Tag: hackers

  • Anonymous stumbles, but hackers still hazardous

    Anonymous stumbles, but hackers still hazardous

    It hasn’t been the best of months for Anonymous, the loose hacktivist collective that likes to view itself as the most potent threat on the Web to big government, big business, and those who do not share its views on pretty much anything — law enforcement, the environment, internet freedom, copyright laws, politics etc. Several of its recent claims have been exposed as not just inflated, but outright fabrications.

    FBI hack refuted

    Earlier this month, AntiSec, an offshoot of Anonymous, posted more than 1 million Apple Unique Device Identifiers (UDID) to Pastebin, and claimed it had stolen more than 12 million of them from an FBI agent’s laptop in March.

    The group claimed to have personal mailing addresses and phone numbers besides the UDIDs, plus device tokens for the Apple Push Notification Service (APNS) for numerous types of Apple devices such as iPhones, iPads and iPod Touches.
    The FBI immediately denied that any of its computers had been compromised. Apple said it had never provided UDIDs to the FBI. And, as Michael Mimoso noted on the Kaspersky Labs blog Threatpost, David Schuetz, a senior consultant with Intrepidus Group, found that the real source of the breach was BlueToad, a Florida based technology provider for digital publishers.
    “[Schuetz] found a password dump online for BlueToad dated March 14, the same week AntiSec said it had breached the FBI computer. Any hesitancy Schuetz had regarding BlueToad’s connection to the breach was evaporating,” Mimoso wrote.
    Earlier this week, BlueToad CEO Paul DeHart publicly confirmed via the company’s blog that it was the source of the breach, that it had contacted law enforcement and was cooperating in the investigation.

    GoDaddy’s outage claimed

    There was also the recent boast by Twitter user @AnonymousOwn3r that he had shut down the website provider and domain name registrar GoDaddy on Sunday with a distributed denial-of-service (DDoS) attack.
    Wrong again, said GoDaddy interim CEO Scott Wagner, who explained on the company website that the problem was a “service outage due to a series of internal network events that corrupted router data tables.”
    [Slide show: Anonymous and LulzSec – 10 greatest hits]

    Then there was the claim last month that Anonymous was looking to break into the communication system between NASA and the Mars rover Curiosity.
    That didn’t even pass the laugh test for most security professionals, who viewed it as a bad joke or a weak attempt at trolling.
    Last March, LulzSec, which operated under the Anonymous umbrella, after the FBI arrested and then flipped its leader, Hector Xavier Monsegur, who went by the hacker name of “Sabu.”
    Does all this mean that the Anonymous brand has been undermined? Do its boasts and threats have any credibility in the security community?

    Anonymous uneven

    Yes and no, say those who track its exploits. Most agree with Cole Stryker, an author who has researched Anonymous and who The New York Times quoted describing it as “a handful of geniuses surrounded by a legion of idiots.”
    Those idiots, say experts, are going to make a host of errors and laughable claims. But that does not mean there is no danger from the core group.

    “What we have here is a bunch of kids, largely in UK and here and dozens of other places such as Brazil, Turkey, Iran, China, Ukraine, Romania and lesser numbers in other places across the planet — a bunch of really bored kids who want to be a part of something, but have no clue,” said Kevin McAleavey, cofounder of the KNOS Project and a malware and hacking expert.

    “How seriously do I take Anonymous’s claims? About as seriously as I take ‘The Daily Show,’” he said. “Yes, there are a handful of really dangerous people who those kids admire and who occasionally feed them a breath mint. One or two of them have already been apprehended. The rest have gone back to collecting exploits and writing malware, and selling them to criminals and government spooks for real cash. They won’t touch Anonymous any more because the heat is too high.”
    Nick Selby, a Texas police officer and information security consultant who runs a police-led intelligence blog, noted at the time of the LulzSec bust that there is essentially no barrier to claim membership in Anonymous. “It doesn’t require massive technical skills — just reasonable knowledge and a willingness to break the law,” he said.
    But Aaron Cohen, founder of the Hacker Academy, said he thinks it would be foolish to discount the group’s skill and power. He said he has a hard time talking about Anonymous, “because we don’t know who they are. People are out there doing things under the name of Anonymous, but you don’t really know if that’s true.”
    Cohen said the whole idea of an Anonymous brand misses the point. “They’re not looking for branding,” he said. “They’re doing it under a pseudo name. There is no call to arms to get somebody. But if one person says they’re going to get a company, then everybody tends to rally around that person.”
    But Cohen adds that he thinks Anonymous has been “pretty reliable so far,” in both its claims and its threats. And he said whether it is Anonymous or some other group, good hackers are proof that “if people want to break into something badly enough, they can.”
    “So if you’re a target, it’s best to tighten up,” he said.

  • How to Protect Your Social Network Accounts from Hackers

    How to Protect Your Social Network Accounts from Hackers

    A tech journalist learned a tough lesson recently. But using two-factor log-ons help guard your Google, Facebook, and Twitter accounts from being hijacked. If you haven’t read about Wired reporter Mat Honan’s ordeal at the hands of malicious hackers, take some time and read it now. (I’ll wait.) His story about how a passel of juvenile hackers managed to get into his Apple account and wipe all the data off his iPhone, iPad, and Mac— as well as hijack his Google, Twitter, and Amazon accounts – should be required reading for anyone who uses those services, and especially those of us who’ve blithely linked our social media accounts together using the same e-mail address. Honan didn’t do anything to tick those hackers off. He was targeted simply because they coveted his @mat Twitter handle. Which means that the same thing could happen to you or me just as easily, and we wouldn’t know we’d been jobbed until far too late.
    One thing Honan notes with regret is his failure to turn on two-factor authentication for his Gmail account. If he’d done that, anyone who tried to access his e-mail would have also had to enter a six-digit PIN, which is randomly generated and sent via text message to his phone.
    So your first order of business for today: Setting up two-factor authentication for Google. To do that, you’ll need to go into your Gmail Settings (it’s the icon that looks like a little gear in the upper right corner of your inbox). From there:

    1. Select Settings, then Accounts and Import.
    2. Under Change account settings select “Other Google Account settings”.
    3. That will take you to a Web page for your Accounts. Select Security from the left-hand menu. You may be prompted for your password again.
    4. Under “2-step verification” you’ll see “Status: OFF.” Click the Edit button next to that. That will take you to a Web page wizard that will walk you through the process of having a six-digit verification code sent to you via text or a robo-call.


    Enter the code into the appropriate box, and you’re all set – for that device, anyway.
    Admittedly, this is not as easy as simply using a password. You’ll have to do this for every device and every application that uses your Gmail logon, and every device and application doesn’t work exactly the same way. For example, I was able to log on to Gmail using a PIN on my desktop, laptop, and iPad, but not my Android tablet or Windows smartphone. For those, I had to set up separate one-time-use “subtokens” that look something like this: fztz dgpm oxfi uthb.
    You’ll need to go back to the Accounts Security page and select the Edit button next to “Authorizing Applications and sites” to set up disposable passwords for each device and app. You can also use this tool to manage your list of trusted devices and applications, and revoke access to them at any time.
    So that covers Google. What about Facebook? Here, too, you can beef up your security settings with two-factor authentication. This will prompt you to enter a similar SMS code whenever you log onto Facebook from a new device. The drill is remarkably similar:

    1. Go to your Facebook Account Settings page (found under the down arrow next to the Home tab).
    2. Select Security from the menu on the left.
    3. Under “Login Approvals” click edit and put a check in the box that appears (see below). You may have to adjust your browser settings to accommodate the cookie that Facebook wants to deposit.
    1. In the dialog box that appears, click “Set up now.” You may be prompted again for your Facebook password and to add your mobile phone number if you haven’t provided one already.
    2. Click Continue. If you’ve done this correctly you should receive a six-character PIN. Enter that and the name of your device into the dialog boxes that appear.

    Like Google, this won’t work with every device or application Facebook supports (like the Xbox or Skype). So again you’ll have to generate a disposable app password, which you can do via the same Security Settings dialog box. If you have an android device, you can download a free Code Generator app that can produce usable passcodes without having to send you a text.
    Twitter does not offer two-factor authentication at this time. But you can make it harder for attackers to reset your password by changing a setting in your profile that requires you to provide additional info, such as an e-mail address or phone number, when requesting a new password.
    From your Twitter profile page, click Edit your profile. Then go into your Account settings, scroll to the bottom, and put a checkmark in the box next to “Require personal information to reset my password.”

    The flaw in all of these schemes: If the attackers manage to get hold of your phone as well as your log-ons. Then, my friend, you’re totally screwed.
    Credits:
    For more computing news, visit ITworld. Story copyright © 2011 ITworld Inc. All rights reserved.

  • Yahoo Patches Password Leak

    Yahoo Patches Password Leak

    Yahoo says it has fixed the flaw that allowed hackers to steal more than 450,000 passwords from one of its many services.

    The company also provided more information about whose passwords had been pilfered. “We have…now fixed this vulnerability, deployed additional security measures for affected Yahoo! users, enhanced our underlying security controls and are in the process of notifying affected users,” the company announced in a post to its blog early Friday. Yahoo has offered no specific information about the attack, how it was carried out or even when. Itconfirmed the attack Thursday. The hacker group D33Ds Company took responsibility for the breach, saying it had exploited a basic SQL injection vulnerability in a Yahoo service to steal the usernames and passwords associated with 453,000 accounts. The group published the passwords and e-mail addresses on the Web.

    Hack Affects Associated Content Accounts

    Yahoo also confirmed that the stolen account credentials belonged to registered users of its Yahoo Contributor Network, which was previously known as Associated Content. Yahoo Contributor Network is a platform that generates high-volume, low-cost content by letting writers photographers, and others share their work with Yahoo members and earn money based on the traffic their content generates. Users who contribute to the network are required to sign in using a Yahoo, Google or Facebook ID.

    Associated Content, which was founded in 2005, was bought by Yahoo for just over $100 million in May 2010. Yahoo renamed the service in late 2011, when it also launched Yahoo Voices, a portal where users access content posted by the Yahoo Contributor Network. According to Yahoo, only people who registered as providers with Associated Content before the 2010 acquisition were affected by the password theft. “[The] compromised file was a standalone file that was not used to grant access to Yahoo! systems and services,” Yahoo maintained. Just under a third of the stolen passwords were linked to accounts registered to a yahoo.com e-mail address, security company Rapid7 said Thursday. Significant chunks of the file, however, were composed of Gmail (23.6 percent of all accounts) and Hotmail (12.2 percent) addresses. All users with older Associated Content accounts, no matter the e-mail address used, should immediately change the passwords for those e-mail accounts as well as any identical or similar passwords used to secure other online services or websites, security experts have said. Rapid7 security researcher Marcus Carey said Thursday that the file published by D33Ds included 123 government e-mail accounts — ones ending with “.gov” — and 235 military-related addresses (ending with “.mil”). Among the government e-mail accounts, Carey found several associated with the FBI, the Transportation Security Administration (TSA) and the Department of Homeland Security (DHS).

    Security Experts Blast Yahoo

    Security experts have been scathing in their criticism of Yahoo, in large part because the passwords were stored in plain-text, making the hackers’ job of exploiting the stolen accounts a breeze. Mark Bower, a data protection expert and executive at Voltage Security, said, “It’s utter negligence to store passwords in the clear.” Rob Rachwald, director of security strategy at Imperva, also took Yahoo to the woodshed. “To add insult to injury, the passwords were stored in clear text and not hashed (encoded),” Rachwald wrote in a blog post. “One would think the recent LinkedIn breach would have encouraged change, but no. Rather, this episode will only inspire hackers worldwide.” The LinkedIn breach Rachwald referenced came to light last month, and involved approximately 6.5 million encrypted passwords belonging to members of the networking service. In its Friday blog, Yahoo again apologized to users affected by the password theft.