Friday, October 30, 2009

How Hackers Find Your Weak Spots

A recent article on ComputerWorld.com took a closer look into how hackers are using information gathered from social networking sites to hack into users personal accounts. This is done in several ways. Hackers “friend” users on sites such as Facebook, Twitter or MySpace and then use personal information gathered from their profile to guess either their password or their password security questions. Another common hacking technique is to “friend” a user and then become familiar enough with them to post links on their profiles. When users click on the links, malicious software is automatically downloaded onto their computers and information can then be stolen. Most people don’t think twice when accepting friend requests from people, especially if they seem to be your age or possibly even go to your school. What users of such sites don’t realize is just how easy it is to create a false account and then exploit the information gathered from these profiles. All users should be really selective about what information they put out there, and they should know exactly who they allow to see said information.

http://www.computerworld.com/s/article/343900/How_Hackers_Find_Your_Weak_Spots?taxonomyId=82

Thursday, October 29, 2009

For U Blackberry Lovers

According to the U.S. Computer Emergency Readiness Team, there is a warning Blackberry users need to be aware of. There seems to be a new software that could be used by hackers to turn the smartphone into a listening device. The application is being called the PhoneSnoop. What it actually does is it can configure the phone's speakerphone function to enable a hacker to listen to surrounding conversations remotely. The software uses what is known as a Blackberry API to intercept incoming calls. It is said that once the software is downloaded and installed, the software is triggered by a simple phone call, placing the device into speakerphone mode.

Sheran Gunasekera, who is the known developer of this application, wrote on his blog that he wanted to shed light on the threats posed by careless use of Blackberry smartphones. Gunasekera said "the application can be easily detected and is visible in the Blackberry user interface." According to US CERT, "This software allows an attacker to call a user's BlackBerry and listen to personal conversations." In order to install and setup the PhoneSnoop application, attackers must have physical access to the user's device or convince a user to install PhoneSnoop."

Doesn't seem to be a major threat unless you are careless enough to download it or allow someone else to. I thought this was crazy when i first heard it. That would be horrible if people could just listen to what you were saying. If someone has this program all they have to do is simply delete it. The problem seems to be that a lot of people aren't aware of this application. Awareness seems to be the key to not having this as a problem.

Source: http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1372852,00.html

Firewall Slides

Here are the slides we used in class this week:

Wednesday, October 28, 2009

Internet phone systems become the fraudster's tool

Cybercriminals recently hacked into multiple telephone systems across the US and using them to contact bank customers to give up their bank account information. They are attack smaller regional institutions that have lighter security towards detecting scams. These cybercriminals used the telephone systems to automatically call customers with an automated message. This message states that there is a problem with their billing information and the customer needs to type in their username, password, credit card number, pin number or other sensitive information to fix the problem.

This process of breaking into phone company systems is 20 years old and was know as phreaking, but now that phone systems are integrated with the internet it is giving scammers more opportunities to hack. It is now now as VoIP (voice over internet protocol) which is
a term used to describe a family of transmission technologies for delivery of voice communications over IP networks such as the internet.

The way the hackers got into these VoIP systems is they just guessed thousands of times what the system's password was. Unlike gmail that will block a user if it makes too many guesses, VoIP systems are not set up this way. If they VoIP has a weak password then it doesn't take long for a computer to figure it out. Once these hackers have access they can launch their attack on bank customers. The problem is that it is hard to track these hackers because they use distant VoIPs that are unrelated to themselves.

Scams like these have been a reoccuring theme this year. It is easy to see how these attacks could be prevented. At the level of the VoIP's, stronger passwords, smarter configurations to prevent password guessing attacks, and increased security could easily prevent hacking from cybercriminals. On the side of the victim I have one word: common sense. Who would give their personal information to an automated message? Never give your personal information out, and if you are worried that there is a problem with your billing information call your bank.

Tuesday, October 27, 2009

16 Year Old Hacks NASA haha

Jonathon James became the first juvenile to be sent to prison for hacking at the age of 16 years old. Through our knowledge from this class, James claimed to be gray hat hacker. In an anonymous PBS interview James was quoted saying, “I was just looking around, playing around. What was fun for me was a challenge to see what I could pull off."

James’s actions were directed towards prestigious and important institutions. One institution affected was ironically the Department of Defense. He installed a backdoor into a Defense Threat Reduction Agency server. The DTRA is an agency of the Department of Defense charged with reducing the threat to the U.S. and its allies from nuclear, biological, chemical, conventional and special weapons. The backdoor he created enabled him to view sensitive emails and capture employee usernames and passwords.

Another important institution the 16 year old compromised was NASA! NASA claimed that the boy stole over 1.7 million dollars worth of software. The Department of Justice claimed that the software stolen directly controlled the Space Station’s physical environment, including control of the temperature and humidity within the living space. NASA had to shut down its computer systems which cost them 41,000 dollars. How could a 16 year old boy hack into what millions of people base their safety upon? His response, "The code itself was crappy . . . certainly not worth $1.7 million like they claimed."

With all of the intrusions compiled against James, he would have served at least ten years as an adult. Due to his age, he was banned from computer use and was forced to serve a six-month sentence under house arrest with probation. The funniest part is that he then served six months in prison for violating his parole. James now claims that he learned his lesson and is in the process of starting a computer security company. Regardless, Jonathan James will always be known as the sixteen year old who hacked NASA!

If someone would have asked me what NASA should do to prevent hackers before I read this article, I would’ve said that their security is way beyond my technical knowledge. Although I’m sure the 16 year old was extremely knowledgeable, this should not have been possible. NASA obviously needs to add more firewalls and more up to date virus software. Most importantly, NASA and DTRA should conduct vulnerability tests. Vulnerability tests will highlight flaws and limitations on their systems and can show areas that may need improvement.

http://www.hackronomicon.com/?page_id=30

Wednesday, October 21, 2009

Reflections of Insecurity

There is an interesting article in Scientific American that would make a good case study or blog post for anyone who is looking for a topic...

Friday, October 16, 2009

Notre Dame Federal Credit Union

Today, my mom called me to let me know that a letter for me had been sent to my home address to notify me that my account information with the Notre Dame Federal Credit Union may have been compromised. This was the only form of notification that I received - I did not receive an email, or an additional letter to my campus address which I also provided to the NDFCU. After learning about some of the information security breaches that we have looked at in the case studies, I wonder how long ago my information was made vulnerable to hackers. I plan on looking into this matter further, but because it is the weekend and the banks are closed, for now I can only hope that the NDFCU is taking steps to secure my information. After this incident I am seriously reconsidering how much I need a bank account at school, and I may choose to cancel this account soon.