Hazel Heart Interview| Author | Post |
|---|---|
| Goldstein All-Star Member "You have sacrificed nothing and no one." 3689 Posts 8/10 | [ invalid url ] on Pastebin, a sort of Internet bulletin board, of how he had penetrated the system of the Dutch firm and why, along with his e-mail address. He has also boasted of his own skills, calling his work the “most sophisticated hack of all time,” and at one point exclaiming: “I’m really sharp, powerful, dangerous and smart!” Mikko Hypponen, a security researcher with F-Secure Labs of Helsinki, said the hacker was “somebody who has skills, and he also has the old-school hacker mentality where he likes to boast.” Mr. Hypponen added: “If he were an intelligence analyst for the secret police he wouldn’t be doing this.” Asked whether he was paid for his services, the hacker replied in broken English: “I don’t fight for my belief for award in this world.” The e-mail he sent appears to have come from a computer in Russia, according to an independent security analyst who reviewed it. Comodohacker has either remotely taken control of someone’s computer in Russia, or he may not be an Iranian software engineer at all. [Link] |
| RandomPrecision Senior Member Enjoy! 8175 Posts 3/06 | |
| Goldstein All-Star Member "You have sacrificed nothing and no one." 3689 Posts 8/10 | Could DigiNotar Hack Lead to a Cyberattack on You? By Jeremy A. Kaplan Published September 06, 2011 Hackers colluding with the Iranian government to spy on democratic activists may have made it easier for cybercrooks to spy on you, a security expert told FoxNews.com. The Dutch government over the weekend seized control of DigiNotar -- which sells "SSL" security certificates that act as a handshake guaranteeing online transactions -- saying certificates it had issued were forged and could no longer be relied on. The hack targeted Iranian activists, but you might be a victim too, warned Ira Victor, director of the digital forensics practice with Data Clone Labs and a member of the High Technology Crime Investigation Association (HTCIA) "Millions of websites use SSL to protect their user's information -- that's why the SSL digital certificates are such a tempting target for cybercriminals," Victor told FoxNews.com. The forgeries were used almost exclusively in Iran for political reasons, mainly to spy on Iranian citizens, according to a recent review by IT firm Fox-IT and experts at security firm Kaspersky Labs. But individuals worldwide might end up in the crosshairs anyway, Victor warned. "The [hacker] appears to be politically motivated, but that doesn't prevent him from cashing in on SSL certificates for his own profit, directly, or indirectly, and to use those funds for his political goals," he said, noting that "just about every digital asset is for sale in the digital black market." Experts say most major Internet communications companies had already used the phony forms; fake Google certificates had been used by 300,000 IP addresses, for example, as well as Skype, Microsoft, Facebook and more. SSL digital certificates govern the basic security of all Internet transactions: Log onto a web browser or an email account and you'll often end up sending data that relies on one. With access to that certificate, a cybercrook could snoop the bits and bytes of what should be a secure transaction. It's called a "man in the middle" assault -- and it's anything but common, scoffed Anup Ghosh, chief scientist with security company Invincea. "Most hackers never resort to this," he told FoxNews.com. "If I want to capture your email, your online transactions, I don't need to forge a certificate. I can just compromise your machine." Use of a certificate would require massive rerouting of Internet traffic, Ghosh said -- the sort of thing you'd do to snoop on Iran, not the average citizen. "The only way for you to employ a forged certificate is if you can reroute my request to your server. You'd have to hack infrastructure," he said. That hasn't stopped Microsoft from issuing updates to the Internet Explorer web browser on Windows 7 and Windows Vista, which you can install by running Windows Update. Late Tuesday the company issued an emergency patch for Windows XP as well. Google and Mozilla, maker of the Firefox browser, have also issued updates to their software. Apple has made no official statements about plans to issue a patch for the Safari browser. Victor warns not to wait. "For Apple, iPhone and iPad users, download the Opera browser. They'll be faster to issue a fix for this than Safari. And it's free," he told FoxNews.com. DigiNotar, a subsidiary of Chicago-based Vasco Inc., acknowledged it had been hacked on Aug. 30 only after Google stated that fake certificates for Google sites were circulating in Iran. Google marked the company's certificates as dubious, and other web browser makers followed suit. The hack underscores the increasing importance of what had been an obscure part of computing: digital certificates, which enable nearly all secure transactions online and are a crucial tent pole propping up not just Internet transactions but much of modern business. "Digital certificates were created by the guys at Netscape. It was never envisioned to scale up for payroll data … we're pushing the envelope of what these things can do," Victor advised. "Businesses that are relying on these certificates -- which is just about everybody today -- need to be better prepared," he told FoxNews.com -- one thing he and Gosh can agree upon. The underpinnings of web security that we take for granted … the people that provide those services are just as susceptible as anyone else, Gosh said. "Like planning for a hurricane, you can't wait until the water comes rushing in," Victor said. |
| Goldstein All-Star Member "You have sacrificed nothing and no one." 3689 Posts 8/10 | September 20th, 2011, 12:22 GMT · By Marius Oiaga Microsoft has re-released an update for Windows XP SP3 and Windows Server 2003 designed to revoke the trust of all DigiNotar root certificates. It appears that there were a range of issues with the original KB 2616676, which placed only certain DigiNotar certificates in the Microsoft Untrusted Certificate Store, while still leaving users exposed to potential attacks leveraging others. This is why the Redmond company is now providing a brand new KB 2616676 update, designed to resolve the problems with the initial release. The software company stresses that the refresh only impacts XP and Windows Server 2003. "Microsoft re-released KB2616676 non-security update for customers using Microsoft Windows XP and Windows Server 2003," reveals Dave Forstrom, director, Trustworthy Computing. "Customers who have enabled automatic updates are already protected and no further action is required, and others are recommended to download the cumulative version of the KB2616676 to protect themselves from the fraudulent certificates listed in Security Advisory 2607712." It appears that the original release of KB 2616676 failed to revoke trust for fraudulent digital certificates included into a couple of other updates 2607712 and 2524375. "Before September 19, 2011, the versions of update 2616676 for Windows XP and for Windows Server 2003 contained only the latest six digital certificates cross-signed by GTE and Entrust. These versions of the update did not contain the digital certificates that were included in update 2607712 or 2524375," Microsoft explained. "Update 2616676 also incorrectly proceeded update 2607712. Therefore, before September 19, 2011 if you installed updated 2616676 and had not already installed update 2607712 or update 2524375, your system would not have been protected from the use of fraudulent digital certificates as described in security advisory 2607712." The version of KB2616676 for Windows XP and Windows Server 2003 that users need to make sure they deploy is the one released on September 19, 2011. This refresh is cumulative and covers all the certificates revoked in updates 2524375, 2607712, and the initial 2616676. See the original linked-to article for necessary URL links, if you need them. |
| Goldstein All-Star Member "You have sacrificed nothing and no one." 3689 Posts 8/10 | by Steve Ragan - Sep 20 2011, 12:55 DigiNotar, the Dutch Certificate Authority (CA) that suffered a massive security breach, resulting in nearly 300,000 Iranians being compromised, has filed for bankruptcy. The voluntary petition was granted on Tuesday by a court in The Netherlands. DigiNotar filed for bankruptcy on Monday, less than 24-hours later the petition was approved. In a statement, DigiNotar’s parent company, Vasco, distanced itself from the security breach, promising to cooperate with the Dutch government during the bankruptcy proceedings. "Although we are saddened by this action and the circumstances that necessitated it," said T. Kendall Hunt, VASCO’s Chairman and CEO. "…we plan to cooperate with the Trustee and the Judge to the fullest extent reasonably practicable to bring the affairs of DigiNotar to an appropriate conclusion for its employees and customers. We also plan to cooperate with the Dutch government in its investigation of the person or persons responsible for the attack on DigiNotar." In total, 531 fraudulent certificates were issued during the DigiNotar breach, including certificates for Google, Microsoft, MI6, the CIA, TOR, Mossad, Skype, Twitter, Facebook, Thawte, VeriSign, and Comodo. A security report compiled by Fox-IT, who is investigating the breach, outlined several instances of lackluster security on DigiNotar's network, and noted that some 300,000 Iranians were exposed in the incident. "We found that the hackers were active for a longer period of time. They used both known hacker tools as well as software and scripts developed specifically for this task," the report noted. "The network has been severely breached. All CA servers were members of one Windows domain, which made it possible to access them all using one obtained user/password combination. The password was not very strong (Pr0d@dm1n) and could easily be brute-forced. The software installed on the public web servers was outdated and not patched. No antivirus protection was present on the investigated servers..." Despite the breach of trust, Vasco says they will return to CA business in the future. "We want to emphasize that the bankruptcy filing by DigiNotar, which was primarily a certificate authority, does not involve Vasco's core two-factor authentication business," said Jan Valcke, Vasco's COO. "While we do not plan to re-enter the certificate authority business in the near future, we expect that we will be able to integrate the PKI/identity verification technology acquired from DigiNotar into our core authentication platform." It is unknown if said PKI/identity verification technology was also compromised during the breach, though it is assumed that it wasn't by many following the situation. After the breach made headlines, Microsoft, Mozilla, and Google revoked DigiNotar's trusted status, pulling their root certificates from all of their products. "The CA business is all about selling trust. After all, a CA is supposed to be a trusted third party. Let's hope all the remaining ones get the right message: it's not about not getting caught being hacked," commented Swa Frantzen, of Section 66 -- a security services firm in Belgium. On the contrary, it's about doing the right thing once you have been hacked. Let's hope it leads to more transparency and public scrutiny of the CAs we trust explicitly or implicitly though the choice of some of our vendors." |
| Use the code below to link to this topic or a specific post. |
| URL of this thread |
| Link to this post with HTML |
| Link to this post with Forum Code |