Friday, October 30, 2009
How Hackers Find Your Weak Spots
http://www.computerworld.com/s/article/343900/How_Hackers_Find_Your_Weak_Spots?taxonomyId=82
Thursday, October 29, 2009
For U Blackberry Lovers
Wednesday, October 28, 2009
Internet phone systems become the fraudster's tool
This process of breaking into phone company systems is 20 years old and was know as phreaking, but now that phone systems are integrated with the internet it is giving scammers more opportunities to hack. It is now now as VoIP (voice over internet protocol) which is a term used to describe a family of transmission technologies for delivery of voice communications over IP networks such as the internet.
The way the hackers got into these VoIP systems is they just guessed thousands of times what the system's password was. Unlike gmail that will block a user if it makes too many guesses, VoIP systems are not set up this way. If they VoIP has a weak password then it doesn't take long for a computer to figure it out. Once these hackers have access they can launch their attack on bank customers. The problem is that it is hard to track these hackers because they use distant VoIPs that are unrelated to themselves.
Scams like these have been a reoccuring theme this year. It is easy to see how these attacks could be prevented. At the level of the VoIP's, stronger passwords, smarter configurations to prevent password guessing attacks, and increased security could easily prevent hacking from cybercriminals. On the side of the victim I have one word: common sense. Who would give their personal information to an automated message? Never give your personal information out, and if you are worried that there is a problem with your billing information call your bank.
Tuesday, October 27, 2009
16 Year Old Hacks NASA haha
Jonathon James became the first juvenile to be sent to prison for hacking at the age of 16 years old. Through our knowledge from this class, James claimed to be gray hat hacker. In an anonymous PBS interview James was quoted saying, “I was just looking around, playing around. What was fun for me was a challenge to see what I could pull off."
James’s actions were directed towards prestigious and important institutions. One institution affected was ironically the Department of Defense. He installed a backdoor into a Defense Threat Reduction Agency server. The DTRA is an agency of the Department of Defense charged with reducing the threat to the U.S. and its allies from nuclear, biological, chemical, conventional and special weapons. The backdoor he created enabled him to view sensitive emails and capture employee usernames and passwords.
Another important institution the 16 year old compromised was NASA! NASA claimed that the boy stole over 1.7 million dollars worth of software. The Department of Justice claimed that the software stolen directly controlled the Space Station’s physical environment, including control of the temperature and humidity within the living space. NASA had to shut down its computer systems which cost them 41,000 dollars. How could a 16 year old boy hack into what millions of people base their safety upon? His response, "The code itself was crappy . . . certainly not worth $1.7 million like they claimed."
With all of the intrusions compiled against James, he would have served at least ten years as an adult. Due to his age, he was banned from computer use and was forced to serve a six-month sentence under house arrest with probation. The funniest part is that he then served six months in prison for violating his parole. James now claims that he learned his lesson and is in the process of starting a computer security company. Regardless, Jonathan James will always be known as the sixteen year old who hacked NASA!
If someone would have asked me what NASA should do to prevent hackers before I read this article, I would’ve said that their security is way beyond my technical knowledge. Although I’m sure the 16 year old was extremely knowledgeable, this should not have been possible. NASA obviously needs to add more firewalls and more up to date virus software. Most importantly, NASA and DTRA should conduct vulnerability tests. Vulnerability tests will highlight flaws and limitations on their systems and can show areas that may need improvement.