Posts

Military systems not immune to malware

News of the Conficker/Downadup worm rumble on. Britain's Daily Telegraph is relaying news from a French newspaper that a French naval network was infected, disrupting communications and hence military opertions as the network was isolated for disinfection. The same piece reports that a "report in the military review Defense Tech revealed that in the first days of January 2009 the British Defence Ministry had been attacked by a hybrid of the virus that had substantially and seriously infected the computer systems of more than 24 RAF bases and 75 per cent of the Royal Navy fleet including the aircraft carrier Ark Royal." While the journalists and military PR people are typically at pains to point out that such events affect only unclassified or lowly-classified networks, the impacts sometimes appear to indicate otherwise - unless that is the French navy is in the habit of passing military orders over unclassified networks, which I doubt. The reality of modern...

Alleged Fannie Mae logic bomber denies charges

Reuters says : "A 35-year-old computer programer pleaded not guilty on Friday to charges that he planted a computer virus designed to destroy all the data on 4,000 Fannie Mae computer servers the day he was fired from the company ..." While we read about logic bombs in security textbooks, real world examples are relatively few and far between, in other words the probability of attack is quite low. The impacts could be significant, although in practice most attacks we read about have been thwarted while a proportion of successful attacks are likely either to be misdiagnosed as bugs, viruses, outsider attacks etc . or covered up by embarrassed managers. As so often when assessing information security risks, the true scale of the insider threat can only be surmised from imperfect data and hence contingency planning is sensible in case we miscalculate. Disgruntled technically-competent insiders, usually IT professionals, get the blame for logic bombings. Logic bombs are but on...

Botnets to watch in 2009

A news item about botnets from Secureworks includes some useful information about how botnets are used and protected. They are used to distribute spam (including money mule come-ons, fake pharmaceuticals, enlargement products, loans and more) and malware. The estimated sizes of the botnets range up to about 175,000 compromised machines, with most being a few tens of thousands, well short of the millions that lurid mainstream news headlines sometimes claim. Still tens of thousands of broadband connected computers can do a lot of damage.

Website content integrity failure

While researching for our next awareness module on SCADA security, I came across the Omron PLC website and couldn't help laughing when I read their news items. They haven't been well translated from the original - at least I doubt anyone would seriously have meant to write "The reverend converts the broadcasting waves echolike backwards from the RFID attach into digital aggregation that crapper then be passed on to computers that crapper attain ingest of it.". Let's hope we make more sense of SCADA security in our awareness briefings!

Malwareness

Hi there! We've just released an updated, refreshed and extended awareness module on malware, one of those enduring "core topics" that we have covered several times in the six years or so since we launched our awareness service, and yet the threat is subtly different every year. As with the previous awareness topic, hacking, the most noticeable change lately has been the increasing use of malware for criminal purposes such as identity theft, spamming and industrial espionage. The days of viruses displaying funny graphics and playing silly tunes are long gone. It’s become much more serious, both for individuals and for organizations on the receiving end. Malware authors are constantly exploring different modes of infection, creating new payloads and inventing novel criminal activities. Some malware modifies its own code in order to try to escape detection by pattern-matching antivirus software, or picks up new component parts through the Internet as the in...

"I like to learn something new, to travel, walk on a nature"

Image
I can't resist re-posting this hilarious 419 scam fresh from my inbox, allegedly from innocent Natalya pictured above from the JPG attached to "her" email - I say "her" because the sender was listed as Frederick somebody, hardly a common ladies' name where I come from! Hi! I ask you to read this letter, it will not borrow a lot of your time. This letter not advertising, but this letter from usual Russian woman which wishes to meet the man of she dream... My name is Natalya. I'm 28 years old. My friends speak, that I - very cheerful and sociable woman and I have good sense of humour. I like to learn something new, to travel, walk on a nature. But unfortunately, I did not manage to meet the man to which I could trust, be very close with him and love him. At my age it is time to me to reflect on family, children. But all men whom I met, did not concern to this seriously. Therefore I have decided to try to find the man in other country. I have addressed in...

Hacker desperate to avoid extradition to the US

Hacker Gary McKinnon has to date successfully avoided extradition to the US to face up to his hacking of US military systems in 2001/2002. He continues to make full use of the British and European legal systems, his latest exploit involving allegedly admitting to an offense under the UK Computer Misuse Act in an apparent attempt to be incarcerated at Her Majesty's pleasure rather than, perhaps, end up languishing in an orange jump suit in Cuba. Admitting to the CMA offense is surely a desperate measure since it is hardly likely to improve his defense if he ever stands before the US courts. This is all an object lesson in the perils of hacking Uncle Sam's. It could literally be a life-changing experience.