Monday, 2 November 2009
DeepSec 2009
Forwarded from: DeepSec Conference - Announcement
== DeepSec In-Depth Security Conference 2009 "TripleSec" ==
This is a reminder for the third DeepSec conference, taking place between 17th and 20th November at the Imperial Riding School Renaissance Hotel.
== Schedule ==
The schedule of all presentations can be found on our web site:
Random speaker and content from the schedule:
Karsten Nohl from H4RDW4RE will present the latest development on his project to break A5/1 with the help of pre-computed tables as announced at HAR 2009. Karsten Nohl says, that a public PoC on cracking GSM"s encryption is necessary to raise awareness about the risks of sending sensitive information over GSM networks. In March 2008 the finalisation of A5/1 rainbow tables was announced but never released in public, the first academic attacks date even back to 1997. Today it is believed that agencies and well-funded organizations have access to efficient A5/1 crackers. Publishing a practical attack in public will give a better awareness about the situation of an encryption scheme that was designed and developed in the 1980ies and still used today.
More talks at the conference! - https://deepsec.net/register/
== Sponsors ==
We would like to thank our sponsors that have supported the conference:
Microsoft, Sourcefire, Global Knowledge, The British Bookshop, Viennese Chamber of Commerce and CERT.at.
== About DeepSec ==
DeepSec IDSC is an annual European two-day in-depth conference on computer, network, and application security. The DeepSec Conference will be held from November 17th to 20th 2009 in Vienna, and aims to bring together the world's leading security professionals from academics, government, industry, and the underground hacking community.
In addition to the conference with presentations we will offer a selection of two-day intense security training courses before the main conference.
DeepSec is a non-product, non-vendor-biased conference. Our aim is to present the best research and experience from the fields' leading experts.
Best regards,
DeepSec In-Depth Security Conference organisation team:
Michael Kafka, DeepSec GmbH
René Pfeiffer, DeepSec GmbH
Initiated by Paul Böhm, DeepSec GmbH
Contact: https://deepsec.net/contact/
Swedish Police DDOSED
By Shaun Nichols in San Francisco
V3.co.uk
31 Oct 2009
A denial of service attack crippled the web site for Sweden's police administration earlier this week.
The attacks flooded the site with information requests, causing the servers to crash and take the site offline. According to Swedish news site The Local, at its peak the attack caused traffic to spike from 800 requests per second to more than 400,000 requests per second.
In addition to crippling the police site, the attack also took down as many as 40 media sites also being hosted by service provider Basefarm.
The Local reported that as of Friday evening Swedish time, neither the hosting firm nor police investigators knew who was behind the attacks or their motive for taking the sites down.
In recent years, distributed denial of service attacks have grown increasingly popular as a form of both protest and cyber warfare.
Multiple computers and botnets are used to flood sites with traffic, causing servers to down and taking sites offline for extended periods of time.
site founder DDOSING?
By Dan Goodin in San Francisco
The Register
30th October 2009
Federal prosecutors have accused a co-founder of YouSendIt.com of repeatedly launching web attacks against the popular upload site.
Khalid Shaikh, who was CEO and CTO of the California-based company until he left in 2006, used an Apache benchmarking program to flood YouSendIt servers with more traffic than they could handle, according to documents filed in US District Court in Northern California. Prosecutors allege Shaikh launched the denial of service attacks on four occasions, starting in December 2008 and ending the following June.
"By transmitting the ApacheBench program to YouSendIt's servers, Shaikh was able to overwhelm the server's capabilities and render it unable to handle legitimate network traffic," an indictment filed Wednesday stated.
Shaikh told The Register the allegations are untrue.
"I'm very excited about being able to talk to a judge," said Shaikh, who said he's 32 years old. "They spin a very good story."
Shaikh said he and a brother co-founded YouSendIt in 2004 and ended up leaving the company following differences with the company's investors and remaining executives.
The Register
30th October 2009
Federal prosecutors have accused a co-founder of YouSendIt.com of repeatedly launching web attacks against the popular upload site.
Khalid Shaikh, who was CEO and CTO of the California-based company until he left in 2006, used an Apache benchmarking program to flood YouSendIt servers with more traffic than they could handle, according to documents filed in US District Court in Northern California. Prosecutors allege Shaikh launched the denial of service attacks on four occasions, starting in December 2008 and ending the following June.
"By transmitting the ApacheBench program to YouSendIt's servers, Shaikh was able to overwhelm the server's capabilities and render it unable to handle legitimate network traffic," an indictment filed Wednesday stated.
Shaikh told The Register the allegations are untrue.
"I'm very excited about being able to talk to a judge," said Shaikh, who said he's 32 years old. "They spin a very good story."
Shaikh said he and a brother co-founded YouSendIt in 2004 and ended up leaving the company following differences with the company's investors and remaining executives.
money mules warning
By Kevin Poulsen
Threat Level
Wired.com
October 29, 2009
Bank customers are increasingly being duped into acting as 'money mules'
for hackers, unwittingly laundering cash stolen from business bank accounts, the Federal Deposit Insurance Corporation warned the nation's financial institutions on Thursday.
Using specialized Trojan horse malware, cybercrooks have been intercepting web-banking credentials from the computers of small and midsize businesses, and then initiating wire transfers to mules around the country. The mules are consumers who've been lured into fake work-at-home scams, in which their employment involves receiving money transfers and then forwarding the funds to Eastern Europe, either directly or through other mules.
The scheme has exploded in the last year, with the FBI estimating losses at $40 million so far, according to a recent story from WashingtonPost.com reporter Brian Krebs, who's been closely following the attacks.
Wednesday, 28 October 2009
Facebook Password Reset Confirmation Spam — Bredolab, Zbot, Adware
Another cybercriminal group is abusing the face of Facebook in another malware spam blast, fooling users to install banking password stealing malware and adware on their systems.
The message of the email claims to arrive from “The Facebook Team”, but in fact, the spam is spoofed and not from the team at all:
“Because of the measures taken to provide safety to our clients, your password has been changed.
You can find your new password in attached document.
Thanks,
The Facebook Team”
The real Facebook Team maintains threat-related information, “what-to-do-if” information, and security related stuff here.
The emails maintain an attachment that may have various names. Here are a some of the attachment names that when unzipped and run, ThreatFire has protected its community against in the past day:
Facebook_Password_e9081.zip
FACEBOOK_PASSWORD_52132.ZIP
Facebook_Password_6dd19.zip
Facebook_Password_4cf91.zip
FACEBOOK_PASSWORD_50573-1.ZIP
Facebook_Password_c92dd.zip
FACEBOOK_PASSWORD_7A343.zip

So what is being sent out? Unfortunately, the AV vendors that are starting to detect this variant do not always identify what they are detecting accurately (lucky that they are detecting it at all!). But in the end, the zipped attachment contains an armored downloader. Some of the spammed downloader executables drop multiple variants of multiple families. Adware, spyware, spambots, why not all of them? They are all money makers for this malware distribution group.
The malware package, in some cases, includes the highly active and highly malicious Zbot family. It seems that the Bredolab protector and dropper/downloader in active development has proven to be effective enough against AV scanner detections, so the crimeware groups are re-wrapping their zbot malware with it. Also interesting is that these two families of malware have recently been distributed by groups that implement methods to remove the other bot from victim systems. It’s been described as another “War of the Bots” with Bredolab v. Zbot. Clearly, this active cybercrime group is a separate one with different aims and no internal wars.

Koobface, Bredolab, and Zbot-distributing cybercrime groups all spoof Facebook and other highly popular social networking sites to deliver their malware to victim systems. Avoid the confusion and install a behavioral based layer of protection like ThreatFire that reliably and effectively prevents Bredolab, Zbot, and other highly dangerous malware families. Surf where you want, PC Tools Facebook group here.
The message of the email claims to arrive from “The Facebook Team”, but in fact, the spam is spoofed and not from the team at all:
“Because of the measures taken to provide safety to our clients, your password has been changed.
You can find your new password in attached document.
Thanks,
The Facebook Team”
The real Facebook Team maintains threat-related information, “what-to-do-if” information, and security related stuff here.
The emails maintain an attachment that may have various names. Here are a some of the attachment names that when unzipped and run, ThreatFire has protected its community against in the past day:
Facebook_Password_e9081.zip
FACEBOOK_PASSWORD_52132.ZIP
Facebook_Password_6dd19.zip
Facebook_Password_4cf91.zip
FACEBOOK_PASSWORD_50573-1.ZIP
Facebook_Password_c92dd.zip
FACEBOOK_PASSWORD_7A343.zip

So what is being sent out? Unfortunately, the AV vendors that are starting to detect this variant do not always identify what they are detecting accurately (lucky that they are detecting it at all!). But in the end, the zipped attachment contains an armored downloader. Some of the spammed downloader executables drop multiple variants of multiple families. Adware, spyware, spambots, why not all of them? They are all money makers for this malware distribution group.
The malware package, in some cases, includes the highly active and highly malicious Zbot family. It seems that the Bredolab protector and dropper/downloader in active development has proven to be effective enough against AV scanner detections, so the crimeware groups are re-wrapping their zbot malware with it. Also interesting is that these two families of malware have recently been distributed by groups that implement methods to remove the other bot from victim systems. It’s been described as another “War of the Bots” with Bredolab v. Zbot. Clearly, this active cybercrime group is a separate one with different aims and no internal wars.

Koobface, Bredolab, and Zbot-distributing cybercrime groups all spoof Facebook and other highly popular social networking sites to deliver their malware to victim systems. Avoid the confusion and install a behavioral based layer of protection like ThreatFire that reliably and effectively prevents Bredolab, Zbot, and other highly dangerous malware families. Surf where you want, PC Tools Facebook group here.
For Scareware, Every Day is Halloween
Halloween is all about tricks, treats and pretending to be something your not. Scareware must think every day is Halloween.

Computer experts are reporting that scareware is on the rise. Scareware - a sneaky hacker technique used to steal personal information and spread viruses - is being found in more and more places online and even on trusted sites, like the New York Times.
"The recent scareware attacks are cropping up everywhere and can be found on even the most trusted Web sties online," said Alison Southwick, BBB spokesperson. "The threat of scareware undermines consumer trust in compromised Web sites, and on the Internet in general, but there are steps computer useres can take to protect themselves."
How Scareware Tricks and Treats
Scareware usually presents itself as a pop up window on your computer that looks like it is from your computer. It gives some message that your computer has been infected with a virus that needs to be removed. Often the message tells you to go to the link provided to purchase and download anti-virus software. Once the software is purchased the download begins. Unfortunately, it is not anti-virus software that is being downloaded, but more viruses and malware.If that weren't bad enough, now the hackers have your credit care information too.
This senario is playing out all over the internet. It was in mid-September that visitors to the New York Times web site started getting the infected pop up window. The New York Times traced the infected window back to an unauthorized ad. They later found out that the ad space was sold to hackers posing as Vonage.
But The New York Times is not the only site being affected and pop up windows are only half the story with scareware. According to Computer World Magazine, hackers are also "poisoning Google search results." Hackers monitor popular search topics and then create infected web pages with related content. They work to get those to the top of Google search results and when someone clicks a link in the search results - the infamous pop up window appears.
How to Protect Your Computer
Fortunately there are steps that you can take to protect your computer from scareware:- Never let your guard down. It is a fact that scareware can show up on even the most trusted sites, Google, Twitter, The New York Times, etc.
- Protect your computer. Keep your operating system updated and install a good quality anti-virus program. We recommend the following packages: Norton 360
(includes backup and other features), Norton Internet Security 2010 (good all around option),
or avast! (free and good), and keep it up to date. Also make sure that all security patches and updates are installed for your webrowser and programs like Adobe Flash Player.
- Take immediate action during an attack. If a scareware window opens up force close it using the task manager and then run your trusted anti-virus software.
UPDATE: An article from Wired magazine's Threat Level blog sheds more light on how web sites are being targeted for malware distribution:
Web ads have become much more advanced over the years and many now include scripts that provide data tracking and other functions. Because of this, crooks are working to have their "ads" run on popular websites. Their ads also contain scripts, but the code displays scareware instead of tracking clicks or views.
In the article, Gawker Media - a major blog network of sites like Gizmodo, LifeHacker, Jalopnik and others - was targeted for ad placement, but fortunately Gawker has a team of geeks that digs into the code of any ads and confirms that it contains no malicous code. I'm guessing the NY Times now is enforcing a similar policy (yep, it is now).
Heaven help us when we visit sites that have no such team of geeks to protect us from malicious ads...
Subscribe to:
Posts (Atom)


