Showing posts with label Hackers. Show all posts
Showing posts with label Hackers. Show all posts

Saturday, December 21, 2013

Hackers Hit Servers at The Washington Post for a 3rd Time

Hackers breached The Washington Post’s computer servers for the third time in three years, the newspaper reported late Wednesday.

This time hackers gained access to employee user names and passwords, The Post reported, but it said there was no evidence they obtained subscriber information, like credit cards or home addresses. The paper also said there was no sign the hackers gained access to its publishing system, emails or other personal information of employees, such as their Social Security numbers.

The company said it suspected that Chinese hackers were behind the current raid. Post officials said that they were informed of the breach on Wednesday by Mandiant, its web security contractor, and that it lasted less than a week.

“This is an ongoing investigation, but we believe it was a few days at most,” said Kris Coratti, a Post spokeswoman.

Ms. Coratti did not release a press statement or take questions about the hack, but instead referred reporters to an article in The Post for further information.

The Post system was compromised previously last August, when the Syrian Electronic Army, a hacker collective that supports President Bashar al-Assad of Syria, briefly directed some readers of the paper’s website to a site that lauded President Assad and condemned the country’s rebels.

In 2011,  The Post, as well as The New York Times and The Wall Street Journal, were subject to sophisticated attacks thought to have originated in China. It was believed then that Chinese hackers were looking for sources on stories about the country. At the time, The Post declined to release details of how much information the intruders received, but that first breach was thought to be extensive.

On Wednesday, the paper emphasized the brevity of the most recent attack. But at the same time, it asked employees to change their user names and passwords.

“Although company passwords are stored in encrypted form,” said the newspaper’s article on the episode, “hackers in some cases have shown the ability to decode such information.”

Sunday, June 9, 2013

U.S. Helps Allies Trying to Battle Iranian Hackers

The American officials would not say which countries in the Persian Gulf have signed up for help in countering Iran’s computer abilities. But the list, some officials say, includes the nations that have been the most active in tracking Iranian arms shipments, intercepting them in ports and providing intelligence to the United States about Iranian actions. The three most active in that arena are Saudi Arabia, the United Arab Emirates and Bahrain.

In Asia, the countries most worried about being struck by North Korean computer attacks are South Korea and Japan.

The Defense Department’s assertive new effort in the gulf and Asia is the latest example of how the Obama administration is increasingly tailoring its national security efforts for a new era of digital conflict, in this case assuring the defense of computer networks and, if necessary, striking back against assaults.

A directive signed by the president that surfaced Friday — the third in a series of leaked documents published by the newspapers The Guardian and The Washington Post — underscored how the Obama administration is trying to prepare itself and its allies. The leaks also revealed how the Obama administration has put in place a large Internet surveillance operation to identify terrorism threats.

The presidential directive included the declaration that the United States reserved the right to take “anticipatory action” against “imminent threats,” a reference, it seemed, to the kind of crippling infrastructure attacks that Iran appears to be working on against American and allied targets.

The new help for strengthening computer-network defenses for allies, which has not been publicly announced, closely parallels earlier efforts by the Obama administration in two volatile parts of the world. In recent years it has helped install advanced missile-defense systems and early-warning radars in Persian Gulf nations to counter Iran’s missile ability, and it has done something similar in Asia in response to North Korea’s nuclear weapons program.

But deterring cyberattacks is a far more complex problem, and American officials concede that this effort, which will include providing computer hardware and software and training to allies, is an experiment. It has been propelled by two high-profile attacks in the past year. One was against Saudi Aramco, Saudi Arabia’s largest, state-run oil producer, and according to American officials it was carried out by Iran. That attack crippled 30,000 computers but did not succeed in halting production. The other, an attack on South Korea’s banking and media companies this spring, was later attributed to North Korea. It froze the ability of several banks to operate for days.

“The Iranian attack on the Saudis was a real wake-up call in the region,” said one senior administration official, who would not speak on the record about the American efforts to counter Iran. “It made everyone realize that while the Iranians might think twice about launching a missile attack in the region, they see cyber as a potent way to lash out in response to sanctions.”

The administration is capitalizing on the fear created by those attacks to build on the de facto alliance against Iran that it has constructed in the region. The Pentagon is drawing up proposals for providing advanced hardware and software for computer-network defense that could be sold throughout the Persian Gulf, much as American aircraft and missiles are sold to Arab allies. Training programs are being put together to teach computer security to military and law enforcement in the region, and to collaborate with private companies.

And, just as the Pentagon conducts naval exercises in the Persian Gulf to practice ways of keeping the Strait of Hormuz open, officials say future joint war games would include simulated cyberattacks, similar to the one Iran conducted against Saudi Aramco.

The idea is to give American and allied forces practice carrying out their missions with their networks under duress, officials said.

The new interagency effort in Washington comes at a time when Israeli and American intelligence officials have been concerned by Iran’s swift advances in its computer weaponry, particularly its ability to disrupt existing infrastructure. As one former senior American military commander said recently, “They have startled everyone with the speed at which their capabilities have increased.”

But one continuing point of dispute is whether Iran and North Korea are working together on the development of cyberweapons, the way they have worked together for years on the development of missile technology.

A senior Israeli military official said Israel had evidence that Iran and North Korea were beginning to collaborate on developing cyberweapons. He declined to cite the specific evidence.

Although there is concern in Washington that cooperation between Iran and North Korea could spread to computer tools, American officials say there is no proof of such collaboration.

Friday, May 24, 2013

Bronx Officer Accused of Hiring E-Mail Hackers

But the detective was not seeking to build a case against the outfit, federal prosecutors said on Tuesday. Rather, prosecutors said, he became a client.

Using information bought from the hackers, the detective, Edwin Vargas, obtained login information for at least 43 e-mail accounts associated with 30 people, including at least 19 members of the New York Police Department in the Bronx, according to a complaint unsealed in Federal District Court in Manhattan.

The reason for the digital snooping appeared to be personal, law enforcement officials said: Detective Vargas, 42, suspected a former girlfriend — also an employee of the Police Department, an official said — had started a new relationship with a fellow officer. Detective Vargas and the woman had a child together, officials said, but had broken up.

“A 20-year veteran of the Police Department, never before under suspicion for any impropriety, let alone any criminal activity,”  James Moschella, a lawyer for the detective’s union, said of Detective Vargas, whom he represented at the arraignment. Detective Vargas was released on $50,000 bond.

“It’s my understanding that some of the victims are detectives as well,” said Michael J. Palladino, the head of the detectives’ union. “It would be inappropriate for me to comment any further.”

Prosecutors said that over the course of two years beginning in 2010, Detective Vargas contacted the e-mail hacking group multiple times and paid about $4,050 for the login information for accounts of fellow officers and some private citizens. He paid between $50 and $250 per account, according to the complaint, using a credit card or PayPal account registered to his Bronx address.

The low prices suggested that, for the hackers, the e-mail account information was not difficult to obtain.

It was not clear what was done with the information obtained. Detective Vargas is accused of gaining access to only one of the accounts for which he obtained login details. The complaint did not identify those targeted.

Prosecutors also accused the detective of accessing online records for a cellphone belonging to one of the victims.

The Federal Bureau of Investigation conducted the investigation along with the Police Department’s Internal Affairs Bureau. Law enforcement officials said it was during the course of a broader, continuing investigation into a Los Angeles-based e-mail hacking operation that investigators found accounts belonging to the New York police officers had been hacked. Detective Vargas, who joined the department in 1993, was arraigned on charges of conspiracy to commit computer hacking and of unlawful access to a law enforcement database.

The second charge came from what prosecutors said was an unauthorized use of a national crime database by Detective Vargas to look up information about two officers whose e-mails he had also obtained.

He did so, prosecutors said, from a Bronx precinct where he worked, though the complaint did not specify which one. Detective Vargas had worked at the 44th Precinct, where officials said some of the police officers targeted were based, but was currently assigned to the 40th Precinct.

“Of all places, the Police Department is not a workplace where one should have to be concerned about an unscrupulous fellow employee,” said George Venizelos, the head of the F.B.I.’s New York office.

Monday, May 20, 2013

Hunting for Syrian Hackers’ Chain of Command

The hacking group that calls itself the S.E.A. struck again on Friday, this time breaking into the Twitter accounts and blog headlines of The Financial Times. The attack was part of a crusade that has targeted dozens of media outlets as varied as The Associated Press and The Onion, the parody news site.

But just who is behind the S.E.A.’s cybervandalism remains a mystery. Paralleling the group’s boisterous, pro-Syrian government activity has been a much quieter Internet surveillance campaign aimed at revealing the identities, activities and whereabouts of the Syrian rebels fighting the government of President Bashar al-Assad.

Now sleuths are trying to figure out how much overlap there is between the rowdy pranks playing out on Twitter and the silent spying that also increasingly includes the monitoring of foreign aid workers. It’s a high-stakes search. If researchers prove the Assad regime is closely tied to the group, foreign governments may choose to respond because the attacks have real-world consequences. The S.E.A. nearly crashed the stock market, for example, by planting false tales of White House explosions in a recent hijacking of The A.P.’s Twitter feed.

The mystery is made more curious by the belief among researchers that the hackers currently parading as the S.E.A. are not the same people who started the pro-Assad campaign two years ago.

Experts say the Assad regime benefits from the ambiguity. “They have created extra space between themselves and international law and international opinion,” said James A. Lewis, a security expert with the Center for Strategic and International Studies.

The S.E.A. emerged during the Syrian uprisings in May 2011, they said, to offer a pro-Assad counternarrative to news coming out of Syria. In speeches, Mr. Assad likened the S.E.A. to the government’s own online security corps, referring to the group as “a real army in a virtual reality.”

In its early incarnation, researchers said, the S.E.A. had a clearly defined hierarchy, with leaders, technical experts, a media arm and hundreds of volunteers. Several early members belonged to the Syrian Computer Society, a technical organization run by Mr. Assad before he became president. Until last month, digital records suggest, the Syrian Computer Society still ran much of the S.E.A.’s infrastructure. In April, a raid of S.E.A. Web domains revealed that the majority were still registered to the society.

S.E.A. members initially created pro-Assad Facebook pages and spammed popular pages like President Obama’s and Oprah Winfrey’s with pro-Syrian comments. But by the fall of 2011, S.E.A. activities had become more premeditated. They defaced prominent Web sites like Harvard University’s with pro-Assad messages, in an attack a spokesman characterized as sophisticated.

At some point, the S.E.A.’s crucial players disappeared and a second crop of hackers took over. The current group consists of roughly a dozen new actors led by hackers who call themselves “Th3 Pr0” and “The Shadow” and function more like Anonymous, the loose hacking collective, than a state-sponsored brigade. In interviews, people who now identify as the S.E.A. insist they operate independently from the Assad regime. But researchers who have been following the group’s digital trail aren’t convinced.

“The opportunity for collaboration between the S.E.A. and regime is clear, but what is missing is proof,” said Jacob West, a chief technology officer at Hewlett-Packard. As governments consider stronger responses to malicious cyberactivity, Mr. West said, “the motivation for Syria to maintain plausible deniability is very, very real.”

Long before the S.E.A’s apparent changing of the guard, security researchers unearthed a stealthier surveillance campaign targeting Syrian dissidents that has since grown to include foreign aid workers. Morgan Marquis-Boire, a researcher at the Citizen Lab at the University of Toronto, uncovered spyware with names like “Dark Comet” and “BlackShades” sending information back to a Syrian state-owned telecommunications company. The software — which tracked a target’s location, read e-mails and logged keystrokes — disguised itself as an encryption service for Skype, a program used by many Syrian activists.

Mr. Marquis-Boire has uncovered more than 200 Internet Protocol addresses running the spyware. Some were among the few kept online last week during an Internet disruption in Syria that the government blamed on a “technical malfunction,” but experts described as a systematic government shutdown.

This article has been revised to reflect the following correction:

Correction: May 17, 2013

An earlier version of this article based on previous reporting referred incorrectly to a representative of The Financial Times, Ryann Gastwirth. She is a spokeswoman, not a spokesman.

Sunday, May 19, 2013

Times Site Is Attacked by Hackers

Former Reporter Enjoys White House Hot Seat For Gay Men, a Fear That Feels Familiar Tucked Away in Downtown’s Din Archives at the New York Public Library cross-referenced with long-awaited 1940 data provide eye-opening results.

Telling the Truth on Fees, Warts and All Op-Ed: Goodbye to Bohemia, and a Bar Stuck without a lyric in sight, a songwriter ponders the intricacies of a little bird’s brain.

Monday, April 8, 2013

Op-Ed Contributor: Closing the Door on Hackers

FOR most of my teenage years, I made a hobby of hacking into some of the world’s largest government and corporate computer systems. I was “lucky” enough to be raided by the F.B.I. when I was 17 years old. After that wake-up call, I eventually started a software security company and now find myself helping to plug security holes, not exploit them.

The nature of hacking has changed, too, since I left it in the late 1990s — from a game of curiosity and occasional activism into a central tool in cybercrime and nation-state attacks.

Alongside that shift has come a loud and often misguided conversation about what to do to stop this new breed of hacking. Too much of the debate begins and ends with the perpetrators and the victims of cyberattacks, and not enough is focused on the real problem: the insecure software or technology that allows such attacks to succeed. Instead of focusing solely on employees who accidentally open e-mails, we should also be pressuring software makers to make significant investments in their products’ security.

When you read headlines about the latest cyberattack, you typically do not hear about how attackers were able to put a virus or other malware on a system in the first place. In many cases, it begins with attackers exploiting a software vulnerability or weakness in order to install their malware.

The unspoken truth is that for the most part, large software companies are not motivated to make software secure. It’s a question of investment priorities: they care more about staying competitive with their products, and that means developing the latest features and functions that consumers and businesses are looking to buy. Security issues are often treated more as a marketing challenge than an engineering one.

A result is an open door to hackers inside some of the world’s most popular software systems. Perhaps most famously, during the early to middle parts of the last decade, hackers discovered a significant number of glaring security weaknesses in Microsoft products (some of which were discovered by my company). Several of these weaknesses were exploited in high-profile computer virus and worm attacks.

To be fair, securing software is not a trivial task. Often it means building in multiple barriers to entry and keeping those defenses current with the latest developments in hacker techniques. Security has to be a central and significant investment in any software development project.

Still, given the heightened impact of recent attacks on both corporate and government operations, we must begin to hold software companies accountable for such vulnerabilities.

Fortunately, there is a lot a company can do to secure its code, should it choose to. After Microsoft’s software vulnerabilities drew significant negative attention — one of the few times the public has correctly affixed blame to a software company — Bill Gates himself addressed the issue in 2002 in his now famous “Trustworthy Computing” memo.

In that memo, sent to all Microsoft employees, Mr. Gates made it clear that the company’s future depended on building software and a platform that could be reliably secure. It was more than talk: in the decade or so since, Microsoft fundamentally changed its software development process to make security a core part of the program.

Too many other companies, though, seem to have missed the memo.

Take Oracle, and specifically the security challenges surrounding its Java software, which the company inherited through its 2010 acquisition of Sun Microsystems. Java, one of the most ubiquitous pieces of software in the world, is so full of security holes — including multiple avenues for hackers to take control of a computer remotely — that the Department of Homeland Security recommends that its users completely disable the software in their browsers.

Oracle is not alone. Adobe, which makes the popular Adobe Reader and Flash applications, has seen a significant number of security weaknesses over the years and also a sharp increase in its software’s being a gateway for cyberattacks. The risks associated with Flash were one reason Apple decided not to allow it on iPhones.

Like Microsoft, Adobe has made strides to increase the security of its technology over the last couple of years, and more recently some of those security improvements seem to be paying off. But it still has work to do.

In his 2002 memo, Mr. Gates cast the security challenge as not just a Microsoft problem, but one for the overall industry. A computer or a network is only as secure as its weakest link — no matter how secure one program might be, a poorly protected bit of software could compromise everything.

That means that on top of investing in their own security, companies have to make efforts to coordinate with other developers to present a united front. Adobe and Microsoft have worked together in recent years to identify and close off mutual vulnerabilities, and other companies should follow suit.

A lot of the talk around cybersecurity has centered on the role of government. But investing in software security and cooperating across the software industry shouldn’t take an act of Congress. It will, however, take a new mind-set on the part of developers. They should no longer see security as an add-on feature, nor should they regard holes in their competitors’ security efforts as merely a competitive advantage. As the world comes to depend more and more on their products, it should demand nothing less.

Marc Maiffret is the chief technology officer of BeyondTrust, an enterprise security management company.

Sunday, March 17, 2013

Media Decoder: Editor Charged With Aiding Hackers Group

8:30 p.m. | Updated Matthew Keys, a 26-year-old deputy social media editor at Thomson Reuters, has been charged with assisting the hacking collective Anonymous in an attack on the Web site of The Los Angeles Times, the Justice Department said Thursday.

A federal indictment of Mr. Keys, formerly a Web producer at KTXL Fox 40, which, like The Los Angeles Times, is owned by the Tribune Company, said that he went by a user name of “AESCracked” and assisted in a cyberattack on the newspaper’s Web site. The attack reportedly allowed the group to gain access and alter a news feature.

The three-count indictment includes charges that  Mr. Keys provided Anonymous with login information for computers owned by the Tribune Company. The indictment also states that he encouraged the hackers, with whom he worked from Dec. 10 to Dec. 15, 2010, to log on to the Tribune Company server “to make unauthorized changes to Web sites” owned by the company and “to damage computer systems” used at the Tribune Company.

A Los Angeles Times news article with the headline “Pressure Builds in House to Pass Tax-Cut Package” was renamed “Pressure Builds in the House to Elect CHIPPY 1337,” according to the indictment.

If convicted, Mr. Keys could face up to 10 years in prison for each substantive count and three years of supervised release and a fine of $250,000 for each count, the Justice Department said in a news release. A spokesman for Reuters said that the news organization was aware of the charges against Mr. Keys and that the alleged misconduct occurred before Mr. Keys joined Reuters in 2012. A spokesman for Tribune Company declined to comment.

The charges came as a shock in social media circles where Mr. Keys, considered a wunderkind of new media, cut a popular presence, including being named one of Time Magazine’s 140 best Twitter feeds. But the tsunami of social media also appeared to have taken a toll on Mr. Keys.

After posting more than 46,000 Twitter messages, Mr. Keys publicly took a break from the social media Web site. In an interview with Ad Week in July, he said Twitter had kept him up at night. “I got sucked into that. I loved it. I still love it. But at some point you have to take a break,” Mr. Keys said. (In a Twitter post on Thursday, Mr. Keys again said he intended to take a break.)

The length of his potential sentence reignited online protests on Thursday over the way federal prosecutors approached the Internet. Those protests from open Internet proponents like the Electronic Frontier Foundation, exploded in January after the computer programming prodigy Aaron Swartz, also 26 and facing federal charges related to hacking, committed suicide.

The charges against Mr. Keys came as other media organizations were facing computer threats. Chinese hackers have compromised the computer systems of several major United States media organizations, including The New York Times and The Wall Street Journal. The Ministry of National Defense of China has denied any involvement in the attacks.

On Wednesday, President Obama met with chief executives to discuss digital security legislation. In an interview with ABC News on Wednesday, he acknowledged the “ramping up of cybersecurity threats.”

Anonymous, a nebulous and global collective of so-called hactivists, often use computers in protesting or supporting political causes. The group demanded Christmas dinner be provided to Pfc. Bradley Manning, the former Army intelligence officer arrested in 2010 on accusations of leaking classified documents to WikiLeaks.

In a Twitter message posted last year, Hector Xavier Monsegur, a hacker known as “Sabu” who led a  hacking collective and worked as an F.B.I. informant, accused Mr. Keys of playing a part in hacking into The Los Angeles Times.

Mr. Keys has written about Sabu and Anonymous for Reuters and been associated with hacking groups in the past, including in a Gawker article that identified him as a “journalist who infiltrated” Anonymous.

“I identified myself as a journalist during my interaction with top-level Anonymous hackers,” Mr. Keys wrote on his personal blog in response to the Gawker article.

The charges against Mr. Keys were first reported by The Huffington Post.

This post has been revised to reflect the following correction:

Correction: March 16, 2013

An earlier version of this post erroneously included Bloomberg News among media organizations whose computer systems were compromised by Chinese hackers. Bloomberg News said its computer systems were targeted, but not compromised.

Wednesday, December 26, 2012

Hackers of Steubenville Football Team’s Web Site Demand Apology in Rape Case

A group calling itself Anonymous, a hacker collective, and KnightSec posted a note and a video on the Web page of the Steubenville High School Big Red football team, a program in the Ohio Valley known for its dominance. The note stated that the city of Steubenville was protecting its beloved team by charging only two of its players with the rape of a girl “when everyone present was guilty.”

The rape case was the subject of an article last week in The New York Times.

In the video, a person wearing a Guy Fawkes mask said that the names, Social Security numbers, addresses, names of relatives and phone numbers of people connected to the case were being compiled and would be made public if an apology from those involved did not come before Jan. 1.

“This is a warning shot to the school faculty, the parents of those involved and those involved especially,” the person said in a computerized voice.

Anonymous is a hacker group that has coordinated cyberattacks on the Web sites of major corporations, like MasterCard, and the government, including the United States Department of Justice. In 2010, it attacked sites of corporations it considered hostile to WikiLeaks and its founder, Julian Assange, and made some Web sites inoperable or slow. It also has been campaigning against the Westboro Baptist Church, most recently because church members had threatened to picket a vigil for the victims of the Newtown, Conn., school shootings.

The hackers’ crusade against the Big Red football team on Sunday ignited activity on the Web about the rape case. The video that Anonymous posted on the team’s Web site was removed from the site Monday morning.

A statement from the Steubenville City Schools said the school system does not own or control the hacked Web site, Rollredroll.com, nor does it have any connection with it.

“We will continue to monitor our Web sites for any inappropriate content,” the statement said.

The unauthorized video posted on the team’s Web site referred to the case of a 16-year-old girl who prosecutors said was raped on the night of Aug. 11 at a series of parties in and around Steubenville. Twitter comments, a photograph on Instagram and at least one video that was posted on YouTube that night documented the rape, the police said. Twitter users wrote the words #rape and #drunkgirl, and some referred to the girl as “the dead body.” At least one Twitter comment suggested that the girl had been urinated on.

Trent Mays, 16, of Bloomingdale, Ohio, and Ma’lik Richmond, 16, of Steubenville — two sophomore standouts on the football team — remain on house arrest on charges that they raped the girl when she was too drunk to resist. Their trial has been set for Feb. 13 in juvenile court.

The case has shaken the football team, which has been the pride of the community for more than 100 years, and has divided Steubenville. The night of the party, residents began taking sides, with some blaming the girl, saying she was trying to defame the team with her accusation. Others said the suspected rape occurred as a result of a hero-worshiping culture of a city obsessed with high school football.

At a hearing in early October, two Big Red football players and one Big Red wrestler testified for the prosecution at a probable cause hearing, with one witness stating that he had seen Mays rape the girl in the back seat of a car while the girl was slurring her words and was unable to walk on her own. That witness said he videotaped the rape, but later deleted the video from his phone. Another witness testified he saw Richmond rape the girl while she was motionless and naked on the basement floor at one party.

The hackers posted the names of those witnesses, as well as the names of other witnesses they said saw the rape that night in August. They referred to those witnesses as “targets.” They also released basic information about some of those people, including addresses, phone numbers and names of their parents.

Wednesday, December 12, 2012

Saudi Aramco Says Hackers Took Aim at Its Production

JEDDAH, Saudi Arabia (Reuters) — Saudi Arabia’s national oil company, Aramco, said on Sunday that a cyberattack against it in August that damaged some 30,000 computers was aimed at stopping oil and gas production in Saudi Arabia, the biggest exporter in the Organization of the Petroleum Exporting Countries.

The attack on Saudi Aramco — which supplies a tenth of the world’s oil — failed to disrupt production, but was one of the most destructive hacker strikes against a single business.

“The main target in this attack was to stop the flow of oil and gas to local and international markets and thank God they were not able to achieve their goals,” Abdullah al-Saadan, Aramco’s vice president for corporate planning, said on Al Ekhbariya television. It was Aramco’s first comments on the apparent aim of the attack.

Hackers from a group called Cutting Sword of Justice claimed responsibility for the attack, saying that their motives were political and that the virus gave them access to documents from Aramco’s computers, which they threatened to release. No documents have yet been published.

Aramco and the Saudi Interior Ministry are investigating the attack. A ministry spokesman, Maj. Gen. Mansour al-Turki, said the attackers were an organized group operating from countries on four continents.

The attack used a computer virus known as Shamoon, which infected workstations on Aug. 15. The company shut its main internal network for more than a week. General Turki said the investigation had not shown any involvement by Aramco employees. He said he could not give more details because the investigation was not complete.

Shamoon spread through Aramco’s network and wiped computers’ hard drives clean. Aramco said damage was limited to office computers and did not affect systems software that might harm technical operations.

In a posting on an online bulletin board the day the files were wiped, the hacker group blamed Saudi Arabia for “crimes and atrocities” in countries including Syria and Bahrain.

Saudi Arabia sent troops into Bahrain last year to back the Persian Gulf state’s rulers, fellow Sunni Muslims, against Shiite-led protesters. Saudi Arabia is also sympathetic to rebels in Syria.

Friday, October 5, 2012

Bits Blog: Hackers Breach 53 Universities and Dump Thousands of Personal Records Online

Hackers published online Monday thousands of personal records from 53 universities, including Harvard, Stanford, Cornell, Princeton, Johns Hopkins, the University of Zurich and other universities around the world.

The group of hackers, calling themselves Team GhostShell, claimed responsibility for the attack on Twitter and published some 36,000 e-mail addresses and thousands of names, usernames, passwords, addresses and phone numbers of students, faculty and staff, to the Web site Pastebin.com. In most cases the data was already publicly available, but in some instances the records included additional sensitive information such as students’ dates of birth and payroll information for university employees.

Typically, hackers seek such information because it can be used to steal identities, crack bank accounts or can be sold on the black market. Universities make ripe targets because they store vast numbers of personal records, often in decentralized servers. The records can be a gold mine because students often have pristine credit reputations and do not monitor their account activity and credit scores as vigilantly as adults.

Dozens of universities have been plagued by breaches recently. Last August alone, the University of Rhode Island warned that students and faculty that their information may have been exposed. And at the University of Arizona, a student discovered a breach after a Google search exposed her personal information — and that of thousands of others at the university. Smaller computer breaches at Queens College and Marquette University were also reported.

In this case, the hackers said they were not motivated by profit but to “raise awareness towards the changes made in today’s education.” In a message accompanying the stolen data, they bemoaned changing education laws in Europe and spikes in tuition fees in the United States. But they also noted that in many cases, the servers they breached had already been compromised.

“When we got there, we found that a lot of them have malware injected,” the hackers wrote on Pastebin.

To breach servers, the hackers used a technique known as an SQL injection, in which they exploit a software vulnerability and enter commands that cause a database to dump its contents. In the case of some universities, the hackers breached multiple servers.

IdentifyFinder, a firm that works to prevent identify theft from security breaches, analyzed the published data and said it appeared to be legitimate. The company analyzed the data and found 36,623 unique e-mail addresses and tens of thousands of student, faculty and staff names as well as thousands more usernames and passwords, some encrypted but many stored in plain text.

Aaron Titus, a spokesman for IdentityFinder, said that in analyzing the hackers’ attack methods, there was evidence that in many cases they had been inside the universities’ systems for “at least four months.”

Lisa Ann Lapin, a spokeswoman for Stanford University, said that the university discovered the breach Tuesday evening. She confirmed that two departmental Web sites belonging to the university had been accessed, but said the servers “have been secured.”

“Our information security officers consider the breaches to be minor in nature,” Ms. Lapin said. “No restricted or prohibited data was compromised, nor was any sensitive or other personal information that could lead to identity theft.”

At colleges across the country, some students set up sites that allowed students and faculty to search the leaked data for their information. For instance, at the University of Pennsylvania, Matt Parmett, a junior, created a Web site that made it possible for classmates to search the leaked data by name.

Sunday, September 30, 2012

Bits Blog: Hackers May Have Had Help With Attacks on U.S. Banks

The hackers claiming responsibility for cyberattacks on American banks over the past week must have had substantial help to disrupt and take down major banking sites, security researchers say.

Bank of America, JPMorgan Chase, Citigroup, U.S. Bancorp, Wells Fargo and PNC all experienced disruptions and delays on their banking sites over the past week because of denial of service or DDoS attacks, in which hackers clog a Web site with data requests until it slows or collapses under the load.

A hacker group, which calls itself the Izz ad-Din al-Qassam Cyber Fighters, took credit for the attacks in online posts. They enlisted volunteers for the attacks with messages on various sites. On one blog, they called on volunteers to visit two Web addresses that would cause their computers to instantly start flooding targets — including the New York Stock Exchange, Nasdaq and Bank of America — with hundreds of data requests each second. This week, hackers asked volunteers to attack banks according to a defined timetable: Wells Fargo on Tuesday, U.S. Bancorp on Wednesday and PNC on Thursday.

Representatives for Wells Fargo, U.S. Bank and PNC all confirmed Wednesday that their Web sites had experienced disruptions because of unexpected volumes of traffic. Both the New York Stock Exchange and Nasdaq saw a slowdown, but no serious disruption, on their Web sites.

Security researchers say the attack methods being peddled by hackers — the custom-built Web sites — were too basic to have generated the disruptions.

“The number of users you need to break those targets is very high,” said Jaime Blasco, a security researcher at AlienVault who has been investigating the attacks. “They must have had help from other sources.”

Those additional sources, Mr. Blasco said, would have to be a well-resourced group, like a nation state, or botnets — networks of infected zombie computers that do the bidding of cybercriminals. Botnets can be rented via black market schemes that are common in the Internet underground, or loaned out by cybercriminals or governments.

Last week, Senator Joseph I. Lieberman, chairman of the Senate Homeland Security Committee, said in an interview  that he believed the attacks on the banks were being sponsored by Iran’s government.

Mr. Blasco said security researchers had noticed an increase in the use of botnets out of Iran recently. But he said he had not been able to track the origin of the attack to Iran. Attacks can be routed through various I.P. addresses to mask their true origin, making attribution “nearly impossible,” Mr. Blasco said.

In the hackers’ post, they said their attacks were not sponsored by Iran, and said they “strongly reject the American officials’ insidious attempts to deceive public opinion.”

They said they conducted the attacks in retaliation for a video, made by amateur filmmakers in the United States, that mocks the Prophet Muhammad.

“Insult to the prophet is not acceptable, especially when it is the last prophet Muhammad,” the hackers said in their post.

They pledged to continue to attack American banking sites and targets in other countries, including France, Israel and the United Kingdom, until the video was pulled offline.