Showing posts with label cert. Show all posts
Showing posts with label cert. Show all posts

Thursday, June 14, 2007

Fed's 'Operation Bot Roast' Reveals 1 Million Victims

As the FBI and the DOJ investigated botnet operators, they began amassing a list of the alleged botnet victims -- with most of them here in the U.S.

Article by Sharon Gaudin, InformationWeek
In the Department of Justice and the FBI's attack on 'botherders', the government has identified more than one million botnet victims. The agencies announced Wednesday the results of an ongoing cybercrime initiative to disrupt and dismantle botherders, a term used for the people creating and operating an increasing number of botnets around the world. The FBI reported in an online advisory that its agents are working with the U.S.-CERT Coordination Center at Carnegie Mellon University to notify the owners of the compromised computers.

Government investigators tracked down the million victims while working on five different cybercrime cases, according to Richard Kolko, a special agent with the FBI. Charges already have been handed down in three of those cases. James C. Brewer of Arlington, Texas, is charged with operating a botnet that infected Chicago area hospitals. His botnet allegedly infected tens of thousands of computers worldwide. The government charged Jason Michael Downey of Covington, Kentucky, with using botnets to launch denial-of-service attacks. Robert Alan Soloway of Seattle was also charged this month with using a large botnet network to spam tens of millions of messages to advertise his Web site.

Kolko told InformationWeek that as agents delved into these three cases, along with two others that are under investigation, they uncovered the botnet victims. "There are hundreds of cybercrime cases at any given time but we put the botnet cases together for this initiative," he said. "We're trying to get people to take care of their computers. They're unaware participants in this criminal activity. We need them to take the proper precautions so we can put a dent in this crime." He also said most of the one million victims they found are in the United States. The government, he added, will continue to try to find more victims so they can notify them and get the compromised machines cleaned up.

Hackers and malware writers conspire to infect computers around the world with viruses and Trojans that allow them to remotely control the victim machines. Then, they amass thousands or hundreds of thousands of these zombie computers, creating great armies -- or botnets -- of them. In recent months, botnets have been increasing in number and in size, as they launch massive waves of spam, malware and even denial-of-service attacks. Most of the owners of the zombie machines don't even know they have been infected or that their machine is being controlled by someone else.

According to the FBI's advisory, because of their widely distributed capabilities, the government considers botnets a growing threat to national security, the national information infrastructure, and the economy. "They were a problem and they're emerging as a greater problem as people use them to get around security measures and cause greater damages," said Assistant U.S. Attorney Erez Liebermann, chief of the computer hacking and intellectual property unit in New Jersey. "The fact that they can do so much damage with the press of a button is a huge problem." A large number of the botnets are controlled by hackers and botherders outside of the U.S., with a growing number being set up in China. Dealing with cybercriminals outside the country's borders has been an issue -- but it's one the U.S. government is working on.

"Generally speaking, international aspects of these cases do have extra hurdles, but more and more countries are cooperating," said Liebermann. "There are efforts to get [cooperation] from China, and they're paying off." In recent months, rival online gangs have even begun a virtual turf war for bragging rights to the largest botnets. Two or three online criminal gangs have been waging an all-out battle for control of the largest botnets, sending out waves of malware aimed at stealing zombie computers from rival gangs to build up their own army. Each online gang is trying to build up the biggest botnet because the bigger the army of infected computers they control, the more money spammers and hackers will pay to use them, said Shane Coursen, a senior technical consultant forKaspersky Lab, in a previous interview.

Friday, June 01, 2007

Popular add-ons to Firefox are the latest criminal attack vector

Article posted by Robert Vamosi on News.com.com
Mozilla enjoys a large development community to build add-ons for its Firefox browser. Now it seems all that development might not be a good thing. A security researcher in Indiana has found that the process used to update some of these add-ons automatically appears to be flawed, allowing criminal hackers to intercept the browser's call to the developer to see if there's a new version available. Worse, the most vulnerable add-ons aren't from vendors you've never heard of; they include brand-name sites like Google, Yahoo, Facebook, and LinkedIn.

Extensions for Firefox contain hard coded Internet addresses for updates. Mozilla provides free hosting for update at addons.mozilla.org, however, many developers choose for various reasons to serve the updates themselves from servers under their control. The servers at Mozilla all use the secure https:// protocol, but since encryption requires more resources, many developers opt to use the less secure, less resource intensive http:// instead. That's where the problem lies.
Researcher Christopher Soghoian's blog describes a scenario where a wireless user in an Internet café starts up the Firefox browser. Home users who have not changed the default password on their wireless routers are also affected. Firefox routinely checks with the extension's update servers to see if there are any updates pending and generally notifies the user. Add-ons using the secure https:// protocol are not affected; a criminal could not intercept that encrypted transmission. However, add-ons using the less secure http:// protocol are open to what's called a man-in-the-middle attack where a criminal hacker can intercept the transmission and substitute a maliciously coded update instead.
While Firefox prompts the user to install any updates, not all updates trigger the prompt. For example, Google Toolbar updates will install automatically. Soghoian says "The problem stems from design flaws, false assumptions, and a lack of solid developer documentation instructing extension authors on the best way to secure their code." He urges Firefox users to uninstall extensions not downloaded from Mozilla.
Among these, Google Toolbar, Google Browser Sync, Yahoo Toolbar, Del.icio.us Extension, Facebook Toolbar, AOL Toolbar, Ask.com Toolbar, LinkedIn Browser Toolbar, Netcraft Anti-Phishing Toolbar, and PhishTank SiteChecker.
Add-ons not vulnerable to this type of attack include NoScript, Greasemonkey, and AdBlock Plus.
Secure add-ons can be downloaded from the official Firefox Add-ons website. Soghoian says he contacted Google and other developers and told Mozilla and specific about this vulnerability on April 16, 2007. Many vendors ignored him. Mozilla did work with some vendors, such as eBay, to fix the problem and has updated its developer site to include safe coding practices to guard against this attack. Abiding by the CERT vulnerability disclosure policy, Shogoian went public 45 days after notifying CERT and the vendors affected. Soghoian is no stranger to controversy. In October, Soghoian printed his own airline tickets much to the dismay of the FAA and Department of Homeland Security. No charges were ever filed.