Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Wednesday, 19 January 2011

Hacker pair involved in 2010 iPad 3G AT&T data breach arrested by the FBI

On Tuesday morning, two members of the group Goatse Security, who hacked into AT&T's customer database last year and delivered close to 120,000 e-mail addresses of iPad 3G owners to Gawker, were arrested by the FBI. The pair, Daniel Spitler, 25, and Andrew Auernheimer, 26, used a "brute force" attack and an AT&T security hole to gather the email addresses.

The pair used the fact that iPad 3G's SIM has an ICC-ID, a 19-digit code that AT&T associated with a user's account and email address. AT&T used the ICC-ID to pre-populate a field containing the owner's email address when the user needed to login and check account status. By attempting ICC-IDs until they got a "hit," the pair was able to gather the email addresses.

AT&T was supremely embarrassed by the incident. Among the notables outed when the story first broke were luminaries such as New York City Mayor Michael Bloomberg, ABC News' Diane Sawyer, movie titan Harvey Weinstein and New York Times Co. CEO Janet Robinson.

In a statement, U.S. Attorney Paul Fishman in New Jersey said:
"Hacking is not a competitive sport, and security breaches are not a game. Companies that are hacked can suffer significant losses, and their customers made vulnerable to other crimes, privacy violations and unwanted contact."
Each of the two was each charged with one count of fraud and one count of conspiracy to access a computer without authorization. Each of those charges carries a maximum punishment of five years in prison plus a $250,000 fine.

Although Goatse Security notified AT&T of the breach after harvesting the data, the U.S. Attorney's statement noted that in chats, it was made clear that the group wasn't doing this to be altruistic. Instead, Fishman said,
"Those chats not only demonstrate that Spitler and Auernheimer were responsible for the data breach, but also that they conducted the breach to simultaneously damage AT&T and promote themselves and Goatse Security."
Last year, Auernheimer was arrested on drug charges. Authorities were actually searching his home for evidence related to the AT&T - iPad investigation.  Auernheimer is pictured above in a booking photo from that arrest.

Monday, 17 January 2011

Facebook profile info used to hack into women's email accounts

People who wonder if perhaps some people give out too much information via social networking sites such as Facebook can look to this story and see the answer is at least sometimes "yes." George Samuel Bronk, 23, used profile information from Facebook to hack into women's e-mail accounts, steal nude images of them, and even blackmail them.

Bronk used an obvious, but clever method to hack into the women's accounts: since Webmail accounts have password recovery schemes that could be bypassed using information from Facebook profiles, such as favorite foods, high-school mascots, favorite colors, and so on, once he obtained that information, he would try to hack into an account. If he did, he would then change the password, locking out the original user, and that was just the beginning.

Bronk would then scan each women's "Sent Message" folder, looking for any nude pictures or videos. If he found any, sometimes he'd pictures to the women's entire contact list, just for fun. On other times, he'd blackmail the woman directly, telling them he'd publish the pictures unless he received more nude pictures from them. One victim called it "virtual rape." He would sometimes even double-dip, emailing Facebook using the stolen account to get the password, then using that account for mischief.

Late last week, Bronk pleaded guilty in Sacramento Superior Court to seven felony charges, including computer intrusion, impersonation and possession of child pornography. He faces up to six years in prison, and will return in March for sentencing.

Reportedly, he hacked into hundreds of accounts, with the women spread across 17 states and even in England.

This is obviously a cautionary tale. While it's probably not going to stop women from sending nude photos to their beaus (which might be a good idea), many Webmail sites allow custom password recover questions. If a user created their own custom question, one which they don't post to their Facebook profile, they wouldn't see this problem happen.

It's also possible to use standard questions if you either don't post the answer to a social networking site, or muck with the answer with a faux response. At any rate, it's just another example of why you shouldn't share "everything" on the Internet.

Sunday, 9 January 2011

Scanner-proof apparel will prompt a pat-down: TSA

Those companies who see the full body scanners at airports as an opportunity to create garments to block the scanners, and make a pretty penny, will be sadly disappointed. The TSA's blog has the bad news.

Blogger Bob, from the TSA Blog Team, said.
If there is something shielding an area and we don’t know what’s under it, we have to conduct a pat-down.

So basically, passengers should be aware that the use of these types of products will likely result in a pat-down. Some might think this is TSA’s way of getting back at clever passengers. That’s not the case at all. It’s just security.
Scanner proof apparel is becoming a growing industry, but this edict by the TSA should put a damper on the industry's prospects.

Saturday, 1 January 2011

New Android malware emerges in China

Just a few days after McAfee released its 2011 Threat Predictions Report, citing mobile as an up-and-coming target, San Francisco-based Lookout Mobile Security reported on a new malware variant targeting Android-based smartphones, appearing in China.

Lookout, which develops antivirus software for Android devices, calls the new malware “Geinimi." Geinimi is being “grafted” onto repackaged versions of legitimate Android applications (mostly games). The malware-laden apps are then distributed via third-party Chinese Android app markets.

That said, it would appear that those sticking to the standard Android Market would be safe. It does point out the dangers of sideloading, which is installing apps that are not hosting in Google's official Android Market.

Lookout notes the following:
[...] this Trojan can compromise a significant amount of personal data on a user’s phone and send it to remote servers. The most sophisticated Android malware we’ve seen to date, Geinimi is also the first Android malware in the wild that displays botnet-like capabilities. Once the malware is installed on a user’s phone, it has the potential to receive commands from a remote server that allow the owner of that server to control the phone. [...]

Lookout has already delivered an update for its Android users to protect them against known instances of the Trojan. If you are already a Lookout user (free or premium), you are protected and no action is needed.
Although most users would probably be happy with Lookout's free app, the premium service (subscription: $2.99 monthly) adds wipe capabilities and the ability to scan apps for privacy issues.

Geinimi runs in the background once a malware-laden app is run. It collects user information, as note below, that is then sent back to a remote server using one of ten embedded domain names. The malware transmits collected device information to the remote server once it connects.

Among the capabilities of Geinimi, Lookout said, are:
  • Send location coordinates (fine location)
  • Send device identifiers (IMEI and IMSI)
  • Download and prompt the user to install an app
  • Prompt the user to uninstall an app
  • Enumerate and send a list of installed apps to the server
Although Lookout, and other antivirus programs in the Android Market, can protect against this malware, a user can also be protected by only installing apps from trusted sources. If possible, don't sideload anything. Additionally, though admittedly a tedious process, checking the permissions that an app requests can help, as if an app asks for permissions that makes no sense for its described purpose, it can be a red flag. Use common sense to ensure that the permissions an app requests match the features the app provides.

This isn't the first Android malware discovered. In August, Kaspersky Labs reported that a virus named TrojaN-SMS.Android OS.FakePlayer-A had surfaced, in the form of a fake media player. The infected app would send SMS messages to expensive phone numbers, passing money from a user’s account to that of the malware writers. The virus reportedly only infected devices in Russia.

As mobile devices take on more and more of a role in the lives of consumers, it was only a matter of time until malware targeting devices would appear. It may be a long, long year for security experts.

GoDaddy.com