четверг, 7 июля 2016 г.

New developmentson Guccifer 2.0

The notorious hacker continues his crusade against U.S. governmental bodies. This time he posted a new set of documents on Trump and DNC titled "Trumpocalypse and other DNC plans for July".
The hacker said on his official website:

"I have a new bunch of docs from the DNC server for you.
It includes the DNC action plan during the Republican National Convention, Surrogate Report, POTUS briefing, financial reports, etc.
This pack was announced two days ago but I had to keep you waiting for some security reasons. I suffered two attacks on my wp account.
You might be aware of the rumors about Marcel Lazar aka Guccifer. Those are a.c. fake stories, but who knows. Please keep me updated if there is any news."

Wikileaks taken down!

OurMine, the hacker group that previously broke into the social accounts of tech heavyweights like Google CEO Sundar Pichai, Facebook founder Mark Zuckerberg and Uber CEO Travis Kalanick, has now taken down the Wikileaks site.

The reason? A spat with Anonymous, the global hacker group that’s been known to take down ISIS social media accounts, publish the names of KKK members and attack a Greek Central Bank’s website to protest the global financial system, which it labeled a “tyrannical institution.”
We’re not usually keen on amplifying internet beefs, but this one affects a major source of once-confidential information that has made a major impact on our world, including a video showing the killing of Iraqi journalists in an American airstrike and secret files concerning the condition of prisoners at Guantanamo Bay.
Last December, when OurMine was a straight-up hacking group (it now labels itself a security firm) that would “we DDoS/hack anyone for no reason”, it took down Wikileaks’ site with a Distributed Denial of Service attack. The method mimics a massive wave of traffic to a targeted site, which crashes its servers temporarily.
Anonymous proceeded to request OurMine to stop compromising the Wikileaks site and then doxxed the group, i.e. published personal information about its members. OurMine claims that the information, which has since been taken down, was incorrect.
More than half a year later, OurMine is out for revenge. Claiming that one of Anonymous’ account holders has continued to abuse the group till today, it took down Wikileaks once again with another DDoS attack and intimated TNW about its actions. We contacted Anonymous but didn’t receive a reply.
It’s worth noting that there are various ways of carrying out a DDoS attack and it isn’t always easy to mitigate them as soon as they occur. However, it appears that Wikileaks is now back online.
It’s hard to take sides in this case, given that the situation seems to have arisen out of a long drawn-out spat between rival hackers. But when a major resource like Wikileaks – which has sought to uncover injustice and wrongdoing by those in power – takes a hit in the crossfire, we all lose.

Tor designed to hack sites!

The internet anonymity service Tor has some bad actors among its volunteer servers set to hack dark net websites.  
Northeastern University professor Guevara Noubir and his graduate student Amirali Sanatinia found the many of the volunteer-run servers making up the Tor network are designed to hack the anonymous sites that connect to it.

More than 95 percent of Tor traffic is used to browse websites such as Facebook and Twitter, and the anonymity it provides allows citizens of oppressive regimes visit sites that would otherwise be tracked, lets abuse victims use the internet without revealing their location and helps privacy-minded individuals feel more secure. The Department of State, the Defense Advanced Research Projects Agency (DARPA) and the governments of Germany and Sweden have all funded Tor for such reasons.
But the other 5 percent of traffic on Tor goes to hidden sites that are not accessible from normal web browsers. Hidden sites enjoy the same anonymity as Tor browsers and can range from news outlets in countries not supportive of an open press to criminal enterprises, including child pornography, drug sales and hackers for hire.
Noubir and Sanatinia found more than 100 of the network’s “exit nodes” were designed to not only store data but to contact the server again to either scan it for vulnerabilities or attack it.
The Tor network is composed of 10,000 volunteer servers that bounce data off of each other in ways that make it difficult to track. Around 3,500 are exit nodes, serving as the last link in the chain and connecting directly with the website.
None of these volunteers are supposed to retain any identifying information on the sites contacted or data transmitted, though Noubir’s and Sanatinia findings prove otherwise.
They set up thousands of fake hidden sites on Tor that were never accessed by any users. Only the two researchers and the exit nodes they connected to knew the internet addresses of the fake sites. But they found those sites were either scanned for vulnerabilities or attacked outright soon after connecting to the exit nodes.
The timing of the attacks ranged from immediate to a two-week delay – long enough to try and divert suspicion away from the exit nodes, but quick enough to guarantee the site would still be there.
“Many dark net sites go away quickly. There is an incentive to attack as soon as possible,” Noubir said.
It is unclear who operates the corrupt exit nodes. It could be hackers looking for victims, governments looking to quash activists or law enforcement looking to crack down on criminal markets. The FBI, for example, recently hacked a wide assortment of computers using Tor to break up a child pornography ring.
Hidden sites make ideal targets for any kind of attack, Noubir said.
“If someone set up a hidden server, they cannot report a hacker because if they did, it would reveal the location and existence of the hidden server,” he said.
Noubir also said such attacks might be a sign of other bad activity the Northeastern group was not checking for.
“To do this, they needed to modify the code for exit nodes. They are familiar with the code and sophisticated enough to modify it – they could be doing something worse,” he warned.
But it is hard to tell who the attackers are, Nourbir said, because so many Tor nodes are set up on cloud accounts. Thus, anyone who has an account with Amazon or Alibaba’s cloud services might be behind the attacks.
Noubir and Santinia will present the details at the hacker research conference DEF CON next month.

NASA Kepler Twitter Hack Becomes Butt Of Jokes

NASA's Kepler spacecraft looks for Earth-like planets orbiting other stars.

 This morning, Kepler's Twitter account got hacked... and showed its 569,000 followers a moon.

The hacker(s?) pinned a tweet displaying a red underwear-clad butt, which has since been deleted, but not before showing up on the NASA homepage. Lots of social media users have been making space-butt jokes about the debacle.
NASA Kepler mission homepage after apparent Twitter hack
NASA Kepler mission homepage after apparent Twitter hack
NASA Kepler mission homepage after apparent Twitter hack
The tweet appeared on NASA's Kepler mission homepage as well.
We saw planet jokes,
moon jokes,
science communication jokes,
and of course, what's a space butt picture without "Uranus?"
People really had at it.
NASAKepler Hacked on Twitter
Screenshot
NASAKepler Hacked on Twitter
Responses to the tweet in question when NASAKepler was hacked on Twitter.
Eventually the folks running the Kepler Twitter caught on...
And that only led to more butt jokes... or requests for more butts.

среда, 6 июля 2016 г.

Bahrain fights opposition shutting down the internet



The latest round of demonstrations in Diraz began on 20 June when Bahrain’s government stripped the country’s highest ranking Shia cleric and Dirza resident, Sheikh Isa Qassim, of his citizenship. 
Bahraini authorities quickly set up checkpoints around the village, refusing entry to those attempting to enter. The heavy police presence in Diraz also comes amid a wider crackdown that has seen human rights defenders jailed and al-Wefaq, the largest Shia opposition group in Bahrain, banned.
Within three days of Qassim's citizenship being revoked, Dirazis began reporting that internet and mobile phone services in their village were “slow, usually unusable” at night. Customers of the three main internet firms in Diraz – Batelco, Zain and Viva – all reported significantly slowed or nonexistent connections since 23 June.
Ali, a student who lives in the village centre, told Middle East Eye: “Every night, we face internet disruptions and disconnections. First the whole signal is disconnected for a few seconds, then the signal is back but there is not cellular data, no 3G, no 4G.
"My service provider is Batelco, there isn’t 3G. My home Wifi is provided by Zain, it has the exact same problem. In fact, it’s worse. It takes longer to come back [after it’s disconnected].”
Ali said internet “comes back for less than a minute every two or three hours," but that phone calls work normally “with slight disruptions”. But the vast majority of communication in Bahrain – including phone calls and messaging – is done via applications that use data.
Ali said the internet and cell data services are cut at 7.30pm every night as people begin to gather for prayers and Iftar outside Qassim’s home, then returns after morning prayer at about 3am when protesters begin to disperse. 
More than a dozen other residents reported similar service disruptions on Batelco, Zain, and Viva, despite no visible change in the cell towers in Diraz. All said everyone they knew in Diraz had been unable to use the internet properly since 23 June.
Many in the village think their internet has been slowed to prevent them from posting pictures and videos of the ongoing demonstrations, which outsiders are no longer allowed to attend.
Activists' posts on Twitter have slowed to a crawl; the hashtags “Diraz”, “Duraz” and “al-Diraz” in Arabic, which for five years have been critical to monitoring and documenting violations by security forces during protests, have been largely absent of content posted locally. 
Instead, the hashtags have been dominated by accounts pushing out random, anti-Shia and sectarian commentary and videos – usually the same three videos. The content rarely has any direct connection to Diraz.

Attack of the 'bots'?

Marc Owen Jones, a fellow at the Institute of Political Science at Tuebingen University in Germany and member of the advocacy group Bahrain Watch, said that many of the accounts flooding the Diraz hashtags with hate speech were probably automated Twitter "bots". 
In a report published last month, Jones found that apparently automated accounts tweeted thousands of sectarian comments per day on the #Bahrain hashtag. As recently as 23 June, more than half of the tweets on the #Bahrain hashtag came from automated accounts.
Jones confirmed the #Diraz hashtag activity was different than previous disruptions. "Today [July 2] 84 percent of tweets with the Diraz hashtag are probably from automated bots tweeting sectarianism. That's about 7,400 out of 8,900 tweets.”
Translation: Video of the Safavid terrorists #Bahrain #Scholar #Leader #Ayatollah_Qasim #Diraz #Bahrain #Shut_down_of_al-Wefaq_group
The apparent bot accounts began tweeting the Diraz hashtag one day after Qassim’s citizenship was stripped and less than 24 hours after thousands of Bahrainis gathered in Diraz to support him.
After two weeks of being largely unable to report what's happening inside Diraz, villagers said the connectivity shortages are an attempt to limit protests.
Ali said: “The main two goals are to stop our news getting out, and our pictures showing the amount of people still gathered. It’s also a collective punishment, to limit participation in the protests.”

'Worse than the Chinese firewall'

Rob Frieden, a professor of telecommunications and law at Penn State University, said that the Bahraini government should be wary of what he called a “sledgehammer to kill a flea” approach to censorship.
“What these people are describing – targeting this village and weakening their internet – is called throttling. It’s dangerous because it doesn't just affect communicating about protests, but also about health, commerce and emergencies. It’s a very poorly calibrated response and punishment of that community.”
Bahrainis in other villages told Middle East Eye that the lack of connectivity inside Diraz had affecting their ability to communicate with relatives. One man living in Janabiyah explained, “I moved away but my grandfather is in Diraz. I can’t get in, he can’t get out, and now he can’t call.”
It’s also affecting students’ ability to complete homework assignments, and business owners who use the Internet to manage operations. One shop in Diraz posted a sign on its window that read: "An announcement to our valued customers: We do not have the card payment service in the evenings because there is no network."
Such acts by government are not unprecedented. In January 2011, Hosni Mubarak’s Egyptian government shut down internet connections as calls for protests mounted on social media networks.
Later that year, public transport authorities in San Francisco, California shut down mobile-internet and phone services ahead of a planned demonstration to protest against the killing of a black man.
However, Frieden said Bahrain’s apparent multi-week attack on communications in Diraz, coupled with the physical barriers restricting access to the village, was rare.
“In some ways, it’s worse than the Chinese firewall, which uses filtering to prevent access to and from specific websites. What Bahrain could easily have done is to prevent access to Twitter or Facebook sites – as opposed to throttling of connectivity.”
Nevertheless, activists inside Diraz, such as Ali, are persisting in their attempts to contact the wider world.
In a text message received at 9.30am Bahrain time, Ali wrote: “I would like to note that these answers were sent at 8.37am. But due to the data disconnections it wasn’t delivered.”
Neither Zain, Batelco, Viva nor the Ministry of Interior has returned requests for comment.

A Cybersecurity Expert on Clinton's Email hack

On Tuesday, FBI Director James Comey announced that his agency would not be recommending charges over former Secretary of State Hillary Clinton's use of a private email server, telling reporters that the bureau's investigators had concluded that "no reasonable prosecutor would try such a case." The announcement attracted harsh words from Clinton's political opponents, like House Speaker Paul Ryan, who wrote that "no one should be above the law," but it almost certainly frees Clinton from the lingering threat of prosecution that has hung over her campaign like a dark cloud.

While Comey acknowledged that the FBI "did not find direct evidence that Secretary Clinton's personal email domain, in its various configurations since 2009, was successfully hacked," he also scolded Clinton for being "careless." The FBI's investigation found that 110 individual messages in 52 email changes contained classified information—and eight of those chains were considered "Top Secret," a category reserved for information that, if unintentionally released, "could be expected to cause exceptionally grave damage" to national security.
In his statement to reporters, Comey suggested that beyond the issue of Clinton's emails, the State Department in general has been too cavalier in its handling of government secrets. While this was not the focus of the FBI's investigation, he said, the agency found "evidence that the security culture of the State Department in general, and with respect to use of unclassified email systems in particular, was generally lacking in the kind of care for classified information found elsewhere in the government."
To learn more about what effects Clinton's apparently lax security protocols could have, I called up Justin Cappos, an assistant professor of computer science at New York University's Tandon School of Engineering and commentator on cybersecurity issues. The conversation below has been edited for clarity.
Related: Why Clinton's 'Extreme Carelessness' With Classified Emails Isn't Criminal
VICE: Does it look to you like Hillary Clinton jeopardized national security by being "careless"?Justin Cappos: In general, it doesn't seem like this is immensely horrendous. [Although] anytime that you go and you set up your own server to store some data, whatever things you pass through there, whatever you process, is potentially attackable. It's really up to the person that's maintaining and setting up the server to keep it properly up to date, to look at what's happening on the server, to try to detect intrusions and things, if they've occurred, based on patterns of network traffic or other activity on the server.
What's a little worrying in this case is it's not clear that an extremely high level of scrutiny has been given to the mail servers' security [to] reliably detect these sorts of attacks.
So it seems like a breach was possible, even if the FBI didn't find direct evidence that Clinton's servers were hacked. It's not uncommon that different [hacking groups], when they go to break into a server, will actually leave some sort of trace. Because they'll go and they'll install a rootkit, or they will modify the firmware or do something else to cause themselves to be inserted and loaded into the system while it's running.
You mean a backdoor. Are you sure attackers didn't just get rid of that backdoor after they used it to steal information?It would have required someone to intentionally go and do this. I mean, it's possible that they did it, and removed all traces of it. It's also possible that the way they did it was through something that every time—for instance—the server rebooted, it had to be redone. It's also quite plausible that it didn't happen. I would imagine that if somebody's breaking in and they understand what they're getting into, in many cases they would rather have persistent access, even if it increases the potential for being detected.
Comey said the State Department is generally lax about information security. So is it even safe to say that if Clinton used a State Department email server, this information would have been safer?Actually, the [State Department has] been hacked during some of that time period. The State Department had Russian hackers—or at least allegedly Russian hackers—inside of their mail servers for a while, which presumably would have given them access to all of this information if Hillary Clinton had been using the State Department mail server. And it's unclear if they were also in [Clinton's] mail server.
So to be clear, you're not necessarily saying the emails were safer on the Clinton server?It was an additional target somebody had to break into, but it's not clear if this helped or harmed security. Let me kind of give you an example to try to make sense of this: Suppose that you work for a company, and you have a bicycle or something from that company, and they give you a bike lock for the bicycle that you have and you lock it with the bike lock—somebody could still cut that bike lock that the company gave you and ride off with that bicycle. It's sort of the company's fault if that happens.
If you put your own lock on that bicycle, and somebody cuts it, then the company might blame you, even if you have a better bike lock, or an equivalent bike lock or maybe it's a slightly worse bike lock but then all of a sudden, you get all the flak for it. Because you're the one that [chose] the bike lock.
So on the whole, do you think it's conceivable that these emails could still have some kind of impact for national security?The issue really comes down to what's in those messages. And that's information that isn't publicly available.

Airlines Look To Invest In Cyber Security

Last week we discussed cyber security and the threat that it poses to the aviation industry if airlines fail to tackle it head on.

On Thursday (June 29), travel technology provider SITA released its 2016 Airline IT Trends Survey that stated 9 per cent of airlines now plan to invest in cyber security programs within the next three years.
The report found that: “more than 60 per cent of airlines place oversight for cyber security at the board level rather than within IT departments, suggesting it is starting to be viewed much more as a business risk” - something that will certainly be music to the ears of the International Air Transport Association, which has been an advocate of cyber security for several years now.
Indeed, airlines are increasingly investing in more ‘passenger first’ services, from mobile apps for smartphones to loyalty programs, and this has played a big part in encouraging airlines to improve their cyber security, because they now have even more data to look after.
In addition, the industry trend of adopting Internet of Things (IoT) technologies has put a spotlight onto the possible vulnerability of passenger data. Thus, somewhat unsurprisingly so, the report stated that 97 per cent of airlines believe the perceived invasion of passenger privacy is also an IoT challenge.
So, as the industry moves forward and technologies advance, cyber security is definitely proving to be high on the agenda for a large number of airlines.
Nigel Pickford, director of market insight at SITA, explained: “Airlines are investing in areas which will promote a connected world of travel for the benefit of passengers and the workforce.  We see new priorities attracting more investment, with cyber security and electronic flight bag solutions coming to the fore in this year’s research”.
The report also highlighted that 72 per cent of the 200 airline participants are investing in major cyber security projects, with a further 19% engaged in Research & Development (R&D) projects.
Thus, the results showed that most airlines believe that they are now better positioned to deal with potential cyber threats, compared to a few years ago.
In fact, within three years, the number of airlines that believe they are now prepared for the common types of cyber threats has risen by 31 per cent.