231-922-9460 | Google +

Showing posts with label Internet Security. Show all posts
Showing posts with label Internet Security. Show all posts

Wednesday, May 30, 2012

Flame Malware A Real Scare

Story first appeared in The Wall Street Journal.
The complexity, size and geographic location of the computers affected by Flame, the malware that came to light Monday, points to state-sponsored cyber-espionage, and has been seen mainly as a geopolitical event. But the Flame code, which extracts data from networked computers and sends it to remote servers controlled by hackers, should also be seen by CIOs as a potential commercial threat and should cause them to reassess their Security Solutions – both on-premise and in the cloud.

Flame represents a next generation of malware because, while it combines many known ways of attacking systems and transmitting data back to remote servers, it is unique in how it has combined all of those malicious characteristics. Although many cyber-security experts have said most companies that create intellectual property – including a wide assortment of activities from pharmaceutical research to financial services and oil drilling – have already had their systems hacked, it may not be too late for CIOs to protect critical data. But, say experts, they will have to carefully assess their own networks, as well as their relationships with software vendors and cloud service providers with whom they do business.

Help Desk Services and analysts say that Flame should serve as a reminder to CIOs of how vulnerable they are, and give them a greater sense of urgency. Indeed the CIO of Land O’ Lakes, says he learned about Flame on the radio on his way into the office Tuesday, and his thoughts turned immediately to his cloud vendors. Like many CIOs, he has software running both on-premise and in the cloud, and says Flame is equally threatening to cloud and on-premise applications, but he wonders more about the risk mitigation strategies employed by his cloud partners. The question is, who will respond more quickly — cloud providers or his own internal data centers?

That’s a good question – cloud vendors generally do not accept liability for their clients data in the cloud.

The terms of service for Amazon’s AWS web services stipulate that the cloud vendor doesn’t accept liability for lost or altered data, and that customers are responsible for taking your own steps to maintain appropriate security, protection and backup of Your Content, which may include the use of encryption technology to protect Your Content from unauthorized access and routine archiving Your Content.

A Microsoft spokesperson said the company does accept liability for customer data on its Azure cloud platform, unless the customers themselves configured software improperly or otherwise created the conditions for a data breach. Rackspace and Google did not reply to requests for comment at the time of this writing.

Maintaining network security is hard enough on company-owned networks, but if you throw it over the wall to the cloud vendor and you don’t have visibility and control, it becomes impossible. Cloud vendors should provide customers with security tools, even if the customers themselves are responsible for configuring them.

The senior vice president and CIO of Hostess Brands Corporation, seemed to have these challenges in mind when he said he believes companies are limiting much of the data that they move to the cloud to less-critical information, because they are concerned about security.  Until CIOs can get a comfort level that is tenable and sustained, the movement to the cloud will be selective.

Closer to home, however, CIOs still have work to do. A security and privacy expert with the IEEE, a professional IT organization, says even a next generation of malware such as Flame can only get a toehold in an organization’s network by taking advantage of bad software. He blames vendors for building software that leaves customers susceptible to a malware attack, but says customers have to ask their vendors if the stuff you’re buying from them is secure or not, because a lot of people don’t even ask.

He says responsible vendors will respond honestly to that question.

CIOs need to ensure that software written by their own developers has security built into it, and can do this by following guidelines established in the BSIMM [Building Security In Maturity Model] standard. Beyond that, he said good security practice includes using tools to analyze existing software architecture, review code, and regularly hiring third parties to test the network for vulnerabilities by trying to penetrate it. McGraw says he’s “optimistic we’re actually making progress” in making safe software more ubiquitous. But, he said, the only way we can get in front of [issues like Flame] is building systems to be secure in the first place.

A Gartner analyst says Flame highlights the fact that we have to take a multi-pronged approach to malware. No single approach will be a silver bullet. New technologies that analyze the behavior of applications on networks can identify malware before it executes its code. Older anti-virus applications depend on being able to recognize the code used by malware, whereas newer generations of technology can see whether a particular type of application, like a PDF file, is trying to execute code – which it shouldn’t normally do.

An independent cybersecurity analyst, says CIOs should create an inventory of all a company’s data and classify it according to its value, much like the government does with state secrets. They should then take the equivalent of “top secret” data off the Internet. CIOs should also segregate data that is important but not critical, and monitor which persons and applications have access to it.

The reason this isn’t common practice is that many CIOs think about security in terms of legal requirements rather than common-sense approaches. Security is often a matter of compliance. Knowing where your critical data is isn’t an obligation, so it’s not done.


For more national and worldwide Business News, visit the Peak News Room blog.
For more local and state of Michigan Business News, visit the Michigan Business News blog.
For more Health News, visit the Healthcare and Medical News blog.
For more Electronics News, visit the Electronics America blog.
For more Real Estate News, visit the Commercial and Residential Real Estate blog.
For more Law News, visit the Nation of Law blog.
For more Advertising News, visit the Advertising, Marketing and Media blog.
For more Environmental News, visit the Environmental Responsibility News blog.
For information on website optimization or for the latest SEO News, visit the SEO Done Right blog.

Monday, April 30, 2012

Cybersecurity Bill Up In The Air

Story first appeared in The Wall Street Journal.

Congress moved toward gridlock over how to improve the security of the nation's computer networks when the House of Representatives approved a measure opposed by the White House and at odds with Senate efforts on the issue.

House passage of its measure, the Cyber Intelligence Sharing and Protection Act, came on a 248-168 vote Thursday and was supported by both Republicans and Democrats.

The House vote came despite a warning by the White House that senior advisers would recommend a presidential veto if the measure also passed the Senate, which is considered unlikely.

The White House prefers a Senate bill that would concentrate cybersecurity efforts in the Department of Homeland Security and would require companies to bolster security for critical infrastructure, such as electrical and water systems. The House bill only facilitates the swapping of threat data between private companies and the National Security Agency and other government departments.

The House version also was criticized by civil-liberties groups that said its provisions allowing businesses to share information with the government to improve cybersecurity could compromise American citizens' privacy. The American Civil Liberties Union called it "a dangerously overbroad bill that would allow companies to share our private and sensitive information with the government without a warrant and without proper oversight."

The Obama administration says cybersecurity and IT security solutions should be overseen by civilian agencies. The Senate bill favored by the White House and supported by Democrats would place Homeland Security officials in charge of the effort.

However, the Senate measure is opposed by business groups because of requirements that businesses adopt measures to improve security, steps executives see as burdensome.

The twin controversies—whether to regulate security and whether a civilian agency should head up the effort—seem likely to snarl efforts to plug the growing gaps in network security.

Earlier attempts at cybersecurity legislation drew broad, bipartisan support but little momentum. In the past year, the debate has grown more polarized over whether government should play a larger role in requiring businesses to strengthen their cybersecurity.

House sponsors of the legislation cast it as a necessary first step in the process to protect American networks from groups in places like China and Russia who are pilfering intellectual property from U.S. businesses. Government and industry experts warn that as cyberattack tools become more widely available, capabilities once reserved for governments could extend to rogue states, terrorists or so-called hacktivist groups.

Setting aside the criticism, the House put together a strong bill that will help stop cyberattacks that threaten our economy and our privacy while keeping the Internet free from government control.

But sponsors of the leading Senate measure said Friday that the House should have included provisions to protect computer systems running critical infrastructure, as the Senate bill does.


For more national and worldwide related business news, visit the Peak News Room blog.
For local and Michigan business related news, visit the Michigan Business News blog.
For healthcare and medical related news, visit the Healthcare and Medical blog.
For law related news, visit the Nation of Law blog.
For real estate and home related news, visit the  Commercial and Residential Real Estate blog.
For technology and electronics related news, visit the Electronics America blog.
For organic SEO and web optimization related news, visit the SEO Done Right blog.

Monday, April 23, 2012

Infected PCs May Lose Internet in July

Story first appeared in USA Today.

For computer users, a few mouse clicks could mean the difference between staying online and losing Internet connections this summer.  For some corporations without security measures in place, this could also mean the loss of important business intellectual property, according to Sacramento IP Lawyers.

This image provided by The DNS Changer Working Group (DCWG) shows the checkup webpage. It will only take a few clicks of the mouse. But for hundreds of thousands of computer users, those clicks could mean the difference between staying online and losing their connections this July.

Unknown to most of them, their problem began when international hackers ran an online advertising scam to take control of infected computers around the world. In a highly unusual response, the FBI set up a safety net months ago using government computers to prevent Internet disruptions for those infected users. But that system is to be shut down.  Denver IP Lawyers caution users to investigate their security protocols to avoid loss of important trade secrets.

The FBI is encouraging users to visit a website run by its security partner, http://www.dcwg.org, that will inform them whether they're infected and explain how to fix the problem. After July 9, infected users won't be able to connect to the Internet.

Most victims don't even know their computers have been infected, although the malicious software probably has slowed their web surfing and disabled their antivirus software, making their machines more vulnerable to other problems.  Many corporations have found themselves in need of legal protection, in addition to IT security measures, stated Boston IP Lawyers.

Last November, the FBI and other authorities were preparing to take down a hacker ring that had been running an Internet ad scam on a massive network of infected computers.

The FBI started to realize that there might have a little bit of a problem on our hands because if they just pulled the plug on their criminal infrastructure and threw everybody in jail, the victims of this were going to be without Internet service. The average user would open up Internet Explorer and get 'page not found' and think the Internet is broken.

On the night of the arrests, the agency brought in the chairman and founder of Internet Systems Consortium, to install two Internet servers to take the place of the truckload of impounded rogue servers that infected computers were using. Federal officials planned to keep their servers online until March, giving everyone opportunity to clean their computers. But it wasn't enough time. A federal judge in New York extended the deadline until July.

Now, the full court press is on to get people to address this problem. And it's up to computer users to check their PCs.

Hackers infected a network of probably more than 570,000 computers worldwide. They took advantage of vulnerabilities in the Microsoft Windows operating system to install malicious software on the victim computers. This turned off antivirus updates and changed the way the computers reconcile website addresses behind the scenes on the Internet's domain name system.

The DNS system is a network of servers that translates a web address — such as www.ap.org — into the numerical addresses that computers use. Victim computers were reprogrammed to use rogue DNS servers owned by the attackers. This allowed the attackers to redirect computers to fraudulent versions of any website.

The hackers earned profits from advertisements that appeared on websites that victims were tricked into visiting. The scam netted the hackers at least $14 million, according to the FBI. It also made thousands of computers reliant on the rogue servers for their Internet browsing.

When the FBI and others arrested six Estonians last November, the agency replaced the rogue servers with clean ones. Installing and running the two substitute servers for eight months is costing the federal government about $87,000.

The number of victims is hard to pinpoint, but the FBI believes that on the day of the arrests, at least 568,000 unique Internet addresses were using the rogue servers. Five months later, FBI estimates that the number is down to at least 360,000. The U.S. has the most, about 85,000, federal authorities said. Other countries with more than 20,000 each include Italy, India, England and Germany. Smaller numbers are online in Spain, France, Canada, China and Mexico.

Most of the victims are probably individual home users, rather than corporations that have technology staffs who routinely check the computers.  Many corporations utilize Managed IT Services that provide quality control and Security Solutions to avoid situations such as these.

FBI officials said they organized an unusual system to avoid any appearance of government intrusion into the Internet or private computers. And while this is the first time the FBI used it, it won't be the last.

Until there is a change in legal system, both inside and outside the United States, to get up to speed with the cyber problem, the FBI will have to go down these paths, trail-blazing if you will, on these types of investigations.

Now, every time the agency gets near the end of a cyber case, they get to the point where they say, how are we going to do this, how are we going to clean the system" without creating a bigger mess than before.

For national and worldwide related business news, visit the Peak News Room blog.
For local and Michigan business related news, visit the Michigan Business News blog.
For healthcare and medical related news, visit the Healthcare and Medical blog.
For law related news, visit the Nation of Law blog.
For real estate and home related news, visit the  Commercial and Residential Real Estate blog.
For technology and electronics related news, visit the Electronics America blog.
For organic SEO and web optimization related news, visit the SEO Done Right blog.

Monday, February 13, 2012

New Technology Means New Security Measures


First appeared in the New York Times
When Kenneth G. Lieberthal, a China expert at the Brookings Institution, travels to that country, he follows a routine that seems straight from a spy film.

He leaves his cellphone and laptop at home and instead brings “loaner” devices, which he erases before he leaves the United States and wipes clean the minute he returns. In China, he disables Bluetooth and Wi-Fi, never lets his phone out of his sight and, in meetings, not only turns off his phone but also removes the battery, for fear his microphone could be turned on remotely. He connects to the Internet only through an encrypted, password-protected channel, and copies and pastes his password from a USB thumb drive. He never types in a password directly, because, he said, “the Chinese are very good at installing key-logging software on your laptop.”

What might have once sounded like the behavior of a paranoid is now standard operating procedure for officials at American government agencies, research groups and companies that do business in China and Russia — like Google, the State Department and the Internet security giant McAfee. Digital espionage in these countries, security experts say, is a real and growing threat — whether in pursuit of confidential government information or corporate trade secrets.

“If a company has significant intellectual property that the Chinese and Russians are interested in, and you go over there with mobile devices, your devices will get penetrated,” said Joel F. Brenner, formerly the top counterintelligence official in the office of the director of national intelligence.

Theft of trade secrets was long the work of insiders — corporate moles or disgruntled employees. But it has become easier to steal information remotely because of the Internet, the proliferation of smartphones and the inclination of employees to plug their personal devices into workplace networks and cart proprietary information around. Hackers’ preferred modus operandi, security experts say, is to break into employees’ portable devices and leapfrog into employers’ networks — stealing secrets while leaving nary a trace.

Targets of hack attacks are reluctant to discuss them and statistics are scarce. Most breaches go unreported, security experts say, because corporate victims fear what disclosure might mean for their stock price, or because those affected never knew they were hacked in the first place. But the scope of the problem is illustrated by an incident at the United States Chamber of Commerce in 2010.

The chamber did not learn that it — and its member organizations — were the victims of a cybertheft that had lasted for months until the Federal Bureau of Investigation told the group that servers in China were stealing information from four of its Asia policy experts, who frequent China. By the time the chamber secured its network, hackers had pilfered at least six weeks worth of e-mails with its member organizations, which include most of the nation’s largest corporations. Later still, the chamber discovered that its office printer and even a thermostat in one of its corporate apartments were still communicating with an Internet address in China.

The chamber did not disclose how hackers had infiltrated its systems, but its first step after the attack was to bar employees from taking devices with them “to certain countries,” notably China, a spokesman said.

The implication, said Jacob Olcott, a cybersecurity expert at Good Harbor Consulting, was that devices brought into China were hacked. “Everybody knows that if you are doing business in China, in the 21st century, you don’t bring anything with you. That’s ‘Business 101’ — at least it should be.”

Neither the Chinese nor Russian embassies in Washington responded to several requests for comment. But after Google accused Chinese hackers of breaking into its systems in 2010, Chinese officials gave this statement: “China is committed to protecting the legitimate rights and interests of foreign companies in our country.”

Still, United States security experts and government officials say they are increasingly concerned about breaches from within these countries into corporate networks — whether through mobile devices or other means.

Last week, James R. Clapper, the director of national intelligence, warned in testimony before the Senate Intelligence Committee about theft of trade secrets by “entities” within China and Russia. And Mike McConnell, a former director of national intelligence, and now a private consultant, said in an interview, “In looking at computer systems of consequence — in government, Congress, at the Department of Defense, aerospace, companies with valuable trade secrets — we’ve not examined one yet that has not been infected by an advanced persistent threat.”

Both China and Russia prohibit travelers from entering the country with encrypted devices unless they have government permission. When officials from those countries visit the United States, they take extra precautions to prevent the hacking of their portable devices, according to security experts.

Now, United States companies, government agencies and organizations are doing the same by imposing do-not-carry rules. Representative Mike Rogers, the Michigan Republican who is chairman of the House Intelligence Committee, said its members could bring only “clean” devices to China and were forbidden from connecting to the government’s network while abroad. As for himself, he said he traveled “electronically naked.”

At the State Department, employees get specific instruction on how to secure their devices in Russia and China, and are briefed annually on general principles of security. At the Brookings Institution, Mr. Lieberthal advises companies that do business in China. He said that there was no formal policy mandating that employees leave their devices at home, “but they certainly educate employees who travel to China and Russia to do so.”

McAfee, the security company, said that if any employee’s device was inspected at the Chinese border, it could never be plugged into McAfee’s network again. Ever. “We just wouldn’t take the risk,” said Simon Hunt, a vice president.

At AirPatrol, a company based in Columbia, Md., that specializes in wireless security systems, employees take only loaner devices to China and Russia, never enable Bluetooth and always switch off the microphone and camera. “We operate under the assumption that we will inevitably be compromised,” said Tom Kellermann, the company’s chief technology officer and a member of President Obama’s commission on cybersecurity.

Google said it would not comment on its internal travel policies, but employees who spoke on condition of anonymity said the company prohibited them from bringing sensitive data to China, required they bring only loaner laptops or have their devices inspected upon their return.

Federal lawmakers are considering bills aimed at thwarting cybertheft of trade secrets, although it is unclear whether this legislation would directly address problems that arise from business trips overseas.

In the meantime, companies are leaking critical information, often without realizing it.

“The Chinese are very good at covering their tracks,” said Scott Aken, a former F.B.I. agent who specialized in counterintelligence and computer intrusion. “In most cases, companies don’t realize they’ve been burned until years later when a foreign competitor puts out their very same product — only they’re making it 30 percent cheaper.”

“We’ve already lost our manufacturing base,” he said. “Now we’re losing our R.& D. base. If we lose that, what do we fall back on?”

Tuesday, October 5, 2010

Coalition Starts Cybersecurity Awareness Campaign

USA Today

Stop. Think. Connect.

That's what a high-powered coalition of federal agencies, tech companies, retailers and non-profit groups want you to do every time you use the Internet.

Today, the group launched a milestone public awareness campaign. The goal: to engrain "stop-think-connect" as deeply into culture as the seatbelt reminder "click-it-or-ticket" and Smokey Bear's quote, "Only you can prevent forest fires."

"Cybersecurity is a shared responsibility for all of us," says Joe Sullivan, Facebook's chief security officer. "People will have a better experience on the Internet if they do some basic things."

The campaign stems directly from President Obama's May 2009 pronouncement that the U.S. will assume a leadership role in making the Internet safer.

Overseen by the Department of Homeland Security, the coalition includes Microsoft, Facebook, Google, Intel, AT&T, Visa, PayPal, Wal-Mart, Costco, the Department of Justice and the IRS among its 28 founding members.

The members understand that each of their respective organizations stands to benefit from a unified effort to advance public awareness about Internet threats, says Michael Kaiser, executive director of the non-profit National Cyber Security Alliance. Each will incorporate the stop-think-connect slogan and theme into existing and new public education initiatives.

Facebook, for instance, is preparing a seven-question quiz, which it will make available sometime this month on its security issues page and home page. It will also donate 35 million ad impressions to promote the quiz, which espouses best practices for passwords and browser use.

This is all intended to slow down cybercriminals, who are having a field day. One estimate puts identity theft losses, much of it due to online scams, at $4.5 billion in the past two years, making it the fastest-growing crime in America, says Kaiser.

Online safety has yet to be elevated to a major public safety issue, akin to the way society views drunk driving, forest fires and seat belt usage, he says.

The coalition selected "stop-think-connect" after a year-long process of research, focus groups, polling and government-industry collaboration. That research confirmed that most folks view cybersecurity  and Safe, Secure SEO as a personal responsibility and that any public safety message must address the individual. The founding members voted to go with a message that could be used globally to effect a "big cultural change," says Kaiser.

The group strove to "simplify the messaging and speak in one voice," says Facebook's Sullivan. "If we're using the same terminology, it's going to make the whole process much more effective."

One absence at launch: Apple, which has risen to become one the world's most highly valued companies, measured by its stock price, on the strength of Internet-connected products such as the iPhone and iPad.

Company spokeswoman Natalie Kerris declined comment.

However, the door remains wide open for Apple and others to join the coalition, says Kaiser.

"It takes a group of leaders to start a movement," says Kaiser. "I'm optimistic others will join the effort. We're trying to solve the problem for the benefit of all concerned, not just for the benefit of any individual company."

Tuesday, September 28, 2010

Citi Discovers Security Flaw in iPhone Application

NY Times

 
After Citigroup on Monday discovered a potential security flaw in the Apple iPhone app that its customers use to access its Web site, the bank urged customers to upgrade to a newer version of the software, which it says will correct the problem.

In a statement, Citigroup said the original app accidentally saved information from a banking customer’s account into a hidden file on the iPhone. The statement from Citigroup was first reported by The Wall Street Journal.

Citigroup said the update “deletes any Citi Mobile information that may have been saved” to a customer’s iPhone or computer. The bank also said the update “eliminates the possibility that this will occur in the future.”

Although Citigroup was working with customers to fix the problem, the bank said it did not believe its customers’ personal information was affected. Citigroup also said the bug only affected iPhone users in the United States, though it did not say how many.

John Hering, co-founder of Lookout, a security company specializing in the protection of mobile phones from viruses and malware, said that the vulnerability of smartphones was a growing concern, and that Citigroup’s  announcement shows how unsafe these devices can be.

“I think this just underscores the importance of making sure these devices stay safe and this isn’t a one-time problem either,” he said. “Mobile apps are often exposing more information than people realize.”

Mr. Hering and other security experts believe that the mobile industry is on the verge of some major security problems as more people use their phones for banking and other personal information.

“At this point, it’s not a matter of if, it’s a matter of when,” he said.

Although Apple says the iPhone is a safer environment than other mobile competitors because of the company’s strict rules about approving the apps it allows on the iPhone, bugs like this show that flaws can always make it onto a system, sometimes at the fault of the application’s owner.

“I think this is going to be the beginning of more and more applications that have this kind of problem,” Mr. Hering said. “I commend Citibank for staying on top of this, but in the next scenario it could be a much different story.”

Wednesday, December 16, 2009

Blackmail Comes To Main Street

Wall Street Journal



It's not just people like John Stamos and David Letterman. Even noncelebrities are increasingly being targeted in alleged blackmail plots, say security and law-enforcement experts.

Some private security experts say a growing number of clients are calling on them for protection from extortion threats. The severe recession and high unemployment rates, as well as general turmoil following last year's economic meltdown, appear to be swelling the ranks of blackmailers, they say.

"The economy is at low ebb, and people are looking for a mark," said security consultant Michael Guidry, chief executive of the Guidry Group, in Montgomery, Texas.

Paul Viollis, CEO of the security and investigations firm Risk Control Strategies Inc. in New York, says he's seen a surge in blackmail cases among high-net-worth clients over the past year. He used to handle about eight a year, he says. Now he has 40 active cases, and is adding two to five more each month.

The surge started last November with the attempted blackmail of one of Mr. Viollis's clients by a former business partner who had fallen on hard times. The ex-partner said he had knowledge of past Securities and Exchange Commission violations committed by the client. Mr. Viollis says he helped end the blackmail by meeting the extortionist and telling him he would report him to authorities unless he ceased. Mr. Viollis says the allegations were false and the extortionist knew it. Mr. Viollis's account couldn't be independently verified.

Sometimes it's risky personal conduct that exposes individuals to extortion. Earlier this year, Stephen Dent, 55 years old, of Old Greenwich, Conn., complained to police and the Federal Bureau of Investigation that women he met through a Web dating site catering to wealthy men demanded money in return for keeping his online activities secret from his wife and others. Mr. Dent already had paid hush money in connection with a similar plot in 2007, according to police reports and court documents.

The alleged extortionists were arrested and charged last March, after a probe by the FBI and local police. A male defendant who was indicted in the case—the husband of one of the women—is now serving 18 months in connection with the plot, and his wife received a suspended sentence of five years, according to their attorney, Mark Sherman. A third woman has pleaded not guilty and is awaiting trial. Mr. Dent hasn't been charged with any crime. His attorney, Steven Frederick of Stamford, Conn., didn't return repeated phone calls for comment.

National statistics on blackmail are hard to get because extortion can be a federal or state crime and is charged under a number of different statutes, including larceny, wire fraud and mail fraud. The number of defendants in such federal cases has averaged about 145 per year since 1994, except in 2002, when they suddenly spiked to 205 during the last recession.

Party Photos

The most-publicized recent extortion cases have involved alleged attempts to obtain huge sums of money from well-known entertainers. Just this week, Mr. Stamos, a well-known TV actor, said he went to the FBI after a pair of Michigan residents allegedly demanded $680,000 in exchange for photos taken at a 2004 party in Florida.

According to an FBI affidavit, Mr. Stamos, 46, met the accused at the party and received a number of emails in November threatening to release the pictures to the media. "At the conclusion of the investigation and hearing, the photos will be available and the public will be able to see that the photos are simply John posing with fans," says a spokesman for Mr. Stamos. The defendants were released on bond pending a hearing, according to court records.

Last month, federal officials said supermodel Cindy Crawford and her husband, Rande Gerber, were victims of an alleged plot by a former nanny's boyfriend to extort $100,000 in return for a photo taken by the nanny of their young daughter tied up and gagged.

The boyfriend was deported to Germany but allegedly continued to make demands by phone and email. In mid-November, he turned himself in to German authorities and has been charged with extortion in U.S. District Court in Los Angeles. The U.S. hasn't made any extradition request with Germany, and the nanny hasn't been charged, according to federal prosecutors.

Ms. Crawford and Mr. Gerber said they didn't know of the existence of the photo until they were contacted by the alleged blackmailer in July. They eventually reported the threat to the police, and the FBI began a criminal investigation, the couple said.

"Rande Gerber and Cindy Crawford intend to pursue any and all available legal action against anyone who aids the perpetrator in the distribution or sale of the photograph of their daughter," their spokeswoman said in a statement.

In October, a television news producer was accused by Manhattan prosecutors of attempting to extort $2 million from Mr. Letterman, 62, in return for silence about the talk-show host's affair with a female subordinate and other staff members. The defendant's attorney contends that he was merely offering Mr. Letterman the chance to buy a screenplay based on his affair with the woman, who was also the producer's ex-girlfriend. The producer says he is innocent, and his attorney has asked the New York state judge to dismiss the charges.

Earlier this year, film stars John Travolta, 55, and wife, Kelly Preston, 47, said they were targets of attempted extortion by a Bahamian paramedic and lawmaker after the sudden death of their son, Jett, 16, there in January. The alleged conspirators threatened to imply that Mr. Travolta was culpable in his son's death by releasing a medical document unless they were paid $25 million dollars in cash, according to Mr. Travolta's attorneys. A criminal trial in the Bahamas ended in a mistrial in October. The defendants contend they are innocent.

Security experts say that a growing number of incidents are more about punishing or humiliating the victim than getting money. Often, blackmailers are angry about the success of an associate that they believe is undeserved, say crime experts and academic researchers.

"More than 90% of our cases were opportunistic greed along the lines of [the allegations] in the Travolta case," says Mr. Viollis, the private investigator. "But since October, it has been more anger, resentment and retribution. It is vengeance. Some involve money, and some are just outright, 'I want to see you suffer. Resign your position, admit to the board you are a blank blank blank, and I will go away.' "

In one recent high-profile extortion case, difficult family relationships appeared to play a role. Stuart Ross, 73, of Aventura, Fla., and Stuart Jackson, 80, of Manhasset, N.Y., are accused on felony charges of grand larceny for attempting to extort as much an $11 million in 2008 from David Blitzer, a London-based senior managing director of the Blackstone Group LP, a private-equity fund. Mr. Ross, an entrepreneur who is credited with first importing the popular Smurfs dolls to the U.S. from Belgium in the 1970s, is Mr. Blitzer's father-in-law. The defendants, who are scheduled to go to trial soon in New York, face up to seven years in prison if convicted.

Escalating Demands

Mr. Ross had initially approached Mr. Blitzer for money to start a new business, but his demands continued to escalate after his son-in-law paid him tens of thousands of dollars. Mr. Ross was also upset because Mr. Blitzer didn't send him a family photo at Christmas or invite him to Mr. Blitzer's villa in Italy, among other perceived slights, according to statements he made to investigators in the district attorney's office.

Mr. Ross couldn't be reached for comment, but at a court appearance in August 2008, he told Dow Jones Newswires that "we believe this [prosecution] is totally unlawful and totally malicious." Mr. Jackson, an attorney, also contends he is innocent. "The case is about an effort by Ross, who was my client, to visit his grandchildren," he said in a recent telephone interview.

A spokeswoman for the Blackstone Group said the company and Mr. Blitzer had no comment.

Security experts are advising clients to be guarded in their personal activities and communications—especially electronic communications—and to beef up their defenses. They suggest conducting periodic background checks on key advisers and household employees, because they and their associates are often the perpetrators of such crimes.

They also say victims of attempted extortion should immediately seek help, because payoffs seldom end the threats. But they also warn that if police or federal investigators are notified, the matter will become public.

Tuesday, December 23, 2008

.ASPX .PHP URLs Struggle To Rank in Search Engines - SQL Databases Tied To Third Party Injections Hackers

Posted by Dancho Danchev

Once again confirming the trend of having more legitimate sites serving exploits and malware than purely malicious ones, Chinese hackers have been keeping themselves busy during the last couple of days, launching massive SQL injection attacks affecting over 100,000 web sites.

The SQL injection attacks serving the just patched Internet Explorer XML parsing exploit, are launched by several different Chinese hacking groups, and with several exceptions, are primarily targeting Asian countries which is a pretty logical move given the fact that it’s a password stealing malware for online games that is served at the bottom line.

SQL stands for Structured Query Language that allows webmasters and web editors to communicate with their database. SQL is very complex and the potential for open doors and compromising paths is expansive. Incorrect authoring and implementation along with infrequent code updates can create a vast array of security lapses.

Hackers tend to target SQL databases and simple search boxes and email contact forms looking for server application error messages that contain valuable information that aid hackers in developing a successful hack attack that compromises websites.

Yahoo, Google, and MSN Live can and are used by hackers to as a source to gather key information about a website that often helps hackers find unlocked backdoors, SQL weaknesses, unsecured information and more.
It pays to hire an outside consultant that can identify SQL security holes and flaws and work to build security patches that help seal up vulnerable areas. It also pays huge dividends to outsource with a proven SEO firm that can help update code and provide SQL database security guidance in terms of best practices with IT Security. Page Code is critical to SEO success and also critical in terms of compliance with server side scripting and SQL database integrity.

More than 100,000 web sites have recently been cited as infected by Symantec and thousands more domains are being injected as previous campaigns and the number of affected sites typically accelerates very fast. Consider for a while the big picture. With or without a patch for the IE SQL exploit, committing cybercrimes through the exploitation of already patched client-side vulnerabilities would continue growing - it has been throughout all of 2008. Despite being old-fashioned compared to Russian cybercriminals that would have included the exploit within their web malware exploitation kits and started serving banker malware instead of password stealing malware, the Chinese attackers appear to be well aware of this trend, and therefore all of the IE exploit serving SQL sites are also serving several other exploits targeting Adobe’s Flash, Acrobat Reader and RealPlayer for starters.

Recent studies continue emphasizing on the fact that millions of users not only continue browsing the web using insecure browsers, but also, are so browser vulnerabilities centered and they ignore the rest of the software running on their PCs as a potential infection vector given they’re running an insecure versions of it - and yes they are. Cybercriminals are aware of this insecure Internet browsing, and are therefore including sets of exploits targeting each and every version known to be vulnerable of a particular software in order to increase the chances for a successful infection. This particular SQL injection attack is the most recent example of this mentality.

In 2008, cybercriminals continue infecting thousands of new hosts on daily basis using 2007’s critical vulnerabilities, because instead of patching vulnerable software, the majority of end users remain comfortable with their false feeling of security. Also the major search engines are responding by restricting .php, .asp, and .aspx urls pushing these urls far down in their organic search results in an effort to maintain the integrity of the organic search results and prevent further malware distribution.

Websites using SQL databases must take additional "white Hat SEO" steps to secure and maintain premium keyword rankings and top search listings in the major search engines, especially Google.
The author Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and E-crime incident response. Dancho is also involved in business development, marketing research and competitive intelligence as an independent contractor. He's been an active security blogger since 2007, and maintains a popular security blog sharing real-time threats intelligence data with the rest of the community on a daily basis.