Wednesday, June 22, 2011
UK teenager arrested in global hacking probe
British police arrested a 19-year-old man in England on suspicions that he was linked to cyber attacks on the CIA, Britain’s anti-organised crime agency and Sony Corp.
As part of international efforts to catch the culprits behind a string of high-profile hacks, London’s Metropolitan Police, working with the US FBI, said they arrested the teenager in the town of Wickford, close to London.
The raid was linked to recent attacks on the websites of the US Central Intelligence Agency and the British police Serious Organised Crime Agency (SOCA), which targets organised crime in Britain and overseas, police said.
The suspect’s computer was being examined for data linked to Sony, whose websites have also been attacked.
The Lulz Security group of hackers has claimed responsibility for these attacks, but police declined to say whether the suspect was linked to that organization.
Lulz Security said on Twitter that the suspect was not a group leader. It said he was “at best, mildly associated” with the group and that Lulz Security used one of his servers to host one of several chatrooms.
In addition to attacks on Sony, the CIA and SOCA, Lulz Security has also claimed responsibility for targeting the US Public Broadcasting Service and Fox.com. Fox is a unit of News Corp.
But no hackers have claimed responsibility so far for some more serious recent security breaches including attacks on the International Monetary Fund, Lockheed Martin Corp, Citigroup Inc, Google Inc and Michaels Stores.
Lulz Security has also not claimed responsibility for two major attacks against Sony that captured personal data of more than 100 million customers, including 77 million PlayStation Network and Qriocity accounts.
Computer misuse and fraud
Lulz Security often uses so-called denial-of-service attacks to overwhelm websites with Internet traffic.
SOCA’s website, which is used purely for public information, went down for a short time on Monday before being brought back up. Hackers would not have had access to confidential data or information about ongoing operations, a SOCA spokesman said.
Police said the teenager, who was being held at a central London police station, was arrested on suspicion of computer misuse and fraud offences.
The London Force said forensic experts were examining “a significant amount of material” following searches at the home where the arrest took place.
“The arrest follows an investigation into network intrusions and Distributed Denial of Service (DDoS) attacks against a number of international business and intelligence agencies by what is believed to be the same hacking group,” the London force said.
Lulz Security said on Sunday that it has teamed up with Anonymous, a group of hacker activists, or “hactivists,” in a campaign to steal highly sensitive government data.
Anonymous has publicly targeted websites of companies that it says are foes of the “WikiLeaks” website and governments that it describes as oppresive.
Spanish police arrested on June 10 three suspected members of Anonymous.
Wednesday, June 15, 2011
Hackers break into US Senate computers
The US Sergeant at Arms Office confirmed yesterday that the Senate’s website had been hacked this past weekend and that it had ordered a review of all Senate computer sites.
“Although this intrusion is inconvenient, it does not compromise the security of the Senate’s network, its members or staff,” a Sergeant at Arms Office official said. “Specifically, there is no individual user account information on the server supporting senate.gov that could have been compromised.”
The revelation came after a loosely aligned group of computer hackers calling themselves Lulz Security said they broke into the US Senate’s computer network.
Lulz Security, who have hacked into Sony’s website and the US Public Broadcasting System, posted online a list of files that appear not to be sensitive but indicate the hackers had been into the Senate’s computer network.
“We don’t like the US government very much,” Lulz Security said at the top of their release. “This is a small, just-for-kicks release of some internal data from Senate.gov — is this an act of war, gentlemen? Problem?”
The comment refers to reports that the US military had decided that it could respond to cyber attacks from foreign countries with traditional military force.
Senate staffers asked about the hack were unaware of it.
“They (Lulz) certainly demonstrated that they were in and they found the file server,” said Stewart Baker, a former cyber official at the Department of Homeland Security.
Tuesday, June 7, 2011
China paper warns Google may pay price for hacking claims
Google says China-based hackers were responsible for a spate of phishing attacks on Gmail users. —
Google has become a “political tool” vilifying the Chinese government, an official Beijing newspaper said today, warning that the US Internet giant’s statements about hacking attacks traced to China could hurt its business.
The tough warning appeared in the overseas edition of the People’s Daily, the leading newspaper of China’s ruling Communist Party, indicating that political tensions between the United States and China over Internet security could linger.
Last week, Google said it had broken up an effort to steal the passwords of hundreds of Google email account holders, including US government officials, Chinese human rights advocates and journalists. It said the attacks appeared to come from China.
The Chinese Foreign Ministry rejected those accusations, and the party newspaper warned Google against playing a risky political game.
By saying that Chinese human rights activists were among the targets of the hacking, Google was “deliberately pandering to negative Western perceptions of China, and strongly hinting that the hacking attacks were the work of the Chinese government,” the People’s Daily overseas edition, a small offshoot of the main domestic paper, said in a front-page commentary.
“Google’s accusations aimed at China are spurious, have ulterior motives, and bear malign intentions,” said the commentary, written by an editor at the paper.
“Google should not become overly embroiled in international political struggle, playing the role of a tool for political contention,” the paper added.
“For when the international winds shift direction, it may become sacrificed to politics and will be spurned by the marketplace,” it said, without specifying how Google’s business could be hurt.
A Google spokeswoman said the US firm had no comment on the remarks.
The latest friction with Google could bring Internet policy back to the foreground of US-China relations, reprising tensions last year when the Obama administration took up Google’s complaints about hacking and censorship from China.
Google partly pulled out of China after that dispute. Since then, it has lost more share to rival Baidu Inc in China’s Internet market, the world’s largest by user numbers with more than 450 million users.
Google said last week that the hacking attacks appeared to come from Jinan, the capital of China’s eastern Shandong province and home to an intelligence unit of the People’s Liberation Army.
US Defense Secretary Robert Gates over the weekend warned that Washington was prepared to use force against cyber-attacks it considered acts of war.
In February, overseas Chinese websites, inspired by anti-authoritarian uprisings across the Arab world, called for protests across China, raising Beijing’s alarm about dissent and prompting tightened censorship of the Internet.
China already blocks major foreign social websites such as Facebook and Twitter.
Friday, April 1, 2011
Malicious attack hits a million web pages
More than one million website pages have been hit by a sophisticated hacking attack that injects code into sites that redirect users to a fraudulent software sales operation.
The so-called “mass-injection” attack, which experts say is the largest of its kind ever seen, has managed to insert malicious code into websites by gaining access to the servers running the databases behind the Internet, according to the technology security company that discovered it.
Websense, which first found evidence of the attack earlier this week, has called it ‘LizaMoon,’ after the site to which the malicious code first directed its researchers.
Users can see that they are being redirected when they attempt to visit an infected address, and can close the window with no ill effects, said Patrik Runald, a senior manager of security research at Websense.
The attack has largely affected small websites so far, he said, with no evidence that popular corporate or government websites have been compromised.
If users do not close the window after typing an infected address, or clicking an infected link, they are redirected to a page showing a warning from ‘Windows Stability Center’ — posing as a Microsoft Corp security product — that there are problems with their computer and they are urged to pay for software to fix it.
Websense said the site appeared to be set up by sophisticated fraudsters out to make money, but it was not clear whether the site also planted malicious software on users’ computers if they made a purchase on the site, or if the operation was linked to an identity theft scam.
The presentation of the bogus website, as shown by Websense, is high quality but clearly fraudulent. Microsoft has no product called ‘Windows Stability Center”. The company did not immediately have a comment on the attack.
Websense said some third-party Web addresses containing information about podcasts available on Apple Inc’s iTunes service had been compromised, but said Apple appeared to have prevented the malicious links from working. Apple did not respond to a request for comment.
The attack may take some time to be tamed, warned Runald, as researchers first have to identify the software being compromised, and then website operators have to install updated software.
“Attacks like this tend to stay for a very long time,” he said. “Once they are onto something, it tends to stay with us. This LizaMoon event won’t disappear over a day.”
Saturday, January 29, 2011
UK police arrest WikiLeaks backers for Web attacks
British police arrested five young men yesterday as they and US authorities conducted searches as part of a probe into Internet activists who carried out cyber attacks against groups they viewed as enemies of the WikiLeaks website.
“The arrests were related to recent ‘distributed denial of service’ (DDoS) attacks by an online group calling themselves Anonymous,” London police said in a statement.
In the United States, the Federal Bureau of Investigation said that agents executed more than 40 search warrants as part of its investigation and that the attacks were facilitated by software the group made available for free on the Internet.
“The FBI is working closely with its international law enforcement partners and others to mitigate these threats,” the agency said in a statement, adding that there were other, unspecified investigative and enforcement actions in the Netherlands, Germany and France.
WikiLeaks, which was founded by Australian-born Julian Assange, has disclosed classified US diplomatic dispatches which included candid and embarrassing assessments of world leaders as well as classified documents related to the wars in Iraq and Afghanistan.
In addition to the probe into the cyber attacks, US authorities have been investigating the leak of the documents themselves and their prime suspect has been a former US Army intelligence analyst, Bradley Manning.
Internet activists last month carried out a series of online assaults against institutions they viewed as enemies of WikiLeaks, temporarily bringing down the websites of credit-card giants Visa and MasterCard, Amazon.com and of the Swedish government.
Sweden wants Assange extradited from Britain so he can answer questions over sexual assault allegations.
Officers from a specialist London police unit dealing with online crime detained the five males, aged from 15 to 26, in raids at homes in central and southern England.
Dutch police last month arrested two teenagers suspected of involvement in the online campaign. They face trial later this year.
A DDoS attack consists of swamping the resources of a computer such as a server to make it unavailable to users.
The maximum penalty in Britain for offences of computer misuse is 10 years imprisonment and a fine of £5,000 (RM24,272).
In the United States, such a cyber attack carries a maximum punishment of 10 years in prison and significant fines.
Wednesday, October 13, 2010
World's 'sexiest computer hacker' appears in court charged with $3m computer scam
The Russian femme fatale has been compared to former Russian spy Anna Chapman for her role in helping to mastermind a multi-million pound bank fraud scheme.
The 21-year-old was arrested in New York this month for her role in a internet fraud ring who used computer viruses to steal more than $3 million from US bank accounts
Svechinskaya was one of 37 people charged for their involvement in the scheme, which saw hackers use 'Zeus Trojan' and other Malware, to hack into people's computers.
The computer hackers then secretly monitored the victim's computer activity, stealing bank numbers and passwords, which they used to steal thousands of pounds from people's personal bank accounts.
The stolen money was transferred into hundreds of fake bank accounts set up by 'money mules' in the US.
Russian-born Svechinskaya was one of many 'money mules' who helped open false bank accounts for a ten per-cent cut of the stolen money.
She allegedly opened at least five accounts under her own name and the aliases, Anastasia Opokina and Svetlana Makarova, into which over $35,000 was fraudulently deposited and $11,000 successfully withdrawn.
The brunette beauty now faces up to 40 years behind bars for conspiracy to commit bank fraud and false use of a passport.
She will appear in court in New York tomorrow.
Preet Bharara, Manhattan, US Attorney, said: 'The digital age brings with it many benefits, but also many challenges for law enforcement and our financial institutions.
'As these arrests show, the modern, high-tech bank heist does not require a gun, a mask, a note, or a getaway car.
'It requires only the internet and ingenuity and can be accomplished in the blink of an eye, with just a click of the mouse.
Femme fatale: The hacker has been compared to Anna Chapman, a Russian spy
Monday, May 3, 2010
Denmark's KFC website targeted by Islamist hackers
Information: The video gave a brief rundown of the Islamic beliefs, while the instructions told the government to introduce a law to prevent people insulting religion.Hacked: Islamits targeted Denmark's KFC website and left an educational video about their religion, as well as instructions to the Danish government
Denmark's KFC website has been targeted by Islamist hackers.
The hackers decided to gain access to the fast food site and post an educational video about their religion on the page.
They also left instructions to the Danish government to introduce a new law to punish people who publicly insult religion.
The hackers implied in their demands that if the law is not introduced, the hacking of Danish websites will continue.
While it is not clear why the KFC site in particular was chosen, some have speculated it is because of the lack of security on the webpage.
The hackers left a slightly cryptic message on the site, which read: 'If your Gov. don't make rules for Punishing anyone Insult Religions in the name of (Freedom of Speech ! ) or ( Freedom to Insult ) :)
'So, take this rule of Hacking ! in the name of
'[ Hacking is a Knowledge and the Knowledge is Free ! ] It means [ Hacking Anyone I want !!!!]
'If your People can behave and Learn how to Respect , act rationally and stop to Insult Other Religions
'under the name of ( Freedom to Insult ) or ( Freedom of Speech )
'Then the Rule of Hacking will be stopped
'Finally , I would like to remind also with the decree which the Human Rights Agency in the United Nations adopted on the 12th of April 2005. This decree insisted on the ban of distortions and vicious attack against religions and especially Islam; which had been strongly attacked in the last few years !
'Don't worry .. No files deleted .. Just my Index* has been added to your lame bOx ;)
'Greets Go To: All My Friends in MSN :)'
But it is clear why Denmark was targeted - following a controversial cartoon depicting the Prophet Muhammad wearing a bomb-shaped turban being printed in a Danish newspaper.
The drawing was one of 12 caricatures that sparked angry protests in Muslim countries in 2005 after they were published by a newspaper.
Politiken and other Danish newspapers then reprinted the cartoon in 2008 after police revealed a plot to kill the cartoonist behind the drawing.
Eleven Danish newspapers were contacted by a Saudi lawyer Faisal Yamani, who represents eight Muslim groups in the Middle East and Australia, last year.
Yamani demanded that the cartoons were removed from their websites, that the newspapers print an apology and they agree not to use them again.
The Politiken Daily have now issued an apology, with editor in chief Toeger Seidenfaden saying: 'We have the right to print Kurt Westergaard's drawings, we have the right to print the original 12 drawings, we have the right to print all the caricatures in the world.
'We apologise for the offense which the reprint has caused. That is what we apologise for.'
Kurt Westergaard, one of the cartoonists whose home was the target of an attempted attack earlier this year, said he believed the apology was prompted by fear.
'I fear this is a setback for the freedom of speech,' Westergaard told AP.
'In Denmark we play by a set of rules, which we don't deviate from, and that's freedom of speech.'
Thursday, March 25, 2010
Obama Twitter account 'hacked by Frenchman'
-------------
It is not clear if the hacker posted anything on Mr Obama's Twitter page
President Barack Obama talks on the phone en route to George Mason University in Fairfax, Virginia, in this handout picture taken on March 19, 2010
A Frenchman who police say hacked Twitter accounts belonging to US President Barack Obama and celebrities could face jail.
The unemployed 25-year-old was arrested on Tuesday after an operation lasting several months, conducted by French police with agents from the FBI.
The 25-year-old is said to have hacked into the micro-blogging website, by simply guessing users' passwords.
The suspect reportedly targeted other celebrities, including Britney Spears.
After being questioned by police, he was ordered to appear at court in the central French city of Clermont-Ferrand on 24 June.
Hacking into a database in France is a crime which can carry a two-year jail term.
The suspect, who used the pseudonym "Hacker Croll", had no specialist training, Adeline Champagnat, head of the French central office against online fraud, told Reuters news agency.
He gained access to Twitter accounts by simply working out the answers to password reminder questions on targets' e-mail accounts, according to investigators.
An unemployed Frenchman has been arrested for targeting the Twitter accounts of President Barack Obama and singer Britney Spears, French police said on Wednesday.
Captain Adeline Champagnat, a senior member of the police cyber crimes unit, said the 25-year-old man gained access to passwords of Twitter administrators and used them to try to break into the accounts of U.S. politicians and stars.
"He didn't get as far as their personal accounts. But he had gained control of Twitter," she told Reuters Television in an interview.
She said the FBI had tipped off the French police in July last year that one or more people were trying to get access to Twitter and had gained control of the social network.
That enabled them to create and delete accounts and steal confidential information.
The hacker, who went by the online name of HackerCroll, is under arrest in the central French town of Clermont Ferrand.
He was known to have carried out minor internet fraud but in this case was driven by the thrill of the challenge and appeared to be more interested in the private life of his victims than on obtaining sensitive data, Champagnat said.
"His aim wasn't to make money. It was simply to show that he was able to access accounts of Twitter members. And the best proof of that is that he did screen grabs of certain confidential data which he tried to post on blogs that are reserved for pirates or hackers," she said.
She said several FBI agents were currently in France to help their French counterparts carry out searches.
"The collaboration was very good with the FBI and it's always very good with the FBI, because there's a real exchange of information. It's good cooperation to arrest the offender," she said.
Friday, December 18, 2009
Twitter hacked and front page replaced-by Iranian Cyber Army
Click to enlarge
Iranian hackers brought down micro-blogging website Twitter for around two hours this morning.
The attack took place at around 6am and left the site's estimated 30million users unable to send messages or post 'tweets'.
The main Twitter homepage had been replaced with a black and red screen featuring an image of a green flag.
The page carried the message: 'This site has been hacked by the Iranian Cyber Army.
The site reappeared around two hours later, with staff telling users: 'We are working to recovery from an unplanned downtime and will update more as we learn the cause of this outage.'
It is believed that Twitter's DNS records were hijacked in the attack meaning that users who were trying to visit the site were actually redirected to the new page.
The DNS, which stands for Domain Name System, connects the name of a website, in this case twitter.com, to the servers which hold its contents.
A short statement was issued on the company's blog.
The site reappeared around two hours later, with staff telling users: 'We are working to recovery from an unplanned downtime and will update more as we learn the cause of this outage.'
It is believed that Twitter's DNS records were hijacked in the attack meaning that users who were trying to visit the site were actually redirected to the new page.
The DNS, which stands for Domain Name System, connects the name of a website, in this case twitter.com, to the servers which hold its contents.
A short statement was issued on the company's blog.
RELATED POSTS:-
Saturday, November 21, 2009
3 Hacker charged for hacking into leading Climate Research Unit university

Hackers targeted the University of East Anglia¿s Climatic Research Unit, pictured, and published sensitive emails on the internet
Hackers targeted the University of East Anglia’s Climatic Research Unit and published the files, including some personal messages, on the internet.
Among the most damaging is one which appears to suggest using a ‘trick’ to massage years of temperature data to ‘hide the decline’.
The CRU, which plays a leading role in compiling UN reports and tracks long-term
changes in temperature, has repeatedly refused to provide detailed information about the data underlying the temperature records.
It is thought that this could have triggered the theft. Climate change sceptics claim that some of the leaked messages discuss ways of manipulating data that fails to comply
with the establishment view that climate change is real and is being driven by man.
The email suggesting ‘hiding the decline’ is purported to be from Phil Jones, the unit’s
director.
He denied trying to mislead, telling the TGIF digital newspaper he had no idea what he
meant by the phrase.
‘That was an email from ten years ago,’ he said. ‘Can you remember the exact context of an email you wrote ten years ago?’
Another message has been interpreted as an attempt to control the publication of
research carried out by sceptical scientists.
One way of doing this would be by loading the panel of researchers who review papers ahead of publication with experts who are ‘on-message’.
Talk of a figure being ‘shoehorned’ into a report from the UN’s International Panel of
Climate Change appears in another of the documents.
Although the data was stored on the university’s computer system, the email exchanges also involve experts from other institutions around the world.
A spokesman for the University of East Anglia said: ‘We are aware that information from a server used for research information in one area of the university has been made available on public websites.
‘Because of the volume of this information we cannot currently confirm that all of
this material is genuine.
‘This information has been obtained and published without our permission and we took immediate action to remove the server in question from operation.
‘We are undertaking a thorough internal investigation and we have involved the
police in this inquiry.’
The Met Office collaborates with the East Anglia unit on a variety of research projects,
including global temperature records.
Spokesman Dave Britton said the two organisations had to turn down numerous Freedom of Information requests because they did not hold the copyright to the data.
‘There is a feeling we are hiding something,’ he said. ‘But we are not, we just can’t
release the data.’
He said that is was unclear whether some of the documents had been tampered
with, adding: ‘We are not concerned about the robustness of the science we are pushing but we are worried about it being interpreted out of context.’
Three alleged members of the hacker gang Kryogeniks were hit with a federal conspiracy charge Thursday for a 2008 stunt that replaced Comcast's homepage with a shout-out to other hackers.
Prosecutors identified Christopher Allen Lewis, 19, and James Robert Black Jr., 20, as the hackers "EBK" and "Defiant" -- known for hijacking Comcast's domain name in May of last year.
The prank took down the cable giant's homepage and Web mail service for more than five hours and allegedly cost the company over $128,000.
Visitors to Comcast.net had been redirected to a simple page reading "KRYOGENIKS EBK and DEFIANT RoXed COMCAST sHouTz To VIRUS Warlock elul21 coll1er seven."
A third man, Michael Paul Lebel, 28, was also charged with helping the duo, though his alleged handle "Slacker" was not credited in the defacement message.
As described in the indictment, the hackers got control of the domain with two phone calls, and an e-mail was sent to the company's domain registrar, Network Solutions, from a hacked Comcast e-mail account.
That gave them entry to the Network Solutions control panel for Comcast's 200 domains, according to the indictment.
In an interview the day after the attack, Defiant and EBK told Wired magazine's Threat Level that they didn't initially set out to redirect the site's traffic. Instead, they merely changed the contact information for the Comcast.net domain to Defiant's e-mail address; for the street address, they used a false address using crass language.
Then, the hackers said, they contacted Comcast's original technical contact at his home number to tell him what they'd done. It was only when the Comcast manager scoffed at their claim and hung up on them that EBK said it was decided to take the more drastic measure of redirecting the site's traffic to servers under the hackers' control.
"I was trying to say we shouldn't do this the whole damn time," Defiant said last year.
"But once we were in," added EBK, "it was, like, [expletive] it."
The indictment also says that the hackers phoned the Comcast official at home.
In the interview last year, the hackers expressed some shock about the attention the attack garnered.
"The situation has kind of blown up here, a lot bigger than I thought it would," said Defiant, who said he was 19 years old and his first name was James. "I wish I was a minor right now because this is going to be really bad."
RELATED POSTS:-
- Search dogs detect something on Garrido property- May found bodies in the house property.
- Lab Technician Is Charged in Yale Grad Student's Killing - Believe as Workplace violence.
- Police in Yale killing stake out hotel room-watching hotel where person of interest Raymond Clark is staying in murder case Annie Le
- Suspects in Dugard case investigated in two more disappearances-9 and 13 year old girl.
- Police serve warrants in Yale grad student slaying-Cops searched the home of Yale lab tech Raymond Clark, who is a 'person of interest' murder case
- Annie Le body found in behind Yale Uni Lab wall - Missing 5 days before wedding - Found dead behind wall on wedding day.
- FBI, Police Raid New York Homes in Terror Probe
- Breaking News :-Police: Body found could be missing Yale student at wall in the basement
- Evangelist sentenced to 175 years for sex crimes
- DC sniper's execution met with grief, bitterness-Death by Lethal injection
- Terrifying moment crowd is engulfed by 20ft fireball at family festival after 'yob threw aerosol can into flames'
- Detecting glimpses of humanity in DC sniper-Is to Be Executed on Tuesday
- U.S. had al Qaeda intelligence on Fort Hood shooter-Fort Hood suspect was reportedly e-mailing al-Qaeda supporter
- A shoplifting mother... now England soccer captain's father is caught on film selling cocaine
- Fort Hood shooting suspect's ties to mosque investigated same mosque with 9 11 terrorists-Shouted Allah Akbar before gun rampage kill 13 wounds 31
- Executed in broad daylight: The chilling moment a Mafia hitman strikes outside a Naples bar... but no-one saw a thing
- Coroner says 6 women whose bodies were found at home died violently
- Richmond Police Make Sixth Arrest in Gang Rape-Friend of gang rape victim blasts school officials over safety
- Girl, 15, gang raped outside school dance while witnesses film horror attack
- Affidavit: Mom told deputies balloon saga was hoax