Showing posts with label hackers. Show all posts
Showing posts with label hackers. Show all posts

Thursday, March 21, 2013

NASA steps up security. Blocks access by Chinese to stop Data Loss

NASA has shut down access to an online database and banned new requests from Chinese and some other foreign nationals seeking access to its facilities amid mounting concerns about espionage and export control violations, the U.S. space agency's administrator said on Wednesday.

The security measures include a complete ban on remote computer access by Chinese and some other non-U.S. contractors already working at NASA centers, agency chief Charles Bolden said at a congressional oversight hearing in Washington.

The tightening of security follows the arrest on Saturday of Chinese national Bo Jiang, a former NASA contractor.

He was attempting to return to China with "a large amount of information technology that he may not have been entitled to possess," said Representative Frank Wolf, a Republican whose Virginia district includes the NASA Langley Research Center, where Jiang worked.

The FBI arrested Jiang at Dulles International Airport outside Washington, where he had boarded a flight to Beijing, court papers provided by Wolf's office show.

Jiang was arraigned on Monday in U.S. district court in Norfolk, Virginia. A detention hearing is scheduled for Thursday.

He is charged with lying to federal law enforcement agents about computer hardware he planned to take with him to China, the court documents show.

Wolf, who chairs the House Appropriations subcommittee on commerce, justice and science, identified Jiang last week during another hearing on possible security lapses at NASA field centers.

"We know that China is an active, aggressive espionage threat," Wolf, a longtime China critic, said during Wednesday's hearing.

"A recent White House report said that the technologies NASA works on - aerospace and aeronautics - are those that the Chinese have most heavily targeted," Wolf added.

NASA is cooperating with federal investigators, in addition to conducting two internal reviews, Bolden said.

The reviews are expected to be completed within a week, likely to be followed by an external investigation, Bolden added.

In the interim, NASA closed its Technical Reports database "while we review whether there is a risk of export control documents being made available on this website," Bolden said.

Other security upgrades include a moratorium on granting any new access to NASA facilities for individuals from China, Myanmar, Eritrea, Iran, North Korea, Saudi Arabia, Sudan and Uzbekistan.

In addition, 281 foreign nationals, including 192 from China, who currently have access to NASA facilities have had their remote computer access shut down, Bolden said.

"This is about national security, not about NASA security, and I take that personally. I'm responsible and I will hold myself accountable once those reviews are completed," Bolden said.

Saturday, March 3, 2012

NASA successfully hacked 13 times last year

According to a US Government paper, NASA said hackers stole employee credentials and gained access to mission-critical projects last year in 13 major network breaches that could compromise U.S. national security.

National Aeronautics and Space Administration Inspector General Paul Martin testified before Congress this week on the breaches, which appear to be among the more significant in a string of security problems for federal agencies.

The space agency discovered in November that hackers working through an Internet Protocol address in China broke into the -network of NASA's Jet Propulsion Laboratory, Martin said in testimony released on Wednesday.

One of NASA's key labs, JPL manages 23 spacecraft conducting active space missions, including missions to Jupiter, Mars and Saturn.

The hackers gained full system access, which allowed them to modify, copy, or delete sensitive files, create new user accounts and upload hacking tools to steal user credentials and compromise other NASA systems. They were also able to modify system logs to conceal their actions.

"Our review disclosed that the intruders had compromised the accounts of the most privileged JPL users, giving the intruders access to most of JPL's networks," he said.

In another attack last year, intruders stole credentials for accessing NASA systems from more than 150 employees. Martin said the his office identified thousands of computer security lapses at the agency in 2010 and 2011.

He also said NASA has moved too slowly to encrypt or scramble the data on its laptop computers to protect information from falling into the wrong hands.

Unencrypted notebook computers that have been lost or stolen include ones containing codes for controlling the International Space Station, as well as sensitive data on NASA's Constellation and Orion programs, Martin said.

A NASA spokesman told Reuters on Friday the agency was implementing recommendations made by the Inspector General's Office.

"NASA takes the issue of IT security very seriously, and at no point in time have operations of the International Space Station been in jeopardy due to a data breach," said NASA spokesman Michael Cabbagehe.

Monday, June 20, 2011

Small security system keeps hackers away from your implant

MIT and UMass scientists have designed a transmitter that jams wireless signals sent to medical implants by unauthorized users.

Pacemakers, drug pumps, defibrillators… they all have wireless connections that allow doctors to monitor vital signs or revise treatments. But this also leaves them vulnerable to attack.

A hacker could, conceivably, kill someone by instructing the implant to deliver lethal doses of drugs or electricity.

No such attacks have been documented… but with millions of Americans carrying implantable medical devices (IMDs) in them, and about 300,000 people getting new ones every year around the world, it’s really not a system you want compromised.

So, researchers created a system that has a second transmitter to jam unauthorized signals directly eavesdropping in an implant’s operating frequency. And it only allows authorized users to communicate with it (diagrammed above).

A doctor-sanctioned device, which has access to the implant, would send encrypted instructions to the second transmitter, which then decodes and relays them.

They call this jamming transmitter, the “shield.” And it’s small enough to wear as a necklace or watch.

A few years ago, a team led by Kevin Fu of the University of Massachusetts, Amherst demonstrated they could overhear defibrillators’ signals, learning things like patient names and diagnoses.

So they started experimenting with implantable defibrillators obtained secondhand from Boston-area hospitals, and programmable off-the-shelf radio transmitters simulated the shield.
  •  Without the shield, defibrillators obeyed commands from transmitters more than 40 feet away.
  • With the shield, potential harm-doers as close as 8 inches couldn’t control or listen in on the devices.
The shield, and not the implant, would handle the encryption and authentication. “It’s hard to put [encryption] on these devices,” says project researcher Dina Katabi of MIT. “There are many of these devices that are really small, so for power reasons, for form-factor reasons, it might not make sense to put the [encryption] on them.”

Some other smart things about having an external shield:
  • It would work with existing implantable devices.
  • It’ll be easier to upgrade or replace without surgery.
  • For emergency medical providers who need to communicate with an incapacitated patient’s implant, having to retrieve an encryption key could cause fatal delays. Whereas with this new security system, an emergency responder could just remove the shield.
The key is a new technique that allows the shield to simultaneously send and receive signals in the same frequency band. With ordinary wireless technology, the transmitted signal interferes with the received signal, making it unintelligible.

“Think of the jamming signal that we are creating as a secret key,” Katabi explains. “Everyone who doesn’t know the secret key just sees a garbage signal.” Because the shield knows the shape of its own jamming signal, however, it can, in effect, subtract it from the received signal.

The team will present the system [pdf] at the Association for Computing Machinery’s upcoming SIGCOMM conference in Toronto this August.

Via MIT News.

Sunday, August 9, 2009

White Hats versus the Black Hats: Virtual Army takes on Conficker Worm and the Evil Botnets

"So we meet again in Cyberspace! Only this time I have the evil Conficker worms to do my bidding! "

Unfortunately, it's not another dubious plot in a Bond movie, its' real life in the virtual world of Cyberspace.

More than 1 million 'super-hero' virtual computers are set to provide insight into how the evil 'super-villain' botnets, networks of infected computers wreak havoc on the internet.

The Conficker worm is currently the most infamous and notorious of these. Much has been written about the damage it has done recently and much time nd effort is going into counter-measures.

Ron Minnich and Don Rudish of Sandia National Laboratories in Livermore, California, crammed 250 independent linux "kernels" - the core system of a computer - onto each of 4400 networked Thunderbird machines, creating a total of over 1.1 million individual virtual computers.

While this network cannot mimic the internet's estimated 600 million computers, the duo hope to use it to study how a small number of machines can attack and bring down larger networks. They can also study, for example, why some botnets prefer to be small and others large.

A good anti-Malware application will detect a high percentage of botnets but not the very smart ones. The most insidious of the botnets are the ones that use stealth to infect and remain resident and undetected on a "victim's" system. Good Luck guys!

Monday, August 3, 2009

Korean 'journalists' Expelled From Defcon Black Hat Conference - Spy-on-Spy Action!

Conference Officials announced that 4 South Korean 'Journalists' had been ejected from the Defcon BlackHat conference in Vegas, after attendees became suspicious of their strange behaviour and dubious credentials.

Trojan 'Journalists' Ejected

Conference representatives released few details of the incident but they did say that on Sunday they had ejected the journalists two days earlier, after deciding that they simply weren't acting like normal press corp.

'Cyber-Tourists'?

They believe that one member of the group was a legitimate journalist, but that the other three were part of some sort of intelligence-gathering expedition.

Asking Strange Questions

Hackers who the group interviewed at the show said that their questions seemed strangely inappropriate, organisers said. The journalists had attended one day of Defcon's Black Hat sister conference before being ejected on Friday.

Normal Practice
Defcon did not release the names of the journalists or say who they claimed to work for but they did say that this kind of incident happens nearly every year. A comment made by the show's senior organisers who goes by the name "Priest."

The French Foreign Legion

In the past, they say they've caught members of Mossad, the French Foreign Legion, and other organisations posing as press. It is simply by registering as journalists, they can get more time to query researchers and if they do it correctly, they can raise no suspicions by asking probing questions.

Good Cover
"When you think about it, being a member of the press is a pretty good cover because you can ask difficult questions, people love to see their names in print and in neon lights, so they're much more likely to talk to you. You can get away with a lot more," Priest said.

Body Type
The French Legionnaires were easy to spot, he said. "There's a certain body type you find with people who are in that type of work," he said. "Broad shoulders, narrow waist, not very tall. I'm looking at these guys, thinking, 'You're in far, far too good shape to be a member of the press.'"

'Spot the Fed!'
The Legionnaires eventually admitted that they were not press and were allowed to stay at the show as regular attendees. They even went on stage for Defcon's annual "spot the fed" contest where people are invited to pick out government employees from a group of attendees.

Undercover techies
Government employees posing as press often move very quickly to technical questions, rarely showing any interest in the motivation behind the research. They get "very technical very quickly," Priest said. "They're much more interested in what the latest is and what the greatest is and how they can use it."

Intelligence gathering
Often they also ask about U.S. government systems or seem to be gathering intelligence on the presenters, he added and often attendees are happy to provide the information, thinking that it may be used in an article, particularly young, inexperienced hackers, Priest said.

Young Geeks
"You've got usually a very introverted individual (on the autistic scale), who usually doesn't have a lot of friends, and if you have someone paying some attention to you and your favourite subject, then, yeah, you're flattered; you're ego's being stroked; you're much more likely to try to impress that person."

Spy on Spy Action
So who is spying on the spies when the spies are spying on the hackers? or is that a cyclic argument?

Friday, July 17, 2009

Twitter Hacked, What Secrets will Be Revealed?

The Google Apps documents connected with the hacked Twitter accounts have been plundered by the raiders. Bad news all round.

Wednesday, May 6, 2009

The Internet: How easily could it be shut down?

How easy is it to SHUTDOWN the Internet?

The experts and geeks alike will tell you that it is impossible! "Almost, certainly not." They would say in their clearly doubtful manner.

Why not?, you ask. Well, much of the infrastructure, the servers, cabling, satellites, and the internet service providers (ISPs) that run them, is in private hands. A single government might be able to command ISPs in their territory to shut down, but people could still receive data through satellite links controlled by other companies not answerable to that government. Hmm! OK so far.

To extend that shutdown across national borders is barely conceivable. "One very powerful government could have strong effects on their own country, but it would be very difficult to do this on a worldwide basis," says Milton Mueller, and he should know, he represents the international Internet Governance Project.

Who would 'want' to shut down the internet? Even the biggest cyber-attacks cause much less economic damage than closing the internet would. What's more, the experts say, malicious attempts to disable the internet are testimony to the difficulty of the task: the biggest attack in history came in February 2007, and you probably didn't even notice.

This attack attempted to overwhelm the 13 "root name servers" that carry the directory of all the internet addresses in use worldwide - data vital to the smooth running of the net. Two servers, both in the US, were affected, but with 11 others untouched, the attack failed.

ICANN has now begun to implement a further safeguard system, known as Anycast, by which each of the internet's 13 root name servers also acts as a duplicate, or mirror, for some of the others. "A root server in California can be mirrored in Taiwan or the Middle East," Mueller says. "By playing tricks with the addressing, we effectively have hundreds of these root servers."

If cyber-assaults get nowhere in shutting down the net, physical attacks on the infrastructure are unlikely to fare any better. You would have to physically plant bombs to destroy undersea cables, before launching missile attacks on the root name servers that are spread around the planet. "Then the internet will be the least of your worries," says Mueller. "We're talking about full-fledged international war."

There is another question that puzzles me. Why would the cyber-criminals and hackers want to shut down the web? It is the source of all their revenue, thrills and raison d'etre. I believe that the 'manipulation' and 'control' of the internet is a more probably target and that again is only partly possible with or without government funding, allegedly.