Organic SEO Blog

231-922-9460 • Contact UsFree SEO Site Audit
Showing posts with label cybercrime. Show all posts
Showing posts with label cybercrime. Show all posts

Wednesday, May 28, 2014

HACKER HELPED DISRUPT 300 WEB ATTACKS, PROSECUTORS SAY

Original Story:  NYTimes.com

A prominent hacker set to be sentenced in federal court this week for breaking into numerous computer systems worldwide has provided a trove of information to the authorities, allowing them to disrupt at least 300 cyberattacks on targets that included the United States military, Congress, the federal courts, NASA and private companies, according to a newly filed government court document.

The hacker, Hector Xavier Monsegur, also helped the authorities dismantle a particularly aggressive cell of the hacking collective Anonymous, leading to the arrest of eight of its members in Europe and the United States, including Jeremy Hammond, who the Federal Bureau of Investigation said was its top “cybercriminal target,” the document said. Mr. Hammond is serving a 10-year prison term.

The court document was prepared by prosecutors who are asking a judge, Loretta A. Preska, for leniency for Mr. Monsegur because of his “extraordinary cooperation.” He is set to be sentenced on Tuesday in Federal District Court in Manhattan on hacking conspiracy and other charges that could result in a long prison term.

It has been known since 2012 that Mr. Monsegur, who was arrested in 2011, was acting as a government mole in the shadowy world of computer hacking, but the memorandum submitted to Judge Preska late on Friday reveals for the first time the extent of his assistance and what the government perceives of its value. It also offers the government’s first explanation of Mr. Monsegur’s involvement in a series of coordinated attacks on foreign websites in early 2012, though his precise role is in dispute.

The whereabouts of Mr. Monsegur have been shrouded in mystery. Since his cooperation with the authorities became known, he has been vilified online by supporters of Anonymous, of which he was a member. The memo, meanwhile, said the government became so concerned about his safety that it relocated him and some members of his family.

“Monsegur repeatedly was approached on the street and threatened or menaced about his cooperation once it became publicly known,” said the memo, which was filed by the office of Preet Bharara, the United States attorney in Manhattan.

Born in 1983, Mr. Monsegur moved to the Jacob Riis housing project on the Lower East Side of Manhattan at a young age, where he lived with his grandmother after his father and aunt were arrested for selling heroin. He became involved with hacking groups in the late 1990s, drawn, he has indicated, to the groups’ anti-government philosophies.

Mr. Monsegur’s role emerged in March 2012 when the authorities announced charges against Mr. Hammond and others. A few months later, Mr. Monsegur’s bail was revoked after he made “unauthorized online postings,” the document said without elaboration. He was jailed for about seven months, then released on bail in December 2012, and has made no further postings, it said.



The memo said that when Mr. Monsegur (who used the Internet alias Sabu) was first approached by F.B.I. agents in June 2011 and questioned about his online activities, he admitted to criminal conduct and immediately agreed to cooperate with law enforcement.

That night, he reviewed his computer files with the agents, and throughout the summer, he daily “provided, in real time, information” that allowed the government to disrupt attacks and identify “vulnerabilities in significant computer systems,” the memo said.

“Working sometimes literally around the clock,” it added, “at the direction of law enforcement, Monsegur engaged his co-conspirators in online chats that were critical to confirming their identities and whereabouts.”

His primary assistance was his cooperation against Anonymous and its splinter groups Internet Feds and LulzSec.

“He provided detailed historical information about the activities of Anonymous, contributing greatly to law enforcement’s understanding of how Anonymous operates,” the memo said.

Neither Mr. Bharara’s office nor a lawyer for Mr. Monsegur would comment about the memo.

Mr. Monsegur provided an extraordinary window on the activities of LulzSec, which he and five other members of Anonymous had created. The memo describes LulzSec as a “tightly knit group of hackers” who worked as a team with “complementary, specialized skills that enabled them to gain unauthorized access to computer systems, damage and exploit those systems, and publicize their hacking activities.”

The memo said that LulzSec had developed an “action plan to destroy evidence and disband if the group determined that any of its members had been arrested, or were out of touch,” and it credits Mr. Monsegur for agreeing so quickly to cooperate after being confronted by the bureau. Had he delayed his decision and remained offline for an extended period, the document said, “it is likely that much of the evidence regarding LulzSec’s activities would have been destroyed.”

After his arrest, Mr. Monsegur provided information that helped repair a hack of PBS’s website in which he had been a “direct participant,” and helped patch a vulnerability in the Senate’s website. He also provided information about “vulnerabilities in critical infrastructure, including at a water utility for an American city, and a foreign energy company,” the document said.

The coordinated attacks on foreign government websites in 2012 exploited a vulnerability in a popular web hosting software. The targets included Iran, Pakistan, Turkey and Brazil, according to court documents in Mr. Hammond’s case. The memo said that “at law enforcement direction,” Mr. Monsegur tried to obtain details about the software vulnerability but was unsuccessful.

“At the same time, Monsegur was able to learn of many hacks, including hacks of foreign government computer servers, committed by these targets and other hackers, enabling the government to notify the victims, wherever feasible,” the memo said.

The memo does not specify which of the foreign governments the United States alerted about the vulnerabilities.

But according to a recent prison interview with Mr. Hammond as well as logs of Internet chats between him and Mr. Monsegur, which were submitted to the court in Mr. Hammond’s case, Mr. Monsegur seemed to have played a more active role in directing some of the attacks. In the chat logs, Mr. Monsegur directed Mr. Hammond to hack numerous foreign websites, and closely monitored whether Mr. Hammond had success in gaining access to the sites.

Sarah Kunstler, a lawyer for Mr. Hammond, said on Saturday: “The government’s characterization of Sabu’s role is false. Far from protecting foreign governments, Sabu identified targets and actively facilitated the hacks of their computer systems.”

At his sentencing in November, Mr. Hammond was prohibited by Judge Preska from naming the foreign governments that Mr. Monsegur had asked him to hack. But, according to an uncensored version of a court statement by Mr. Hammond that appeared online that day, the target list included more than 2,000 Internet domains in numerous countries.

Mr. Hammond’s sentencing statement also said that Mr. Monsegur encouraged other hackers to give him data from Syrian government websites, including those of banks and ministries associated with the leadership of President Bashar al-Assad.

Friday, July 27, 2012

10,000 Arrested in China Internet Crackdown

Story first reported from USA Today

Chinese authorities say they have arrested more than 10,000 suspects and smashed more than 600 gangs during a four-month crackdown on Internet crimes, according to news reports.

At the same time, Beijing police are threatening to punish any online "political rumor" or "attack" on Communist Party leaders, the system or the country, raising fears of tighter controls on speech on the country's 538 million Internet users.

The Ministry of Public Security said "major crimes uncovered" during the nationwide operation since May include pornographic information, gun trading, wiretapping devices, counterfeiting, as well as illegally collecting and selling citizens' personal information, the official Xinhua News Agency writes.

The cyber-police have also deleted 3.2 million messages deemed "harmful," closed hundreds of Internet cafes and punished 30 service providers for granting access to unlicensed sites, the BBC says.

Additionally, 62 websites and online forums were ordered to remove "inappropriate content."

In southern China, police reported detaining "a gang of hackers" believed responsible for attacks on 185 government websites, the state-run China Daily newspaper says.

The warning from Beijing's Public Security Bureau about Internet comments came Tuesday during a meeting about protecting minors online, the Global Times  reports.

In May, a BBC article asked, "Will China's Great Firewall backfire?"

China's crackdown comes as the U.S. Congress is considering new cybersecurity legislation.

The Senate voted today to begin debating and amending the Cybersecurity Act of 2012, which is intended to bolster cyber-defenses against attacks on communications systems and infrastructure.

The measure "calls for the Department of Homeland Security (DHS) to assess risks and vulnerabilities of computer systems running at critical infrastructure sites such as power companies and electricity and water utilities and to work with the operators to develop security standards that they would be required to meet," Cnet wrote when the legislation was introduced in February.

The Electronic Frontier Foundation says the Cybersecurity Act "poses serious threats to online rights."

The House approved a similar bill in April -- the Cyber Intelligence Sharing and Protection Act -- despite a threatened White House veto. The measure encourages but does not require companies and the federal government to share information collected on the Internet to prevent against online attacks.

For more national and worldwide Business News, visit the Peak News Room blog.
For more local and state of Michigan Business News, visit the Michigan Business News  blog.
For more Health News, visit the Healthcare and Medical News blog.
For more Electronics News, visit the Electronics America blog.
For more Real Estate News, visit the Commercial and Residential Real Estate blog.
For more Law News, visit the Nation of Law blog.
For more Advertising News, visit the Advertising, Marketing and Media blog.
For more Environmental News, visit the Environmental Responsibility News blog.
For information on website optimization or for the latest SEO News, visit the SEO Done Right blog.

Tuesday, June 12, 2012

Flame Virus Scares Microsoft

Story first appeared on CNBC.

Discovery of the Flame virus that mainly affected computers in the Middle East, has prompted Microsoft Corp to strengthen the security of a Windows program that helps customers secure their PCs and update software.

The senior director of the Microsoft Security Response Center said in a blog post that the world's biggest software maker plans to boost security measures on the Windows Update software that is included with the operating system that runs the majority of the world's PCs.

Microsoft disclosed over the weekend that the hackers who built Flame exploited a flaw in Windows that allowed them to trick PCs into believing it was a legitimate piece of software from Microsoft. The software was then downloaded onto computers using the Microsoft Update feature.

News of the Flame virus surfaced a week ago when cyber security experts described it as one of the most sophisticated pieces of malicious software discovered to date. They are still investigating the virus, which they believe was released specifically to target computers in Iran and across the Middle East, similar to the Stuxnet worm that attacked Iran's nuclear program in 2010.

The security experts said Flame likely only infected several thousand computers and was targeted at entities that would be of interest to nations involved in espionage.

Microsoft said on its website on Sunday that it was releasing software to fix the bug using its Windows Update system. But security experts said machines infected with some advanced viruses may not benefit from that update because those viruses had disabled the Windows Update software.

That is partially what prompted the need to further boost the security of the Windows Update feature, they said.

If Microsoft is going to 'harden' the update feature, they must also prevent writers of malicious software from disabling the updating process on local computers.

Microsoft disclosed the plan to boost security of Windows Update late Monday on a Microsoft Security Response Center blog: http://blogs.technet.com/b/msrc/

Windows has said that it was taking the flaw in Windows seriously because the bug could be exploited by developers of less sophisticated viruses to launch more widespread attacks.


For information on website optimization or for the latest SEO News, visit the SEO Done Right blog.
For more national and worldwide Business News, visit the Peak News Room blog.
For more local and state of Michigan Business News, visit the Michigan Business News blog.
For more Health News, visit the Healthcare and Medical News blog.
For more Electronics News, visit the Electronics America blog.
For more Real Estate News, visit the Commercial and Residential Real Estate blog.
For more Law News, visit the Nation of Law blog.
For more Advertising News, visit the Advertising, Marketing and Media blog.
For more Environmental News, visit the Environmental Responsibility News blog.

Tuesday, August 24, 2010

Hacker’s Arrest Offers Glimpse Into Crime in Russia

NY Times

 
On the Internet, he was known as BadB, a disembodied criminal flitting from one server to another selling stolen credit card numbers despite being pursued by the United States Secret Service.

And in real life, he was nearly as untouchable — because he lived in Russia.

BadB’s real name is Vladislav A. Horohorin, according to a statement released last week by the United States Justice Department, and he was a resident of Moscow before his arrest by the police in France during a trip to that country earlier this month.

He is expected to appear soon before a French court that will decide on his potential extradition to the United States, where Mr. Horohorin could face up to 12 years in prison and a fine of $500,000 if he is convicted on charges of fraud and identity theft.

For at least nine months, however, he lived openly in Moscow as one of the world’s most wanted computer criminals.

The seizing of BadB provides a lens onto the shadowy world of Russian hackers, the often well-educated and sometimes darkly ingenious programmers who pose a recognized security threat to online commerce — besides being global spam nuisances — who often seem to operate with relative impunity.

Law enforcement groups in Russia have been reluctant to pursue these talented authors of Internet fraud, for reasons, security experts say, of incompetence, corruption or national pride.

In this environment, BadB’s network arose as “one of the most sophisticated organizations of online financial criminals in the world,” according to a statement issued by Michael P. Merritt, the assistant director of investigations for the Secret Service, which pursues counterfeiting and some electronic financial fraud.

As long ago as November 2009, the United States attorney’s office in Washington, in a sealed indictment, identified BadB as Mr. Horohorin, a 27-year-old residing in Moscow with dual Ukrainian and Israeli citizenship.

But it was not until Aug. 7 this year that Mr. Horohorin, who was traveling from Russia to France, was detained on a warrant from the United States as he boarded a plane to return to Russia at an airport in Nice, in southern France.

The Secret Service released a statement on Aug. 11, when the indictment was unsealed. Max Milien, a Secret Service spokesman in Washington, said the agency could not comment about the decision to arrest Mr. Horohorin in France.

Olga K. Shklyarova, spokeswoman for the Russian bureau of Interpol, said no American law enforcement agency had requested Mr. Horohorin’s arrest in her country. “We never received such a request,” she said by telephone.

According to the Secret Service statement, Mr. Horohorin managed Web sites for hackers who were able to steal large numbers of credit card numbers that were sold online anonymously around the globe.

Those buyers would do the more dangerous work of running up fraudulent bills.

The numbers were exchanged on Web sites called CarderPlanet — carder.su and badb.biz — according to the Secret Service, and payment was made indirectly through accounts at a Russian online settlement system known as Webmoney, an analogue to PayPal.

Underscoring the nationalistic tone of much of Russian computer crime, one site featured a cartoon of the Russian prime minister, Vladimir V. Putin, awarding medals to Russian hackers.

“We awaiting you to fight the imperialism of the U.S.A.” the site said, in approximate English.

Mr. Horohorin lived openly in Moscow. As a foreign citizen, he registered with the police, according to Dmitri Zakharov, a spokesman for the Russian Association of Electronic Communication, an industry lobby for legitimate Russian Internet businesses, who cited a database of such registries.

A phone number for Mr. Horohorin was out of service Thursday.

Arrests in Russia for computer crimes are rare, even when hackers living in Russia have been publicly identified by outside groups, like Spamhaus, a nonprofit group in Geneva and in London that tracks sources of spam.

The F.B.I. in 2002 resorted to luring a Russian suspect, Vasily Gorshkov, to the United States with a fake offer of a job interview (with a fictitious Internet company called Invita), rather than ask the Russian police for help.

To obtain evidence in the case, F.B.I. computer experts had hacked into Mr. Gorshkov’s computer in Russia. When this was revealed, Russian authorities expressed anger that the F.B.I. had resorted to a cross-border tactic.

Online fraud is not a high priority for the Russian police, Mr. Zakharov said, because most of it is aimed at computer users in Europe or the United States. “This is a main reason why spammers are not arrested,” he said.

Politics may also play a role.

Vladimir Sokolov, deputy director of the Institute of Information Security, a Russian research organization, said the United States and Russia were still at odds on basic issues of computer security, although the differences were narrowing.

The United States tends to view computer security as a law enforcement matter. Russia has pushed for an international treaty that would regulate the use of online weapons by military or espionage agencies.

Last year the United States opened talks on a treaty, but it has continued to press for closer law enforcement cooperation, Mr. Sokolov said.

Computer security researchers have raised a more sinister prospect: that criminal spamming gangs have been co-opted by the intelligence agencies in Russia, which provide cover for their activities in exchange for the criminals’ expertise or for allowing their networks of virus-infected computers to be used for political purposes — to crash dissident Web sites, perhaps.

Sometimes, the collateral damage for online business is immediate.

A year ago, for example, hackers used a network of infected computers to direct huge amounts of junk traffic at the social networking accounts of a 34-year-old political blogger in Georgia, a country that fought a war with Russia in 2008.

The attack, though, spun out of control and briefly crashed the global service of Twitter and slowed Facebook and LiveJournal, affecting tens of millions of computer users worldwide. The Russian authorities have repeatedly denied that the state has any connection to such attacks.

Spamhaus says 7 of the top 10 spammers in the world are based in the former Soviet Union, in Ukraine, Russia and Estonia.

More ominously, Western law enforcement agencies have traced a code intended for breaking into banking sites to Russian programming.

In 2007, Swedish experts identified a Russian hacker known only by his colorful sobriquet — the Corpse — as the author of a virus that logged keystrokes on personal computers to capture passwords for Nordea, a Swedish bank, and the accounts were drained of about $1 million.

For a time, these rogue programs were openly for sale on a Russian Web site. The home page displayed an illustration of Lenin making a rude gesture.

Since Mr. Horohorin’s arrest, the badb.biz Web site has gone dark.

But through Monday, at least, its CarderPlanet counterpart, the Russian site carder.su, was still open for business.

Monday, August 02, 2010

Slovene Police, FBI Hail Ties in Cyber Crime Probe

Associated Press

 
An FBI official said Friday a two-year-long multinational investigation led them to nab a 23-year-old Slovenian, who allegedly created a malicious software code that infected 12 million computers worldwide.

Stephen Gaudin, a legal attache of the FBI to the U.S. embassy in Vienna, Austria, told reporters that the cooperation between the FBI, Slovenian and Spanish forces was "unparalleled."

Slovenian police detained and questioned the man, identified only by his code name Iserdo, ten days ago, in the northwestern industrial city of Maribor. He was released after questioning, but police say they have made sure he cannot tamper with evidence or flee the country. They have not given details of how they have ensured that.

The investigation is ongoing and Iserdo was not formally indicted yet.

He is suspected of selling the malware to the operators of the Spanish Mariposa botnet - a network of infected computers - which stole credit cards and online banking credentials.

The Mariposa botnet, which has been dismantled, was easily one of the world's biggest, infecting hundreds of companies and at least 40 major banks in 190 countries since appearing in Dec. 2008.

Toni Kastelic, the head of Slovenian police cyber crime department, said police also questioned another, 24-year-old person, and confiscated 75 computers in seven house searches.

Kastelic said they were tipped off by FBI in April.

He didn't identify the chief suspect, Iserdo - which, read backwards, means "salvation" in Slovenian.

Kastelic said Iserdo sold his code to "a bigger number" of customers, who paid between euro100 ($130) and several thousand euros (dollars) for it, depending on the version. His chief buyers were from Spain, he said.

Iserdo was detained five months after Spanish police broke up the massive cyberscam, arresting three of the alleged ringleaders who operated the Mariposa botnet. They are being prosecuted for computer crimes.

The FBI said earlier this week that this case was significant because it targeted both the creator and operators of the malware. It also said more arrests are expected.

Slovenian media haven't disclose the identity of Iserdo either, only saying that he was a former student of the Maribor Faculty of Computing and IT.

Friday, May 15, 2009

Rapidly Spreading 'Gumblar' Attack Redirects Users' Web Searches
Malware scripts morph from site to site, and even from page to page, within the same site, ScanSafe researchers say

By Tim Wilson, DarkReading, May 14, 2009

A Web-borne malware attack that redirects users' Internet searches is growing "exponentially," and has already infected more than 2,300 Websites, researchers said today.

Researchers at security company ScanSafe are warning users about an emerging series of Website compromises, collectively dubbed "Gumblar," which are spreading at a rapid rate. In the past week, Gumblar site compromises have grown at a rate of 188 percent, making it one of the fastest-growing infections on the Web, ScanSafe says.

"It should be waning by now, but it isn't," says Mary Landesman, senior security researcher at ScanSafe. "It just keeps spreading."

Gumblar, which has been spotted on popular sites such Tennis.com, Variety.com, and Coldwellbanker.com, is believed to be growing rapidly due to its unique combination of characteristics. The malware resulting from Gumblar forcibly redirects search page results to sites other than those users expect. Many of these pages are imitations of the Websites users actually intended to visit.

"For example, if a user is trying to visit Tennis.com via Google, they may be directed to a fraudulent site designed to look like Tennis.com, where a backdoor Trojan will be immediately downloaded," ScanSafe reports. "The Trojan could then allow cybercriminals control of the victim's computer, leading to a myriad of security issues, including personal data theft and stolen FTP credentials. Once cybercriminals are in possession of a victim's FTP credentials, any sites that victim manages can also be targeted for compromise -- a common malware propagation tactic."

One of Gumblar's exploits is to launch a "man-in-the-browser attack," in which the downloaded malware monitors all traffic to and from the browser, Landesman says. From this position, the malware can selectively swap out links in search results, effectively fooling the user into going to an unintended site.

Landesman speculates that Gumblar might be operating as a "botnet for hire," achieving different ends for different "clients." In many cases, the attack seems to be facilitating click fraud, in which the criminal simply redirects Web traffic to a fraud site in order to collect page views and advertising revenue. In other cases, Gumblar is routing users to malicious sites that might load additional malware onto the user's machine.

"A third potential exploit, which we haven't seen yet, is to redirect users from e-commerce or banking sites for the purpose of fraud, like a traditional phishing attack," Landesman says.

Gumblar is difficult to detect because its scripts vary from site to site, and even from page to page, Landesman says. "The cybercriminals responsible for Gumblar have learned to morph its features quickly," Landesman says. "This, coupled with Gumblar's other dynamic characteristics, is allowing the compromise to disseminate more rapidly than others we've seen."

The rapidly changing nature of the attack also makes it difficult for traditional signature detection or blacklisting tools to block, Landesman says. "If you were an individual user, I'd just tell you to disable JavaScript," she says. "But that's not possible for most businesses to do."

ScanSafe is attacking the problem via Web filtering, essentially preventing the user from going to the Gumblar sites and being infected in the first place, Landesman says. "Prevention is really the only workable defense because once you've been infected and your FTP credentials have been stolen, the criminal can modify passwords and make it difficult for you to get control back," she says.

The Gumblar Website, which dishes out the malware, is going to be difficult to find and bring down, Landesman says. While the site itself has a Chinese registry (Gumblar.cn), its source IP addresses have been traced to Latvia and Russia, and its servers are located in the U.K. "The criminals are doing a really good job of hiding their actual location," she says.

ScanSafe has posted blogs on its Website that describe the malware and its potential effects on enterprises and end users. The company will continue to post updates as the attack spreads, Landesman says.

Wednesday, April 15, 2009

Who's Taking Your Data? The Mob
Story from the Washington Post

A string of data breaches orchestrated principally by a handful of organized cyber-crime gangs translated into the loss of hundreds of millions of consumer records last year, security experts say.

The size and scope of the breaches, some of which have previously not been disclosed, illustrate the extent that organized cyber thieves are methodically targeting computer systems connected to the global financial network.

Forensics investigators at Verizon Business, a firm hired by major companies to investigate breaches, responded to roughly 100 confirmed data breaches last year involving roughly 285 million consumer records. That staggering number -- nearly one breached record for every American -- exceeds the combined total breached from break-ins the company investigated from 2004 to 2007.

In all, breaches at financial institutions were responsible for 93 percent of all such records compromised last year, Verizon reported. Unlike attacks studied between 2004 and 2007 -- which were characterized by hackers seeking out companies that used computer software and hardware that harbored known security flaws -- more than 90 percent of the records compromised in the breaches Verizon investigated in 2008 came from targeted attacks where the hackers carefully picked their targets first and then figured out a way to exploit them later.

Bryan Sartin, director of investigative response at Verizon Business, said criminals in Eastern Europe played a major role in breaches throughout 2008.

"About 50 percent of the confirmed breach cases we investigated shared perpetrators," Sartin said. "Organized crime is playing a much larger part of the caseload we're seeing. We've seen that both [the FBI] and the Secret Service have initiatives underway to go back through their cyber crime case histories over the past several years, to start tying together all of the common characteristics of the attacks to individuals, to really try and get a firm handle on the individuals responsible for these attacks."

For example, a single organized criminal group based in Eastern Europe is believed to have hacked Web sites and databases belonging to hundreds of banks, payment processors, prepaid card vendors and retailers over the last year. Most of the activity from this group occurred in the first five months of 2008. But some of that activity persisted throughout the year at specific targets, according to experts who helped law enforcement officials respond to the attacks, but asked not to be identified because they are not authorized to speak on the record.

Shawn Henry, assistant director of the FBI's cyber division, said the bureau is making real progress in working with foreign law enforcement to track down the major sources of cyber crime.

"The sophistication of these attacks has gone up, the bravado has gone up, and our commitment is steadfast," Henry said. "We're working very closely with foreign law enforcement and with some of the victims, and we certainly recognize how significant these threats are coming from all over Eastern Europe."

One hacking group, which security experts say is based in Russia, attacked and infiltrated more than 300 companies -- mainly financial institutions -- in the United States and elsewhere, using a sophisticated Web-based exploitation service that the hackers accessed remotely. In an 18-page alert published to retail and banking partners in November, VISA described this hacker service in intricate detail, listing the names of the Web sites and malicious software used in the attack, as well as the Internet addresses of dozens of sites that were used to offload stolen data.

"This information was recently used by several entities to discover security breaches that were otherwise undetected," VISA wrote.

The Washington Post obtained a partial list of the companies targeted by the Russian hacking group from a security researcher, which was left behind on one of the Web servers the attackers used. More than a dozen companies on that list acknowledged first learning about intrusions after being contacted by law enforcement agencies tracking the activities of the cyber gang.

This group's most high profile and lucrative haul last year came from Atlanta-based payment processor and payroll card giant RBS WorldPay. In that attack, which the company disclosed on Dec. 23, 2008, the hackers siphoned nearly $10 million from the U.S. banking system by artificially inflating the balances on prepaid credit or cash cards. The thieves extracted money from the system by distributing the cards to dozens of so-called "money mules," who used them to withdraw millions in cash from ATMs in cities across the country in a coordinated heist that took less than 24 hours.

The same hacking group also was responsible for a breach last year at Okemo Mountain Ski Resort in Ludlow, Vermont. In that attack, which Okemo disclosed on April 1, 2008, the criminals stole payment data encoded on more than 28,000 credit and debit card that the company processed from skiers during a 16-day period in early February.

A month prior to that, this hacker group broke into OmniAmerican Bank, based in Fort Worth, Texas. As a result, criminals were able to fabricate debit cards and PINs, and then withdraw an undisclosed amount of cash from ATMs in Russia and Ukraine

Other breaches attributed to this group has not been disclosed until now. The Web site for Euronet Worldwide, a Leawood, Kan., based electronic payment processor that operates a major ATM network in Europe, Asia and the Middle East, also was included on the hacker group's hit list. Euronet spokeswoman Shruthi Fielder confirmed that the company learned in March 2008 that "a portion of its Indian subsystem was attacked by a sophisticated cyber-crime group through a Web-facing program." Data concerning 38,000 bankcards was compromised in the breach. The company said it did not previously disclose the breach until contacted by a Washington Post reporter because the victims resided outside of the United States and beyond the reach of domestic data breach disclosure laws.

The attackers weren't always able to make off with cash or bank account data after successfully breaching a financial institution last year. The same group of attackers also broke into TSYS, currently the world's second largest credit and debit card processor on March 8, 2008.

TSYS spokesman Cyle Mims said the break-in was quickly detected and contained by the company's security staff.

"We found out about it and corrected it within hours, and no proprietary data of any kind was taken," Mims said, adding that the FBI contacted the company several months later to inform them that TSYS systems may have been targeted.

Attackers in this group also went after FirstData ATM Services, a division of Greenwood Village, Colo., based payment processor First Data Corp., which provides technology-based ATM and POS solutions to financial institutions and independent sales organizations nationwide.

A spokeswoman for the FirstData declined to say whether the attackers were successful in breaking in. The company would say only that no personal data was stolen.

"As with many other commercial Web sites, firstdataatm.com experiences unauthorized attempts to access information contained within the site," the company said in a written statement. "Our security infrastructure has been able to detect and prevent the unauthorized access of any personal information from the site."

Experts say a different cyber-crime gang operating out of Eastern Europe was responsible for what may turn out to be last year's biggest cyber heist. Princeton, N.J., based credit card processor Heartland Payment Systems disclosed on Jan. 20 that hackers had breached its systems last summer, planting malicious software designed to capture and secretly siphon account numbers as they traversed the company's internal processing networks.

Heartland, which processes roughly 100 million credit and debit card transactions per month, hasn't disclosed how many accounts may have been compromised. Company officials declined to comment for this story, citing pending class-action litigation against Heartland by entities affected by the breach. But so far, more than 600 banks have reported cards compromised as a result of the Heartland breach, according to Bankinfosecurity.com.

Steve Santorelli, director of investigations at Team Cymru, a small group of researchers who work to discover who is behind Internet crime, said the hackers behind the Heartland breach and the other break-ins mentioned in this story appear to have been aware of one another and unofficially divided up targets.

"There seem, on the face of anecdotal observations, to be at least two main groups behind many of the major database compromises of recent years," Santorelli said. "Both groups appear to be giving each other a wide berth to not to step on each others' toes."

In Feb. 2009, the Secret Service and FBI issued a rare joint advisory through VISA's Web site, warning banks and retailers about the techniques the hackers were using and some of telltale signs that hackers may have broken in.

"Over the past year, there has been a considerable spike in cyber attacks against the financial services and the online retail industry," the advisory begins. It goes on to list a variety of methods online merchants can use to detect and block the most common types of attacks.

In all of specific attacks mentioned above, the methods used and tools used by the hackers were remarkably similar: The crooks scanned hundreds of financial company Web sites or partner sites for known security holes. Once they had exploited those holes and had made their way to the target's internal network, the attackers would install a variety of hacking tools and begin mapping the network.

According to the FBI and Secret Service, those tools usually included "sniffer" programs designed to capture credit and debit card information flowing across the bank or processor's internal networks. In addition, the crooks also installed "beacons" that allowed the attackers to connect back to the hacked sites in the future, as well as offload stolen data.

Verizon's Sartin, said hackers last year mostly went after entities that held large stores of debit card information and corresponding PINs, information that criminals could use to extract cash from ATMs once they had imprinted the stolen data on fabricated cards.

Unlike credit card fraud, debit card fraud often hits consumers directly in the pocketbook.

"ATM fraud is a much different story, because meanwhile your cash assets are missing and the burden is now on you to prove that it wasn't you who took all the money out of the account," Sartin said.

Nicholas Percoco, vice president of SpiderLabs, the incident response department at Chicago-based security vendor Trustwave, said that the methods described by federal investigators are consistent with a large number of the successful break-ins they examined.

Percoco said a majority of the breaches at financial institutions last year show strong signs of being the work of organized criminal gangs in Russia and Eastern Europe.

In August 2008, the Justice Department announced its largest identity theft and hacking case ever prosecuted, against 11 members of what it called "international hacking rings" allegedly responsible for the theft and sale of more than 40 million debit and credit card numbers stolen from various retailers, including JX Companies, BJ's Wholesale Club, OfficeMax, Boston Market, Barnes & Noble, Sports Authority, Forever 21 and DSW.

Sartin said that regardless of whether the criminals behind these attacks are apprehended, the breach reports from last year will be trickling in for some time, while other breaches may never be disclosed.

"About a third of the breaches investigated by our team last year are publicly disclosed. More, especially those toward the end of the year, are likely to follow. Others will likely remain unknown to the world as they do not fall under any legal disclosure requirements," he said.

Tuesday, March 17, 2009

aspx php urls rank poorly in google
.ASPX And .PHP URL's Don't Rank Well In Google
Website-Infecting SQL Injection Attacks Hit 450,000 Per Day
Originally Posted at USA Today

Cybercriminals are spreading invisible infections far and wide across the Internet by hammering hundreds of thousands of websites each day with so-called SQL injection attacks.

The trend started last summer and has continued to accelerate. IBM Internet Security Systems says it identified 50% more infected Web pages in the last three months of 2008 than it did in all of 2007.

Click on one and you won't notice anything. Your PC gets turned into an obedient "bot," short for robot, deployed to attack other computers. All of your sensitive data get stolen.

SQL attacks take aim at the database layer of websites. They typically were manual attacks designed to pilfer customer data from merchant websites. But last June someone figured out how to automate the attacks, and use them to plant infections.

"It was a brilliant tactical move. You sit back and wait for someone to visit the site, and soon you infect thousands of PCs," says Ryan Barnett, Breach Security's director of research.

An infected PC thereafter gets put to work delivering spam and spreading more infections. And any sensitive data, such as log-ons and account numbers, get stolen.

For the first five months of 2008 IBM ISS helped large corporations block about 5,000 SQL attacks a day. By mid-June, daily attacks spiked to 25,000; by October they topped 450,000 a day. Holly Stewart, IBM ISS threat response manager, says the infections take advantage of security flaws in cool website features, such as online-delivered video, music, photos, documents and work files.

"Web applications are one of the most outward facing components a corporation could have, and one of the least protected," she says. "And SQL injection is the fastest-growing category of attacks affecting Web applications."

Giant financial institutions and online merchants have put up strong defenses, says Phil Neray, vice president of security strategy at Guardium, a database security firm. "The same is not necessarily true of regional banks and credit unions, smaller online retailers and state government agencies."

Security experts say consumers must keep updates for anything to do with their browser current, though most now do not do this. This includes updates for Internet Explorer, Firefox, Safari, Opera, Chrome, Adobe Flash, Adobe Reader, iTunes, QuickTime, Windows Media Player and RealPlayer. Such updates increasingly include important security patches that can block infections from taking hold.

Peak Positions Organic SEO News has more on why .aspx .php urls struggle to rank in google