Showing posts with label Hackers. Show all posts
Showing posts with label Hackers. Show all posts

Friday, January 13, 2012

Social Engineering: The Art of Human Hacking

The first book to reveal and dissect the technical aspect of many social engineering manoeuvres.

From elicitation, pretexting, influence and manipulation all aspects of social engineering are picked apart, discussed and explained by using real world examples, personal experience and the science behind them to unraveled the mystery in social engineering.


Kevin Mitnick: One of the most famous social engineers in the world. popularised the term “social engineering.”

He explained that it is much easier to trick someone into revealing a password for a system than to exert the effort of hacking into the system.

Mitnick claims that this social engineering tactic was the single-most effective method in his arsenal.

This indispensable book examines a variety of maneuvers that are aimed at deceiving unsuspecting victims, while it also addresses ways to prevent social engineering threats.
  • Examines social engineering, the science of influencing a target to perform a desired task or divulge information 
  • Arms you with invaluable information about the many methods of trickery that hackers use in order to gather information with the intent of executing identity theft, fraud, or gaining computer system access 
  • Reveals vital steps for preventing social engineering threats
Social Engineering: The Art of Human Hacking does its part to prepare you against nefarious hackers—now you can do your part by putting to good use the critical information within its pages.


Tour the Dark World of Social Engineering
  • Learn the psychological principles employed by social engineers and how they’re used
  • Discover persuasion secrets that social engineers know well
  • See how the crafty crook takes advantage of cameras, GPS devices, and caller ID
  • Find out what information is, unbelievably, available online
  • Study real-world social engineering exploits step by step
“Most malware and client-side attacks have a social engineering component to deceive the user into letting the bad guys in. You can patch technical vulnerabilities as they evolve, but there is no patch for stupidity, or rather gullibility. Chris will show you how it’s done by revealing the social engineering vectors used by today’s intruders. His book will help you gain better insight on how to recognize these types of attacks.”
Kevin Mitnick, Author, Speaker, and Consultant

“Chris Hadnagy has penned the ultimate text on social engineering. Meticulously researched and teeming with practical applications, this brilliant book offers solutions to very real problems and ever-present dangers to your business — and even to yourself. Truly groundbreaking.”
Kevin Hogan, author of The Science of Influence: How to Get Anyone to Say “Yes” in 8 Minutes or Less

Read More at Elite Professionals website

Tuesday, October 5, 2010

Changing Password does not Secure Hacked E-mail Account

People are baffled when their Gmail account is re-compromised and often have no idea how it keeps happening. So I’ve laid out some of the more obvious items that need to be checked to ensure that your Gmail/Google account is locked down.

Mind your filtersThe best method for an attacker to get back into your account is to keep reading your emails even after you’ve changed your password. So the basics of any Gmail backdoor will be to setup some email forwarding rules that send him or her a copy of your messages as they arrive - including password reset messages. Make sure you disable these following any compromise.

Under Settings> Forwarding and POP/IMAP ensure that disable forwarding is selected and that your incoming email is not being forwarded to the attacker. Next, check your filters list in Gmail and make sure there are not any rules setup that forward email to the attacker.

Check the Password Recovery settingsThe next best method of a backdoor is for the attacker to have the ability to recover or reset your password. This is not the sneakiest of routes but it accomplishes the job well. Ensure an additional recovery email address was not added to your account.This will allow an attacker to get the password reset link straight to his email.

Go to settings> Accounts and Import > Google account settings> Change password recovery options> Email.

Make sure the SMS number has not been changed in Google account settings. Also, make sure your security question has not been changed to a question known by the attacker. Sneaky attackers will leave your question the same but change the answer to one they know. Go ahead and change your question and answer.

Watch out for rogue applications
Gmail isn't just an email program, its part of an entire Web based application ecosystem. Check your authorized applications to see if the attacker added their own malicious application to be allowed on your account.

Everyone today adds social applications and gives permission to their Facebook/Google accounts through third party applications. Most people don't even look at what permissions the third party applications have.

In Gmail applications can pretty much do everything an attacker would want to do. Even better, from the attacker's stand point, is that no one even knows where how to revoke or check permissions on these applications once they've been approved, they're forgotten.

There are open source applications will grant full IMAP/SMTP access using OAUTH. Once the Gmail account is hijacked, an attacker can run this script and grant access to the application for full privileges.

Even if you change your password multiple times, a rogue application can continue reading your email and accessing your personal data.

Think beyond e-mail
Not only back doors allowing full access to read email should be considered. Attackers have several options to obtain your data in the world of open social collaboration that is easier then ever.

If you have Google voice, go into voice settings and make sure voicemail and text messages are not being sent to additional email addresses.

If you have important Google documents in Google Docs, ensure the attacker has not enabled sharing. Google calendar is a very nice backdoor. I'm sure you don't want someone unexpectedly dropping in and listening on your next board meeting. If so, there are a couple areas you need to check.

In the Calendar Settings, click on your calendars to display the detailed view and make sure you click "reset private URLs" in the private address section. This will change the private address that can be used to retrieve your calendar feed.

As an attacker I can easily just copy this URL and monitor your calendar. Next, click 'Share this calendar' tab and make sure that no email addresses are added that you don't recognise.

Friday, May 14, 2010

DDoS Attacks Targetting Web Servers over PCs

Security experts have warned of a new distributed denial of service (DDoS) attack that targets full on web servers rather than individual PCs.

The hackers infect servers with an application and, through a very simple software program, are able to identify the URLs they want to attack and hit them in a click of a button.

Imperva, the security firm which discovered the attacks, has the source code for the original application, along with screenshots, showing it only contained 90 lines of PHP code.

“Although servers are typically harder to compromise than PCs, by capitalising on their greater horsepower, the hackers create a much more efficient and powerful DDoS tool using servers as the attack platform,” said Imperva in a statement.

“By using web servers, the attackers are even less detectable. Trace backs typically lead to a lone server at a random hosting company.”

Amichai Shulman, chief technology officer at Imperva, has claimed that unlike most DDoS attacks, this is not a one off and the attacks “will be ongoing.”

He advises companies to be on the look out and monitor Google presence to check if they have been compromised.

Monday, February 8, 2010

China closes biggest hacker training site | IT PRO

China closes biggest hacker training site IT PRO

The largest hacker training website in China has been closed down, seeing three of its members arrested in the process, according to reports.

The "Black Hawk Safety Net" website taught hacking techniques and provided malicious software downloads for its 12,000 members in exchange for a fee, the Wuhan Evening News newspaper reported this weekend, citing police in Huanggang, just east of Wuhan.

Hacking from China has received international attention since Google threatened to quit China last month after a serious hacking attempt originating from China, resulting in the theft of its intellectual property.

China has denied involvement in the hacking episode and said it does not condone hacking.

The website was shut in late November and three of its members arrested on suspicion of criminal activity, the newspaper reported, without saying why the news was only released now.

Wuhan happens to be home to the Communication Command Academy, which trains hackers, according to US congressional testimony by cyber expert James Mulvenon in 2008.

The popularity of hacking in China, and hackers' use of multiple addresses and servers, in Taiwan and elsewhere, makes it hard to prove how or by whom they are coordinated.

Would-be hackers in China do not have to look far to figure out how to do it, thanks to a healthy hacking industry and sites such as Black Hawk Safety Net (www.3800hk.com), which was unavailable on Monday.

Friday, December 18, 2009

Chinese ISP hosts 1 in 7 Conficker infections - Network World

Chinese ISP hosts 1 in 7 Conficker infections - Network World

Security experts have known for months that some countries have had a harder time battling the Conficker worm than others. But thanks to data released Wednesday by Shadowserver, a volunteer-run organization, they now have a better idea of which Internet Service Providers have the biggest problem.

In terms of the total number of infected computers, China Telecom's Chinanet seems to have been hardest hit by the worm, which began spreading late last year.

The Chinese ISP had more than 1 million infected systems within its massive 94 million IP address network. That amounts to just over 1 percent of the company's network. But while Chinanet has the most total infections -- amounting to about 14 percent of all known copies of the worm -- it doesn't have the highest percentage of infected systems. Other, smaller ISPs show up on Shadowserver's list with infection rates as high as 25 percent.

"There's definitely a challenge at the ISP level with remediation," said Andre DiMino one of Shadowserver's founders.

Conficker got a lot of attention earlier in the year, including a late March segment on the 60 Minutes television program warning of an April 1 upgrade to the worm. Because Conficker is the most widespread botnet ever reported, security experts worry that it could be used to launch an unprecedented denial of service attack.

But, despite its size, the network of hacked computers has been associated with very little malicious activity. That's given computer users a false sense of security, DiMino said.

"The rate of remediation is not as good as we would have liked," he said. "The awareness and the alarm about Conficker kind of faded out after April 1st because nothing really dramatic happened."

Some ISPs, such as U.S.-based Comcast have taken to notifying users when their computers are infected or offering them free security software so they can get cleaned up. Comcast had a 0.05 percent infection rate, according to Shadowserver's numbers. AT&T was measured at 0.02 percent.

Tuesday, December 15, 2009

Hackers Brew Self-Destruct Code to Counter Police Forensics

Hackers have released an application designed to thwart a Microsoft-packaged forensic toolkit used by law enforcement agencies to examine a suspect’s hard drive during a raid.

The hacker tool, dubbed DECAF, is designed to counteract the Computer Online Forensic Evidence Extractor, aka COFEE. The latter is a suite of 150 bundled, off-the-shelf forensic tools that run from a script. Microsoft combined the programs into a portable tool that can be used by law enforcement agents in the field before they bring a computer back to their forensic lab. The script runs on a USB stick that agents plug into the machine.

The tools scan files and gather information about activities performed on the machine, such as where the user surfed on the internet or what files were downloaded.

Someone submitted the COFEE suite to the whistleblower site Cryptome last month, prompting Microsoft lawyers to issue a take-down notice to the site. The tool was also being distributed through the Bit Torrent file sharing network.

This week two unnamed hackers released DECAF, an application that monitors a computer for any signs that COFEE is operating on the machine.

According to the Register, the program deletes temporary files or processes associated with COFEE, erases all COFEE logs, disables USB drives, and contaminates or spoofs a variety of MAC addresses to muddy forensic tracks.

The hackers say that later releases of the program will allow computer owners to remotely lock down their machine once they detect that it has fallen into law enforcement hands. The hackers, however, have not released source code for the program, which would make it easy for anyone to see if the program contains malware that might also harm a computer or allow the attackers to take control of it.

Update: The developers of DECAF have taken issue with Threat Level referring to them as hackers. “We’re just two developers who support the free flow of information and privacy,” one of them wrote Threat Level in an anonymous e-mail. “You could say we’re just average joes.”

Wednesday, August 5, 2009

Rejoice! Latvian ISP linked to online criminal activity booted out of Internet

IDG News Service — A Latvian ISP linked to online criminal activity has been cut off from the Internet, following complaints from Internet security researchers.

Real Host, based in Riga, Latvia was thought to control command-and-control servers for infected botnet PCs, and had been linked to phishing sites, Web sites that launched attack code at visitors and were also home to malicious "rogue" antivirus products, according to a researcher using the pseudonym Jart Armin, who works on the Hostexploit.com Web site.

"This is maybe one of the top European centers of crap," he said in an e-mail interview.

"It was a cesspool of criminal activity," said Paul Ferguson a researcher with Trend Micro.

The ISP was disconnected from the Internet by its upstream provider, Junik, on Monday, after its provider, TeliaSonera told it to stop servicing Real Host or face sanctions Armin said.

Real Host was considered a "bullet proof" hosting provider, that would allow customers to remain online even after they had been linked to malicious activity. It had been linked to the Zeus botnet-making software.

This isn't the first time this type of hosting provider has been knocked offline. In the past year, at least three U.S. ISPs: Atrivo, McColo and 3FN have been unplugged after security researchers built cases against them. Atrivo and McColo were also taken offline by their upstream providers. 3FN was shut down by the U.S. Federal Trade Commission.

But according to Armin, this may be the "first time an international group has achieved this across borders and in Eastern Europe."

In the past, these takedowns have had a serious affect on spam. And while some observers reported a noticeable drop in spam over the weekend, security experts say that this was probably not attributable to the Real Host takedown.

Observers expect to see the criminal activity linked to Real Host resume soon, but they say that the takedown puts some pressure on the bad guys and the networks that provide service to them. "The precedent that's being set right now is that you need to take some responsibility for your network," said Lawrence Baldwin, owner of security research firm Mynetwatchman.

"There actually are some consequences now for allowing an obviously heavy concentration of criminal activity on your networks. It's just not going to be accepted anymore."

Tuesday, August 4, 2009

Conficker Worm - Still Ice Cold at DefCon Conference

All talk of the Conficker Worm was sanitised at the Black Hat conference to protect the current investigation.

The criminal ring is very savvy and might have infiltrated the group hunting it down, one investigator says.


The international security team tracking down Conficker thought that the masterminds behind it would have been apprehended by now, according to one of the leaders of the effort to stamp out the resilient worm but that’s not the way it has worked out.

Investigators cautious
A meeting and presentation talk at Black Hat yesterday had to be scaled back because it contained information about Conficker that might tip the investigators’ hand and send the perpetrators further underground, says Mikko Hypponen, chief research officer at F-Secure and a member of the Conficker Working Group.

A Forensic Look
When Hypponen submitted the abstract for his Black Hat briefing more than six months ago, he thought he’d be presenting a forensic look at a dead worm and that the team who had written and managed it would be out of action. “I had hoped that by the end of July we would be in a totally different situation, the case would be closed and the group would be in jail,” Hypponen said in an interview after his talk.

Critical Information

His official line was that he was asked last week not to reveal critical information that might help prolong Conficker’s reign over millions of computers and inhibit the ongoing criminal investigation. “So I will end my presentation here,” Hypponen said at the conclusion of his Black Hat session. “Thank you very much. I will not be taking any questions.”

Holding Back
Hypponen said afterwards that he wasn’t forced to curtail his remarks (Black Hat has been the site of numerous speech-blockings and speech-blocking attempts, including that of a researcher Cisco sued because he was to reveal a flaw in the company's IOS code). Rather, Hypponen had already realised that it made sense to hold back some of what the working group has found out. “It’s better to keep them in the dark about what is known,” he says.

Agility and Precision
Given the agility and precision with which Conficker alters its tactics, Hypponen doesn’t rule out that the Conficker Working Group itself might have been infiltrated by Conficker operatives.
He wouldn’t say how close he thinks authorities are to bringing down the group, but did say there is an indication that it is based in the Ukraine. Some techniques used in Conficker match those used in an earlier worm, which might mean the same people were behind both.

Ukrainian Police
That earlier worm avoided propagating to machines in the Ukraine, which might mean that the group is based there and was trying to avoid committing a local crime to keep Ukrainian police off their backs, Hypponen says.

Technical Sophistication
During his talk Hypponen outlined some of Confickter’s technical sophistication. In one version change – the worm has gone through five major revisions – the worm adopted the MD-6 cryptographic hash algorithm. Investigators estimate that MD-6 was only a month or so old when it was incorporated in Conficker, making the worm one of the earliest implementations of MD-6, he says.

Buffer Overflow

The next major revision of Conficker patched an MD-6 buffer-overflow vulnerability that was publicly announced about six weeks earlier, which means the criminals keep themselves in the loop with the latest advances, he says. (The patch they used was identical to the one issued by MD-6 creators.)

Disables Infected Machines
The worm avoids sending itself to domains owned by members of the Conficker Working Group, and it disables infected machines so they can’t reach sites where they might seek help.

F-Secure Help Site
Hypponen’s company set up a help site with a different domain name from its regular business site that included the term F-secure, and the next version of Conficker blocked it. The company changed the term to Fsecure with no hyphen, and the next revision blocked that, too, he says.

The worm had been propagating to eight top level Internet domains and the working group mustered enough cooperation to shut it down in all those domains, Hypponen says. The next version propagated to 116 domains, he says.

Strategy Weak
“These guys are very good in cryptography and code development,” he says, but maybe not so good about strategy, given the attention they drew to themselves. “They didn’t know better than to infect 10 million computers in a couple of days.” The goal of any botnet ought to be to remain hidden, not draw attention to itself, he says.

“They might have experience in another crime business but hadn’t run a botnet before. If they were more experienced, they’d know better.”

The Malady Lingers on
It would make sense, Hypponen says, for the Conficker gang to abandon its current botnet and build a new one that doesn’t get too big too fast and doesn’t draw a team of experts to fight it. “Maybe they already have,” he says.