.com INR-2

Thursday, June 23, 2011

Anonymous Denies Hacking Sony, Stealing Credit Cards

The hacking group Anonymous has denied responsibility for the attack on Sony's networks, claiming that it has "never...engaged in credit card theft."

Computerworld— The hacking group Anonymous has denied responsibility for the attack on Sony's networks, claiming that it has "never...engaged in credit card theft."
In a long statement posted to the Daily KOS site, the group said others were trying to frame it for the hack of Sony's PlayStation and Online Entertainment networks.
"Whoever broke into Sony's servers to steal the credit card info and left a document blaming Anonymous clearly wanted Anonymous to be blamed for the most significant digital theft in history," said Anonymous. "No one who is actually associated with our movement would do something that would prompt a massive law enforcement response."
Although Sony declined to testify yesterday before a House subcommittee investigating data breaches, in its written response Tuesday to questions ( download PDF ) the company said Anonymous was at least partially responsible for the hacks because it had conducted denial-of-service (DoS) attacks against Sony in the weeks prior to the credit card hack.
"Whether those who participated in the in the denial of services attacks were conspirators or whether they were simply duped into providing cover for a very clever thief, we may never know," said Sony. "In any case, those who participated in the denial of service attacks should understand that -- whether they knew it or not -- they were aiding in a well planned, well executed, large-scale that that left not only Sony a victim, but also Sony's many customers around the world."
Sony also said the credit card hackers had left a file named "Anonymous" on one of its servers. The file contained the words "We are legion," a trademark phrase of the group.
"Anonymous has never been known to have engaged in credit card theft," the group countered Wednesday.
Tuesday's accusations that Anonymous may have been involved was a reversal for Sony.
In a Tokyo press conference Monday, Kaz Hirai, CEO of Sony's games subsidiary, said the company had not found find any link between Anonymous and the newest attacks.
Anonymous had denied responsibility for the Sony network breaches before. On April 22, it issued a statement titled, "For Once We Didn't Do It" that argued "Sony is taking advantage of Anonymous' previous ill-will toward the company to distract users from the fact that the [PlayStation Network] outage is actually an internal problem with the company's servers."
The group had taken credit for the DoS attacks against Sony two weeks before the April breach. Those attacks were launched as a protest of Sony's legal pursuit of George Hotz, who had hacked the PlayStation 3 to run Linux OS.


Hotz, who settled with Sony, has also said he had nothing to do with the network attacks.
"I'm not crazy, and would prefer to not have the FBI knocking on my door," Hotz said in an April 28 blog post . "Hacking into someone else's server and stealing databases of user info is not cool. You make the hacking community look bad, even if it is aimed at douches like Sony."
But Hotz also said Sony had essentially reaped the whirlwind.
"The fault lies with the executives who declared a war on hackers, laughed at the idea of people penetrating the fortress that once was Sony, whined incessantly about piracy, and kept hiring more lawyers when they really needed to hire good security experts," said Hotz. "Alienating the hacker community is not a good idea."
It would obviously be in Anonymous' interest to deny responsibility for the credit card theft. Sony contacted the Federal Bureau of Investigation (FBI) three days after it discovered the intrusion, and five days later met with the agency to provide details of the attack.
The FBI, along with law enforcement authorities in other countries, have been pursuing Anonymous since last year, when the group targeted a large number of Web sites -- including those for Amazon, PayPal, MasterCard and Visa -- for withdrawing services from Wikileaks , the document leaking organization that began publishing U.S. diplomatic cables in November 2010.
In December 2010 and January 2011, the FBI seized hardware from several U.S. Internet service providers, then executed dozens of search warrants in its search for Anonymous.
Sony took its PlayStation Network offline on April 20. As of today, that network, as well as the Online Entertainment network, was not operational.
The company told Congress on Tuesday that it had not identified the people who broke into its servers and lifted the personal information -- and possibly credit card numbers, as well -- of millions of customers.

Internet hit by wave of Fake PC 'defrag' tools

A spate of scareware apps that trick users into buying useless hard disk repair tools appears to be part of a concerted campaign to push fake 'defrag' software, a security company has said.
The Internet abounds with Windows utilities, usually free, some not very good. Users have an unquenchable appetite for them.
According to a GFI-Sunbelt Security blog, a new type of bogus disk software has suddenly become very common on the back of this, with a clutch of convincing examples appearing in recent weeks.
Users encountering new examples HDDRepair, HDDRescue and HDDPlus should ignore them. They are bogus applications that claim to defragment a user's hard disk even though such a requirement is barely needed given that Windows does a lot of this work behind the scenes anyway.
The apps will, however, claim that a user's hard disk is riddled with problems, as will the slightly older examples UltraDefragger, ScanDisk, Defrag Express and WinHDD. Sorting out the non-existent issue can cost anything from $20 and up.
Such apps have been around for some time in fact but have simply been less documented compared to the fake antivirus programs that have caused chaos on the Internet in the last two years.
The phenomenon of fake software is now deeply entrenched on the Internet and criminals have even taken to aping the way security companies are creating all-purpose security programs. Fake apps adopting this verisimilitude tactic include PCoptomizer, PCprotection Center and Privacy Corrector.
A quick trawl of Google reveals that all of the above scareware examples are easy to encounter. So how does a user tell the real and useful from the fake and expensive?
Depending on the type of app, it is sometimes easier to consult lists of real apps that worry about working out which ones aren't genuine.
As the author points out, the overworked Virus Total is one site that allows files and URLs to be checked against known rogue lists, while certification company ICSA Labs publishes a separate, more high-level list of known vendors. These are not perfect warning systems however. Rogue URLs change constantly and might not be spotted by Virus Total, for instance.

Security researchers split on whether 'ComodoHacker' is the real deal

Security researchers split on whether 'ComodoHacker' is the real deal

Computerworld - A solo Iranian hacker on Saturday claimed responsibility for stealing multiple SSL certificates belonging to some of the Web's biggest sites, including Google, Microsoft, Skype and Yahoo.
Early reaction from security experts was mixed, with some believing the hacker's claim, while others were dubious.
Last week, conjecture had focused on a state-sponsored attack, perhaps funded or conducted by the Iranian government, that hacked a certificate reseller affiliated with U.S.-based Comodo.
On March 23, Comodo acknowledged the attack, saying that eight days earlier, hackers had obtained nine bogus certificates for the log-on sites of Microsoft's Hotmail, Google's Gmail, the Internet phone and chat service Skype and Yahoo Mail. A certificate for Mozilla's Firefox add-on site was also acquired.
SSL certificates validate the legitimacy of a Web site to the browser, assuring users that they're connecting to the real site, and that the traffic between their browsers and the site is encrypted.
Comodo CEO Melih Abdulhayoglu said last week that circumstantial evidence pointed to a state-backed attack, and claimed the Iranian government was probably behind it. "We believe these are politically motivated, state driven/funded attacks," said Abdulhayoglu.
He based his opinion on the fact that only Iran's government -- which could jigger the country's DNS (domain name system) to funnel traffic through fake sites secured by the stolen certificates -- would benefit.
In Abdulhayoglu's analysis, authorities could have used the certificates to dupe anti-government activists into believing they were at a legitimate Yahoo Mail, for example. In reality, however, the phony sites would have collected users' usernames and passwords, and thus given the government access to their e-mail or Skype accounts.
On Sunday, a single hacker took responsibility for the Comodo attack, backing up his claim with decompiled code.
"I'm not a group of hacker [sic], I'm single hacker with experience of 1,000 hackers," wrote the attacker in a post on Pastebin.com late Saturday. He called himself "ComodoHacker" and said he's 21 years old.
ComodoHacker alleged that he had gained full access to InstantSSL.it, the Italian arm of Comodo's InstantSLL certificate selling service, then decompiled a DLL file he found on its server to uncover the reseller account's username and password.
With the username and password in hand, said ComodoHacker, he was able to generate the nine certificates, "all in about 10-15 minutes." His message was signed "Janam Fadaye Rahbar," which reportedly means "I will sacrifice my soul for my leader."
The InstantSLL.it Web site is currently offline.
Robert Graham, the CEO of Errata Security, believes ComodoHacker is telling a straight story.
"As a pentester who does attacks similar to what the ComodoHacker did, I find it credible," Graham said Sunday on the Errata blog. "I find it probable that (1) this is the guy, (2) he acted alone, (3) he is Iranian, (4) he's patriotic but not political."
But Mikko Hypponen, the chief research officer of Helsinki-based F-Secure, sounded skeptical.
"Do we really believe that a lone hacker gets into a [certificate authority], can generate any cert he wants...and goes after login.live.com instead of paypal.com?" asked Hypponen on Twitter.
Graham had an answer for Hypponen's question.
"[Comodo Hacker] started with one goal, that of factoring RSA keys, and ended up reaching a related goal, forging certificates," said Graham. "He didn't think of PayPal because he wasn't trying to do anything at all with the forged certificates."
ComodoHacker also lit into the West -- Western media in particular -- for quickly concluding that the Iranian government was involved when it had downplayed possible U.S. and Israeli connections to Stuxnet, the worm that most experts believe was aimed at Iran's nuclear program.
He also threatened to unleash his skills against those he said were enemies of Iran.
"Anyone inside Iran with problems, from fake Green Movement to all MKO members and two-faced terrorists, should [be] afraid of me personally," said ComodoHacker. "I won't let anyone inside Iran, harm people of Iran, harm my country's Nuclear Scientists, harm my Leader (which nobody can), harm my President."
MKO, or the "People's Mujahedin of Iran," is an Islamic group that advocates the overthrow of the current government of Iran.
"As I live, you don't have privacy in internet, you don't have security in digital world, just wait and see," ComodoHacker said.
Comodo was not available Sunday for comment on ComodoHacker's claims.