Breaking:

Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Friday, July 27, 2012

Virus rocks Iran's Nuke reactors


A new worm targeted Iran’s nuclear program, closing down the “automation network” at the Natanz and Fordo facilities, the Internet security site reported, citing an e-mail it said was sent by a scientist inside Iran’s Atomic Energy Organization.

The virus also prompted several of the computers on site to play the song “Thunderstruck” by AC/DC at full volume in the middle of the night, according to the e-mail, part of which is published in English on the website.
F-Secure Security Labs, which is linked to F-Secure Oyj (FSC1V), the Finnish maker of security and cloud software, said that while it was unable to verify the details of the attack described, it had confirmed that the scientist who reported them was sending and receiving the e-mails from within Iran’s Atomic Energy Organization.
Iran’s nuclear program and oil facilities have been subject to a succession of cyber attacks that the Foreign Ministry said in May were launched by hostile governments as part of a broader “soft war.” Iran accuses the U.S. and Israel of trying to sabotage its technological progress. Both countries say Iran’s nuclear activities may have military intent, an allegation that Iran denies.

E-Mail Exchange

Mikko Hypponen, chief security officer at F-Secure Security Labs and the person involved in the correspondence, said he received three e-mails on July 22 from an individual with an aeoi.org.ir e-mail address, receiving replies after he responded. After researching the person’s name on the internet, Hypponen said he found “plenty of nuclear science papers and articles published by someone with this name.”
“I can’t confirm that the person was who he said he was. And I can’t confirm any of the things he said actually happened,” Hypponen wrote in reply to e-mailed questions. “But I can confirm I was emailing with someone who had access to an aeoi.org.ir address.”
Iran has called on the United Nations to condemn organized cyber attacks against nations, the head of Iran’s Information Technology Organization, Ali Hakim Javadi, said today, according to a report by the state-run news channel Press TV. Significant investment is needed for the creation of malware viruses such as Stuxnet or Flame, which previously targeted Iran, indicating that they were not produced by individuals, the Iranian official said.

High Voltage

AC/DC have played “high voltage rock ’n’ roll” since they were formed in 1973 in Australia, according to the band’s website. Their songs were among the loud music played to detainees at the Guantanamo Bay prison facility in preparation for interrogations, the Associated Press reported in October 2009, citing the National Security Archive in Washington.
An attack where the infected PCs start playing AC/DC isn’t that likely “unless the attacker really wants the victim to know they are hit,” Hypponen said.
F-Secure Security Labs is involved in analyzing viruses, spyware and spam attacks, according to its website.
Source : Here

To contact the reporter on this story: Ladane Nasseri in Dubai at lnasseri@bloomberg.net
To contact the editor responsible for this story: Andrew J. Barden at barden@bloomberg.net.
Read more »

Thursday, May 31, 2012

The Flame Virus:one of the most complex threats ever discovered

A frightening computer virus called Flame is on the loose in Iran and other parts of the Middle East, infecting PCs and stealing sensitive data. Now, the United Nations' International Telecommunications Union warns that other nations face the risk of attack.
But what is Flame, exactly, and is it cause for concern among ordinary PC users? Here's what you need to know about what Kaspersky calls “one of the most complex threats ever discovered.”

Flame Virus: The Basics

Kaspersky describes Flame as a backdoor and a Trojan with worm-like features. The initial point of entry for the virus is unknown -- spearphishing or infected websites are possibilities -- but after the initial infection, the virus can spread through USB sticks or local networks.
Flame is meant to gather information from infected PCs. As Kaspersky's Vitaly Kamlyuk told RT, the virus can sniff out information from input boxes, including passwords hidden by asterisks, record audio from a connected microphone and take screenshots of applications that the virus deems important, such as IM programs. It can also collect information about nearby discoverable Bluetooth devices. The virus then uploads all this information to command and control servers, of which there are about a dozen scattered around the world.
The virus is reminiscent of the Stuxnet worm that wreaked havoc on Iran in 2010, but Kaspersky says Flame is much complex, with its modules occupying more than 20 MB of code. “Consider this: it took us several months to analyze the 500K code of Stuxnet. It will probably take year to fully understand the 20MB of code of Flame,” the firm said.

What Are Flame's Origins?

The Flame Virus: Your FAQs AnsweredFlame has been in the wild since 2010, according to Kaspersky, but its creation date is unclear. The virus was discovered a month ago after Iran's oil ministry learned that several companies' servers had been attacked. That finding led to more evidence of attacks on other government ministries and industries in Iran.
Iran has claimed that the attacks also wiped the hard drives of some machines, but Kaspersky claims that the malware responsible, called Wiper, isn't necessarily related. Wiper attacks were isolated to Iran, while Flame has been found in other countries.
Flame's creator is also unknown, but a nation-state was likely behind it. The virus is not designed to steal money from bank accounts, and is much more complex than anything commonly used by “hacktivists,” so a nation-created virus is the only other possibility that makes sense.

Who is at Risk?

The United Nations' International Telecommunications Union is now warning other nations to “be on alert” for the virus, which could potentially be used to attack critical infrastructure. In a statement to Reuters, the U.S. Department of Homeland Security said it was “notified of the malware and has been working with our federal partners to determine and analyze its potential impact on the U.S.”
Security firms have not been warning of any direct risk to average Internet users. Sophos' Graham Cluley noted that Flame has only been discovered in a few hundred computers. “Certainly, it's pretty insignificant when you compare it to the 600,000 Mac computers which were infected by the Flashback malware earlier this year,” Cluley wrote in a blog post.

Friday, June 17, 2011

Lulz Security Takes FBI Partner In Atlanta

You must have heard of Lulz Security by now. Lulz Security is the team of hackers responsible for some of the PSN hacks, the X-Factor hack, PBS, several hacks of Sony Entertainment and now they’ve turned to an FBI partner company based in Atlanta.
InfraGard Atlanta is described by Yahoo London as  a “public-private partnership devoted to sharing information about threats to the U.S. physical and Internet infrastructure”. Wait a second did they say that InfrafGard shares information about threats against the US Internet infrastructure? And they got hacked by Lulz Security?
That’s right, according to sources Lulz Security obtained email addresses, passwords and some identifying information about over 180 members of the InfraGard organization. They were also able to use the information gained from the InfraGard hack to steal nearly 1000 work and personal emails from the Chief Executive at Delaware based Unveillance LLC.
It’s a little disconcerting to find that an organization like Lulz Security is able to hack the FBI partner used to help prevent this kind of thing from happening.  What makes it even worse is that Lulz Security has indicated that all of their hacks to this point have been relatively easy.
Nintendo was able to thwart an attack from Lulz security.  According to Nintendo Lulz Security hacked into their site but walked away empty handed.  Sony on the other hand hasn’t had that much luck these days in terms of security.  Their PSN network has been hacked several times with millions of customer data, including credit card numbers, stolen.  Sony BMG, Sony Music and Sony Pictures all had internal email addresses and passwords stolen along with coupon codes from a hack of their Belgium and Netherlands websites.
Source: Yahoo

Thursday, September 16, 2010

Staying secure when using Wi-Fi hotspots


Like many of your loyal readers, I frequently use public Wi-Fi places like coffee shops. I would appreciate some tips on how to improve my computer's security under this circumstance.

Dr David Null

Wi-Fi hotspots are often unprotected and unencrypted, with users doing their email and surfing the web in plain text. Anyone nearby can pick up the same radio signals and read them. Often this doesn't matter, but in general, it's best to avoid using public networks for banking and shopping. Note that sharing a public network can also provide access to your PC, so you must run a firewall and perhaps disable file and printer sharing in Windows. In Windows 7 and Vista, you can choose the park bench icon for an untrusted Public Network and not a Home or Work network. Microsoft has an advice page, 7 tips for working securely from wireless hotspots, with other details.
Some web pages, such as log-on pages, need better security, and these often use SSL (Secure Sockets Layer) connections. You can tell when you're using SSL because the page address starts with https:// instead of http://, and the browser will show a lock icon in the bottom right-hand corner. However, some sites that use SSL to protect log-in details then switch to plain text for normal surfing.

Monday, May 3, 2010

Some Numbers About Md5 !!



MD5 (Message Digest 5) est une fonction de hachage cryptographique qui calcule, à partir d'un fichier numérique, son empreinte numérique (en l'occurrence une séquence de 128 bits ou 32 caractères en notation hexadécimale) avec une probabilité très forte que deux fichiers différents donnent deux empreintes différentes.


On cherche a calculer les probabilites de 3 caracteres (a , b et c)


a b c
aa bb cc ab ac ba bc ca cb
aaa aab aac aba abb abc aca acb acc baa bab bac bba bbb bbc bca bcb bcc caa cab cac cba cbb cbc cca ccb ccc


Donc :


3 ^ 1=3
3 ^ 2=9
3 ^ 3=27


3 ^ 3 + 3 ^ 2 + 3 ^ 1=3 + 9 + 27 = 39


x ^ x + x ^ x-1 + .... + x ^ 1


Maintenant On cherche a Calculer les Probabilites de 70 caracteres !!!!!!!!!!!!!


qwertyuioplkjhgfdsazxcvnmQWERTYUIOPLKJHGFDSAZXCVBNM1234567890()!.<>/\



70 ^ 1 = 70 Je crois pas que qu'un admin met un 1 char comme pwd
70 ^ 2 = 4 900 .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .
70 ^ 3 = 343 000 Peut etre 10 %
70 ^ 4 = 24 010 000 Peut etre 20 %
70 ^ 5 = 1 680 700 000 Peut etre 30 %
70 ^ 6 = 117 649 000 000 Peut etre 40 %
. ^ .
. ^ .
. ^ .
70 ^ 70=1,4350360160986843428560307635667e+129 c'est plus que 20 milles :XD


On peut calculer 3 + 9 + 27 Mais c dommage on peut pas lire ce chiffre 1,4350360160986843428560307635667e+129

 

follow us on facebook

Social Profiles