Wednesday, July 22, 2009

Chinese News Sites Go Down After Reporting on Government Scandal

The Namib Desert a source of wealth and minerals as well as stunning beauty and mystery!

Two of China's most popular technology news Web sites went offline Tuesday, after carrying news reports that linked the son of China's president to a corrupt African deal.

The technology news sections disappeared for several hours from major Chinese portals Sina.com.cn and NetEase.com early Tuesday afternoon, when they started redirecting viewers to general news pages.

Both tech sections had carried reports on a state-owned company accused of bribing Namibian officials in the last day, but those reports were missing when the Web pages reappeared.

The suspensions appeared to be a government penalty against the companies for reporting on a sensitive political anti-government issues.

Media Censorship - "I'm impressed by the bravery of Sina and Netease in attempting to report this at all," said Rebecca MacKinnon, a Hong Kong-based expert on the Internet in China, in an online message. Clearly, the threats and intimidation being meeted out is having an effect in the media's self-censorship.

The Golden Children - Information on top leaders' children has always been off-limits in Chinese media, though the Internet has made it more difficult to control discussions on such topics, MacKinnon said.

Internet Police - Chinese police heavily patrol the Internet, and Internet companies run rigorous screening to prevent sensitive information from appearing on user forums or in search results on their sites. Companies can be punished if that process fails to catch certain political or pornographic content.

"This is not particularly surprising or different from long-standing censorship patterns," MacKinnon said.

NetEase story canned - A story posted on the NetEase tech page the night before its suspension cited English broadcaster BBC as saying that Nuctech, a Chinese company, was suspected of bribery in a deal to provide scanners for airports and ports in Namibia.

The BBC report had said Namibian authorities wanted to question Hu Haifeng, the former company president and son of Chinese president Hu Jintao, but did not suspect him in the case.

The NetEase story was careful not mention Hu, but it said that Namibia wanted to question "relevant" Nuctech executives.

Sina's article blocked - Sina's tech page carried a similar article the next morning, hours before the sites went down. After the tech sections returned to the portals, visiting the URLs of the scandal reports returned messages that they could not be found or had been deleted.

An employee who answered the phone at NetEase Tuesday said its tech section was down for tests. Sina did not respond to a request for comment.

Big Brother Tsinghua - Nuctech's parent company, Tsinghua Holdings, controls a range of other technology companies including Chinese PC maker Tsinghua Tongfang.

Tuesday, July 21, 2009

Iran using more Sophisticated Tactics to Block Internet Access for Government Critics

Iran is using a number of new technologies to censor the Web. Some of these Government tools are simplistic and blunt, while others are more precise and surgical. Both are intended to stifle so-called dissidents.

One month after a disputed presidential election sparked widespread unrest in Iran, the country's government has initiated a cyber-crackdown that is challenging hackers across the globe to find new ways to help keep Iranian dissidents connected to the Web.

Iranian Government Strategy step-up
While the government's initial efforts to censor the Internet were crude and consequently ineffective, it has started employing more sophisticated tools to thwart dissidents' attempts to communicate with each other and the outside world. Iranian dissidents are not alone in their struggle, however, as several sympathetic hacker groups have been working to keep them online.

NedaNet

One such group is NedaNet, whose mission is to "help the Iranian people by setting up networks of proxy severs, anonymisers, and any other appropriate technologies that can enable them to communicate and organise."

NedaNet project coordinator Morgan Sennhauser, who has just written a paper detailing the Iranian government's latest efforts to thwart hackers, says that the government's actions have been surprisingly robust and have challenged hackers in ways that the Chinese government's efforts at censorship have not.

Chinese Internet censorship: An inside look
"China has several gigabytes per second of traffic to deal with and has a lot more international businesses," he says. "They can't be as heavy-handed with their filtration. The Iranians aren't as concerned about that, so they get to use all these fancy toys that, if the Chinese used them, could cripple their economy."

Here are five of the most commonly-used technologies the Iranian government has been using to stifle dissents, as outlined in Sennhauser's paper.

IP Blocking
IP Blocking is one of the most basic methods that governments such as Iran are using for online censorship. It simply prevents all packets going to or from targeted IP addresses. Sennhauser says that this was how the government banned access to the BBC's Persian news services and how it took down websites that were critical or in any way negative about the election.

While these operations are relatively simple to execute, they don't tackle the problem of individual communications between users, especially if the users have set up multi-hop circuits that, in themselves use multiple servers to create a proxy ring.

Traffic Classification (QoS)
QoS is a much more sophisticated method of blocking traffic than IP blocking, because governments can halt any file sent through a certain type of protocol, such as FTP. They can simply limit the bandwidth available on that port and throttle transfers because the government knows that FTP transfers are most often sent through TCP port 21.

Sennhauser says that this type of traffic shaping practice is the most common one used by governments today, as "it is not too resource intensive and is fairly easy to set up."

Shallow Packet Inspection
Shallow packet inspection is basically a blunter, broader version of the deep packet inspection (DPI) technique that is used to block packets based on their content. 'Shallow packet' inspection makes broad generalities about traffic, based solely on checking out the packet header, unlike DPI, which intercepts packets and inspects their fingerprints, headers and payloads.

Although shallow packet inspection can't provide the Iranian government with the same detailed traffic assessments as DPI, Sennhauser says that it is much better at handling volume than DPI.

Reading the label on the packet

"It's a less refined tool, but it can also deal with a lot more traffic than true DPI." he explains. "Shallow packet inspection is more like judging a book by its cover. If a packet says that it's SSL (Secure Sockets Layer) in the header, then a shallow packet inspector takes it at face value."

However, this is a double-edged sword. If a user disguises their SSL packets as FTP packets in the header, the shallow packet inspector won't be able to tell the difference.

Packet Fingerprinting

This is a slightly more refined method of throttling packets than 'shallow packet' inspection, as it looks not only at the packet header but at its length, frequency of transmission and other characteristics to make a rough determination of its content.

Sennhauser says the government can use this technique to better classify packets and not throttle traffic sent out by key businesses.

Mix 'n Match

"A lot of things don't explicitly say what they are, e.g. a lot of VPN traffic is indistinguishable from SSH traffic, which means that it would be throttled if SSH was," he says. "but what if businesses relied on VPN connections? You'd move the system to fingerprinting, where the two are easily distinguishable."

Deep Packet Inspection / Packet Content Filtering
DPI is the most refined method that the government has for blocking Internet traffic. As mentioned above, deep packet inspectors examine not only a packet's header but also its payload. This gives governments the ability to filter packets at a more surgical level than any of the other techniques discussed so far.

"Viewing a packet's contents doesn't tell you much on its own, especially if it's encrypted," he says. "But combining it with the knowledge gained from fingerprinting and shallow packet inspection, it is usually more than enough to figure out what sort of traffic you're looking at."

DPI Downside

There are downsides to using DPI, of course: it's much more complicated to run and is far more labour-intensive than other traffic-shaping technologies. On the down side, Sennhauser says there is no magic bullet for getting around DPI. Users can usually only temporarily elude it by "finding flaws in their system." and even this won't help for long, as the government can simply correct their system's flaws once they're discovered.

"Once they fix the flaw, you've lost unless you can figure out some real way to circumvent it," Sennhauser notes.

Endgame still unclear

Sennhauser says that the government has employed these technologies very quickly and very smartly, despite being caught flat-footed by the initial furor after the election. Indeed, he thinks the only reason that Iran hasn't yet completely shut down dissidents' communications is that they've had to fight with an army of hackers who tirelessly search for flaws in their system.

"It really is like an arms race," he says. "They create a problem, we circumvent it, they create another, we get around that one. This continues on until the need to do so is removed. The circumstances which will end the competition aren't clear yet."

Monday, July 20, 2009

NYPD Spend $1M on New Typewriters! Change what change?

They say you can't stop or turn back Time but the NYPD have found another option for not progressing, avoid change and live in the Past!

Why is IT Change so Difficult for Political and Government bodies alike? It is bad enough that Typewriters are still in use by the NYPD but now the city of New York has signed a new three-year, $1 million deal for MORE typewriters, the majority of which will be used by the NYPD.

While the department has endured a major, multiyear technology overhaul, with some big success, it demonstrates that IT change is often well intended, meticulously planned but not always carried out or implemented in its entirety.

New York Post
Technological change is never easy, or quick, or perfect, especially for big bureaucracies. Unfortunately, the NYPD made news this week when the New York Post reported that the City of New York had signed up a $1 million contract with a typewriter vendor to purchase thousands of new manual and electric typewriters, during the next three years.

Improvements made
The NYPD's typewriter requirements, accounted for the bulk of the contract. The article describes how NYPD Deputy Commissioner and CIO Jim Onalfo, who took over the reins in May 2003, had invigourated the NYPD's IT department and brought them into the 21st century.

The article also reported that changes to the insular and bureaucratic culture and legacy loaded IT environment, had been vast. Massive improvements were made in areas of disaster recovery, wireless communications, networking infrastructure, and many others.

Three Years In
Even three years into Onalfo's serious IT overhaul in 2006, glaring disconnects were still present: "Each of the 76 precincts is now connected by a videoconferencing system that ties into a command center at One Police Plaza," the article stated. "Within some of the precincts, however, there are still detectives using typewriters to fill out paper reports and filing carbon copies."

Essential Typewriters
NYPD cops "still use typewriters to fill out property and evidence vouchers, which are printed on carbon-paper forms. There are typewriters in every police precinct, including one in every detective squad." This is not felt to be part of a strategic disaster recovery solution but the NYPD stated; "We are working on software to eliminate the old machines," a police representative stated.

Huge Strides with RTCC
It should be noted that NYPD IT and CIO Onalfo have made huge strides in overhauling how the NYPD uses new technologies. The NYPD relies heavily on the Real-Time Crime Center (RTCC), a high-tech "war room" where detectives are able to tap into dozens of police, government and other related databases. As an example of the RTCC's power, real-time information from police officers at the scenes of crime can be meshed with the sophisticated database queries made at the RTCC to help to track down criminals.

Crime Stoppers Hotline
In addition, emergency 911 capabilities allow citizens to directly transmit photos and videos to the police at the RTCC. New Yorkers can also send text messages and multi-language e-mails to its Crime Stoppers hotline program.

Typewriters Everywhere
In truth, there are probably a lot of businesses and government agencies that have stashes of typewriters in their offices, just like the NYPD does. But until everything is digitized, there will be a seemingly mind-boggling need for typewriters.

The NYPD's typewriters are both a lasting vestige of the way things were and how they uses to be done in the past but it is a shocking reminder of just how much more change and education needs to be done.

Saturday, July 18, 2009

Woman with swine flu dies 'after giving birth'

A woman in the UK who had contracted swine flu, died shortly after giving birth prematurely.

The woman, who died in Whipps Cross Hospital, was named by her brother as Ruptara Miah.She is thought to be from Bangladesh.

Abdul Malik told BBC News his sister had used a wheelchair for 15 years after a road traffic accident but had led a normal life and had brought up six daughters. "We are very, very upset as a family. It has really taken me by shock," he said. "We thought she was going to recover."

His sister, the eldest of 10 children, was admitted to hospital three weeks ago with a cough and chest infection, he said. She was treated in intensive care, where she gave birth to a son prematurely, but never regained full consciousness, he added.

The baby is now in intensive care as a precaution

A spokesman for Whipps Cross said: "Whipps Cross University Hospital NHS Trust can confirm that a 39-year-old woman passed away on July 13 2009, and that she was infected with pandemic H1N1. The trust can confirm that she had underlying health conditions. No further comments can be made at this time."

Friday, July 17, 2009

UK Investigation into Cyber Attack goes Global

UK authorities have launched an investigation into the recent cyberattacks that crippled Web sites in the U.S. and South Korea, as the trail to find the perpetrators stretches around the world.

On Tuesday, the Vietnamese security vendor Bach Khoa Internetwork Security (Bkis) said it had identified a master command-and-control server used to coordinate the denial-of-service attacks, which took down major U.S. and South Korean government Web sites.

Zombie PCs

A command-and-control server is used to distribute instructions to zombie PCs, which form a botnet that can be used to bombard Web sites with traffic, rendering the sites useless. The server was on an IP (Internet Protocol) address used by Global Digital Broadcast, an IP TV technology company based in Brighton, England, according to Bkis.

BKIS control

That master server distributed instructions to eight other command-and-control servers used in the attacks. Bkis, which managed to gain control of two of the eight servers, said that 166,908 hacked computers in 74 countries were used in the attacks and were programmed to seek out and download new instructions every three minutes, from designated random sites.

Miami Master Server

But the master server isn't in the U.K.; it's in Miami, according to Tim Wray, one of the owners of Digital Global Broadcast, who spoke to IDG News Service on Tuesday evening, London time.
The server belongs to Digital Latin America (DLA), which is one of Digital Global Broadcast's partners. DLA encodes Latin American programming for distribution over IP TV-compatible devices, such as set-top boxes.

VPN Connections
New programs are taken from satellite and encoded into the proper format, then sent over VPN (Virtual Private Network) to the U.K., where Digital Global Broadcast distributes the content, Wray said. The VPN connection made it appear the master server belonged to Digital Global Broadcast when it actually is in DLA's Miami data center.

Engineers from Digital Global Broadcast quickly discounted that the attacks originated with the North Korean government, which South Korean authorities have suggested may be responsible.

Digital Global Broadcast notified

Digital Global Broadcast was notified of a problem by its hosting provider, C4L, Wray said. His company has also been contacted by the U.K.'s Serious Organised Crime Agency (SOCA). A SOCA official said she could not confirm or deny an investigation.

Amaya Ariztoy, general counsel for DLA, said the company examined the server in question today and found "viruses" on it. "We are conducting an investigation internally," Ariztoy said.

Forensic Analysis
Investigators will need to seize that master server for forensic analysis. It's often a race against the hackers, since if the server is still under their control, critical data could be erased that would help an investigation.

"It's a tedious process and you want to do it as quickly as possible," said Jose Nazario, manager of security research for Arbor Networks.

Data Logs Audit
Data such as log files, audit trails and uploaded files will be sought by investigators, Nazario said. "The holy grail you are looking for are pieces of forensics that reveal where the attacker connected from and when," he said.

D-o-S MyDoom Variant
To conduct the attacks, the hackers modified a relatively old piece of malware called MyDoom, which first appeared in January 2004. MyDoom has e-mail worm characteristics and can also download other malware to a PC and be programmed to conduct denial-of-service attacks against Web sites.

The Evidence Trail
Analysis of the MyDoom variant used in the attacks isn't that impressive. "I still think the code is pretty sloppy, which I hope means they [the hackers] leave a good evidence trail," Nazario said.

Perpetrator Profile
It could also be that the perpetrator is either very confident that they will not be found, is trying to hide in the pseudo amateur world of the cyber geeks and cyber vandals, is not concerned or is immune from discovery.

Maybe, a virtual self destructive personality that is implementing a non fatal 'suicide' mission for yet to be revealed reasons.

Surf the Internet Freely and Safely: Care of Symantec

Everything you wanted to know about safety and security on the Internet but were afraid to ask!
Symantec have created a really friendly easy to use web page that provides basic information and advice on Internet and Credit card security, etc.

Chinese Hackers Exploit Microsoft Internet Explorer Weakness!

Symantec, Sunbelt Software and SANS' Internet Storm Center (ISC) increased their threat level warnings yesterday, after Microsoft announced that attackers were exploiting a bug in an ActiveX control used by Internet Explorer (IE) to display Excel spreadsheets.

There is no patch for the vulnerability, nor will Microsoft release one later today when it issues its July batch of patches.

Temporary Fixes
A temporary fix that sets the "kill bits" of the ActiveX control is available, but experts believe it's likely most users won't take advantage of the protection.

Threat Ranking
Symantec raised its ThreatCon ranking to the second of four steps. "We're seeing it exploited, but currently on a limited scale," said Ben Greenbaum, a senior researcher with Symantec security response.

Sunbelt Ranking raised
Sunbelt also bumped up its ranking, to high, the company noted today. "We just set the Sunbelt Threat Level to high since our researchers and at least two other major organizations have found in-the-wild exploit code," said Tom Kelchner, malware researcher with the Florida-based firm.

ISC at Condition Yellow
Meanwhile, the ISC went to condition Yellow after discovering numerous sites hosting attack code. The ISC reported both broad and targeted attacks using exploit code against the new zero-day. "[There was] a highly-targeted attack against an organization earlier today who received a Microsoft Office document with embedded HTML," said the ISC in a frequently-updated blog post. "This one was particularly nasty.... It was specifically crafted for the target, with the document being tailored with appropriate contact information and subject matter that were specific to the targeted recipient."

China sites Compromised
Broader attacks are originating from compromised sites in China, the ISC added. "A .cn domain [is] using a heavily obfuscated version of the exploit, which may become an attack kit (think MPACK), and is similar to recent DirectShow attacks," said the center.

Unpatched Microsoft Bug
Last week, Microsoft confirmed that hackers were exploiting an unpatched bug in an ActiveX control that's part of DirectShow, a component of the DirectX graphics platform within Windows.

McAfee confirm attack code targeting
McAfee echoed the ISC late on Monday, confirming that attack code targeting yesterday's ActiveX bug has been added to a Web exploit toolkit and is being distributed from hijacked Chinese sites. The toolkit also contained attack code for last week's DirectShow vulnerability. Some computers in Spain, the U.K. and Germany also showed evidence of compromises, McAfee researcher Haowei Ren said in an entry to the company's security blog.

Early Days
Symantec's Greenbaum added that while his company is seeing only a small number of attacks currently "It's not in the top 500 attacks," he said. This has the potential to get big, and big quickly. "It's the kind of attack that can be very easily hosted on a Web server, and meets all the criteria for large-scale attacks in the relatively near future," Greenbaum said.

The number and diversity of attacks will likely increase because working exploit code is publicly available, he said.

Microsoft Patch
Although Microsoft is working on a patch for the new vulnerability, it's unclear when it will be ready. Users will definitely not receive any automatic protection today, however.

"Unfortunately, the comprehensive update for this vulnerability is not quite ready for broad distribution," a company spokesman said yesterday afternoon. "We recommend that customers follow the automatic 'Fix It' workaround ... to help secure their environment against this vulnerability while we finish up development and testing of the comprehensive update."

Manually Steer Browser
Fix It requires users to manually steer their browser to Microsoft's support site and download, install and run the tool to disable the ActiveX control.

That means many users won't currently be protected. "Most users won't [manually] mitigate," agreed Greenbaum. The message is clear 'Don't be in this vulnerable group.'