<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CounterMeasures -  A Security Blog  hacked</title>
	<atom:link href="http://countermeasures.trendmicro.eu/tag/hacked/feed/" rel="self" type="application/rss+xml" />
	<link>http://countermeasures.trendmicro.eu</link>
	<description>Rik Ferguson blogs about current security issues.</description>
	<lastBuildDate>Wed, 28 Jul 2010 17:12:49 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>China&#8217;s got Talent, but no email.</title>
		<link>http://countermeasures.trendmicro.eu/chinas-got-talent-but-no-email/</link>
		<comments>http://countermeasures.trendmicro.eu/chinas-got-talent-but-no-email/#comments</comments>
		<pubDate>Thu, 20 May 2010 08:46:56 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Opinion]]></category>
		<category><![CDATA[data leakage]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[celebrity]]></category>
		<category><![CDATA[compromise]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[snooping]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=2014</guid>
		<description><![CDATA[The Shanghai Daily today reports that &#8220;the internet mailbox&#8221; belonging to the official show &#8220;China&#8217;s Got Talent&#8221; (yes that nonsense gets everywhere) has been compromised. &#160; &#160; The mailbox contained (note the past tense) about 900 mails detailing the show&#8217;s running order, schedules, plans, contestant details and much more. These mails have now all been [...]]]></description>
			<content:encoded><![CDATA[<p><strong>The Shanghai Daily today </strong><a title="China's got talented thieves, show learns" href="http://www.shanghaidaily.com/sp/article/2010/201005/20100520/article_437572.htm" target="_blank"><strong>reports </strong></a><strong>that &#8220;the internet mailbox&#8221; belonging to the official show &#8220;<em><a href="http://daren2010.dragontv.cn/" target="_blank">China&#8217;s Got Talent</a></em>&#8221; (yes that nonsense gets everywhere) has been compromised.</strong><br />
&nbsp;<br />
<div id="attachment_2015" class="wp-caption alignleft" style="width: 385px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/05/3782936120_4596346572.jpg"><img class="size-full wp-image-2015" title="3782936120_4596346572" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/05/3782936120_4596346572.jpg" alt="Photo from Julien Lozelli's photostream on Flicker - Creative Commons" width="375" height="500" /></a><p class="wp-caption-text">Photo from Julien Lozelli&#39;s photostream on Flicker - Creative Commons</p></div><br />
&nbsp;<br />
The mailbox contained (note the past tense) about 900 mails detailing the show&#8217;s running order, schedules, plans, contestant details and much more. These mails have now all been deleted and the tone of the article and the concern from Dragon TV certainly seem to suggest that there may not have been a backup in place.<br />
&nbsp;<br />
As well as the show and contestant details, the biggest loss to Dragon TV is the production manual for the series, purchased from Freemantle Media. This document is reportedly worth around US$400,000. Show organisers are extremely worried that this information may have been stolen and will appear posted on public websites. They have requested domestic websites to delete the data should it appear, personally I doubt the effectiveness of such a strategy.<br />
&nbsp;<br />
For me the most shocking quote from the article is:</p>
<blockquote><p>&#8220;<em>The mailbox was for the use of the Dragon TV&#8217;s internal employees only so it had simple passwords for easy communication.&#8221;</em></p></blockquote>
<p>So, an internet-facing, shared mailbox containing highly confidential information with simple passwords? Normally at this point in a blog article I suppose I would begin to point out things that could have been done to limit the possibilities of such an event. It seems almost too incredible that the aforementioned combination of circumstances should even occur, but here you go&#8230;<br />
&nbsp;<br />
If information is sensitive, do not allow access to it from the internet.<br />
&nbsp;<br />
If information is sensitive do not store it in a shared mailbox, it is impossible to audit effectively<br />
&nbsp;<br />
Never use simple passwords, for any reason, ever.<br />
&nbsp;<br />
If you have a document worth almost half a million dollars&#8230; Encrypt it.</p>
]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/chinas-got-talent-but-no-email/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>GORDON&#8217;S ALIVE?! Tory online campaign fail.</title>
		<link>http://countermeasures.trendmicro.eu/gordons-alive-tory-online-campaign-fail/</link>
		<comments>http://countermeasures.trendmicro.eu/gordons-alive-tory-online-campaign-fail/#comments</comments>
		<pubDate>Mon, 22 Mar 2010 17:11:05 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Site Compromise]]></category>
		<category><![CDATA[Web 2.0]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[hacktivism]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=1944</guid>
		<description><![CDATA[The Conservative party this weekend unveiled a social media marketing campaign aimed at embarassing the Labour Party. The plan has backfired quite spectacularly&#8230; &#160; The &#8220;Cash Gordon&#8221; web site was highly dynamic and tied in with many popular social networking sites and tools. It capitalised on user generated content and relied on organic sharing and [...]]]></description>
			<content:encoded><![CDATA[<p>The Conservative party this weekend unveiled a social media marketing campaign aimed at embarassing the Labour Party. The plan has backfired quite spectacularly&#8230;<br />
&nbsp;<br />
The &#8220;<a href="http://cash-gordon.com/">Cash Gordon</a>&#8221; web site was highly dynamic and tied in with many popular social networking sites and tools. It capitalised on user generated content and relied on organic sharing and interaction. In a blog post on the Conservative home page Samuel Coates <a title="Using Facebook Connect to spread the word" href="http://blog.conservatives.com/index.php/2010/03/21/using-facebook-connect-to-spread-the-word/" target="_blank">said</a></p>
<blockquote><p>&#8220;Once users have connected to the Cash-Gordon campaign, they can start accruing “action points” for reading briefings about the issue, getting their friends involved, donating, or even for directly asking Charlie Whelan a question.&#8221;</p></blockquote>
<p>However today it&#8217;s the Conservatives that have been left with red faces, after a web site configuration error (or maybe just a lack of planning) saw the site abused to the point of being taken offline.<br />
&nbsp;<br />
The Cash Gordon website was set up to collect any message posted on Twitter that contained the <a href="http://help.twitter.com/forums/10711/entries/49309" target="_blank">hashtag</a> #cashgordon and republish it in a live stream in a widget on the home page of Cash Gordon. <br />
&nbsp;<br />
Obviously this was duly noted and passed around. It was soon discovered that if you tweeted HTML or JavaScript instead of standard messages, this content would be interpreted and rendered by the visitor’s browser as legitimate part of the Cash Gordon site, allowing pranksters to redirect visitors to any site of the miscreant’s choosing.<br />
&nbsp;<br />
The screen shot below shows the steady stream of tweets that ensured that visitors to the web site were constantly redirected to many different, sometimes salacious, destinations.<br />
&nbsp;<br />
<div id="attachment_1945" class="wp-caption alignleft" style="width: 510px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/03/Tweedirect.png"><img class="size-full wp-image-1945" title="Tweets containing JavaScript and #cashgordon hashtag" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/03/Tweedirect.png" alt="Tweets containing JavaScript and #cashgordon hashtag" width="500" height="431" /></a><p class="wp-caption-text">Tweets containing JavaScript and #cashgordon hashtag</p></div><br />
&nbsp;<br />
This isn&#8217;t all fun and games though, configuration oversights can lead to serious harm. This latest in a line of social media marketing related fails is a salutary warning not to underestimate the technical know-how of the world wide audience you are inviting.<br />
&nbsp;<br />
In reality this poor configuration could have posed a serious risk to the Tory party’s own supporters as well as any other curious visitor. Those responsible for the page should have been filtering incoming Tweets  or simply sanitising the code before it was reposted. This could just as easily been used as a means to infect visitors by redirecting them to malicious web sites.</p>
]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/gordons-alive-tory-online-campaign-fail/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>YES the partner friendly exploit system.</title>
		<link>http://countermeasures.trendmicro.eu/yes-the-partner-friendly-exploit-system/</link>
		<comments>http://countermeasures.trendmicro.eu/yes-the-partner-friendly-exploit-system/#comments</comments>
		<pubDate>Thu, 11 Mar 2010 16:01:31 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Underground Economy]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[malicious code]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=1884</guid>
		<description><![CDATA[The Russian crimeware &#8220;YES Exploit System&#8221; is a fully manageable system that generates malicious code for injecting into compromised pages or malicious web sites. This code is designed to redirect victims to files on your own hosted exploit server allowing you to push out malicious files invisibly and instantly, and it just got a major [...]]]></description>
			<content:encoded><![CDATA[<p>The Russian crimeware &#8220;YES Exploit System&#8221; is a fully manageable system that generates malicious code for injecting into compromised pages or malicious web sites. This code is designed to redirect victims to files on your own hosted exploit server allowing you to push out malicious files invisibly and instantly, and it just got a major version update.<br />
&nbsp;<br />
The advertisement for the latest version boasts:</p>
<blockquote><p>&#8220;Hacked all Windows version 9x to 7 32 bit and 64 bit<br />
Hacked all browsers running a vulnerable plug-in&#8221;</p></blockquote>
<p>Using the built in TDS (Traffic Direction System) criminals can specify which malware they want to push out by country, by browser and by OS. It is clearly designed to support the inter-related vendor infrastructure of the criminal economy. YES Exploit System is a fully fledged platform for delivering malware on behalf of other criminal enterprises, perhaps to seed a new ZeuS campaign or maybe to push out some scareware. As <a title="Kneber for sale or rent" href="http://countermeasures.trendmicro.eu/kneber-for-sale-or-rent-rooms-to-let-50-cents/" target="_blank">previous blog posts </a>have shown YES is often bundled into full service underground ZeuS offerings. As you can see from the screen shot below, projects can be divided on a per-customer basis.<br />
&nbsp;<br />
<div id="attachment_1885" class="wp-caption alignleft" style="width: 548px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/03/loads.1png.png"><img class="size-full wp-image-1885  " title="YES Exploit Pack interface" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/03/loads.1png.png" alt="YES Exploit Pack interface" width="510" height="191" /></a><p class="wp-caption-text">click to enlarge</p></div><br />
&nbsp;<br />
One feature that really stood out for me in this new version, in light of other <a title="Cybercriminals research their own bad reputation" href="http://countermeasures.trendmicro.eu/cybercriminals-research-their-own-bad-reputation/" target="_blank">recent blog postings</a>, was the addition of a module that automates testing against AV vendors to ensure the malware remains undetected. This is in addition to URL checking functionality already released in earlier versions of YES.<br />
&nbsp;<br />
In another illustration of cloud adoption in online crime, the module is priced on a subscription basis at $70USD per month (including support of course) and tests malicious files against 26 of the biggest security companies out there. All processing is offloaded so as not to overburden your own server.<br />
&nbsp;<br />
<div id="attachment_1890" class="wp-caption alignleft" style="width: 463px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/03/virtest.png"><img class="size-full wp-image-1890  " title="Virus scanning results" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/03/virtest.png" alt="Virus scanning results" width="453" height="255" /></a><p class="wp-caption-text">click to enlarge</p></div><br />
&nbsp;<br />
As is so often the case, the first step in this chain of compromise is a malicious script inserted into an otherwise innocent website, my <a href="http://countermeasures.trendmicro.eu/which-browser-is-the-most-secure-is-that-the-question/">previous blog</a> gives you a few tips on securing your browser against these types of attack.</p>
]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/yes-the-partner-friendly-exploit-system/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Polticians and scum-sucking pigs make uncomfortable bedfellows</title>
		<link>http://countermeasures.trendmicro.eu/polticians-and-scum-sucking-pigs-make-uncomfortable-bedfellows/</link>
		<comments>http://countermeasures.trendmicro.eu/polticians-and-scum-sucking-pigs-make-uncomfortable-bedfellows/#comments</comments>
		<pubDate>Tue, 16 Feb 2010 11:27:05 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Web 2.0]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=1775</guid>
		<description><![CDATA[In yet another example of the potential pitfalls of social networking in the workplace, a British MP for Telford and party whip is today at the centre of a storm over an offensive post on the micro-blogging site Twitter. &#160; &#160; Yesterday evening, the Twitter account of MP David Wright posted the message &#8220;#ivenevervotedtory because you [...]]]></description>
			<content:encoded><![CDATA[<p>In yet another example of the potential pitfalls of social networking in the workplace, a British MP for Telford and <a title="Wikipedia - Whip (politics)" href="http://en.wikipedia.org/wiki/Whip_%28politics%29" target="_blank">party whip</a> is today at the centre of a storm over an offensive post on the micro-blogging site Twitter.<br />
&nbsp;<br />
<div id="attachment_1786" class="wp-caption alignleft" style="width: 630px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/02/tinkered1.gif"><img class="size-full wp-image-1786" title="MP David Wright tweets" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/02/tinkered1.gif" alt="MP David Wright tweets" width="510" height="220" /></a><p class="wp-caption-text">MP David Wright tweets</p></div><br />
&nbsp;<br />
Yesterday evening, the Twitter account of MP David Wright posted the message</p>
<blockquote><p>&#8220;#ivenevervotedtory because you can put lipstick on a scum-sucking pig, but it&#8217;s still a scum-sucking pig.&#8221;</p></blockquote>
<p>The tweet was joining in with the Twitter meme responding to the latest Tory poster campaign which features the tag line &#8220;I have never voted Tory before but&#8230;&#8221;. However the turn of phrase has hit a raw nerve among many Twitter users, prompting the MP to delete the offensive tweet and apologise.<br />
&nbsp; </p>
<p><div id="attachment_1777" class="wp-caption alignleft" style="width: 444px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/02/TrippyPip.gif"><img class="size-full wp-image-1777" title="TrippyPip talks to David Wright MP" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/02/TrippyPip.gif" alt="TrippyPip talks to David Wright MP" width="434" height="347" /></a><p class="wp-caption-text">TrippyPip talks to David Wright MP</p></div><br />
&nbsp;<br />
 <br />
Out of interest, in response to the question above &#8220;<em>Do you *really* think it&#8217;s acceptable to call people &#8216;scum-sucking pigs&#8221;???&#8221;</em> The MP responded as in the next image:<br />
 &nbsp;</p>
<p><div id="attachment_1778" class="wp-caption alignleft" style="width: 409px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/02/fair-game.gif"><img class="size-full wp-image-1778" title="MP David Wright tweets" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/02/fair-game.gif" alt="MP David Wright tweets" width="399" height="61" /></a><p class="wp-caption-text">MP David Wright tweets</p></div><br />
&nbsp;<br />
 <br />
The story doesn&#8217;t end there though.. David Wright MP has said that he actually posted the comment as &#8220;<em>#ivenevervotedtory because you can put lipstick on a pig, but it&#8217;s still a pig</em>.&#8221; (in a kind of homage to Barack Obama use of the phrase during his election campaign) but that his message was subsequently &#8220;<em>tinkered with</em>&#8221; and the extra words added. Mr Wright <a title="Labour MP apologises over Tory 'pig' comments" href="http://news.bbc.co.uk/1/hi/uk_politics/8517278.stm" target="_blank">told the BBC</a> that this was a legitimate &#8220;<em>edgy Twitter comment about the political process</em>&#8221; and the Tories&#8217; &#8220;<em>general policy position</em>&#8220;.<br />
 &nbsp;<br />
I&#8217;ll be very interested to see how this story ends, because currently neither the Twitter interface or any of the third-party Twitter clients have any kind of functionality that allows the editing of Tweets once they have been posted. So for these words to have been mischievously added by persons unknown must mean a quite substantial security failure at Twitter themselves. Either that or Mr. Wright just forgot what he actually typed.</p>
]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/polticians-and-scum-sucking-pigs-make-uncomfortable-bedfellows/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Twitter.Grader.com hacked?</title>
		<link>http://countermeasures.trendmicro.eu/grader-com-hacked/</link>
		<comments>http://countermeasures.trendmicro.eu/grader-com-hacked/#comments</comments>
		<pubDate>Thu, 11 Feb 2010 20:07:29 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[SEO]]></category>
		<category><![CDATA[Site Compromise]]></category>
		<category><![CDATA[Web 2.0]]></category>
		<category><![CDATA[data leakage]]></category>
		<category><![CDATA[compromise]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=1757</guid>
		<description><![CDATA[&#160;  UPDATE: You will see in the comments on this post an update from HubSpot with a link to their blog explaining the incident, I know a lot of folks don&#8217;t read the comments, so here it is in full. &#8220;We are very sorry for the mistake. It is completely our fault. As your article [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_1758" class="wp-caption alignleft" style="width: 650px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/02/grader.gif"><img class="size-full wp-image-1758" title="Twitter Grader home page" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/02/grader.gif" alt="Twitter Grader home page" width="510" height="165" /></a><p class="wp-caption-text">Twitter Grader home page</p></div>
<p>&nbsp; <br />
<strong>UPDATE</strong>: You will see in the comments on this post an update from HubSpot with a link to their blog explaining the incident, I know a lot of folks don&#8217;t read the comments, so here it is in full.</p>
<blockquote><p>&#8220;We are very sorry for the mistake. It is completely our fault. As your article mentions, we have contained the situation and stopped the malicious tweets.</p>
<p>We do want to make clear that by design, the HubSpot software applications are on different servers and systems from our free Grader.com tools. This attack did NOT affect the HubSpot software used by our 2,100 customers. Again, there is no impact on our paid product or paying customers.</p>
<p>We have posted an article on our company blog with more information:</p>
<p>http://www.hubspot.com/blog/bid/5594/One-Lesson-From-The-Twitter-Grader-Screw-up-OAuth-Rocks</p>
<p>- Mike Volpe<br />
HubSpot (makers of Twitter Grader)&#8221;</p></blockquote>
<p>&#8230;and that, ladies and gents, is an object lesson in how to deal with an event like this. Much respect to HubSpot.</p>
<p>&nbsp;<br />
__________________________________________________________________________________________</p>
<p>In what looks like another compromise related to Twitter services, a large number of Twitter users who have granted access to their accounts to the web service Twitter.Grader.com have all begun tweeting a bizarre and unauthorised message.<br />
&nbsp;</p>
<div class="mceTemp">
<dl id="attachment_1759" class="wp-caption alignleft" style="width: 557px;">
<dt class="wp-caption-dt"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/02/posts.gif"><img class="size-full wp-image-1759" title="Example of affected accounts" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/02/posts.gif" alt="Example of affected accounts" width="510" height="354" /></a></dt>
<dd class="wp-caption-dd">Example of affected accounts (search by Twitscoop)</dd>
</dl>
<p>&nbsp;<br />
Fortunately the link that has been endlessly tweeted by grader users does not appear to host any malicious content. It points to a blog with an embedded YouTube video of Biz Stone back in 2006 promoting Twitter.</p></div>
<p>&nbsp;</p>
<div class="mceTemp">The domain name of the destination site however might give us a clue to the motivation behind the attack. Seonix presumably refers to Search Engine Optimisation and perhaps that is the real purpose of this attack. Forcing large numbers of Twitter users to tweet a link to the site may well be an effective method of pushing it up the search engine rankings. The domain seonix.org was created on the 11th February 2010 and the details of the owner have been anonymised.</div>
<p>&nbsp;</p>
<div class="mceTemp">Embarassingly the victims of this attack also include Dharmesh Shah, the founder of Grader</div>
<div class="mceTemp">
&nbsp;</p>
<div class="mceTemp">
<dl id="attachment_1760" class="wp-caption alignleft" style="width: 581px;">
<dt class="wp-caption-dt"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/02/dharmesh.gif"><img class="size-full wp-image-1760" title="Dharmesh Shah on Twitter" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/02/dharmesh.gif" alt="Dharmesh Shah on Twitter" width="510" height="359" /></a></dt>
<dd class="wp-caption-dd">Dharmesh Shah on Twitter</dd>
</dl>
<p>&nbsp;<br />
<strong>UPDATE</strong>: Hubspot, the parent company have <a href="http://twitter.com/HubSpot/status/8974998969">tweeted</a> that they are aware of the hack and working on a solution. In the meantime, if you are a Grader user, you may want to consider temporarily revoking Access to Grader in your Twitter profile <a href="http://twitter.com/account/connections">via Settings -> Connections</a>.</div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/grader-com-hacked/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Google, China, Chicken Little and Cyber Armageddon.</title>
		<link>http://countermeasures.trendmicro.eu/google-china-chicken-little-and-cyber-armageddon/</link>
		<comments>http://countermeasures.trendmicro.eu/google-china-chicken-little-and-cyber-armageddon/#comments</comments>
		<pubDate>Tue, 19 Jan 2010 14:00:10 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[Encryption]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Updates & Patches]]></category>
		<category><![CDATA[data leakage]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[compromise]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[malicious code]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=1680</guid>
		<description><![CDATA[&#160; In the wake of the highly publicised &#8220;highly sophisticated and targeted&#8221; attacks on Google, at least three major governments have issued advisories urging their citizens to switch browsers away from Microsoft Internet Explorer. A well-known security company has redesigned their web sites to include a large ominous &#8220;Operation Aurora&#8221; graphic (that links to trial [...]]]></description>
			<content:encoded><![CDATA[<p><div id="attachment_1707" class="wp-caption alignleft" style="width: 510px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/01/Chicken-Little.jpg"><img class="size-full wp-image-1707" title="Foxy Loxy by Gustaf Tenggren" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/01/Chicken-Little.jpg" alt="" width="500" height="399" /></a><p class="wp-caption-text">Foxy Loxy by Gustaf Tenggren</p></div><br />
&nbsp;<br />
In the wake of the highly publicised &#8220;highly sophisticated and targeted&#8221; attacks on Google, at least three major governments have <a title="British government ignores MS browser fears" href="http://www.theregister.co.uk/2010/01/18/browser_hole/" target="_blank">issued advisories </a>urging their citizens to switch browsers away from Microsoft Internet Explorer. A well-known security company has redesigned their web sites to include a large ominous &#8220;Operation Aurora&#8221; graphic (that links to trial downloads of pre-existing software). The attacks have been <a title="McAfee SI blog" href="http://siblog.mcafee.com/cto/operation-%E2%80%9Caurora%E2%80%9D-hit-google-others/" target="_blank">described as </a>&#8220;changing the world&#8221; by the CTO of that same security company and as &#8220;something quite different&#8221; by Google.<br />
&nbsp;<br />
How much of this is real, justified and proportionate?<br />
&nbsp;<br />
So what do we know so far? Well <a title="A new approach to China" href="http://googleblog.blogspot.com/2010/01/new-approach-to-china.html?utm_campaign=en&amp;utm_source=en-ha-ww-ww-bk-cn&amp;utm_medium=ha&amp;utm_term=google%20china" target="_blank">according to Google </a>&#8220;<em>In mid-December, we detected a highly sophisticated and targeted attack on our corporate infrastructure originating from China that resulted in the theft of intellectual property from Google</em>&#8220;. They go on to say &#8220;<em>As part of our investigation we have discovered that at least twenty other large companies from a wide range of businesses&#8211;including the Internet, finance, technology, media and chemical sectors&#8211;have been similarly targeted. We are currently in the process of notifying those companies</em>&#8220;.<br />
&nbsp;<br />
Subsequent external conjecture, comment and analysis has blamed unpatched vulnerabilities in Internet Explorer and also in Acrobat Reader, the malware involved has been identified both <a title="Wired online" href="http://www.wired.com/threatlevel/2010/01/google-hack-attack/" target="_blank">as</a> variants of the <a title="TrendLabs Threat Encyclopedia" href="http://threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_HYDRAQ.A&amp;VSect=P" target="_blank">Hydraq Trojan </a>and also as new malware, dubbed by McAfee as <a title="McAfee VIL" href="http://vil.nai.com/vil/content/v_253415.htm" target="_blank">Roarur.dr</a> and as <a title="TrendLabs Threat Encyclopedia" href="http://threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_PIDIEF.SHK" target="_blank">TROJ_PIDIEF.SHK</a>. The attack vectors have been identified as mail with malicious PDF attachments and drive-by downloads.<br />
&nbsp;<br />
Google, who were hit by the zero-day vulnerability in Internet Explorer, state that at least 20 other companies were victimised, and iDefense who have customers who were hit by the zero-day vulnerability in Acrobat Reader state that <a title="Wired online" href="http://www.wired.com/threatlevel/2010/01/google-hack-attack/" target="_blank">33 companies </a>were affected.<br />
&nbsp;<br />
The motivation for the attack has been described both as an attempt to steal intellectual property  and also as an attempt to breach the security of email accounts belonging to Chinese human rights activists. The attacks &#8220;appear to have been launched from at least six Internet addresses located in Taiwan&#8221; <a title="China warns of exit over hacking" href="http://online.wsj.com/article/SB126333757451026659.html" target="_blank">according to</a> James Mulvenon, director of the Center for Intelligence Research and Analysis at Defense Group Inc<br />
&nbsp;<br />
&#8220;Changing the world&#8221;? I say not.<br />
&nbsp;<br />
The attacks are not the first to use zero-day vulnerabilities, in fact we have most often seen zero-day exploits being first used in targeted attacks before becoming more widely spread and widely abused.<br />
 &nbsp;<br />
The attacks are not the first to use drive-by download or malicious PDF attachments to achieve their goal.<br />
 &nbsp;<br />
The attacks are not the most complex multi-component system yet seen, you want complex, <a title="The Heart of Koobface" href="http://us.trendmicro.com/imperia/md/content/us/trendwatch/researchandanalysis/the_20heart_20of_20koobface_final_1_.pdf" target="_blank">look at Koobface</a>!<br />
 &nbsp;<br />
This is <a title="Microsoft races out 'security patch' for Internet Explorer after Chinese fraudsters use flaw to hijack computers" href="http://www.dailymail.co.uk/news/article-1095266/Microsoft-races-security-patch-Internet-Explorer-Chinese-fraudsters-use-flaw-hijack-computers.html" target="_blank">not the first time </a>that warnings have been given to use alternative browsers until a patch becomes available.<br />
 &nbsp;<br />
This is <a title="Gh0stly Chinese Whispers" href="http://countermeasures.trendmicro.eu/gh0stly-chinese-whispers/" target="_blank">not the first time </a>that the finger has been pointed at China for a widespread globally distributed espionage attack.<br />
 &nbsp;<br />
There is no doubt that this attack, or these attacks are methodologically sophisticated. The bad guys were visibly successful at delivering their malicious payloads to the right people in the right companies to get access to things like source code and email accounts, but I don&#8217;t see anything here that changes the world.<br />
 &nbsp;<br />
Social engineering, lack of awareness of the threat landscape, a willingness to share too much information, the highly developed underground economy will all have contributed to the possibility and the success of these attacks.<br />
 &nbsp;<br />
What can companies and individuals do to try to avoid falling victim to these kinds of attack?</p>
<ul>
<li>Educate yourselves and your users, clicking a link is enough, opening a PDF is enough to infect you, even on a fully patched system.</li>
<p>&nbsp;</p>
<li>That being said make sure all applications and systems are fully patched, if that is not possible, use host-based intrusion prevention to &#8220;virtually patch&#8221; systems and to secure against zero-day exploits.</li>
<p>&nbsp;</p>
<li>When an unpatched vulnerability is identified be sure to follow vendor advice to minimise the risk as soon as possible.</li>
<p>&nbsp;</p>
<li>Encrypt valuable personal and intellectual property at file level, that way, even if it is stolen it is of limited value or use.</li>
<p>&nbsp;</p>
<li>Consider the deployment of data leakage prevention technologies that will recognise and stop sensitive content from leaving your network.</li>
<p>&nbsp;</p>
<li>Rethink your security model from an outside in approach, to an inside out one. Secure data, secure access rights, secure applications. Your perimeter only exists on a network diagram.</li>
<p>&nbsp;</p>
<li>At the risk of repeating myself, educate your users not to share too much personal information regarding employers, job roles, contact details. Currently far too many targets are far too visible.</li>
<p>&nbsp;</p>
<li>Don&#8217;t let Chicken Little run your security.</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/google-china-chicken-little-and-cyber-armageddon/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Pakistani National Response Center for Cyber Crimes&#8230; Hacked!</title>
		<link>http://countermeasures.trendmicro.eu/pakistani-national-response-center-for-cyber-crimes-hacked/</link>
		<comments>http://countermeasures.trendmicro.eu/pakistani-national-response-center-for-cyber-crimes-hacked/#comments</comments>
		<pubDate>Fri, 08 Jan 2010 11:45:13 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Site Compromise]]></category>
		<category><![CDATA[data leakage]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[compromise]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[hacktivism]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=1655</guid>
		<description><![CDATA[It seems to be the season for defacements and hacktivity. The week began with the Cross Site Scripting attack on the Spanish EU website and the defacement hack of Iranian President Ahmadinejad&#8217;s Official site and it closes with a high profile hack of the Pakistani National Response Center for Cyber Crimes, part of the Federal [...]]]></description>
			<content:encoded><![CDATA[<p>It seems to be the season for defacements and hacktivity. The week began with the <a title="Mr Bean comes out of retirement, takes over Spain" href="http://countermeasures.trendmicro.eu/mr-bean-comes-out-of-retirement-takes-over-spain/" target="_blank">Cross Site Scripting attack</a> on the Spanish EU website and the defacement <a title="Iranian President Ahmadinejad Official web site compromised" href="http://countermeasures.trendmicro.eu/iranian-president-ahmadinejad-official-web-site-compromised/" target="_blank">hack of Iranian President Ahmadinejad&#8217;s Official site </a>and it closes with a high profile hack of the <a title="hacked by zombie_ksa" href="http://www.nr3c.gov.pk/" target="_blank">Pakistani National Response Center for Cyber Crimes</a>, part of the Federal Investigation Authority.</p>
<p>The web site was compromised and defaced as below</p>
<div id="attachment_1656" class="wp-caption alignleft" style="width: 160px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/01/PakbugsFIA.png"><img class="size-thumbnail wp-image-1656" title="PakbugsFIA" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/01/PakbugsFIA-150x150.png" alt="" width="150" height="150" /></a><p class="wp-caption-text">Click for larger image</p></div>
<p> Unfortunately for the Pakistani FIA though this attack appears to go beyond a simple defacement. The hacker &#8220;zombie_ksa&#8221; also states on the defaced page</p>
<blockquote><p>&#8220;<strong><em>your whole database and e-mails are leaked &#8230;. i was really excited to read, see what the f__k is private in here lOl</em></strong>&#8220;</p></blockquote>
<p> At first glance this could well seem like idle l33t H4x0r bragging so I did a bit of digging to see if the boast could be substantiated. In a forum posting, zombie_ksa said</p>
<blockquote><p><em><strong>&#8220;I was Browsing! today </strong></em><a onclick="pageTracker._trackPageview ('/outgoing/http_propakistani_pk_2010_01_07_how_to_register_complaint_with_fia_cyber_crime_wing_');" rel="nofollow" href="http://propakistani.pk/2010/01/07/how-to-register-complaint-with-fia-cyber-crime-wing/" target="_blank"><em><strong>Propakistani.pk</strong></em></a><em><strong> So i saw post about&#8221; how to register complaint with fia cyber crime&#8221;! so i feel to check there Security, and i started Penetration Test On there Webserver, unfortunately I GOT access!! And they got Pwned!! !! thats Sounds crazy ! I got whole database! and e-mail Backup! everything!&#8221;</strong></em></p></blockquote>
<p> </p>
<p>The hacker then posted two screen shots, one of the hacked site and second one, below demonstrating his access to their email database (I have sanitised the email addresses here)</p>
<div id="attachment_1659" class="wp-caption alignleft" style="width: 588px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/01/FIAaccounts1.png"><img class="size-full wp-image-1659" title="Screen shot posted by the hacker" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/01/FIAaccounts1.png" alt="Screen shot posted by the hacker" width="510" height="367" /></a><p class="wp-caption-text">Screen shot posted by the hacker</p></div>
<p>So it seems that from an amateur penetration test a hacker has access at least to the full email database and possibly the backups, of a National Response Center for Cyber Crimes in a highly politically sensitive country. The forum post was made at 4 in the afternoon yesterday and the hack is still live at the time of writing. To say this hack has national security implications would not be overstating the matter.</p>
<p>Any organisation holding material this sensitive should, as a priority, make sure all Internet facing servers are hardened and fully patched, the servers should also be regularly audited, preferably daily to look for evidence of new vulnerabilities as they arise. Web application firewalls should be used to look for evidence of and block anomalous or malicious behaviour.</p>
<p>But perhaps most importantly emails dealing with matters this sensitive should not be connected with, or stored on your public web server and they should always be stored in a secure encrypted format.</p>
]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/pakistani-national-response-center-for-cyber-crimes-hacked/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Iranian President Ahmadinejad Official web site compromised</title>
		<link>http://countermeasures.trendmicro.eu/iranian-president-ahmadinejad-official-web-site-compromised/</link>
		<comments>http://countermeasures.trendmicro.eu/iranian-president-ahmadinejad-official-web-site-compromised/#comments</comments>
		<pubDate>Tue, 05 Jan 2010 10:21:28 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Site Compromise]]></category>
		<category><![CDATA[compromise]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[hacktivism]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=1628</guid>
		<description><![CDATA[Hot on the heels of the Cross Site Scripting attack on the Spanish EU Presidency site, the  official web site of President Ahmadinejad of Iran appears to have also been compromised. The site www.ahmadinejad.ir, otherwise known as &#8220;Mahmoud Ahmadinejad &#8211; The Official Blog &#8211; Tehran, Islamic Republic of Iran&#8220; has been compromised and is currently hosting [...]]]></description>
			<content:encoded><![CDATA[<p>Hot on the heels of the <a title="Mr Bean comes out of retirement, takes over Spain" href="http://countermeasures.trendmicro.eu/mr-bean-comes-out-of-retirement-takes-over-spain/" target="_blank">Cross Site Scripting attack</a> on the Spanish EU Presidency site, the  official web site of President Ahmadinejad of Iran appears to have also been compromised.</p>
<p>The site <a href="http://www.ahmadinejad.ir">www.ahmadinejad.ir</a>, otherwise known as &#8220;<em>Mahmoud Ahmadinejad &#8211; The Official Blog &#8211; Tehran, Islamic Republic of Iran</em>&#8220; has been compromised and is currently hosting a file called &#8220;owned.txt&#8221; at the URL <a href="http://www.ahmadinejad.ir/userfiles/file/owned.txt">http://www.ahmadinejad.ir/userfiles/file/owned.txt</a>. <strong>UPDATE</strong>: The file has now been removed, see screen capture below.</p>
<div class="wp-caption alignnone" style="width: 567px"><a href="http://www.trendmicro.co.uk/countermeasures/ahmad.png"><img title="Screen capture from compromised site" src="http://www.trendmicro.co.uk/countermeasures/ahmad.png" alt="Screen capture from compromised site" width="510" height="109" /></a><p class="wp-caption-text">Click preview for larger image</p></div>
<p>The file says</p>
<blockquote><p>&#8220;Dear God, In 2009 you took my favorite singer &#8211; Michael Jackson, my favorite actress &#8211; Farrah Fawcett, my favorite actor &#8211; Patrick Swayze, my favorite voice &#8211; Neda.<br />
Please, please, don&#8217;t forget my favorite politician &#8211; Ahmadinejad and my favorite dictator &#8211; Khamenei in the year 2010. Thank you.&#8221;</p></blockquote>
<p> </p>
<p>The reference to &#8220;favourite voice&#8221; is probably referring to Neda Agha-Soltan who was shot dead during the 2009 Iranian election protests.</p>
<p>No further details are yet available on how the compromise was effected or who is responsible, if more information comes to light I will update this blog post.</p>
]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/iranian-president-ahmadinejad-official-web-site-compromised/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Mr Bean comes out of retirement, takes over Spain</title>
		<link>http://countermeasures.trendmicro.eu/mr-bean-comes-out-of-retirement-takes-over-spain/</link>
		<comments>http://countermeasures.trendmicro.eu/mr-bean-comes-out-of-retirement-takes-over-spain/#comments</comments>
		<pubDate>Tue, 05 Jan 2010 10:01:34 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Site Compromise]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[compromise]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=1624</guid>
		<description><![CDATA[As reported by Reuters and the BBC, the official website set up by the Spanish government to mark it&#8217;s six-month presidency of the EU was briefly compromised yesterday afternoon.   Mischievous hackers reportedly took advantage of Cross-Site Scripting (XSS) vulnerabilities on www.eu2010.es and replaced an image of Spanish Prime Minister Jose Luis Rodriguez Zapatero with the smiling [...]]]></description>
			<content:encoded><![CDATA[<p>As reported by Reuters and the BBC, the official website set up by the Spanish government to mark it&#8217;s six-month presidency of the EU was briefly compromised yesterday afternoon.</p>
<div class="wp-caption alignnone" style="width: 480px"><img title="Mr Bean on Spanish site" src="http://estaticos03.cache.el-mundo.net/elmundo/imagenes/2010/01/04/1262610678_0.jpg" alt="" width="470" height="310" /><p class="wp-caption-text">Image Courtesy of El Mundo</p></div>
<p> </p>
<p>Mischievous hackers reportedly took advantage of Cross-Site Scripting (XSS) vulnerabilities on <a href="http://www.eu2010.es">www.eu2010.es</a> and replaced an image of Spanish Prime Minister Jose Luis Rodriguez Zapatero with the smiling face of Rowan Atkinson in his Mr. Bean guise, complete with friendly greeting &#8220;Hi there!&#8221; Perhaps the hackers were hoping the attack would go unnoticed, as apparently there is a physical resemblance between Mr. Zapatero and Mr. Bean (of course I couldn&#8217;t possibly comment). The compromise only lasted a few hours until the original content was restored, by 4pm GMT yesterday afternoon, the site administrators were <a title="El Mundo report - Spanish" href="http://www.elmundo.es/elmundo/2010/01/04/union_europea/1262610678.html" target="_blank">reportedly </a>working on a fix.</p>
<p>In this instance there does not appear to have been any malicious intent, but the dangers of XSS vulnerabilities should not be underestimated. Cross Site Scripting vulnerabilities allow attackers to inject code into innocent web pages in which it would not otherwise appear. This can be used to steal information such as logins or banking credentials, redirect users to malicious web sites or even to directly infect visitors to the site. The real problem is that many web site admins are unaware of the dangers, and <a title="More bad news for McAfee, HackerSafe certification" href="http://blogs.zdnet.com/security/?p=1068" target="_blank">even some security companies </a>continue to underestimate and downplay the importance of XSS vulnerabilities and attacks.</p>
<p>On an interesting side note, El Mundo also <a title="Moncloa gastará 23 millones en los preparativos del semestre europeo" href="http://www.elmundo.es/elmundo/2010/01/03/union_europea/1262518145.html" target="_blank">reported </a>recently that more then 12 million Euros had been spent on &#8220;technical assistance and security for the website of the Spanish Presidency [of the EU]&#8220;. Again, I couldn&#8217;t possibly comment, but <a title="Trend Micro SecureSite" href="http://uk.trendmicro.com/uk/products/sb/worry-free-secure-site/" target="_blank">SecureSite</a> and <a title="Trend Micro Web Application Security" href="http://uk.trendmicro.com/uk/products/enterprise/web-application-security/index.html" target="_blank">Web Application Security</a> are both an awful lot cheaper than that&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/mr-bean-comes-out-of-retirement-takes-over-spain/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Twitter (not) hacked by Iranian Cyber Army</title>
		<link>http://countermeasures.trendmicro.eu/twitter-not-hacked-by-iranian-cyber-army/</link>
		<comments>http://countermeasures.trendmicro.eu/twitter-not-hacked-by-iranian-cyber-army/#comments</comments>
		<pubDate>Fri, 18 Dec 2009 09:03:37 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Site Compromise]]></category>
		<category><![CDATA[Web 2.0]]></category>
		<category><![CDATA[compromise]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[hacktivism]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=1614</guid>
		<description><![CDATA[UPDATE: I was asked to talk to Channel 4 news in the UK about this incident this evening and they have been good enough to share the full content of my interview and a subsequent interview on the same subject with Tim Stevens from King&#8217;s College London. _________________________________________________________________________________________ Original post:   At about 6am GMT [...]]]></description>
			<content:encoded><![CDATA[<div class="mceTemp mceIEcenter" style="text-align: left;"><strong>UPDATE</strong>: I was asked to talk to Channel 4 news in the UK about this incident this evening and they have been good enough to share the full content of my interview and a subsequent interview on the same subject with Tim Stevens from King&#8217;s College London.</div>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="486" height="412" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="name" value="flashObj" /><param name="bgcolor" value="#FFFFFF" /><param name="flashvars" value="videoId=58082549001&amp;playerId=1184614595&amp;viewerSecureGatewayURL=https://console.brightcove.com/services/amfgateway&amp;servicesURL=http://services.brightcove.com/services&amp;cdnURL=http://admin.brightcove.com&amp;domain=embed&amp;autoStart=false&amp;" /><param name="src" value="http://c.brightcove.com/services/viewer/federated_f8/1184614595" /><embed type="application/x-shockwave-flash" width="486" height="412" src="http://c.brightcove.com/services/viewer/federated_f8/1184614595" flashvars="videoId=58082549001&amp;playerId=1184614595&amp;viewerSecureGatewayURL=https://console.brightcove.com/services/amfgateway&amp;servicesURL=http://services.brightcove.com/services&amp;cdnURL=http://admin.brightcove.com&amp;domain=embed&amp;autoStart=false&amp;" bgcolor="#FFFFFF" name="flashObj"></embed></object></p>
<div class="mceTemp mceIEcenter" style="text-align: left;">_________________________________________________________________________________________</div>
<div class="mceTemp mceIEcenter" style="text-align: left;"><strong>Original post</strong>:</div>
<div class="wp-caption aligncenter" style="width: 469px"><img title="Iranian Cyber Army" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/12/ICA1.png" alt="Banner from hacked site" width="459" height="76" /><p class="wp-caption-text">Banner from hacked site</p></div>
<p> </p>
<p>At about 6am GMT Twitter fell victim to a DNS hijacking attack by a group calling itself the &#8220;Iranian Cyber Army&#8221; (I wonder if they noticed the CIA irony)? The site was affected for the best part of an hour.</p>
<div class="wp-caption alignnone" style="width: 365px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/12/ICA.png"><img class=" " title="Full hacked page" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/12/ICA.png" alt="Full hacked page" width="355" height="349" /></a><p class="wp-caption-text">Full hacked page</p></div>
<p> </p>
<p>The initial attack has left many users confused and widespread belief that the Twitter servers themselves were compromised. This does not appear to have been the case. The latest update on the <a title="Twitter Blog" href="http://blog.twitter.com/" target="_blank">Twitter blog</a> says</p>
<blockquote><p>&#8220;<em>As we </em><a href="http://twitter.com/twitter/status/6789717364"><em>tweeted a bit ago</em></a><em>, Twitter&#8217;s DNS records were temporarily compromised tonight but have now been fixed. As some noticed, Twitter.com was redirected for a while but API and platform applications were working. We will update with more information and details once we&#8217;ve investigated more fully.&#8221;</em></p></blockquote>
<p> </p>
<p>This kind of DNS hijacking usually involves compromising the registrar responsible for the DNS records of the victim company, the attackers then make unauthorised changes to the DNS records. These changes mean that when you or I type a web site address into our browsers, we are directed not to the real web site but to a second site, set up by the hackers, in this case the &#8220;<em>Iranian Cyber Army&#8221;</em>. This has the net effect of making it look like, in this example, servers belonging to Twitter were compromised when in reality that was not the case.</p>
<p> </p>
<p>These sorts of attacks are usually limited to hacktivism activities like this one today, but imagine the potential to criminals if they could pull this off against any site requiring log in credentials, such as PayPal, eBay, MSN, Facebook. One has to wonder how quickly the attack would be noted if the dummy site was an exact replica of the victim and was simply there to harvest credentials and redirect the user then into the real site. This attack is called Pharming and currently mostly happens as a result of local malware modifying individual PCs, not through the compromise of global DNS records, but the potential is demonstrably there. Companies should be monitoring their DNS resolution on several servers to become aware as early as possible when this kind of attack takes place.</p>
<p> </p>
<p>Twitter was not the only web site affected by thsi compromise, a quick search revealed one other site displaying the same content.</p>
<div class="wp-caption alignnone" style="width: 470px"><img title="Google search result" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/12/mowjcampresult.png" alt="Google search result" width="460" height="105" /><p class="wp-caption-text">Google search result</p></div>
<p> </p>
<p>When it comes to attacking high profile targets it can often be that the registrar is the chink in the security armour. In fact <a title="Zone-H" href="http://zone-h.org/" target="_blank">Zone-H</a>, the defacement archive, has previously noted that registrars have been “<em>one of the main aims of the past months</em>“.</p>
<p> </p>
<p>If attacks like this can be said to serve any purpose at all, then perhaps they can serve as a reminder that we all need to absolutely ensure that our business partners meet our own high security standards, and that stands in both the on and offline worlds.</p>
]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/twitter-not-hacked-by-iranian-cyber-army/feed/</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
	</channel>
</rss>
