Thursday, June 2, 2011

Hackers stole secret Canadian government data

Hackers who attacked two of Canada's federal departments stole classified information before being discovered last January.

Hackers sent malicious emails to staff that appeared to be coming from senior managers. When staff opened the attachments, hackers found a path into the federal network, providing access to classified information.

The linked article contains a chronology of the attack.

Saturday, April 9, 2011

Hacking ATM Users by Gluing Down Keys

Apparently thieves have begun gluing down the "Enter", "Cancel"and "Clear" buttons on certain bank machines. The guise is simple - some ATM machines also have a touch-screen display. If the customer is unaware of this, or just not thinking too clearly, they may enter the pin, and then not getting the results they expected, figure that the machine is broken. They then leave the machine unattended. The thief then presses the "Enter" equivalent on the touch screen, takes the money, and runs.

Condé Nast scammed out of $8 million with single spear phishing email

Condé Nast - the company that publishes popular magazines such as Vogue, GQ, Architectural Digest, Wired, Vanity Fair, and many others - has been nearly defrauded of almost $8 million with a single, well-crafted spear phishing email.

The perp was caught, but this case demonstrates how the proper use of reconnaissance can lead to an efficient, yet devastating attack.

Tuesday, March 8, 2011

Nexus S Android Sniffs and Emulates RFID tags

The Nexus S Android phone is capable of reading and emulating RFID. An application called Farebot demonstrates how the phone could be used to emulate RFID fare cards. This apparently could make it cheaper and more convenient for transit riders. However, the software's author also points out how many of these cards keep records trip information in clear-text. This creates a bit of a privacy issue since it is so easy for this software to read cards from people who merely happen to walk close enough to you.

Currently FareBot can parse and display balance and trip history information from Seattle’s ORCA card, and can dump raw data from any other MIFARE DESFire card including San Francisco’s Clipper card. FareBot is open-source and designed to be flexible so that hopefully other developers will add support for other types of cards.

Friday, March 4, 2011

The HBGary story keeps getting more and more interesting

Another PDF file today - But well worth the read. The more we witness the fallout from Anonymous' exploits, the more interesting it gets.

According to a letter signed by 20 members of congress, HBGary and a law firm conspired to sabotage critics of the US Chamber of Commerce - namely U.S. Chamber Watch, Change to Win, the Center for American Progress, the Service Employees International Union, and others. In their attempt to halt free speech, it seems HBGary and their crew of goons may have carried out, or at least conspired to carry out actions that violate Federal law: Forgery, Mail and Wire Fraud, and Fraud and Related Activity in Connection With Computers.

During a recent password audit

During a recent password audit, it was found that someone was using the following password:
"MickeyMinniePlutoHueyLouieDeweyDonaldGoofySacramento"

When asked why she had such a long password, she said she was told that it had to be at least 8 characters long and include at least one capital.

I don't usually post jokes, but I think this is the first infosec joke I've ever heard. Feel free to post or send along some more if you know a good security joke.

Wednesday, March 2, 2011

Apparently all today's Infosec news is a result of Anonymous' exploits

The servers at Morgan Stanley were broken into. I bet you already guessed it was the Chinese yet again.

It's getting very fashionable to blame the Chinese for most hacks against American computer systems these days. But this is news for an actually interesting reason. We would not have known about it if it wasn't for the emails Anonymous exposed from a company humorously referred to in media as "a cyber-security company working for the bank." Whoever they might have been.

Leaked emails seem to be the current source of daily news these days. It sure is more interesting than watching CNN.