hacked-and-published/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
		<item>
		<title>Sony (not) hacked</title>
		<link>http://countermeasures.trendmicro.eu/sony-not-hacked/</link>
		<comments>http://countermeasures.trendmicro.eu/sony-not-hacked/#comments</comments>
		<pubDate>Wed, 12 Oct 2011 13:45:25 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[data protection]]></category>
		<category><![CDATA[Family Safety]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Underground Economy]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[compromise]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=3069</guid>
		<description><![CDATA[&#160; News reports today are characterising an attack against the Sony PlayStation Network (PSN) and Sony Entertainment Online (SOE) as &#8220;another hack&#8221; or &#8220;Sony hacked again&#8220;. However, according to a blog post from Sony&#8217;s SVP and Chief Information Security Officer, that simply isn&#8217;t the case. Â &#160; The attack against PSN accounts belonging to Sony subscribers [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/sony-not-hacked/' addthis:title='Sony (not) hacked '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p><div id="attachment_3075" class="wp-caption alignleft" style="width: 510px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2011/10/password.jpg"><img src="http://countermeasures.trendmicro.eu/wp-content/uploads/2011/10/password.jpg" alt="Enter your password" title="Enter your password" width="500" height="293" class="size-full wp-image-3075" /></a><p class="wp-caption-text">Enter your password</p></div><br />
&nbsp;<br />
News reports today are characterising an attack against the Sony PlayStation Network (PSN) and Sony Entertainment Online (SOE) as &#8220;<a title="Sony hacked again (again)" href="http://news.techeye.net/security/sony-hacked-again-again" target="_blank">another hack</a>&#8221; or &#8220;<a title="Sony hacked again" href="http://crave.cnet.co.uk/gamesgear/sony-hacked-again-with-93000-accounts-compromised-50005593/" target="_blank">Sony hacked again</a>&#8220;. However, according to a <a title="An important message from Sony's Chief Information Security Officer" href="http://blog.us.playstation.com/2011/10/11/an-important-message-from-sonys-chief-information-security-officer/">blog post</a> from Sony&#8217;s SVP and Chief Information Security Officer, that simply isn&#8217;t the case.<br />
Â &nbsp;<br />
The attack against PSN accounts belonging to Sony subscribers went like this&#8230; Person or persons unknown, built or obtained a database of username and password pairs which they attempted to use to log into the PSN and SOE. The &#8220;overwhelming majority&#8221; of access attempts using these pairs of credentials failed, in fact less than 0.1% were successful. For this reason Sony suspect that the credentials used were not stolen from Sony directly, either now or in past intrusions. The database in question was most probably email and password pairs that have been obtained elsewhere but were being used in a brute force attack against Sony, in the knowledge that users have the unfortunate habit of reusing passwords across multiple services.<br />
Â &nbsp;<br />
When Sony detected this irregular activity against its servers it immediately locked out all of the affected accounts and is informing the affected users that they need to change their passwords. Only a small fraction of that 0.1% showed evidence of irregular activity before Sony locked them down, meaning that the damage was successfully contained.<br />
Â &nbsp;<br />
In reality this story should not be characterised as a failure over at Sony, but rather a success. Through their own monitoring systems they detected anomalous behaviour, acted quickly to contain the damage and locked out the accounts affected. They are also obliging the affected users to change their service passwords to better secure themselves in the future. Of course given the <a href="http://countermeasures.trendmicro.eu/70-million-customers-affected-by-the-sony-breach/" title="70 million customers affected by the Sony breach" target="_blank">past intrusion at Sony</a>, there is every possibility that the data does relate to that stolen from Sony earlier but also indicates that the mass password reset policy it instituted after the event served toÂ render the majority of that data unusable.<br />
Â &nbsp;<br />
After all it is not, as Sony have learned to their cost, whether you get attacked that is important, it&#8217;s how you deal with it. The lesson for Sony customers is not that Sony hasn&#8217;t learned lessons, it is rather that we as users still have some important lessons to learn.<br />
&nbsp;<br />
It is never a good idea to use the same password across multiple web sites, so try to have a unique one for every site you use. While this may sound complex and impossible to remember there is simple way to acheive this. Create a complex password using upper and lower case letters, numbers and special characters such as $%&#038;!. Devise a way to differentiate your password for each site you use, for example putting the first and last letters of the web site name at the beginning and end of your initial complex password, making it unique yet easy to remember<br />
 &nbsp;<br />
As for those security or password reset questions, this is also one of the most common ways to break into an account. If you are asked to provide answers to â€śSecurity questionsâ€ť consider whether the answers are really secure. Secure means that you are the only person who can answer the question. If the possibility exists to create your own questions, use it. If you are obliged to answer more standard questions such as â€śFirst schoolâ€ťor â€śFirst petâ€ť remember the answer doesnâ€™t have to be the truth, it only has to be something you can remember.<br />
&nbsp;</p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/sony-not-hacked/' addthis:title='Sony (not) hacked '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/sony-not-hacked/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>All your citizens are (not) belong to us</title>
		<link>http://countermeasures.trendmicro.eu/all-your-citizens-are-belong-to-us/</link>
		<comments>http://countermeasures.trendmicro.eu/all-your-citizens-are-belong-to-us/#comments</comments>
		<pubDate>Tue, 21 Jun 2011 10:39:48 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[data leakage]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[Family Safety]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Opinion]]></category>
		<category><![CDATA[compromise]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[hacktivism]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[snooping]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=2879</guid>
		<description><![CDATA[UPDATE III: I just received the following statement from the Office for National Statisitcs in the UK &#160; &#8220;Census data secure The Office for National Statistics reaffirmed today (Wednesday) that personal census information is secure and an allegation made yesterday that it has been hacked is without foundation. Census Director, Glen Watson, said: â€śI can [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/all-your-citizens-are-belong-to-us/' addthis:title='All your citizens are (not) belong to us '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p><strong>UPDATE III</strong>: I just received the following statement from the Office for National Statisitcs in the UK<br />
&nbsp;</p>
<blockquote><p>&#8220;Census data secure</p>
<p>   The Office for National Statistics reaffirmed today (Wednesday) that personal census information is secure and an allegation made yesterday that it has been hacked is without foundation.</p>
<p>   Census Director, Glen Watson, said:</p>
<p>   â€śI can reassure the public that their census records are secure. We have strict measures in place protecting the nationâ€™s census information. The claim that hackers got in looks like a hoax and our investigation concluded that there is no sign of any suspicious activity. The alleged hackers have also denied any involvement.</p>
<p>   â€śHowever, we are not complacent and will remain vigilant. The security and confidentiality of census data remain our top priority.&#8221;"</p></blockquote>
<p>&nbsp;</p>
<p><strong>UPDATE II</strong>: <a href="http://twitter.com/#!/LulzSec/status/83172089711964161">Recent tweets</a> on the LulzSec Twitter account deny any truth to the UK Census data rumours.<br />
&nbsp;<br />
<strong>UPDATE</strong>: The Metropolitan Police Cental e-crime Unit PCeU have <a href="http://content.met.police.uk/News/eCrime-unit-arrest-man/1260269113895/1257246745756">confirmed </a>that a 19 year-old man has been arrested in connection with LulzSec activity. If LulzSec preparation was in anyway similar to<a href="http://www.wired.com/threatlevel/2010/07/wikileaks-insurance-file/"> that of Wikileaks</a>, should expect to start seeing mass release of previously witheld information?<br />
_________________________________________________<br />
&nbsp;<br />
In a surprising and worrying development, an unconfirmed post on <a href="http://pastebin.com/K1nerhk0">Pastebin</a>, purportedly from Lulz Sec, claims that they are in possession of the entire UK census data for 2011.<br />
&nbsp;<br />
So far this claim has not been backed up on the <a href="http://twitter.com/#!/lulzsec">LulzSec Twitter account</a>, which is their usual habit, although a couple of prior post do lend some credence to it<br />
&nbsp;<br />
Yesterday they <a href="http://twitter.com/#!/LulzSec/status/82841336683831296">tweeted </a><br />
&nbsp;</p>
<blockquote><p>&#8220;<em>Government hacking is taking place right now behind the scenes</em>&#8220;</p></blockquote>
<p>&nbsp;<br />
and a few hours ago, they posted a couple of statements that are similar in tone to the PasteBin document:<br />
&nbsp;</p>
<blockquote><p>&#8220;<em><a href="http://twitter.com/#!/LulzSec/status/83016584972607488">Thank you to the supporters who have assisted in leaks. Like @WikiLeaks, our sources remain anonymous. Leak payloads are being decided now</a></em>.&#8221;</p></blockquote>
<p>&nbsp;<br />
and<br />
&nbsp;</p>
<blockquote><p>&#8220;<em><a href="http://twitter.com/#!/LulzSec/status/83017011554295808">Our next step is to categorize and format leaked items we acquire and release them in #AntiSec &#8220;payloads&#8221; on our website and The Pirate Bay</a>.</em>&#8220;</p></blockquote>
<p>&nbsp;<br />
No details are included in the PasteBin post regarding how the information was obtained, but the messages posted so far seem to indicate a leak rather than an intrusion or hack.<br />
&nbsp;<br />
If this claim turns out to be true it means the personal details of every UK citizen, names, addresses, religion, family details, income levels, professional details are in the hands of a group who have already shown they have no objection to releasing illegally obtained material publicly.<br />
&nbsp;<br />
This could undermine the confidence of the nation and possibly others to hand over sensitive information to a civil service that has<a href="http://news.bbc.co.uk/1/hi/7104368.stm"> already once demonstrated</a> its inability to encrypt or safeguard it from loss.<br />
&nbsp;<br />
Currently refusal to fill in a census is a criminal offence in the UK, will we be looking at mass criminality when the next census rolls around?<br />
&nbsp;<br />
Lockheed Martin are currently responsible for the UK census. I have approached them to confirm or deny this claim and am awaiting a statement.<br />
&nbsp;</p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/all-your-citizens-are-belong-to-us/' addthis:title='All your citizens are (not) belong to us '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/all-your-citizens-are-belong-to-us/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
	</channel>
</rss>

