Wednesday, June 22, 2011
UK teenager arrested in global hacking probe
British police arrested a 19-year-old man in England on suspicions that he was linked to cyber attacks on the CIA, Britain’s anti-organised crime agency and Sony Corp.
As part of international efforts to catch the culprits behind a string of high-profile hacks, London’s Metropolitan Police, working with the US FBI, said they arrested the teenager in the town of Wickford, close to London.
The raid was linked to recent attacks on the websites of the US Central Intelligence Agency and the British police Serious Organised Crime Agency (SOCA), which targets organised crime in Britain and overseas, police said.
The suspect’s computer was being examined for data linked to Sony, whose websites have also been attacked.
The Lulz Security group of hackers has claimed responsibility for these attacks, but police declined to say whether the suspect was linked to that organization.
Lulz Security said on Twitter that the suspect was not a group leader. It said he was “at best, mildly associated” with the group and that Lulz Security used one of his servers to host one of several chatrooms.
In addition to attacks on Sony, the CIA and SOCA, Lulz Security has also claimed responsibility for targeting the US Public Broadcasting Service and Fox.com. Fox is a unit of News Corp.
But no hackers have claimed responsibility so far for some more serious recent security breaches including attacks on the International Monetary Fund, Lockheed Martin Corp, Citigroup Inc, Google Inc and Michaels Stores.
Lulz Security has also not claimed responsibility for two major attacks against Sony that captured personal data of more than 100 million customers, including 77 million PlayStation Network and Qriocity accounts.
Computer misuse and fraud
Lulz Security often uses so-called denial-of-service attacks to overwhelm websites with Internet traffic.
SOCA’s website, which is used purely for public information, went down for a short time on Monday before being brought back up. Hackers would not have had access to confidential data or information about ongoing operations, a SOCA spokesman said.
Police said the teenager, who was being held at a central London police station, was arrested on suspicion of computer misuse and fraud offences.
The London Force said forensic experts were examining “a significant amount of material” following searches at the home where the arrest took place.
“The arrest follows an investigation into network intrusions and Distributed Denial of Service (DDoS) attacks against a number of international business and intelligence agencies by what is believed to be the same hacking group,” the London force said.
Lulz Security said on Sunday that it has teamed up with Anonymous, a group of hacker activists, or “hactivists,” in a campaign to steal highly sensitive government data.
Anonymous has publicly targeted websites of companies that it says are foes of the “WikiLeaks” website and governments that it describes as oppresive.
Spanish police arrested on June 10 three suspected members of Anonymous.
Wednesday, June 1, 2011
US arms makers said bleeding secrets to cyber foes
Top Pentagon contractors have been bleeding secrets for years as a result of penetrations of their computer networks, current and former US national security officials say.
The US Defense Department, which runs its own worldwide eavesdropping, spying and code-cracking systems, says more than 100 foreign intelligence organisations have been trying to break into US networks.
Some of the perpetrators “already have the capacity to disrupt” US information infrastructure, Deputy Defense Secretary William Lynn, who is leading remedial efforts, wrote last fall in the journal Foreign Affairs.
Joel Brenner, the National Counterintelligence executive from 2006 to 2009, said most if not all of the big defense contractors’ networks had been pierced.
“This has been happening since the late ‘90s,” he told Reuters yesterday. He identified the main threats as coming from Russia, China and Iran.
“They’re after our weapons systems and R&D,” or research and development, said Brenner, now with the law firm of Cooley LLP in Washington.
Lockheed Martin Corp, the Pentagon’s No. 1 supplier by sales, said on Saturday that it had thwarted “a significant and tenacious” attack on its information systems network that it detected May 21. Ten days later, the company says its still working to restore full employee access to the network while maintaining the highest level of security.
Lockheed, which is also the US government’s top information technology provider, said it had become “a frequent target of adversaries from around the world.” A spokeswoman said it said it used the term “adversaries” only in a general sense.
Lockheed builds F-16, F-22 and F-35 fighter jets as well as Aegis naval combat system, THAAD missile defense and other big-ticket weapons systems sold to US allies. It has not disclosed which of its business units was targeted.
Cyber intruders were reported in 2009 to have broken into computers holding data on Lockheed’s projected US$380 billion-plus (RM1.151 trillion-plus) F-35 fighter programme, the Pentagon’s costliest arms purchase.
Other big Pentagon contractors include Boeing Co, Northrop Grumman Corp, General Dynamics Corp, BAE Systems Plc and Raytheon Co. Each of these declined to comment on whether it believed its networks had been penetrated.
James Miller, the principal deputy undersecretary of defense for policy, said last May that the United States was loosing terabytes of data in cyber attacks, enough to fill “multiple Libraries of Congress.” The world’s largest library, its archive totaled about 235 terabytes of data as of April, the Library of Congress says on its web site.
“The scale of compromise, including the loss of sensitive and unclassified data, is staggering,” Miller told a Washington forum.
US Senator Sheldon Whitehouse, who led a Senate Intelligence Committee cyber task force last year, said in March that cybercrime has put the United States “on the losing end of what could be the largest illicit transfer of wealth in world history.”
Retired Air Force General Michael Hayden, a former director of central intelligence and ex-head of the Pentagon’s National Security Agency, said no network was safe if it had Internet access.
“You can isolate a network, a classified network,” he told Reuters in an interview last year. “Maybe you can get a certain level of confidence that you are not penetrated. But if you are out there connected to the world wide web you are vulnerable all the time.”
Anup Ghosh, a former senior scientist at the Pentagon’s Defense Advanced Research Projects Agency, or DARPA, said there had been a string of intrusions into networks of US defense contractors, security companies and US government labs, including the US Energy Department’s Oak Ridge National Laboratory, since the start of this year.
The advantage is with the intruders, said Ghosh, who worked on securing military networks for DARPA from 2002 to 2006 and now heads Invincea, a software security company.
“We’ve failed to innovate in the area of information security,” he said in an email yesterday. “We’re fighting today’s battles with the equivalent of cold-war era defenses.”
Thursday, February 17, 2011
Canada hit by cyberattack from China computers: CBC
The Canadian government was hit by an unprecedented cyber attack from Chinese-based computers last month that penetrated two key economic ministries, the Canadian Broadcasting Corp reported yesterday.
The CBC cited sources as saying the hackers broke into computer systems at the Finance Department and Treasury Board. Once the attack was detected, Internet access in both ministries was cut off.
The Finance Department is preparing the federal budget, which will be delivered next month.
The CBC said the hackers had apparently managed to take control of computers in the offices of senior government executives as part of a scheme to steal the passwords that unlock entire government data systems.
A spokesman for Treasury Board Minister Stockwell Day said officials had detected an unauthorised attempt to access the ministry’s computer networks.
“There are no indications that any data relating to Canadians was compromised,” he said in an e-mail. He did not say whether the attacks had been traced back to Chinese servers, as the CBC reported.
No one from the office of Finance Minister Jim Flaherty responded to a request for comment.
Chinese Foreign Ministry spokesman Ma Zhaoxu denied there was a China link to the hacking.
“What you mentioned is purely fictitious and has an ulterior motive,” he told a regular news briefing in Beijing when asked about the accusations.
“China attaches great importance to computer security and consistently opposes and cracks down on hacking activities according to relative laws and regulations,” Ma added. “Hacking is an international problem and China is affected also.”
Canada’s spy service complains regularly about what it says is industrial espionage by China and other states.
US cables released by WikiLeaks show diplomats blaming China for hacking into Google systems that prompted the Internet giant to pull back from mainland China.
In 2009, The Wall Street Journal said cyber spies who appeared to be based in China had breached the Pentagon’s Joint Strike Fighter project.
The CBC story comes at an awkward time for Canada’s minority Conservative government, which has markedly toned down its criticism of China’s human rights record as it tries to boost bilateral trade ties.
Sunday, May 9, 2010
U.S. should prepare for a cyber attack that will ruin the country in just 15 MINUTES, expert warns
Former head of counterterrorism security has warned of an impending cyber attack
The U.S. should prepare for a cyber attack that could cause destruction on the scale of 9/11 in less than 15 minutes, a leading anti-terrorism expert has warned.
Richard Clarke, a former adviser to both Bill Clinton and George W. Bush, suggests that the lack of security in place against such an attack could lead to an 'electronic Pearl Harbor'.
Writing in his new book Cyber War: The Next National Security Threat, penned with Robert Knake, Mr Clarke says: 'The biggest secret about cyber war may be that at the very same time the U.S. prepares for offensive cyber war, it is continuing policies that make it impossible to defend effectively from cyber attack.'
In the book, Mr Clarke suggests that a cyber attack would first target the Pentagon's computer network, before affecting the rest of the country's electrical grids.
He writes: 'It could blow up pipelines. It could damage electrical power grids. It could confuse financial records, so that we would not know who owned what.'
Mr Clarke says the cyber war could be started by an enemy country of the U.S. or a lone hacker.
He insists that while the U.S. government has introduced measures to protect the country's computer networks, they will not be enough to prevent the attack.
Mr Clarke, who warned of the dangers of terrorist group Al-Qaeda during his time as the former head of counterterrorism security, also said the cyber attack could have similar consequences to 9/11.
However, U.S. President Barack Obama's administration appears to disagree with Mr Clarke's prediction.
Howard Schmidt, Obama's recently appointed cyber expert, said in an interview with Wired.com in March: 'There is no cyber war. I think that is a terrible metaphor and I think that is a terrible concept.
'As for getting into the power grid. I can't see that that's realistic.'
Tuesday, December 22, 2009
US appoints Howard Schmidt as cybersecurity chief

President Obama emphasised cybersecurity while campaigning
The White House has appointed its cyber tsar, following a seven month search.
Howard Schmidt, a former eBay and Microsoft executive who advised President Bush, was appointed after others turned down the job.
Mr Schmidt has been set the task of uniting various disparate agencies and organisations to shore up the country's defence against cyber attack.
In May this year, President Obama pledged to personally appoint someone to the post.
In a letter posted on the White House website, John Brennan, assistant to the President for homeland security and counterterrorism said that protecting the internet was "critical to our national security, public safety and our personal privacy and civil liberties".
"It's also vital to President Obama's efforts to strengthen our country, from the modernisation of our health care system to the high-tech job creation central to our economic recovery."
Mr Schmidt would have "regular access to the President and serve as a key member of his National Security Staff", he said.
The White House's acting cyber-security head, Melissa Hathaway, stood down in August after complaining that the post did not allow her to implement necessary changes.
RELATED POSTS:-
- Obama brings broad agenda to meeting with China's Hu-US owns $1 trillion in debts to China.Obama in a barrel.
- President Obama in China
- First picture of heroine of Fort Hood who took down gunman-Confront the Maj Hasan directly and open fire.Stopped carnage gun rampage.
- Democrats claim big victory on health care-cost in 10 years time $1.05 trilion promised health coverage of 96% of citizen
- After Afghan vote, an awkward task for Obama
- US appoints Howard Schmidt as cybersecurity chief
- Twitter and Facebook website got crashed. FAQ DoS Attack
- FBI, Police Raid New York Homes in Terror Probe
- Obama: US, Russia 'quite close' on new arms treaty
- Obama says 'unprecedented' deal reached on climate-but officials admit is not enought
- Lieberman Stands in Middle of Health Care Debate
- US Federal going to spend more than $150 billion to jolt economy. Obama urges major new stimulus, jobs spending.-Obama eyes repaid gov't bank loans
- EPA's Carbon Decision Gives Obama Copenhagen Tool-Official declared Co2 is dangerous to mankind.-Backlash fear of expensive energy and cut jobs
- Barack Obama’s deadline to bring troops home from Afghanistan starts to slip
- Michele Obama show off lavish decoration for white house for white christmas.
- Obama send 30 000 soldier more so that by July 2011 can start withdrawal soldiers from Afganisthan.Congress reluctantly will support.
- Gordon brown faces critism of lying about withdrawal from Irag to British , as Obama send 30 000 troops more to Afganisthan
Friday, August 7, 2009
Twitter and Facebook website got crashed. FAQ DoS Attack

-In a clear and simple way, this Cisco graphic shows the relationship of the parties in a DDOS attack. -
At 9 a.m., millions of users of Twitter.com found themselves unable to access the microblogging Web site, the modern version of the telephone party line through which more than 40 million people announce what they are doing, reading, eating and thinking at any given moment.
Undaunted, the rejected Twitterers trooped to Facebook.com, the social networking site that has more than 200 million users, which has "status updates" that mimic Twitter feeds. But before users could begin to type, "Is sad that Twitter is down," a terrible and panic-inducing discovery: Facebook was down, too.
Kathleen Loughlin, a spokeswoman for Facebook, also cited a denial-of-service attack, which she said "resulted in degraded service for some users." She added that no user data were at risk during the attack and promised that Facebook was "continuing to monitor the situation to ensure that users have the fast and reliable experience they've come to expect from Facebook."
"On this otherwise happy Thursday morning, Twitter is the target of a denial-of-service attack," Twitter co-founder Biz Stone wrote on the official Twitter blog. "Attacks such as this are malicious efforts orchestrated to disrupt and make unavailable services such as . . . Twitter for intended customers or users. We are defending against this attack now."
The first big DDoS attack, in February 2000 took down some of the Web's most popular sites for hours, including Yahoo, CNN, eBay, Amazon.com, Buy.com, and E*Trade. The U.S. Federal Bureau of Investigation promptly held a news conference to discuss the disruption to the Internet and eventually tracked down the perpetrator, 15-year-old "Mafiaboy," after he bragged about it to friends online.
Mafiaboy was most likely trying to get attention, like script kiddie hackers do when they deface Web sites. Other attackers have different agendas. For instance, there are politically motivated DDoS attacks, such as those involving Russian and Georgian sites last year. Estonia sites were attacked in 2007. Meanwhile, the origin of recent DDoS attacks targeting U.S. government sites and sites in South Korea remain a mystery.
---------
Twitter users were unable to log in for several hours after the social networking site became the victim of a cyber attack.
-----
What's a denial-of-service attack?
A denial-of-service (DoS) attack is any effort designed to interfere with access to a Web site or Internet service. A common method of attack involves flooding a target server with so many communications requests that legitimate traffic can not get through. This can shut down or slow down the site temporarily.
Web sites aren't the only things that can be targeted in DoS attacks. Unplugging someone's computer is a very basic type of DoS attack.
What's a distributed-denial-of-service (DDoS) attack?
Because Web sites are built to handle a lot of traffic, it can take millions of simultaneous communications requests to have enough affect on the performance of the server for an attack. In a DDoS attack, tens of thousands or even millions of computers are used to send traffic to the target site all at the same time and repeatedly."It's a bit like 15 fat men trying to get through a revolving door at the same time--nothing can move."
The hijacked PCs that are used in a DDoS attack comprise a botnet. The individual computers are called "bots," "zombies" or "slaves" and are controlled remotely by the "master" attacker. The attacker relays instructions to the bots via a command-and-control server, typically using IRC (Internet Relay Chat). Botnets are also used to distribute spam. Some newer botnets, like one created by a version of Conficker, relay instructions via peer-to-peer.
How many bots are needed to take down a Web site?
The number depends on how much resources, servers and bandwidth, the target site has. It can take 25,000 to 50,000 bots to cripple a typical site and as few as 10,000 or less for a small Web site, according to Kevin Stevens, a security researcher for SecureWorks' Counter Threat Unit.
It's difficult to know exactly how big any particular botnet is and guesses vary widely. For example, estimates of the Conficker botnet ranged from 500,000 PCs to 10 million.
What kind of damage can a DoS attack do?
A DoS can make a Web site completely inaccessible to anyone for a period of time, like the most recent attack did with Twitter. Or it can be equivalent to a hiccup, slowing down page loads or affecting only part of the site.
Sites that aren't in the direct line of fire can also be affected. For example, if a company that is attacked is hosting images or content that is fed to other sites, those other sites may have trouble. So many sites feature Twitter updates that it's likely some of those associated sites were impacted when Twitter was down and the ancillary site's requests to get updates were ignored.
How can a DDoS be prevented or stopped?
In 2001, the White House was able to thwart a DDoS attack that was programmed into the code of the Code Red virus by moving the site away from the targeted IP address.
And in 2005, Microsoft sidestepped a DDoS that was going to be triggered by PCs infected with the Blaster virus by killing the targeted IP address.
A company can reduce its risk by buying plenty of servers and bandwidth, and hosting content on backup servers. Companies can also limit the number of connections that the Web server allows at any one time and set the firewall to block certain types of data that are used in DDoS attacks, said SecureWorks' Stevens.
What can individuals do to prevent their computers from being used in a DDoS attack?
To keep malware off a computer, people should install the latest operating system and application patches, update their antivirus and other security software, consider using auto-updates for browsers and be careful about opening up attachments and visiting Web sites.