(osnn.net) -- Microsoft has issued a pre-patch security advisory warning about the Microsoft Office Snapshot Viewer ActiveX control. It contains a vulnerability which can allow a remote unauthenticated attacker to download arbitrary files to arbitrary locations.
Vulnerability Note VU#837785 @ US-CERT
This advisory has information on setting the killbit in order to avoid this attack.
See the Microsoft Security Advisory 955179 for more information.
See also Microsoft Support Document 240797 about how to set the kill bit.
08 July 2008
Microsoft warns of “active, targeted” ActiveX control attacks
01 July 2008
Kaspersky adds anti-keylogger keyboard
(techworld) -- The new version of Kaspersky’s security suite, Internet Security 2009, features a novel but simple defence against keylogging malware – a virtual keyboard.
Full details have yet to be confirmed, but it is understood that the program will let users bring up the keyboard from which to enter login details for websites such as online banks that might be vulnerable. The on-screen keyboard will cache the keystrokes, protecting them from recording programs that would pick up physical keystrokes coming via the keyboard driver.
It’s not a new idea but Kaspersky is the first major security vendor to include such a feature in a standard Net security program.
The company has also announced a raft of other enhancements to Internet Security 2009, and Anti-Virus 2009, both due out this month.
For the first time, Internet Security will feature applications whitelisting, which will analyse programs against a database from security vendor Bit9 - users will be told about apps that don’t show up with a digital ‘fingerprint’ in this database. There will also the ability to enforce restrictions on external devices such as USB drives, and a security analysis tool will tell users which third-party software needs patching, in a similar mould to Secunia’s Software Inspector.
The company claims it has overhauled the Anti-Virus program to better detect and deal with malware, especially rootkits, found on the system at the point it is installed, as well as adding improved self-protection against malware that tries to subvert Kaspersky itself.
If all this sounds as if it might cause performance to deteriorate, the company has an answer to that too. The new ‘iSwift’ checksumming feature – something that was popular in anti-virus programs as long ago as the early 1990s – will reduce scan loads by analysing only files that have changed since that last scan was performed.
“Our 2009 technology provides […] an unobtrusive security solution that will not slow down their gaming, email, instant messaging, downloading, home working or social networking and other activities. The Virtual Keyboard will further protect those using online banking, to ensure that their money and account details remain safe,” said Kaspersky’s David Emm.
Internet Security 2009 UK Edition, single user, costs £39.99 per annum (£27.99 renewal), with Kaspersky Anti-Virus 2009 UK Edition, single user at £29.99 per annum (£20.99 renewal), available for download from this month.
Firefox 3.1 expected this month
(pcpro.co.uk) -- Just one week has passed since the final release of Firefox 3.0 and Mozilla has suggested that version 3.1 may be open for download as early as this month.
The news emerged at a Mozilla meeting this week when a draft schedule for Firefox development was discussed.
The release would be a first developer preview, with a beta following in August and a full release scheduled in early 2009.
This schedule has yet to be approved, but Mike Schroepfer, Mozilla's vice
president of engineering, has previously said that he hopes to ship the software even sooner, by the end of 2008.
The short delay between updates is partly due to the fact that many of the features expected in the upcoming release are already "nearly complete", according to Schroepfer. They represent code that narrowly missed inclusion in version 3.0.
Expected in the new software are improvements to the bookmarking functions and an update to the awesome bar, as well as several improvements to the rendering engine courtesy of Gecko 1.9.1, which is under parallel development.
Mozilla claims that over 8 million people downloaded Firefox 3.0 on the day of its release. This is expected to become a world record for the number of downloads on a release day, although officials from Guinness have yet to verify the figure.
21 June 2008
Teens Charged With Loading Spyware, Changing Grades
(pcworld) -- Two Orange County, California, teenagers have been charged with breaking into high school offices and using stolen usernames and passwords to change lackluster grades to A's.
Omar Khan and Tanvir Singh, both 18, are facing multiple felony charges following a series of break-ins at Tesoro High School in Rancho Santa Margarita, California. Khan was arrested Monday, and Singh was expected to turn himself into court on Tuesday for arraignment.
According to prosecutors, Khan changed the D's and C's he was receiving in Spanish, Calculus and English to two A's and a B+. He's also charged with stealing tests before they had been given and using a stolen username and password to break into school computers and change the grades of 12 other students.
He is also alleged to have installed spyware software on the computer hosting the school district's grades database so that he could remotely access this system.
The police were called in after Khan requested a copy of his transcript and school officials noticed his stellar grades, the Orange County district attorney's office said.
If convicted, Khan could be sentenced to more than 38 years in prison.
Singh, who faces fewer charges, faces three years in prison. He's charged with breaking into the school with Khan in order to steal an English test on May 19. According to court filings he sent a text message to Khan around 4 p.m. planning the crime. "Hey wana go to the school tonight," he wrote. "I need someone with balls there with me."
Hong Kong is Beating Spam, Registrar Says
(pcworld) -- The Hong Kong Domain Name Registration Company (HKDNR) announced late last week that the daily average number of .hk domain name spam and phishing cases drops 92 percent year-on-year.
According to the "'.hk' Domain Name Spamvertising & Phishing Report" compiled the HKDNR, a daily average of 38 such cases was recorded throughout 2007, while the number dropped to 3 from January to May 2008.
The announcement contradicts -- and may be in response to -- a recent assertion by security vendor McAfee that the ".hk" domain name is the most dangerous, with about 19 percent of its sites serving up malware.
Registrar's Efforts
"HKDNR is committed to providing a safe Internet environment for the community and has put in place various measures against suspicious websites," said Jonathan Shea, CEO of HKDNR. "We have been working closely with the Office of the Telecommunications Authority Hong Kong Police and Hong Kong Computer Emergency Response Team Coordination Centre (HKCERT) to monitor and control the situation,".
"We actively review our systems and domain name registration procedures and policies. In particular, we have implemented more stringent documentary requirements to combat suspicious applications in order to keep pace with the fast-changing Internet world," he added.
Shea noted that the HKDNR has also adopted additional verification measures for online payment of domain registration. He added that The Hong Kong Police inform HKDNR of criminal cases involving '.hk' domains in a timely manner and the HKCERT help HKDNR develop guidelines for verification of phishing domains while OFTA provided an updated list of spamvertising '.hk' domains to HKDNR daily and advised on spamvertising verification criteria.
As a result of these initiatives, more than 14,000 '.hk' domain names were suspended by HKDNR this year by the end of May, he said. Around 85 percent of these were related to spamvertising activities and about 15 percent were related to phishing websites, he added.
Cyber scamsters run for cover
AHMEDABAD (timesofindia.indiatimes) -- Cyber hackers are ducking for cover after the nation-wide police crackdown following the busting of the online shopping fraud by the Ahmedabad police.
After the arrest of their kingpins in Mumbai, Chennai and Ahmedabad, there are warnings posted on hacking websites against "indulging in 'carding' for the time being".
"Carding in hackers' jargon stands for dealing in a huge database containing confidential information of credit card holders such as user name, expiry date, credit value verification (CVV) numbers and address. Such data are kept by the IT division of any financial institute. Most of the times, hackers enter into protected servers and steal the data. They do it with utmost care and expertise. At any given time, there are more than 5,000 database available on various websites. However, to access it, one has to become member of the paid community," said Sunny Vaghela, a cyber security expert. These hacking websites had many members posting links to TOI's published stories on the online shopping fraud and discussed the implications of opening up of their network.
One post read: "Hope they will come out soon", about the hackers caught. Another read: "Oh s*@#! If they got cards from here then maybe we should close registrations quicker...damn that's lame...old members." In another community, a seeming veteran advised juniors "not to leave cyber footprints and clear up the record before logging out".
The same website forum has tutorials on how to hack into government and non-government organizations and to access backdoor password of financial gateways. After the surfacing of eBay hacking incidents, the website says, cyber crime cells are active in various affected countries and are keeping a tab on suspicious websites.
Lazy Hacker Trick: Tricking Script Kiddies
(internetnews) -- Security software and consulting vendor Panda is tracking the latest Constructor/Wormer worm threat, and its approach by malware networks to entice script kiddies to their bidding.
The bad guys in this case are cyber criminals, who target databases and banks.
Unleashing applications that make it easy to create malware isn't quite new, but their approaches this time are, according to Panda, which is in the business of providing software and technology security consulting services.
Constructor/Worm's main function is to turn an executable file into a worm. The application is easy to use -- by checking different flags, users can design a worm with different functionalities, according to Ryan Sherstobitoff, chief corporate evangelist for Panda Security USA, which created PandaLabs.
Not only that, it allows them to compress the application with UPX, a free, portable, extensible, high-performance executable packer which is distributed under the terms of the GNU General Public License, or with MuteX, another tool. Compressing malware makes it harder for lab engineers to reverse-engineer.
Advanced options include selecting an infection date, disabling different features in Windows such as the Task Manager, the Windows Registry Editor or the Folder options.
Sherstobitoff thinks the malware was released on the Internet as part of a two-pronged attack by criminals.
"We've seen many of these tools, and the idea is for script kiddies to create malware that will be a distraction while some of the more insidious banker Trojans are committing mass identity theft," he said.
Apparently, cyber criminals hope that wannabe hackers, also known as script kiddies, will be enchanted enough by the ease with which the tool lets them create malware that they'll flood the Internet with new forms of it.
One of the most notorious cyber criminal networks is the Russian Business Network, thought to have been led by the nephew of a well-connected Russian politician.
At its height, it was suspected to have been behind up to 50 percent of the phishing incidents worldwide.
Phishing is an an e-mail attack claiming to be a consumers' bank, asking for details of their accounts.
After its brazen exploits attracted the attention of security experts worldwide, the Russian Business Network went underground for a while. It's now believed to have resurfaced in China.
A similar group in Britain, using the ShadowCrew Website, has been arrested and its leader, Bryn Wellman, was sentenced to 10 years in jail earlier this year.
And according to a survey of 1,000 PC users in March conducted by antivirus software vendor AVG Technologies, formerly known as Grisoft, U.S. citizens are more afraid of being the victims of cyber crime than they are of burglary or assault.
The problem is so bad that more than 200 people from government agencies and private companies in Europe, the U.S., Africa and South America attended a Council of Europe cyber crime forum in Strasbourg in April to develop guidelines for closer international cooperation between law enforcement and Internet service providers
Storm variant targets Olympics fans
(vnunet) -- Security organisations have warned of a new virus attack that uses the upcoming Beijing Olympics to spread a new variant of the Storm malware.
The vector of attack is an email purporting to contain the news that the Olympics will be delayed or cancelled due to earthquake damage.
Emails contain a link that claims to be a video to back up the information, but the file downloads an application named beijing.exe containing the Trojan.
"Some advice for the day: do not click on every link in your email," said Symantec researcher Vikram Thakur in a blog posting.
"It looks like the Peacomm [Storm] authors have decided to use past and future events in China as lures for their latest creation.
"A new spam run is in progress with links to a file called beijing.exe, which is currently detected by Symantec as Trojan.Peacomm.D."
The US Computer Emergency Readiness Team has also issued a warning about the attack, saying that the emails have been widely spammed out and that phishing activity linked to the malware has already been detected.
Storm was one of the most successful Trojans of last year, with many infections reported.
There had been hopes that malware users were switching to other code but this latest attack has professionals worried that internet users could be facing another onslaught.
"The first time we saw Storm was when they sent out emails that reported violent storms through Europe. That's why we named it Storm," said Patrik Runald, security researcher at F-Secure.
"We are still expecting to see Storm, and other malware, use the Olympic Games in August as a social engineering trick, so be on the lookout for those in a few weeks."
Trend Micro's new vision: Signatures in the cloud
(zdnet) -- Trend Micro chief executive and co-founder Eva Chen unveiled a new vision for the company that includes 'in-the-cloud' malware analysis.
Unlike the computer viruses of 20 years ago, which were slow to evolve and infected thousands of systems worldwide, malware today evolves rapidly and infects relatively few systems, creating thousands of new variants each day.
Chen admitted that traditional signature-based antivirus strategies may seem rather outdated, but argued that pattern matching is still faster than running a full heuristic check of each new malware specimen. Her answer is to throw all the unknown samples up into the cloud for deeper and faster pattern recognition.
Over the last few years, Trend Micro has been building robust servers around the world, enabling it to offer more and more software-as-a-service (SaaS) solutions to its medium-sized business customers. Now Trend Micro is planning to include its in-the-cloud network service in two new suites for enterprises, and may, in the future, incorporate some of the technology in its home and small business offerings.
With faster internet connections available worldwide, Chen argued that it is faster to do a suspected malware check in the cloud than to initiate and execute a sandbox heuristic environment on the desktop.
The time taken for an in-the-cloud check is milliseconds rather than the one to two seconds required for each sandbox inspection. Over several thousand samples, the time savings add up. Also, all unknown samples could be gathered from around the world, and new signatures could be sent out worldwide.
Chen said she envisions a 15 minute turnaround from discovery to mitigation of each new piece of malware detected.
On Wednesday, Trend Micro announced two enterprise suites: a Threat Discovery Suite (due in the third quarter of 2008) to find internal security threats on a network, and a Threat Mitigation Suite (due in the fourth quarter of 2008) to provide analysis and policy review to protect against future threats.
Videogame piracy helps sales, says Sony
(electricpig) -- While crafty modders and homebrewers are praised by some of the gaming community, they’re the bane of videogame bigwigs. However, SCEE president David Reeves admits that while piracy “is a problem”, it can help improve sales.
Within months of Sony’s PSP being out, naughty hackers cracked it open, proving that no matter how tough a piece of tech is, there’s always some way to hack into its gadgety innards.
Since then hackers have been able to do almost anything with it, including play games from other consoles, and SCEE are not a bunch of happy bunnies.
“There is a piracy problem on PSP,” Reeves said at the recent DevStation conference in London (MCV reports). “We know about it, we know how it’s done.
“It sometimes fuels the growth of hardware sales, but on balance we are not happy about it,” he said, while explaining that Sony will soon be introducing new measures to tackle piracy on the handheld.
Clouds and silver, anyone? Still, there’s probably a few hackers out there thinking, ‘sounds like a challenge’.
Microsoft blames human error for critical security update failure
(itwire) -- "Human issues" are being blamed for a Microsoft security update failing to protect users of Windows XP SP2 and SP3 from a critical vulnerability. The Bluetooth flaw could allow remote execution of code on a targeted computer.
Arriving as part of June's Patch Tuesday releases, MS08-030 was supposed to fix a flaw that could allow an attack via Bluetooth.
Such an attack could theoretically lead to the execution of arbitrary code, but Microsoft security specialists determined that the chance of a successful exploit were slight for several reasons, but largely because of a small timing window and the need to place the code in the correct location.
The flaw affects Windows XP SP2 and SP3, XP Professional x64 (including SP 2), and Vista (both x86 and x64, including SP1).
After the updates were release, Microsoft realised that XP SP2 and SP3 were not being protected, and began work on a revision, which has now been released.
The Microsoft Security Response Center recommends users of Windows SP2 or SP3 test and deploy the new version of the update. For most of us, that means running Windows Update again, or allowing Automatic Updates to do its thing.
The other versions of Windows do not require a further update.
But how did the XP problem occur, and what's Microsoft going to do about it?
Once the XP update had been revamped, Microsoft began an investigation of the events leading up to the glitch.
According to security program manager Christopher Budd, "early on, it appears that there may have been two separate human issues involved. When we’re done with our investigation, we’ll take steps to better prevent it in the future."
20 June 2008
Mac OS X Trojan reported in the wild
(betanews) -- At least two Mac-focused security firms warned late this week of a Trojan horse that takes advantage of flaws in remote management software in Mac OS X to run code on the affected computer.
As with most Mac flaws, the user must first download and open the file in order for it to take effect. Once it is opened, the Trojan -- dubbed "AppleScript.THT" -- adds itself to the login process and can perform a variety of functions, including keystroke logging.
It can also take pictures with the iSight camera and screenshots and turn on file sharing, security firm SecureMac said. Intego, the other firm to highlight the issue, said the Trojan could be used to run arbitrary code.
A flaw within the Apple Remote Desktop Agent is the source of the problem, which exists in both Mac OS X 10.4 and 10.5. It is potentially very dangerous due to the fact that it could be run with root privileges.
SecureMac reports that it is being distributed from a site frequented by malicious users, and files containing the Trojan were being sent through both iChat and Limewire. Bundled within an AppleScript, the files containing it have the names "ASthtv05" and "ASthtv06."
Any user running either 10.4 or 10.5 are said to be at risk, and currently the only interim solution being advertised is to only download files from trusted sources until the problem is fixed.
Users of either company's security products, MacScan 2.5.2 (with the 2008011 definitions update) or VirusBarrier X5 (with the June 19 definitions) would be protected from the Trojan, the company said.
Either way, this latest security threat is evidence that Mac users will need to be ever more vigilant. "As Apple's market share continues to grow, so will security research and hack attempts against OS X," SecureMac president Nicholas Raba said.
18 June 2008
Student's life as a hacker exposed by eBay tip-off
T Bharathwaj Purohit (TOI Photo)
CHENNAI (timesofindia.indiatimes) -- Police on Tuesday arrested a college student for purchasing electronic goods online using credit card details of card holders from across the world.
T Bharathwaj Purohit (20), a resident of MKB Nagar and a member of a community of hackers, had been buying electronic goods online using other people’s credit cards since April. Police recovered an electric guitar, a printer, an LCD TV, a digital camera, a weighing scale, a mobile and a laptop all worth Rs three lakh, and Rs 38,500 in cash from him.
Purohit met Charu Sharma of Mumbai and Hathi Gogaiyan of Ahmedabad online a few months ago. They introduced him to an online hackers’ community on the net and gave him credit card details to make purchases.
“Following Sharma and Gogaiyan’s advice, Purohit tried to book an expensive mobile and i-pod using the data they provided. To his surprise, he received the items within a week. He also couriered the valuables to them as gifts. He started buying more goods online on ‘eBay’, an online auction website,” deputy commissioner of police B Vijayakumari said.
Sharma and Gogaiyan had given Purohit details of US credit card holders. Following complaints from an eBay investigation officer, the city police arrested Purohit. He had made his purchases from his personal computer. The police, with the help of the cyber crime wing, tracked down his IP address. Preliminary inquires revealed that this group of hackers got bank accounts and credit card details of people for a price.
“We have received information that the Mumbai police cornered Sharma and Gogaiyan a few days ago for another credit card cheating case in Mumbai. We have taken Purohit into custody to get more details,” a senior police officer said.
Police booked Purohit under several sections of the IPC, including 420 (cheating). He was remanded in judicial custody after being produced before the magistrate court on Tuesday.
Firefox 3.0 Released, Servers Overwhelmed

(pcworld/macworld) -- Mozilla has released Firefox 3.0, the final release of the newest version of its popular Web browser. The company may have been a bit unprepared for the onslaught of Web traffic the release generated; reports note that its servers have been overwhelmed since the release.
Mozilla released Firefox on Tuesday after a public preview that lasted months, through myriad alpha and beta development builds and several release candidates.
New features in Firefox 3.0 include one-click bookmarking, instant Web site ID (to help identify online scams and unsafe transactions), improved performance, Web page zooming, password management, a smart location bar, and platform-native look and feel.
Mozilla hopes to set a world record for downloads with Firefox 3 on Tuesday. Though the big "Download Day" was set to begin at 1 p.m. ET, Mozilla's Web site was down or working sporadically all morning on the East Coast, and users still could not download Firefox 3 from the site more than an hour later.
A Firefox spokeswoman said via e-mail just after 2 p.m. that the company was aware of the problem and "working to get it back up quickly."
Mozilla also outlined the problems it was having with its Web site in a blog entry.
"The outpouring of interest and enthusiasm around Firefox 3 has been overwhelming (literally!)," according to the post. "Our servers are currently feeling the burn and should be back to normal shortly."
Mozilla will begin registering downloads for the record for 24 hours from the moment the site goes live, according to the post.
System requirements call for Mac OS X v10.4 or later, G3 or better (including Intel), 128MB RAM, 200MB hard disk space.
12 June 2008
Opera 9.5 browser released
(webuser) -- Opera Software has made the final public release of its new browser, Opera 9.5, available for download.
One of the key features in version 9.5 is Opera Link, which will synchronise the browser across several different devices such as mobile phones, desktops, PDAs and even Wii games consoles, keeping your bookmarks and other settings up-to-date.
Opera first started testing the latest build nine months ago and the release comes just days before Mozilla releases the full version of its Firefox 3 browser.
Another feature new to Opera 9.5 is Quick Find, designed to help surfers locate pages in their history just by typing a key word into their address bar. Firefox has a similar feature called the "Awesome Bar" built into its latest browser release.
Security against malware and phishing has also been strengthened in Opera 9.5.
"Opera's Fraud Protection not only protects you from fraudulent websites, it is now the first browser publically available to protect you from malware and other malicious software on the web, " the company said.
Versions of Opera 9.5 are available for download from the Opera homepage for Mac, Linux and Windows platforms, in 30 different languages.
www.opera.com
Lawmakers: Capitol computers hacked by Chinese
WASHINGTON (AP/bostonherald) -- Multiple congressional computers have been hacked by people working from inside China, lawmakers said today, suggesting the Chinese were seeking lists of dissidents.
Two congressmen, both longtime critics of Beijing’s record on human rights, said the compromised computers contained information about political dissidents from around the world. One of the lawmakers said he’d been discouraged from disclosing the computer attacks by other U.S. officials.
Virginia Rep. Frank Wolf said four of his computers were compromised, beginning in 2006. New Jersey Rep. Chris Smith, a senior Republican on the House Foreign Affairs Committee, said two of his computers were attacked, in December 2006 and March 2007.
Wolf said that following one of the attacks, a car with license plates belonging to Chinese officials went to the home of a dissident in Fairfax County, Va., outside Washington and photographed it.
During the same time period, The House International Relations Committee — now known as the House Foreign Affairs Committee — was targeted at least once by someone working inside China, said committee spokeswoman Lynne Weil.
Wednesday’s disclosures came as U.S. authorities continued to investigate whether Chinese officials secretly copied the contents of a government laptop computer during a visit to China by Commerce Secretary Carlos M. Gutierrez and used the information to try to hack into Commerce Department computers.
The Pentagon last month acknowledged at a closed House Intelligence committee meeting that its vast computer network is scanned or attacked by outsiders more than 300 million times each day.
Wolf said the FBI had told him that computers of other House members and at least one House committee had been accessed by sources working from inside China. The Virginia Republican suggested that Senate computers could have been attacked as well.
He said the hacking of computers in his Capitol Hill office began in August 2006, that he had known about it for a long time and that he had been discouraged from disclosing it by people in the U.S. government he refused to identify.
"The problem has been that no one wants to talk about this issue," he said. "Every time I’ve started to do something I’ve been told ’You can’t do this.’ A lot of people have made it very, very difficult."
The FBI and the White House declined to comment.
The Bush administration has been increasingly reluctant publicly to discuss or acknowledge cyber attacks, especially ones traced to China.
In the Senate, the office of Sen. Dick Durbin, D-Ill., who chairs the Senate’s subcommittee on humanitarian issues, asked the sergeant at arms to investigate whether Senate computers have been compromised.
Wolf said the first computer hacked in his office belonged to the staffer who works on human rights cases and that others included the machines of Wolf’s chief of staff and legislative director.
"They knew which ones to get," said Dan Scandling, who currently is on leave of absence from his job as Wolf’s chief of staff. "It was a very sophisticated operation," he said. "The FBI verified that it had been done."
Smith said the attacks on his office computers were "very much an orchestrated effort."
He said that after the first intrusion in December 2006, "that was the last time" his office put the names of dissidents on its computers.
In Beijing, the Chinese Ministry of Foreign Affairs had no immediate comment on the allegations by Wolf and Smith.
Last week, China denied the accusations regarding Gutierrez’s laptop and the alleged effort to hack Commerce Department computers.
Wolf said he was introducing a House resolution that would help ensure protection for all House computers and information systems.
It calls for the chief administrative officer and sergeant at arms of the House, in consultation with the FBI, to alert members and their staffs to the danger of electronic attacks. Wolf also wants lawmakers to be fully briefed on ways to safeguard official records from electronic security breaches.
"My own suspicion is I was targeted by China because of my long history of speaking out about China’s abysmal human rights record," Wolf said in a draft of remarks he prepared to give on the House floor.
He said Congress should hold hearings, specifically the House Intelligence Committee, Armed Services Committee and Government Operations Committee.
Speaking generally in May 2006, Wolf called Chinese spying efforts "frightening" and said it was no secret that the United States is a principal target of Chinese intelligence services.
Wolf thinks that President Bush should stay away from the Olympics because of China’s human rights record.
He also has been outspoken on the subject of violence in the Darfur region of Sudan, where China has major oil interests.
Smith has introduced the Global Online Freedom Act which would prohibit U.S. Internet companies from cooperating with countries such as China that restrict information about human rights and democracy on the Internet.
Wolf and Smith both traveled to Beijing 17 years ago seeking the release of 77 people imprisoned or under house arrest because of their religious activities.
Firefox RC3 fixes Mac bug
(pcpro) -- Mozilla has pushed out a third release candidate for Firefox 3, fixing a bug that could cause crashes and lock-ups in OS X.
The problem was caused by a change that Apple recently made to a browser plugin that Firefox accesses from time to time. Mozilla decided to workaround the problem, though it stresses that Firefox was not itself responsible.
The RC3 release is available from mozilla.com/en-US/firefox/all-rc.html.
Mozilla expects to release the finished Firefox 3 on 17 June.
10 June 2008
FBI Charges Blind Phone Phreak With Intimidating a Verizon Security Official
(wired) -- Less than two months after his celebrating his 18th birthday, a blind, East Boston-based phone hacker has been arrested for paying a Sunday afternoon visit to the Verizon security officer who'd been chasing him.
Matthew Weigman, known on the telephone chat lines as Li'l Hacker, is charged in federal court in Dallas with obstruction of justice and retaliation against a witness, after he was picked up by local police in Amherst, New Hampshire over Memorial Day weekend.
Weigman allegedly persuaded a friend to drive him and his brother 66 miles to the home of William Smith, a Verizon security investigator who'd been monitoring Weigman's hacking and phoning in updates to the FBI. Smith was outside doing yard work when the three men drove up, according to an FBI affidavit. Weigman introduced himself and said he wanted to talk to Smith, who instead went inside and called the police.
While the circumstances are bizarre, Weigman's arrest comes as little surprise. As we reported last February, the FBI has been investigating the hacker since he was 15-years-old, at times courting him as an informant.
Weigman is widely considered one of the best active phone hackers alive. Relying on an ironclad memory and detailed knowledge of the phone system, he uses social engineering to manipulate phone company workers and others into divulging confidential information, and into entering commands into computers and telephone switching equipment on his behalf.
"I've been interested in phones since I've been about 8," Weigman said in an interview last year. "I talked to technicians when they came down here to do things on my phone."
Weigman was a juvenile when the FBI's Dallas office rounded up five party line associates of his who specialized in "swatting" -- a mean hoax in which they used Caller ID spoofing to phone fake hostage crises into police dispatch centers, getting their enemies raided by armed cops. Four members of the swatting gang have been sentenced to prison terms between 30 months and five years. The girlfriend of one member has pleaded guilty to conspiracy charges, and is awaiting sentencing.
The FBI says the group made hundreds of false emergency calls, resulting in at least one injury, and some victims being evicted or fired from their jobs.
Weigman is suspected of gathering information, like unlisted phone numbers, the swatters used to make some calls. He's also suspected of personally making a 2005 swatting call that sent police to the Colorado home of Richard Gasper, a TSA screener whose daughter refused phone sex with Weigman.
Weigman was 15 at the time. When the FBI eventually caught up with him more than a year later, FBI cyber crime agent Allyn Lynd offered to make him a confidential informant. But Lynd called off the deal when AT&T discovered that Weigman was still manipulating the phone company. The agent later told a police detective that Weigman couldn't stop hacking for more than 72 hours.
Those who know Weigman from the party lines agreed, and predicted that turning 18 would not deter the youth from his hacking, despite the risk that he could be charged as an adult. According to a May 22 affidavit by Lynd, they were right.
In April, the month he reached adulthood, Verizon noticed that Weigman had used the name and identifying information of a Texas woman to turn on phone service at the East Boston apartment he shares with his mother and siblings.
When Smith disconnected the fraudulent account, Weigman turned it back on again.
Then Weigman allegedly began making harassing phone calls to Smith at his house. To trick the security worker into picking up the phone, the hacker allegedly social engineered phone company employees into sharing Smith's billing records in near-real time, then used Caller ID spoofing to make Smith think someone was returning his own calls.
"For example, Smith would call a travel agency to arrange for a flight," Lynd writes. "A few minutes later, he would receive a phone call which appeared to be coming from the travel agency that he had just booked a flight through. When Smith answered the phone, Weigman would begin harassing him again."
Smith began complaining about the harassment to Lynd, the FBI agent who busted the swatting crew, and has been investigating Weigman for nearly two years. Smith told the agent that he was worried that Weigman was preparing to send a SWAT team to his house, and that he was warning the local police so "there would be less chance of accidental injury."
Instead, on May 18, Weigman showed up at his house personally.
According to the FBI, Smith believed he was in danger of having more than his phone disconnected. "Smith told me that he felt threatened with physical violence by Weigman, despite Weigman being blind," Lynd wrote, "because Weigman had arrived at Smith's house without invitation, had arrived with two people, include Weigman's brother, who was very large and intimidating, he knew Weigman was blind and must therefore have gone to great lengths to arrange for someone to drive him to Smith's house, that Weigman was not supposed to know where he lived, and that Weigman had arrived in the middle of a Sunday."
When the cops showed up, Weigman allegedly told them that he was visiting Smith because the Verizon officer had been harassing him as part of a "vendetta" against Weigman.
Jeff Daniels, Weigman's longtime hacking mentor, says he doesn't think Weigman planned to hurt anybody. "What's ... a blind kid really going to do? I don't think that they had any kind of malicious intent overtly," he says.
Sean Paul Benton drove the car, and is also charged in the case. Weigman's brother is not charged. Weigman is being held at the Plymouth County Jail in Massachusetts. A bail hearing is set for Tuesday morning. His attorney did not return a phone call Monday.
Daniels says Weigman -- as expected -- did not quit phone hacking when he turned 18. "Even after his birthday he was still doing little silly stuff," he says. "I had pretty much washed my hands. I still love the kid, but I washed my hands of him."
Gpcode gets bigger and better with 1024-bit key
Kaspersky located stronger version of Gpcode -- wants help to crack it. (IMG: J.Anderson)
(thetechherald) -- Kaspersky Lab is reporting on a new version of an old trick. The Gpcode virus, a nasty bit of work that holds files for ransom after it has encrypted them, has gotten an upgrade from its author. The old version used a 660-bit encryption and had a few errors, now after two years in existence, the blackmail virus has better code and an RSA standard 1024-bit encryption key.
To be blunt, if you are infected with this nasty bit of Malware, you are up the proverbial creek without a paddle. Gpcode encrypts files with various extensions including, .doc, .txt, .pdf, .xls, .jpg, .png, .cpp, .h and more using an RSA encryption algorithm with a 1024-bit key. Kaspersky Lab succeeded in thwarting previous variants of Gpcode, when Kaspersky virus researchers were able to crack the private key after in-depth cryptographic analysis. The author of Gpcode has taken two years to improve the virus: the previous errors have been fixed and the key has been lengthened to 1024 bits instead of 660 bits.
“Once the virus has encrypted a user's files, it leaves the following text message along with the files it has encrypted:
Your files are encrypted with RSA-1024 algorithm.
To recovery your files you need to buy our decryptor.
To buy decrypting tool contact us at: ********@yahoo.com»,” Kaspersky says.
Kaspersky is doing research and hopes to get some method of cracking the key and releasing encrypted files, but they need help.
“Along with antivirus companies around the world, we're faced with the task of cracking the RSA 1024-bit key. This is a huge cryptographic challenge. We estimate it would take around 15 million modern computers, running for about a year, to crack such a key. Of course, we don't have that type of computing power at our disposal. This is a case where we need to work together and apply all our collective knowledge and resources to the problem. So we're calling on you: cryptographers, governmental and scientific institutions, antivirus companies, independent researchers…join with us to stop Gpcode. This is a unique project – uniting brain-power and resources out of ethical, rather than theoretical or malicious considerations.”
If you want to help, and try to take on this mammoth task, Kaspersky offers the public keys for your research.
(Taken from: http://www.viruslist.com/en/weblog?calendar=2008-06)
The first is used for encryption in Windows XP and higher.
Key type: RSA KeyExchange
bitlength: 1024
RSA exponent: 00010001
RSA modulus:
c0c21d693223d68fb573c5318982595799d2d295ed37da38be41ac8486ef900a
ee78b4729668fc920ee15fe0b587d1b61894d1ee15f5793c18e2d2c8cc64b053
9e01d088e41e0eafd85055b6f55d232749ef48cfe6fe905011c197e4ac6498c0
e60567819eab1471cfa4f2f4a27e3275b62d4d1bf0c79c66546782b81e93f85d
The second is used for encryption in versions of Windows prior to XP.
Key type: RSA KeyExchange
bitlength: 1024
RSA exponent: 00010001
RSA modulus:
d6046ad6f2773df8dc98b4033a3205f21c44703da73d91631c6523fe73560724
7cc9a5e0f936ed75c75ac7ce5c6ef32fff996e94c01ed301289479d8d7d708b2
c030fb79d225a7e0be2a64e5e46e8336e03e0f6ced482939fc571514b8d7280a
b5f4045106b7a4b7fa6bd586c8d26dafb14b3de71ca521432d6538526f308afb
The RSA exponent for both keys is 0x10001 (65537).
If you can get involved, it will help people sure, but for research alone it would be worth the while to some of you.
09 June 2008
Symantec tool cleans up Windows XP SP3 registry corruption
(infoworld) -- Symantec Thursday released a free tool that wipes spurious entries from Windows' registry that had crippled some PCs running the company's security software after they were upgraded to Windows XP Service Pack 3 (SP3) or Vista SP1.
The tool, SymRegFix, had been promised by Symantec two weeks ago when users reported that upgrading to XP SP3 emptied Windows' Device Manager, deleted network connections and packed the registry with thousands of bogus entries.
Symantec initially blamed Microsoft for the snafu, but later accepted some responsibility. Last week, the company said the combination of a Microsoft process and the SymProtect feature of its Norton-branded consumer security software had added the errant registry entries, and it told users to turn off that feature before upgrading.
SymProtect, designed to protect Symantec's security software from being hacked by malware, guards against unauthorized changes to the registry.
Reese Anschultz, a senior Symantec manager, announced the availability of SymRegFix on a company support forum Thursday.
When some users on that same thread noted that the tool had not deleted all the spurious registry keys, another Symantec employee stepped in. "The other garbage entries may have been created by Microsoft's Fixccs.exe outside of the Symantec registry keys," said Steve Dang.
Earlier, Symantec had identified the Fixccs.exe executable as the Microsoft side of the problem; it had also contended that other security software that monitors registry changes can cause registry pollution, although few incidents have been logged to Microsoft's support forums.
"If you have any other security applications, especially any that monitors/protects the registry, please disable those," said Dang. "Then, open a command prompt and type 'symregfix /override.' This will attempt to delete the garbage registry keys under the entire HKLMSystemCurrentControlSet hive, not just those under the Symantec registry keys."
Symantec has also issued a patch via its LiveUpdate service that prevents the registry corruption from occurring, although users must run LiveUpdate from within their security software, then reboot the PC before attempting an upgrade to Windows XP SP3 or Vista SP1.
That the problem could also affect users updating to Vista SP1 was new information last week; before then, only Windows XP SP3 upgrades had been fingered as causing trouble. In a message posted to the Symantec support forum last Friday, Anschultz downplayed the threat posed to Vista users. "Given how long Vista SP1 has been available relative to the XP SP3 upgrade and the rarity of this issue on Vista, it appears that the FixCCS.exe program doesn't need to 'fix' stuff as often on Vista, but it may on occasion," he said.
Symantec's SymRegFix clean-up tool can be downloaded from the company's site.