Showing posts with label law. Show all posts
Showing posts with label law. Show all posts

Wednesday, December 12, 2012

Ransom hackers encrypt medical centre's entire database

An Australian medical centre is reported to be considering paying a ransom demand of $4,000 AUD (US$4215) after blackmailers broke into the organisation’s servers and encrypted its entire patient database.

 If crime doesn't pay, why is this clinic considering making it profitable? Paying ransom only perpetuates the problem. Instead they should be spending the money on securing their systems. The clinic should be asking themselves:


  1. Why should I make this crime profitable for the attacker? 
  2. How do I know they will provide the password and instructions for decrypting the data? 
  3. How do I know that if I decrypt the database, the data hasn't been tampered with? 
  4.  If I pay the ransom, what is to stop them from increasing the demand lest they publish the data online?
  5. What is a better plan for securing the systems and moving on? 


They already lost once. If they don't bite the bullet and move on, they risk losing again and again. They would also be giving the attackers valuable incentives for attacking more sites.

Monday, November 12, 2012

John McAfee Wanted For Murder

Antivirus pioneer John McAfee is on the run for murder, according to Belizean police. This story is about to go viral.

Tuesday, March 20, 2012

Communication costs in Canada about to skyrocket

Warrantless spying is about to cause Canada's already too high price of communications to skyrocket. Thanks Stephen Harper. Now even the police are getting greedy.

Tuesday, February 28, 2012

Anonymous, joining Wikileaks, hacks into the big time

Anonymous, a hacker collective that stays true to its name, appears to be entering the big time.

After hacking the emails of Stratfor, the global intelligence firm, and on Monday cooperating with Wikileaks — already world famous for exposing classified US military documents and diplomatic cables — to publish those emails, Anonymous has gained a new level of notoriety among the public, and attention from authorities.

On Monday morning, twitter account @AnonymousIRC published a series of tweets revealing the hacker group as the source of the Stratfor emails and linking it to Wikileaks. Anonymous first accessed Stratfor's emails in December.

"We promised you those mails and now they'll finally be delivered. Five million (that's 5,000,000) emails at your pleasure," the tweet read.


Anonymous has long defended Wikileaks, most notably in its attacks against Visa, Mastercard and Paypal after those companies blocked customers from using their services to donate money to the secret-sharing site last year. But this appears to be the first time the two organizations have cooperated so directly.

Analysts say that Anonymous' collaboration with Wikileaks, along with recent hacks against the FBI and its release of a video Monday declaring "war" on the US government, has elevated the hacker group in the eyes of US security agencies from its previous status as a petty annoyance to a real threat.

Monday, February 27, 2012

FBI turns off 3,000 GPS trackers after Supreme Court ruling

Andrew Weissmann, general counsel for the FBI, has announced that his agency is switching off thousands of Global Positioning System-based tracking devices used for surveillance after a Supreme Court decision last month. Weissmann made the statement during a University of San Francisco School of Law symposium on communications privacy this past Friday.

Wednesday, November 16, 2011

Europe Bans X-Ray Body Scanners Used at U.S. Airports

The European Union on Monday prohibited the use of X-ray body scanners in European airports, parting ways with the U.S. Transportation Security Administration, which has deployed hundreds of the scanners as a way to screen millions of airline passengers for explosives hidden under clothing.

The European Commission, which enforces common policies of the EU's 27 member countries, adopted the rule “in order not to risk jeopardizing citizens’ health and safety.”

Police trick 19 criminals into coming forward with free beer

Undercover officers at Derbyshire police sent letters to dozens of people who had evaded arrest asking them to ring a marketing company to collect a free crate of beer.

A total of 19 suspects fell for the hoax and called the number on the letter, which put them through to police officers based at Chesterfield Police Station.

They were told that they needed to arrange a date and time for the free alcohol to be dropped off at an agreed address.

But instead of being handed free ale the wanted men found themselves confronted by police, handcuffed and under arrest.

Friday, September 30, 2011

Lie Detector Leads to Execution of Innocent Man

Chiang Kuo-ching, a Taiwanese airman was executed in 1997 for the rape and murder of a five-year-old girl. Military investigators tortured a confession out of Chiang after he failed to pass a lie detector “test.” Since then, DNA evidence and a palm-print have incriminated a different person.

Clenching your butt at the wrong time will cause you to appear guilty on a polygraph. It's time to throw this system out with the water dousers.

Sunday, August 14, 2011

Pakistan Let China See Crashed U.S. "Stealth" Helicopter

Pakistan gave China access to the previously unknown U.S. "stealth" helicopter that crashed during the commando raid that killed Osama bin Laden in May despite explicit requests from the CIA not to, the Financial Times reported on Sunday.

Tuesday, August 9, 2011

"Spam King" Surrenders.

Sanford Wallace, a.k.a. "the Spam King," has surrendered to federal law
enforcement agents in California. Wallace has been charged with sending
millions of spam messages to Facebook users. He allegedly tricked users
into submitting their account login details. An estimated 500,000
Facebook accounts were compromised. Once he had access to compromised
accounts, he accessed their friends lists and posted junk messages on
their walls. Facebook won a US $711 million judgment against Wallace in
2009. Wallace faces charges of electronic mail fraud, intentional damage
to a protected computer and criminal contempt. He has been released
after posting US $100,000 bail.

I doubt many people are feeling sorry for him.

Sunday, August 7, 2011

Check out The INTRUDER Daily

The INTRUDER Daily is a newspaper style aggregation of information security news. Check it out!

Tuesday, June 28, 2011

DMCA Takedown

Today we had to send out a DMCA Takedown Notice to a site that has stolen from me and my consulting firm twice in the past. Now we're in for round 3. We aren't sure what kind of nonsense game these charlatans are playing, but this time we decided an immediate takedown at the ISP level was required.

It is impossible to tell how much damage The Management Group have caused their unwitting customers. Even more pathetically, they appear to sell their lies to the US Government. I wonder if there are laws against that.

By openly stealing my content and making false claims about the origin of my published work, these guys do a disservice to all in the Information Security industry, and especially to their customers and partner organizations.

---- letter body follows ----

I am the sole copyright owner of the text content and IP rights being infringed at:

http://www.mgt-gp.com/articles/view/information-security-servicecapabilities
https://www.gsaadvantage.gov/ref_text/GS35F0658N/GS35F0658N_online.htm

The owner of these sites has been asked to remove this content twice in the past. After first claiming that he indeed is the writer of the Offensive Operations Model (A claim falsely repeated throughout the above named websites), the owner said he would remove the content and the fraudulent claims that he is the developer of the model. The Offensive Operations Model is a model I wrote in 1998 and was published by the IEEE in 2004, and is available online from many sites who do properly credit me as the author and developer. The owner of these above referenced sites has no right to abuse my copyrights in this manner. The entirety of text content on these pages was written by myself years before they appeared on these websites. After several phone calls from myself to the owner of these pages, the text disappeared only for a short time, and has at some point resurfaced with nothing more than a cosmetic makeover. This is now my THIRD time approaching these people about the offending content. I am willing to provide absolute proof via the WAYBACK MACHINE on archive.org which demonstrates clearly that the entirety of the text content of these pages was written by myself years before they began appearing on these 2 sites in question. Comparing this way shows the exact month and year that this person began stealing my work. The Offensive Operations Model that this person claims he wrote, is available from the IEEE website, and of course is listed with my name as the author.

Here is a link to an article I wrote about this thievery back in 2006. You will notice the mgt-gp site is specifically referenced. The link I proviced no longer works since the owner did change the URLs after I phoned him repeatedly. 

http://penetrationtestdotcom.blogspot.com/2006_10_01_archive.html

Please note: At the time I initially caught this person stealing my content, there were 7 other sites infringing my content in the same manner. All sites removed the content without question, save for the owner of these two sites listed above. He is not only cheating me by claiming copyright to the Offensive Operations Model. He also cheats his customers since in our phone conversation in 2006 it was clear he didn't even know really what the Offensive Operations Model was.

This letter is official notification under the provisions of Section 512(c) of the Digital Millennium Copyright Act (“DMCA”) to effect removal of the above-reported infringements. I request that you immediately issue a cancellation message as specified in RFC 1036 for the specified postings and prevent the infringer, who is identified by its Web address, from posting the infringing text and references to the Offensive Operations Model to your servers in the future. Please be advised that law requires you, as a service provider, to “expeditiously remove or disable access to” the infringing content upon receiving this notice. Noncompliance may result in a loss of immunity for liability under the DMCA.

I have a good faith belief that use of the material in the manner complained of here is not authorized by me, the copyright holder, or the law. The information provided here is accurate to the best of my knowledge. I swear under penalty of perjury that I am the copyright holder.

Please send me at the address noted below a prompt response indicating the actions you have taken to resolve this matter. If this DMCA Takedown Notice needs to be sent to any other parties, please let me know who they are.

-----

DMCA takedown template written by attorney Carolyn E. Wright.

Tuesday, June 21, 2011

'LulzSec suspect' arrested by New Scotland Yard

New Scotland Yard has confirmed that it has arrested a 19-year old suspected hacker in Essex, UK, in connection with a series of hacks and denial-of-service attacks against a number of organisations.

It is being widely speculated that the arrest is in connection with the high-profile attacks by the LulzSec hacking group, which has claimed amongst its victims Sony, the CIA, the FBI, and the Serious Organised Crime Agency (SOCA).

Saturday, April 9, 2011

Condé Nast scammed out of $8 million with single spear phishing email

Condé Nast - the company that publishes popular magazines such as Vogue, GQ, Architectural Digest, Wired, Vanity Fair, and many others - has been nearly defrauded of almost $8 million with a single, well-crafted spear phishing email.

The perp was caught, but this case demonstrates how the proper use of reconnaissance can lead to an efficient, yet devastating attack.

Friday, March 4, 2011

The HBGary story keeps getting more and more interesting

Another PDF file today - But well worth the read. The more we witness the fallout from Anonymous' exploits, the more interesting it gets.

According to a letter signed by 20 members of congress, HBGary and a law firm conspired to sabotage critics of the US Chamber of Commerce - namely U.S. Chamber Watch, Change to Win, the Center for American Progress, the Service Employees International Union, and others. In their attempt to halt free speech, it seems HBGary and their crew of goons may have carried out, or at least conspired to carry out actions that violate Federal law: Forgery, Mail and Wire Fraud, and Fraud and Related Activity in Connection With Computers.

Thursday, September 2, 2010

Pentagon Going Postal

The Pentagon is contemplating an aggressive approach to defending its computer systems that includes preemptive actions such as knocking out parts of an adversary's computer network overseas. Of course, this doesn't come without a laundry list of issues that have to be dealt with first.

Using a Blackberry in the UAE?

Apparently Arabic blackberries aren't the only devices with neutered security controls.  According to Slate, mobile phone company Etisalat is the digital certificate authority in the UAE. This would allow Etisalat to decrypt any messages relying on their services.

It is worth noting that Etisalat is already known to spy on their Blackberry users, by deliberately keeping copies of all emails passing through the service.

Monday, August 2, 2010

A DEF CON speaker was detained at the US border and asked about his involvement with the Wikileaks.org whistle-blowing website. They returned his laptop, but three of his cell phones were confiscated, and will probably never be seen again.

After mentioning this during his presentation (which was about onion routing), he was greeted by FBI agents who hoped to probe him. One of the spooks was quoted as saying "sometimes it's nice to have a conversation to flesh things out."

Thursday, July 15, 2010

FBI Raids ‘Electronik Tribulation Army’ Over Witness Intimidation

FBI agents have raided the homes of three alleged members of a hacker gang that harassed a security expert who helped put the group’s leader in jail, according to a recently unsealed search warrant affidavit.

Jesse William McGraw, aka “GhostExodus,” pleaded guilty in May to computer-tampering charges for putting malware on a dozen machines at the Texas hospital where he worked as a security guard. He also installed the remote-access program LogMeIn on the hospital’s Windows-controlled HVAC system.

Internet Luring - 2 Cases, 2 different outcomes

2 Internet child luring cases that occurred recently ended with 2 very interesting outcomes.

In the first case, a police officer was charged for trying to "communicate with a minor" for some sort of evil deed. The undercover officer who busted him was found to be guilty of luring since the evidence showed that the accused officer repeatedly turned down girls who claimed to be under-aged. In the end, it sounds like the cop harassed him into the communications that occurred, and that in no way did the officer try to "persuade" the apparently under-aged teen.

In the second case, a man is charged with a similar offense for chatting up a 13 year old boy for some extra-curricular grown-up activities. The accused argued that the boy's profile stated that he was 18 years old. However, in chat transcripts, the boy repeatedly told him that he was actually 13. The accuse states that he did not believe the boy was under-aged because of *unverified* profile information, and that the boy typed much too fast to be so young.

Isn't it obvious? If you are hitting on someone online, and then they tell you repeatedly that they are under-aged.... isn't that a sign to RUN AWAY FROM THEM? Such acts of willful blindness have rarely convinced the courts, and certainly this one wasn't fooled.

In the first case, the accused appears to have been pressured and entrapped. In the second, the accused seems to have been exercising a textbook case of confirmation bias.