Showing posts with label hackers. Show all posts
Showing posts with label hackers. Show all posts

Sunday, March 25, 2007

Study: Hackers Attack Every 39 Seconds

Are hackers trying to get into your computer right now? And what are they up to? A Clark School study is one of the first to quantify the near-constant rate of hacker attacks of computers with Internet accessevery 39 seconds on average—and the non-secure usernames and passwords we use that give attackers more chance of success.

The study, conducted by Michel Cukier, Clark School assistant professor of mechanical engineering and affiliate of the Clark School's Center for Risk and Reliability and Institute for Systems Research, profiled the behavior of "brute force" hackers, who use simple software-aided techniques to randomly attack large numbers of computers. The researchers discovered which usernames and passwords are tried most often, and what hackers do when they gain access to a computer.

On TV and in film, these kinds of hackers have been portrayed as people with grudges who target specific institutions and manually try to break into their computers. But in reality, Cukier says, "most of these attacks employ automated scripts that indiscriminately seek out thousands of computers at a time, looking for vulnerabilities." "Our data provide quantifiable evidence that attacks are happening all the time to computers with Internet connections," Cukier notes. "The computers in our study were attacked, on average, 2,244 times a day."

Cukier and two of his graduate students, Daniel Ramsbrock and Robin Berthier, set up weak security on four Linux computers with Internet access, then recorded what happened as the individual machines were attacked. They discovered the vast majority of attacks came from relatively unsophisticated hackers using "dictionary scripts," a type of software that runs through lists of common usernames and passwords attempting to break into a computer.

"Root" was the top username guess by dictionary scripts—attempted 12 times as often as the second-place "admin." Successful 'root' access would open the entire computer to the hacker, while 'admin' would grant access to somewhat lesser administrative privileges. Other top usernames in the hackers' scripts were "test," "guest," "info," "adm," "mysql," "user," "administrator" and "oracle." All should be avoided as usernames, Cukier advises. The researchers found the most common password-guessing ploy was to reenter or try variations of the username. Some 43 percent of all password-guessing attempts simply reentered the username. The username followed by "123" was the second most-tried choice. Other common passwords attempted included "123456," "password," "1234," "12345," "passwd," "123," "test," and "1." These findings support the warnings of security experts that a password should never be identical or even related to its associated username, Cukier says.

Once hackers gain access to a computer, they swiftly act to determine whether it could be of use to them. During the study, the hackers' most common sequence of actions was to check the accessed computer's software configuration, change the password, check the hardware and/or software configuration again, download a file, install the downloaded program, and then run it. What are the hackers trying to accomplish? "The scripts return a list of 'most likely prospect' computers to the hacker, who then attempts to access and compromise as many as possible," Cukier says. "Often they set up 'back doors' — undetected entrances into the computer that they controlso they can create 'botnets,' for profit or disreputable purposes." A botnet is a collection of compromised computers that are controlled by autonomous software robots answering to a hacker who manipulates the computers remotely. Botnets can act to perpetrate fraud or identity theft, disrupt other networks, and damage computer files, among other things.

This study provides solid statistical evidence that supports widely held beliefs about username/password vulnerability and post-compromise attacking behavior. Computer users should avoid all of the usernames and passwords identified in the research and choose longer, more difficult and less obvious passwords with combinations of upper and lowercase letters and numbers that are not open to brute-force dictionary attacks.

Tuesday, March 06, 2007

Technology History: Michelangelo

The Michelangelo virus was the first computer virus to capture the attention of the mass media. Set to execute on March 6, 1992 (the birth day of the famous Renaissance artist of the same name), the virus was predicted to destroy data on all personal computers on which it was loaded. The hype lead to many first-time installations of anti-virus software and other computer checks. All told, less than 10,000 PCs worldwide were affected as a result of the Michelangelo virus.
The good news is that consumers woke up to the fact that hackers were out there trying to damage their systems.

Wednesday, January 03, 2007

Its a Month of Apple Bugs; for Some!

Source: TechTree
A zero-day vulnerability in Apple Computer's QuickTime media player has been posted, kicking off a project quite strangely titled as the "Month of Apple Bugs" (MoAB).
What has also been posted is an exploit that can be used by hackers to compromise, hijack, or infect computers running Microsoft Windows or Apple Mac OS X.
The QuickTime vulnerability lies in the way the media player software handles Real Time Streaming Protocol or RTSP. An attacker can create a special RTSP string in a rigged QuickTime file that would cause a buffer overflow. The vulnerability affects QuickTime 7.1.3 on both Mac OS X and Windows systems. Previous versions of QuickTime could also be vulnerable.
A sequel to the 'Month of Kernel Bugs' project, MoAB is hosted by a hacker who goes under the initials, LMH, and a researcher, Kevin Finisterre, who has posted several such Mac vulnerabilities on his Web site.
MoAB takes upon itself the task of announcing a new security vulnerability in Apple's OS or other Mac OS X software each day of this month. Of the QuickTime vulnerability, LMH says, "The risk is having your system compromised by a remote attacker, who can perform any operation under privileges of your user account. It can be triggered via JavaScript, Flash, common links, QTL files, and any other method that starts QuickTime."
Both LMH and Finisterre write about the vulnerability on the MoAB Web site, saying that exploitation of this bug is trivial, and that the associated exploit code has been tested on Mac OS X running on Intel-based systems, and works against QuickTime 7.1.3, the current version of the player. However, Danish security major, Secunia, has given the bug a 'highly critical' rating. Apple, on its part, continues to remain non-committal. In an email, a spokesperson for Apple has said the company takes security very seriously, and that it welcomes feedback on how to improve security on the Mac.
In any case, till such a time this potential bug is patched, users are advised to cripple QuickTime's ability to process rtsp:// links. As regards users of Microsoft Windows, they are advised to launch QuickTime, select Edit|Preferences|QuickTime Preferences, click the File Types tab, expand Streaming, and clear the box marked "RTSP stream descriptor". Users of Mac OS X are advised to select System Preferences|QuickTime|Advanced|MIME Settings|Streaming|Streaming Movies, and clear the "RTSP stream descriptor" box.