Showing posts sorted by date for query Stuxnet. Sort by relevance Show all posts
Showing posts sorted by date for query Stuxnet. Sort by relevance Show all posts

Operation Intifada By Anonymous (DDOS attack on Israel Gov)


The latest target of Operation Anonymous, which following the dissolution of LulzSec is the last substantial non-amorphous hacker collective left out there, could lead to some substantial geopolitical fallout. That is because the target of the just announced upcoming DDOS attack is none other than the Israeli Parliament, the Knesset, and while Israel has allegedly been happy to dispense hack attacks in the past, the onslaught on the Iranian nuclear power plant courtesy of the Stuxnet virus coming to mind, we doubt it will as happy to be seen on the receiving end of decentralized computer warfare. Either way, with the world focusing on Greece tomorrow, this development, and specifically what form of retaliation Israel adopts, will be yet another important factor to keep track of over the next 24 hours. 
-Source Zerohedge


SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Germany Launches Cyber Defense Center


Germany is the latest country to build itself its very own cyber-defense center to build a strategy to defend against cyber-warfare, a hot issue this year. The National Cyber-Defense Center is located in Bonn at the Federal Office for Information Security building. For now, it had ten permanent employees with the German Federal Police, Federal Intelligence Service and Armed Forces to join the effort in the coming months. The Interior ministry said it recorded a record number of attempted cyber attacks last year, nearly double the number of attempts in 2009.

"At the heart of cyber-security is the protection of critical infrastructures," said Federal Interior Minister Friedrich. "Stuxnet and the most recent example of the hacker attack on the French nuclear company EDF (Electricité de France) have shown that IT systems represent critical infrastructure in the context of cyber-attacks." 

Germany's move follows other's around the world, including the UK's Cyber Security Operations Center (CSOC) and the United States' Cyber Command center. Estonia, which was the victim of a country-wide cyber-attack in 2007 in a dispute over the moving of a soviet-era war monument, is also planning to build its own cyber defenses.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Black Hat, the World's Leading Security Conference, on Abu Dhabi



IT security professionals will be delighted to learn the UAE Telecommunications Regulatory Authority (TRA), represented by the UAE Computer Emergency Response Team (aeCERT), in cooperation with Khalifa University of Science and Technology, has partnered with UBM again to bring the second edition of the world's leading information security conference, Black Hat to Abu Dhabi.
This year's Black Hat Abu Dhabi will take place from the 12th to 15th December 2011 at the luxurious Emirates Palace and will concentrate on 2 days of training sessions and 2 days of briefings which will discuss and demonstrate the latest and most important security issues faced in the market today.  Last year, this included among others, a new Android attack demonstration, new web attack and password cracking tool, a new chip was broken, new code released, a new ID card was broken and new Stuxnet conclusions were presented.
The event fits with aeCERT policy to assist the process of identifying, preventing and responding to cyber security attacks; coming up with operating mechanisms for the TRA's strategy to increase cyber security in the UAE.
His Excellency Mohamed Nasser Al Ghanim, Director General of the TRA, said: "We have decided to partner with UBM to hold Black Hat Abu Dhabi for a second time because of the increasing need to protect our IT systems from attack, because of the enormous success of the first Black Hat Abu Dhabi and partnership fostered between UBM, the TRA, aeCERT and Khalifa University.  The event continues to support the TRA vision to make the UAE's ICT sector a leader in the global market place.  As such, the TRA is proud to be the leading partner of Black Hat Abu Dhabi for the second time."
UBM is inviting potential sponsors, exhibitors and delegates to take part in Black Hat Abu Dhabi, which will attract only the highest-placed security professionals from government entities, academia and private companies with the power to make security buying decisions.  


Jeff Moss, founder and Conference Chair of Black Hat, stated: "We are excited to be able to bring Black Hat back to the Middle East. Our partners are continuing thevisionto establish a culture of cybersecurity within their public and private sector organizations and Black Hat is supporting those endeavours by bringing the best trainings and latest research to Abu Dhabi and the Middle East. We will to continue to build upon the foundation from last year's event and once again showcase the commitment of the UAE ICT sector to being a leader in the globalmarkets for security."


Black Hat Abu Dhabi will offer a full range of sessions, including ten training programmes running on 12th and 13th December, followed by three briefing tracks running simultaneously on the 14th and 15th alongside the exhibition.
Companies, government agencies, associations, institutions and individuals who wish to get involved as a sponsor or delegate should contact the organiser UBM Middle East.  
For more information or to register your interest please visit: http://www.blackhat.com or contact becky.crayman@ubm.com.
Notes to the editor
For more information please see http://www.blackhat.com  
Individuals, associations, government bodies, academic institutions and companies interested in finding out more about Black Hat Abu Dhabi should contact the organisers, UBM Middle East for information, on +971-2-406-4471 or email becky.crayman@ubm.com
Black Hat briefings and training is the largest and most important security conference series in the world.  Black Hat Abu Dhabi is organised by UBM Middle East on behalf of TechWeb, a division of United Business Media.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

NATO Said:- Anonymous will be "infiltrated" and "persecuted"


The North Atlantic Treaty Organization contains the combined military might of 28 member countries, including Germany, the United Kingdom, and France. All three of those nations, and the United States, possess huge armies, nuclear weapons, and are committed to Article Five of NATO's charter:
"The Parties agree that an armed attack against one or more of them in Europe or North America shall be considered an attack against them all and consequently they agree that, if such an armed attack occurs, each of them, in exercise of the right of individual or collective self-defence recognised by Article 51 of the Charter of the United Nations, will assist the Party or Parties so attacked."
Yet reading NATO's new draft general report on cyber security, one gets the impression that what the alliance worries about most these days is not an "armed attack," but a cyberattack on its network servers, or the infrastructure of any of its member countries.
"In this Information Age, the North Atlantic Alliance faces a dilemma of how to maintain cohesion in the environment where sharing information with Allies increases information security risks," NATO's Information and National Security survey observes, "but where withholding it undermines the relevance and capabilities of the Alliance."
And WikLeaks and Anonymous get top billing as visible threats to NATO's efforts to control its information perimeters.
"The time it takes to cross the Atlantic has shrunk to 30 milliseconds, compared with 30 minutes for ICBMs and several months going by boat," the report warns. "Meanwhile, a whole new family of actors are emerging on the international stage, such as virtual 'hactivist' groups. These could potentially lead to a new class of international conflicts between these groups and nation states, or even to conflicts between exclusively virtual entities."

The irony of 9/11:-

Authored by Lord Michael Jopling, Rapporteur for NATO, the study begins with an irony. Following the attacks of September 11, 2001 on New York City and Washington, DC, the United States government concluded that one of the reasons that the plot succeeded was because information about its perpetrators wasn't widely shared among US intelligence agencies, especially the Department of Defense, CIA, State Department, and Federal Bureau of Investigation.
And so the US opened up its data sharing practices. This made matter worse, Jopling appears to suggest. It "resulted in an exponential number of people obtaining access to classified information." Over 850,000 functionaries now enjoy some kind of "top-secret" security status, he claims. Many have access to the DoD's Secret Internet Protocol Router Network (SIPRNet), dispenser of embassy cables.
The study cites critics of SIPRNet who say that it lacks the ability to detect unauthorized access. "Thus, those in charge of the network design relied on those who had access to this sensitive data to protect it from abuse. These users were never scrutinized by any state agency responsible for the data-sharing system."
Jopling doesn't explicitly blame this openness policy for WikiLeaks phenomenon, but his narrative leads right into Private Bradley Manning, accused of providing documents for the outfit, prompting the group's famous publication of a continuous stream of State Department cables.
Not surprisingly, he thinks that this is bad:
The Rapporteur believes that even if one is in favour of transparency, military and intelligence operations simply cannot be planned and consulted with the public. Transparency cannot exist without control. The government, and especially its security agencies, must have the right to limit access to information in order to govern and to protect. This is based on the premise that states and corporations have the right to privacy as much as individuals do and that secrecy is required for efficient management of the state institutions and organizations.

Hacktivity:-

A big chunk of the assessment is devoted to the activities of Anonymous, most notably its denial-of-service attacks against PayPal, MasterCard, Visa, and Amazon.com for shutting down financial and server space services to WikiLeaks. Next comes the Anonymous assault on HBGary Federal, which had been planning some methods to take down WikiLeaks and expose Anonymous. It didn't turn out that way, of course. Instead, Anonymous penetrated the security company, erasing data, publishing e-mails, and wrecking its website.
The author seems confident, however, that the notorious group's days are numbered. "It remains to be seen how much time Anonymous has for pursuing such paths," Jopling writes. "The longer these attacks persist the more likely countermeasures will be developed, implemented, the groups will be infiltrated and perpetrators persecuted."
But the larger question hovering over this document is what NATO should do if one of its over two-dozen member nations is cyberattacked. The US has lately been pondering this dilemma as well.
"Certain hostile acts conducted through cyberspace could compel actions under the commitments we have with our military treaty partners," says a White House strategy report published in mid-May. "When warranted, the United States will respond to hostile acts in cyberspace as we would any other threat to our country."
This NATO draft seems to want to go in a similar direction—especially if something on the scale of a Stuxnet malware attack is deployed against a member nation. Designed to penetrate software for industrial equipment, researchers believe that it was originally intended for Iran's nuclear program.
"Some argue that Article 5 should not be applied with respect to cyberattacks because their effect so far has been limited to creating inconvenience rather than causing the loss of human lives and because it is hard to determine the attacker," Jopling notes. "However, The Rapporteur believes that the application of Article 5 should not be ruled out, given that new developments in cyber weapons such as Stuxnet might eventually cause damage comparable to that of a conventional military attack."

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

dna-stuxnet.in hacked by shadow008



Hacker site hacked again. This time famous black hat community, specialist in server rooting site dna-stuxnet.in got hacked by Shadow008 (Pak Cyber Army)

Hacked Site:- 
http://www.dna-stuxnet.in/


Mirror Link:- 
http://zone-h.com/mirror/id/14090295

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Cybercrime can ruin the entire economies



Russian anti-virus guru Eugene Kaspersky does a quick calculation in his head as he blinks at the ceiling.Satisfied, he announces: "About 200000."

That's the number of virus-infected computers in a targeted attack on SA's internet infrastructure that would shut it off from the rest of the world. No e-mail. No electronic transactions. No web searches. No e-government. No Skype, Twitter or Facebook. Nothing.

He's not being alarmist - it happened in Estonia in 2007.
And 200000 rogue computers is not a huge number. Organised syndicates or loners with modest technical know-how and resources can harness millions of virus-infected machines they effectively control to add muscle to their efforts - from stealing money and identities to managing online corporate espionage or collapsing the infrastructure and function of a country's economy and government.
Kaspersky is CEO and founder of Kaspersky Lab, one of the world's top four anti-virus software companies and Europe's biggest. Worldwide, the software anti-virus industry is worth about $7-billion a year in profit for firms in the sector. His fortune is estimated at $800-million and Forbes rates him as Russia's 125th-richest person. He was in SA to talk to business executives and security experts about the rising cybercrime threat to business, governments and organisations of all types.
"There are literally millions of computer viruses in the wild," he says. "Last year alone we collected 20million of them. Most are variations on a theme and can be dealt with automatically in our labs. However, there are teams of experts at anti-virus organisations around the world that work against new threats round the clock. Once a virus is discovered, it can be reverse-engineered and countered with an antidote pretty quickly," says Kaspersky.
He worries about the ability of viruses, or malware (malicious software) to perform increasingly sophisticated and sinister attacks. Typically, these are denial of service (DOS) assaults using networks of computers infected by malware to bring down websites or online services by bombarding them with data. People who control these botnets can trigger a destructive payload at will.
The 2007 Estonian attack showed a botnet with enough resources could shut down banks, government departments, education networks, the media - just about any organisation with an online presence.
DOS attacks are just one aspect of the destructiveness of modern malware. Malware can also help with identity theft and data theft. The damage can be devastating.
"Estimates put the cost to business of cybercrime at anything between $100-billion to $1-trillion," he says . "One of the reasons it's so hard to put a figure on it is organisations that have been compromised are reluctant to talk about it."
Another is they don't know about it. Data theft is big business but differs from other forms of pilfering in that the original data stays where it is while a copy is spirited away, often undetected, via the ether.
"Some businesses are aware and active in countering virus attacks. Banks, for example, now build losses from cybercrime into the cost of doing business - they have a budget for it which includes defending against it and compensating for it when breaches occur. Computer viruses have permeated every part of society," he says.
In August 2008, a Spanair airliner crashed just after taking off from Madrid. It was that year's deadliest aviation accident and 154 people died.
Kaspersky says the airline found the computer system used to monitor aircraft technical problems was infected with malware that probably prevented detection of a system failure.
Last year marked the appearance of the Stuxnet virus, a virus so complicated to produce and dispatch it was probably at least partly the work of, or funded by, a nation state. Speculation is Stuxnet's purpose was to sabotage an Iranian nuclear reactor, although it can damage a variety of industrial systems.
Computer viruses have come a long way since the first, written in 1982 by US schoolboy Rich Skrenta, 15. Called Elk Cloner and written for early Apple II systems, it replicated itself on floppy disks and displayed a poem, sometimes corrupting disks it infected.
Brain was the first virus to infect IBM PCs and was released in 1986. It was written by two Pakistani brothers and distributed with their medical software to prevent piracy. It replicated itself and slowed systems.
The advent of the commercial internet in the early 1990s provided the ideal vehicle to spread viruses.
More advanced techniques used by virus writers meant they could be used to do anything from data theft and identity fraud to corporate espionage, blackmail and extortion.
Kaspersky says a Swedish bank was attacked in February and the remote access Trojan fooled operators into thinking that the screens they were monitoring had been frozen by a Windows blue screen computer error.
"The first rule when this happens is don't touch anything. They didn't. But the machine wasn't frozen, the virus had generated the blue screen and was diverting funds in the background from a perfectly functioning system that the operators thought wasn't working.
"Now malware writers are using social networks like Facebook and Twitter to spread their work." Organisations were threatened from within by disgruntled staff or criminals as shown by malware found on organisations' computers not connected to the internet.
Kaspersky says the computer virus threat is on the rise and inadequately protected businesses are vulnerable.
"Cybercrime is an industry now. Governments are finding it difficult to fight it because any laws they make regarding cybercrime are difficult if not impossible to enforce in the online world where attacks may come from networks made up of computers in different countries.
"Even on home soil, laws are difficult to keep relevant as the nature of attacks change. And in Japan, for example, there's simply no law against writing computer viruses.
"Lack of understanding the real threat of viruses is a dangerous game for businesses and organisations of all sizes to play," he says.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

U.N. Nuclear Agency Reportedly Fears that it Was Hacked By Iran





The U.N. nuclear agency is investigating reports from its experts that their cellphones and laptops may have been hacked into by Iranian officials looking for confidential information while the equipment was left unattended during inspection tours in the Islamic Republic, diplomats have told The Associated Press.
One of the diplomats said the International Atomic Energy Agency is examining "a range of events, ranging from those where it is certain something has happened to suppositions," all in the first quarter of this year. He said the Vienna-based nuclear watchdog agency was alerted by inspectors reporting "unusual events," suggesting that outsiders had tampered with their electronic equipment.
Two other diplomats in senior positions confirmed the essence of the report but said they had no further information. All three envoys come from member nations of the International Atomic Energy Agency and spoke on condition of anonymity because their information was privileged.
Agency spokeswoman Gill Tudor said the IAEA had no comment on the issue. IAEA inspectors are in Iran touring various facilities every other week.
A woman answering the cell phone of Ali Asghar Soltanieh, Iran's senior envoy to the agency, said Soltanieh "wishes to give no interviews" after the caller identified himself as an AP reporter and before the reporter could say what the call was about.
An agency official, who also spoke on condition that he not be identified, said strict security measures included inspectors' placing their cellphones into seamless paper envelopes, then sealing these and writing across the seal and the envelope to spot any unauthorized opening while they were away.
He said inspectors are not allowed to take their cellphones with them while touring Iran's uranium enrichment facilities and other venues. Laptops, he said, are either locked in bags or sealed the same way as cellphones when they are left temporarily unattended by inspectors. The computers also are sometimes left unattended in hotel rooms at the end of a work day, he said.
But the diplomat who spoke at greatest length about the reported breach said the Iranians had found ways to overcome the security measures. He said he had no further details.
Iran has been under IAEA inspections for nearly a decade after revelations that it was running a secret uranium enrichment program and has been hit with four rounds of U.N. Security Council sanctions over its refusal to halt the activity.
Tehran insists it wants only to provide peaceful nuclear energy for its rising population and notes that the Nuclear Nonproliferation Treaty allows for enrichment as a source of fuel.
But international concerns have grown. The uranium enrichment program could also make fissile warhead material. Also, Iran refuses to cooperate with U.N. investigations of suspicions that it ran alleged experiments related to making nuclear weapons.
Low-enriched uranium can be used to fuel a reactor to generate electricity, which Iran says is the intention of its program. But if uranium is further enriched to around 90 percent purity, it can be used to develop a nuclear warhead.
Olli Heinonen, who stepped down last year as the IAEA's deputy director general in charge of investigating Iran's nuclear program, said information on the laptops is encrypted – and therefore difficult to decipher. Anybody gaining access to information on cellphones would find little sensitive material, he said.
Heinonen speculated that any attempt to access such equipment might have been meant to plant spyware designed to infect the IAEA computer network once the cellphones or laptops are connected and siphon off information.
"It's possible if there is tampering that something is planted in the computer and when you work with sensitive data it transmits it or it contaminates other computers with sensitive information – like Stuxnet," he said.
IAEA officials attribute a temporary breakdown of Iran's enrichment program late last year to the Stuxnet computer worm, and Tehran has acknowledged that Stuxnet affected a limited number of centrifuges – a key component in uranium enrichment – at its main uranium enrichment facility in the central city of Natanz. Tehran blames the United States and Israel for creating and planting the malware

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Vulnerable information security


A drill against hacking conducted by the National Computing and Information Agency has shown the vulnerability of the country’s information infrastructure. Members of college hacking clubs found unencrypted passwords to a data center that operates the entire information system of the government. In a mock attack in 2007, 57 of 67 government organizations were also found to be vulnerable.
Prosecutors announced Monday that the April 12 cyber attack on the National Agricultural Cooperatives Federation, or Nonghyup, was traced to North Korea. North Korea can also target computer networks of other financial institutions, Korea Exchange, and the Korea Financial Telecommunications and Clearings Institute as well as networks of nuclear power plants, military facilities and transportation systems. The 2007 Hollywood action film “Die Hard 4.0” describes how terrorists can paralyze American transportation, financial, electricity and gas systems by hacking the country’s central computer network. Such a dreadful situation could happen in real life.
In the past, cyber hackers took advantage of the weakness of a system to spread malignant codes and create network disruptions. Nowadays, however, they have become more organized and sophisticated with clear purposes and targets as seen in the hacking into financial institutions and online game sites. To break into computer networks with high security, hackers turn personal computers into zombie PCs. They also employ a stealth method that makes it difficult to detect and analyze malignant codes and hacking techniques.
Stuxnet, which targets national infrastructure, is more dangerous. The malware infiltrates a government organization’s integrated control system and paralyzes it. Last year, Stuxnet attacked a nuclear power plant in Iran and shut down 20 percent of the facility’s centrifuges. Automated control systems at China’s Sanchia dam and high-speed railway were also affected by the malware. Stuxnet moves from PC to PC and infiltrates computers at industrial facilities via USB drivers. Prosecutors said 1,300 personal computers in Korea were infected with the malignant code.
In the wake of the distributed denial of service (DDoS) attack in 2009, the government strengthened its preparedness against cyber attacks and fostered security personnel. As seen in the massive cyber attack on Nonghyup, however, even experts were found to have weak security awareness. In addition, identifying the route of the attack is tough because the bank’s network system was operated by a subcontractor. In this digitalized era, information security is part of a country’s infrastructure. The government needs to conduct a comprehensive review of domestic information infrastructure to preempt a security crisis that can paralyze the entire country.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Security experts can't verify Iran's claims of new worm

 
Without a sample of the new worm that an Iranian official says attacked the country's computers, it's impossible to verify his claims, a security researcher said Monday.
Kevin Haley, the director of Symantec's security response group, said that his team has not found an example of the worm, dubbed "Stars" by the Iranian military commander responsible for investigating Stuxnet, the sophisticated malware that attacked the country's uranium enrichment facilities beginning in June 2009.
"Generally, samples [of malware] do get traded among security vendors," said Haley, explaining that when one antivirus company lacks malware it wants to analyze, it asks other firms to share their samples. "[Iran'] makes this a little more difficult, because we have no direct relationships there," added Haley. "But perhaps someone else does."
Although Symantec has asked researchers in other companies if they have a sample, as of late Monday it has not been able to acquire one.
No other security vendor has stepped forward to say it has a copy of Stars.
Security experts need the malware to corroborate claims by Brigadier Gen. Gholam Reza Jalali, the head of Iran's Passive Defense Organization, the military unit that defends the country's nuclear program.
On Monday, Jalali told Iran's Mehr News Agency that the Stars worm had been detected and thwarted, but provided no information on its function or targets, or when it was discovered.
Jalali's claim came just a week after he blamed Siemens for helping U.S. and Israeli teams create Stuxnet.
Stuxnet, which targeted industrial control systems manufactured by Siemens, has been called a "groundbreaking" piece of malware because it used multiple "zero-day" vulnerabilities, hid while it wreaked havoc on Iran's uranium enrichment hardware, and required enormous resources to create.
It's possible that Stars was not a targeted attack aimed at Iran, but simply part of a more traditional broad-based assault, said Haley.
"It could be a mass attack that got through their defenses," he said. "That could have raised the alarm. They're already paranoid about attacks."
Symantec sees millions of threats every day, the vast majority of which are not targeted, Haley said.
If that's the case, trying to identify Stars would be impossible. "In the case of Stuxnet, we actually had samples, we just didn't understand the significance of the threat until later," Haley said. "Finding [Stars] in our database would be like finding a needle in a haystack" without more information from Iran.
"And even if we found something, we wouldn't know if it was the one they're talking about," said Haley.
Other antivirus vendors, including Helsinki-based F-Secure and U.K. securitycompany Sophos, also acknowledged that they could not verify Iran's claims.
"We can't tie this case to any particular sample we might already have," admitted Mikko Hypponen, F-Secure's chief research officer, in a blog post Monday. "We don't know if Iran[ian] officials have just found some ordinary Windows worm and announced it to be a cyber war attack."
Graham Cluley, a senior security technology consultant at Sophos, also said his company had not been able to identify the malware.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Related Posts Plugin for WordPress, Blogger...