Tuesday, 23 April 2013

US, China agree to work together on cyber security


China and the United States will set up a working group on cyber-security, U.S. Secretary of State John Kerry said on Saturday, as the two sides moved to ease months of tensions and mutual accusations of hacking and Internet theft. Speaking to reporters in Beijing during a visit to China, Kerry said the United States and China had agreed on the need to speed up action on cyber security, an area that Washington says is its top national security concern.
Cyber security, Kerry said "affects the financial sector, banks, financial transactions, every aspect of nations in modern times are affected by the use of cyber networking and obviously all of us - every nation - has an interest in protecting its people, protecting its rights, protecting its infrastructure". Earlier, China's official Xinhua news agency quoted Foreign Minister Wang Yi as telling Kerry in their meeting that China and the United States should make joint efforts to safeguard cyberspace.
Cyberspace should be an area where the two countries can increase mutual trust and cooperation, Wang told Kerry, according to Xinhua. Beijing and Washington have traded accusations in recent months of massive cyber intrusions. The United States says hacking attacks emanating from China have targeted U.S. government and corporate computer networks among others, stealing government and commercial data.
A U.S. computer security firm released a report in February saying a secretive Chinese military unit is believed to be behind a wave of hacking attacks against the United States.
China claims it is the victim of large-scale cyber attacks from the United States, though it has given few details. Wang repeated to Kerry the Chinese government's oft-stated position that it opposes any form of hacking. The working group announcement follows other recent calls for dialogue and cooperation. Officials and business executives attending a China-U.S. Internet Industry Forum in Beijing this week sought to find common ground.
"It's important to have a dialogue on this, but it's also important that the dialogue be a means to an end, and the end is really ending these practices," Under Secretary of State for Economic Affairs Robert Hormats, who spoke at the forum, told Reuters in an interview. Last month China's premier, Li Keqiang called for both sides to stop the war of words over hacking.


Share This on Twitter | Share This Link on Facebook | Share This on Linkedin

Assad sympathisers hacked FIFA Twitter accounts

Two of FIFA's Twitter accounts were hacked on Monday in the latest wave of cyberattacks claimed by Syrian government sympathisers.


Zurich: Two of FIFA's Twitter accounts were hacked on Monday in the latest wave of cyberattacks claimed by Syrian government sympathisers. A series of corruption allegations were made on the official accounts of FIFA President Sepp Blatter and the World Cup, some linked to 2022 World Cup host Qatar, including one libelous post about the Emir of Qatar. "It was decided that the president Sepp Blatter is to step down due to corruption charges," the hackers posted using the (at)FifaWorldCup account. With FIFA unable to regain control of either account, which have more than 500,000 followers combined, the media department confirmed by e-mail that they had been hacked.



"We are looking at this issue at the moment," FIFA said in a statement. "In the meantime, to avoid any doubt, we kindly ask you to verify and check any statements that you see on a FIFA twitter account with the FIFA Media department." The Syrian Electronic Army — hackers sympathetic to Syrian President Bashar Assad — posted messages claiming it had posted the tweets. The group also recently claimed to have hacked the Twitter accounts of the BBC Arabic service and broadcaster Al-Jazeera.



One message Monday also taunted Twitter, which has shut down other SEA accounts. "Twitter (hashtag)Failure... You can't stop us!" read one of 14 rogue posts on the official World Cup account. The hackers also reminded FIFA that the Syria national team was kicked out of the 2014 World Cup qualifying tournament in 2011 for fielding an ineligible player. "The decision to disqualify the Syrian team on a technicality was found to be politically based," one message read.



Share This on Twitter | Share This Link on Facebook | Share This on Linkedin

Monday, 22 April 2013

CBS Got Twitter-Hacked And Spat Out Virus-y Links



Twitter hacks are an unfortunate reality of everyday social media life. Today, it was CBS's 60 Minutes, 48 Hours, and CBS Denver accounts that took the hit and started dishing out some linkbait-y tweets with a virus-laiden garnish. Careful what you click.
Unlike other Twitter hacks of late, this one wasn't particularly funny, and instead leaned towards the straight-up malicious end of the spectrum. The hacktastic payload included not only misinformation, but a viral payload as well, though that's not uncommon for the spammier side of Twitter.
The offending tweets are gone now, but All Things D managed to get a couple of screen grabs. And really, who wouldn't click these? Of course all this could just go away if Twitter would roll out some two-step verification, but who knows how long that'll take. Any bets as to how many more high-profile hacks we'll have to see?

Share This on Twitter | Share This Link on Facebook | Share This on Linkedin

Friday, 19 April 2013

How to Spot Android Malware and Keep Your Data Private


            A new, growing risk that's just as devious as malware is now disguised as adware. While malware is often designed to hide on your device, minimizing impact while nabbing personal files and passwords, adware can operate in plain sight while it collects almost everything else on your smartphone. Much like a burglar, stealthy capabilities combined with security loopholes heighten the danger of malware. Bringing in adware, though, is like recklessly inviting a total stranger for dinner. The conversation may be pleasant, but he may be walking around the house and learning everything there is to know about you.

There is money to be made in using adware to gather personal data from your phone. This attracts legitimate advertisers, and more dubious characters. Keeping a close eye on your device to make sure that it behaves properly is highly recommended. With both personal and work data on your device, imagine what would happen if someone were to gain complete access to it. For instance, if you notice a spike in data consumption without doing anything out of the ordinary, it might reveal that something is smuggling data out of or onto your device. The best way to stay ahead of the problem is to set up a data meter to plug the leak before it causes too much damage.

With smartphones used in online shopping by charging purchases to your carrier phone bill, some malware actually reaches into your pockets and starts sending text messages to premium-rated numbers. You won't know what happened until you get slapped with a phone bill that might make your head spin. A sudden loss in battery performance could also hint that something is running in the background. If it's nothing you can pinpoint and switch off, some nasty piece of malware may be at work. Of course, aggressive adware could also be a culprit here, as location tracking or the constant monitoring of your browser activities could drain more juice than usual. Watch out for apps that display too many ads or send push notifications - they're not only annoying but they also take a toll on your battery. In some cases, you might even experience full performance clogging as too many apps try to feed you push notifications. Your device is biting off more than it can chew, leading to reboots caused by sluggish performance.

With Android malware emulating many features we've seen on PC malware years back, somebody could even eavesdrop on your conversations. If you start noticing call drops although you have plenty of cellphone coverage, or if you hear a strange echo during calls, contact your local carrier and make sure it's not their fault. Malware might be tapping into your conversations and saving them as audio files on your smartphone, waiting for the chance to upload them to an attacker-controlled server. This might sound like science fiction, and you might think it could never happen to you. However, take a step back and think about how many smartphones are there on a global level and how many in your own family. Your personal information is valuable to criminals, and they will go to some serious effort to steal it from you.

There's nothing wrong with a little paranoia when it comes to keeping data on your smartphone safe. Thankfully, an award-winning mobile security software will keep you safe from unnecessary headaches and will let you know when you're about to install apps with aggressive advertising or even malware. If your device is giving you some of the signs outlined above, perhaps it's a good time to give it a quick checkup.


Share This on Twitter | Share This Link on Facebook | Share This on Linkedin

Thursday, 18 April 2013

Largest gathering of offensive hackers converges on Miami


Formidable American offensive security hackers are meeting in Miami with other top hackers from all over the world to hone their technical expertise, swap war stories – and compete in a little digital jiu-jitsu. And real jiu-jitsu. Really. INFILTRATE’s annual summit, focuses entirely on the technical aspects of offensive security issues, bringing together the best and brightest in the hacker community. It’s largest gathering of purely offensive information security experts on the planet, with more than 200 hackers from as far away as Israel, India, Sweden and China.

Organized and sponsored by Immunity, an education firm founded by former NSA hacker Dave Aitel, the conference ran April 11 and 12. Aitel stressed that it was just for offensive work. “Defensive information security tends to focus on potential protective measures,” he told FoxNews.com. “Offensive information security looks purely at getting into computers -- and staying there undetected.”

The hacker way
Offensive techniques are used by a wide range of people from governments and banks through to researchers working on protecting critical national infrastructure. “INFILTRATE is important because it is the only conference dedicated to offensive information security techniques. Deep down this is about the attendees, who all share a technical competence in the area, and a burning interest in learning more about it. There are, of course, plenty of security teams here. For example, Blackberry announced on their twitter feed they are here,” Aitel said. If you don’t understand what TTF Font Fuzzing and Vulnerability means, this is the wrong conference for you, in other words.

The show covers the latest in the field, from computer and network exploitation and vulnerability discovery through to rootkit and trojan covert protocols. And while it sounds esoteric and dry, it has profound ramifications for ordinary Americans. For example, legendary hacker “RenderMan,” also known as Brad Haines, gave an opening keynote on  “Attacking the Next Generation Air Traffic Control System” -- hacking the FAA’s monitoring system. “I came to INFILTRATE to spread knowledge of vulnerabilities in air traffic control in hopes that the attention and collaboration with other hackers would result in a safer and more secure air traffic control system,” 

“Ironically, I'm speaking about vulnerabilities in air traffic control and I have to fly home.  It’s in my best interests to help make it secure. The next generation air traffic control scares the hell out of me,” he added.
Other speakers include Chris Eagle, a lecturer in computer science at the Naval Postgraduate School, and Stephen Watt , a former cybercriminal convicted in 2008. While still under a court-ordered restriction that prohibit him from a wide range of ordinary tech, including owning an iPhone and running a non-Windows operating system on his government-monitored laptop, Watt continues to speak out against computer the commercialization of vulnerability. In addition to briefings by the rock stars of hacking, Immunity offers Master Class training courses in web hacking and unethical hacking. Attendees have also been competing in a wireless + web challenge to win the grand prize -- a free wireless penetration testing tool called SILICA.
Off the keyboard

It may come as some surprise to those outside the hacking community, but many of INFILTRATE 2013's attendees are avid practitioners of the Brazilian martial art jiu-jitsu, sometimes described as “physical chess.”
“Brazilian jiu-jitsu is a shared passion for many in the offensive information security field,” Aitel told FoxNews.com. “It combines large-scale strategic thinking with fast paced tactical technique. For every attack, there is a defense, and for every defense, a counter-attack.” Away from keyboards, INFILTRATE also provides the opportunity for hackers new to the sport to have a go under the supervision of an experienced blackbelt.


Share This on Twitter | Share This Link on Facebook | Share This on Linkedin