[ISN] InfoSec News Mailing List http://www.infosecnews.org/mailman/listinfo/isn InfoSecNews BlackBerry has spyware risk too, researcher says http://www.infosecnews.org/pipermail/isn/2010-February/018747.html InfoSec News: BlackBerry has spyware risk too, researcher says: http://news.cnet.com/8301-27080_3-10448545-245.html <br /> By Elinor Mills InSecurity Complex CNET News February 7, 2010 <br /> We've heard a lot about security issues with the iPhone, but the BlackBerry isn't immune to threats from malicious apps. <br /> Tyler Shields, a senior researcher at the Veracode Research Lab, has written a piece of spyware that allowed me to shoot an SMS command to his phone and have his contact list forwarded to my e-mail address in a demonstration. With another short text command, I was able to get his BlackBerry to e-mail me any SMS messages he sends. <br /> And if I had wanted--and he had allowed me--I could have seen a log of all his calls, monitored his inbound text messages, tracked his location in real-time based on the GPS (Global Positioning System) in his device and turned his microphone on to listen to conversations in the room and record them. <br /> &quot;It's trivial to write this type of code using the mobile provider's own API [application programming interface] they provide to any developer,&quot; Shields said in an interview in advance of his talk on the spyware scheduled for the ShmooCon security show on Sunday. <br /> [...] <br /> IDF considers using BlackBerry http://www.infosecnews.org/pipermail/isn/2010-February/018746.html InfoSec News: IDF considers using BlackBerry: http://www.jpost.com/Israel/Article.aspx?id=167988 <br /> By Yaakov Katz The Jerusalem Post 07/02/2010 <br /> When Barack Obama was elected president of the United States, he was told he could no longer use his personal BlackBerry to receive e-mails, as it is not secure. [...] Why CSOs Should Care About ShmooCon http://www.infosecnews.org/pipermail/isn/2010-February/018745.html InfoSec News: Why CSOs Should Care About ShmooCon: http://www.csoonline.com/article/533363/Why_CSOs_Should_Care_About_ShmooCon_ <br /> By Bill Brenner Senior Editor CSO February 07, 2010 <br /> WASHINGTON, D.C. -- Many CSOs view ShmooCon as an event of small importance. You don't see the suits and ties that are on display at RSA. [...] Biggest hacker training site shut down http://www.infosecnews.org/pipermail/isn/2010-February/018744.html InfoSec News: Biggest hacker training site shut down: http://www.chinadaily.com.cn/china/2010-02/08/content_9440667.htm <br /> By Wu Yiyao China Daily 2010-02-08 <br /> What is believed to be the country's biggest hacker training site has been shut down by police in Central China's Hubei province. <br /> Three people were also arrested, local media reported yesterday. [...] CSIIRW Sixth Cyber Security and Information Intelligence Research Workshop http://www.infosecnews.org/pipermail/isn/2010-February/018743.html InfoSec News: CSIIRW Sixth Cyber Security and Information Intelligence Research Workshop: Forwarded from: Frederick Sheldon &lt;sheldonft (at) ornl.gov&gt; <br /> CALL FOR ABSTRACTS* <br /> CSIIRW-10 http://www.csiir.ornl.gov/csiirw <br /> April 21-23, 2010 <br /> Sixth Cyber Security and Information Intelligence Research Workshop Oak Ridge National Laboratory CSIIRW-09 Proceedings <br /> *My Apology for multiple postings; [...] GAO Report: NASA Still Facing Weaknesses In IT Security http://www.infosecnews.org/pipermail/isn/2010-February/018742.html InfoSec News: GAO Report: NASA Still Facing Weaknesses In IT Security: http://www.darkreading.com/vulnerability_management/security/management/showArticle.jhtml?articleID=222700163 <br /> By Tim Wilson DarkReading Feb 05, 2010 <br /> NASA made history earlier this week by releasing up-close pictures of Pluto. Here on Earth, however, it's the space agency's IT systems and [...] Secunia Weekly Summary - Issue: 2010-05 http://www.infosecnews.org/pipermail/isn/2010-February/018741.html InfoSec News: Secunia Weekly Summary - Issue: 2010-05: ======================================================================== <br /> The Secunia Weekly Advisory Summary 2010-01-28 - 2010-02-04 <br /> This week: 60 advisories [...] Fugitive VoIP hacker admits 10 million minute spree http://www.infosecnews.org/pipermail/isn/2010-February/018740.html InfoSec News: Fugitive VoIP hacker admits 10 million minute spree: http://www.theregister.co.uk/2010/02/03/voip_hacker_guilty/ <br /> By Dan Goodin in San Francisco The Register 3rd February 2010 <br /> A Miami hacker has admitted he pocketed more than $1m by selling millions of minutes of voice over IP calls and surreptitiously routing [...] Military Intelligence: IDF is prepared for Cyberwarfare http://www.infosecnews.org/pipermail/isn/2010-February/018739.html InfoSec News: Military Intelligence: IDF is prepared for Cyberwarfare: http://dover.idf.il/IDF/English/News/today/10/02/0304.htm <br /> By Arnon Ben-Dror Israel Defense Forces 03 February 2010 <br /> In a paper published by the head of the Military Intelligence Directorate, Major General Amos Yadlin, in the Intelligence Research [...] Report Details Hacks Targeting Google, Others http://www.infosecnews.org/pipermail/isn/2010-February/018738.html InfoSec News: Report Details Hacks Targeting Google, Others: http://www.wired.com/threatlevel/2010/02/apt-hacks/ <br /> By Kim Zetter Threat Level Wired.com February 3, 2010 <br /> Until now we've only known that the attackers got in through a vulnerability in Internet Explorer and that they obtained intellectual property and access to the Gmail accounts of two human rights activists whose work revolves around China. We also know a few details about how the hackers siphoned the stolen data, which went to IP addresses in Taiwan. About 34 mostly undisclosed companies were breached. <br /> Now a leading computer forensic firm is providing the closest look so far at the nature of the attacks, and attackers, that struck Google and others. The report never mentions Google by name, or any other companies, but focuses on information gathered from hundreds of forensic investigations the firm has conducted that are identical to what we know about the Google hack. <br /> What the information indicates is that the attack that hit Google is identical to publicly undisclosed attacks that have quietly plagued thousands of other U.S. companies and government agencies since 2002 and are rapidly growing. They represent a sea change from the kinds of attacks that have commonly hit networks and made headlines. <br /> &quot;The scope of this is much larger than anybody has every conveyed,&quot; says Kevin Mandia, CEO and president of Virginia-based computer security and forensic firm Mandiant. &quot;There [are] not 50 companies compromised. There are thousands of companies compromised. Actively, right now.&quot; <br /> Mandiant released the report last week at a closed-door cybercrime conference, sponsored by the U.S. Defense Department, in an effort to make companies aware of the threat. <br /> [...] <br /> Black Hat: Microsoft Enhances SDL Offerings http://www.infosecnews.org/pipermail/isn/2010-February/018737.html InfoSec News: Black Hat: Microsoft Enhances SDL Offerings: http://www.informationweek.com/news/security/client/showArticle.jhtml?articleID=222601024 <br /> By Thomas Claburn InformationWeek February 3, 2010 <br /> At the Black Hat security conference in Washington, D.C., on Tuesday, Microsoft introduced new software, a new membership program, and [...] Hackers Try to Steal $150,000 from United Way http://www.infosecnews.org/pipermail/isn/2010-February/018736.html InfoSec News: Hackers Try to Steal $150,000 from United Way: http://www.krebsonsecurity.com/2010/02/hackers-try-to-steal-150000-from-united-way/ <br /> By Brian Krebs Krebs on Security February 3rd, 2010 <br /> Hackers broke into computer systems at a Massachusetts chapter of the United Way last month and attempted to make off with more than $150,000 [...] Phishing Scam Cripples European Emissions Trading http://www.infosecnews.org/pipermail/isn/2010-February/018735.html InfoSec News: Phishing Scam Cripples European Emissions Trading: http://www.spiegel.de/international/europe/0,1518,675725,00.html <br /> Spiegel Online 02/03/2010 <br /> Sneaky cyber-thieves have made millions by fraudulently obtaining European greenhouse gas emissions allowances and reselling them. The scam has hampered trading of the credits, which are seen as an important tool in curbing climate change, in several European countries. <br /> Most Internet users are familiar with the e-mail scam known in the jargon as &quot;phishing.&quot; A plausible-looking e-mail arrives in your in-box, supposedly from your bank or a Web site like Ebay, informing you that your account has been &quot;compromised&quot; and that you urgently need to log in to the company's Web site to rectify matters. The catch is that the Web site the e-mail directs you to is a spoof created by the hackers, meaning that anyone who falls for the trick is unwittingly handing over their all-important user names and passwords to the criminals. <br /> Savvy e-mail users know to delete such e-mails straight away. But canny thieves have now used the technique to make money in a very 21st century fashion -- by fraudulently gaining access to companies' greenhouse gas emissions allowances and selling them on. <br /> According to a report in the Wednesday edition of the Financial Times Deutschland, hackers sent e-mails last Thursday to several companies in Europe, Japan and New Zealand which appeared to originate from the Potsdam-based German Emissions Trading Authority (DEHSt), part of the EU's Emission Trading System (EU ETS). Ironically, the e-mail said that the recipient needed to re-register on the agency's Web site to counter the threat of hacker attacks. <br /> [...] <br /> PACAF stands up Information Protection Directorate http://www.infosecnews.org/pipermail/isn/2010-February/018734.html InfoSec News: PACAF stands up Information Protection Directorate: http://www.pacaf.af.mil/news/story.asp?id=123188985 <br /> Pacific Air Forces Public Affairs 2/3/2010 <br /> JOINT BASE PEARL HARBOR HICKAM, Hawaii -- As the cyberspace battlefield broadens, Pacific Air Forces leadership created the Directorate of Information Protection to effectively protect information across the enterprise. <br /> The structure is mirrored at each wing across the area of responsibility. <br /> The organization goal is to provide an enterprise-wide approach to prevent compromises, loss, unauthorized access, disclosure, destruction, distortion or non-accessibility of information over the life cycle of information and ensure commanders have effective processes and the right people in place to provide a focused, seamless, functional and supportive environment for protecting information at all levels to conduct effective air, space and cyberspace operations. <br /> Information protection refers to the collective policies, processes and use of risk management and mitigation actions instituted to prevent the compromise, loss or unauthorized access of information over its life cycle, regardless of physical form or characteristics. <br /> Information protection encompass multiple disciplines and programs, such as Information security, Personnel Security, Industrial Security, Physical Security, Security Education Training, Classification/Declassification management, Original Classification Authority training, Operation Security, Communication Security, Sensitive Compartmental Information, Special Programs, Technical Communication, Foreign Disclosure, Public Release, and Restricted Data. These processes are executed through a collaborative established Security Advisor Groups at each installation. <br /> &quot;We want to change the culture of our personnel and make information protection methodologies routine and transparent to our business processes to correctly protect vital information on behalf of our warfighter,&quot; said Johnny Bland, PACAF/IP director. &quot;Our goal is not only to protect sensitive information, controlled unclassified information and classified information, but to ensure every PACAF personnel understand the importance of protecting information. Information protection affects every PACAF active-duty member, Reservist, Guardsman, civil servant and contract employee, regardless of rank or position. We all have information protection responsibilities.&quot; <br /> Senior leaders all agree that when Information protection staffs are fully mature, they will serve as a single entity to develop and execute policies and procedures to safeguard all levels and types of information using an enterprise-wide approach. <br /> For more information, call DSN 449-2801/2802/2804. <br /> ITL BULLETIN FOR JANUARY 2010 http://www.infosecnews.org/pipermail/isn/2010-February/018733.html InfoSec News: ITL BULLETIN FOR JANUARY 2010: Forwarded from Lennon, Elizabeth B. &lt;elizabeth.lennon (at) nist.gov&gt; <br /> ITL BULLETIN FOR JANUARY 2010 <br /> SECURITY METRICS: MEASUREMENTS TO SUPPORT THE CONTINUED DEVELOPMENT OF INFORMATION SECURITY TECHNOLOGY <br /> Shirley Radack, Editor Computer Security Division Information Technology Laboratory [...] Swiss Banks Achilles Heel Is Workers Selling Data http://www.infosecnews.org/pipermail/isn/2010-February/018732.html InfoSec News: Swiss Banks Achilles Heel Is Workers Selling Data: http://www.bloomberg.com/apps/news?pid=20601109&amp;sid=akmcfUr7TqHs&amp;pos=11 <br /> By Warren Giles Bloomberg.com Feb. 2, 2010 <br /> (Bloomberg) -- Swiss banks are discovering that the biggest threat to client privacy is their own workers. <br /> German Chancellor Angela Merkel said yesterday her government may buy [...] Researchers Uncover Security Vulnerabilities in Femtocell Technology http://www.infosecnews.org/pipermail/isn/2010-February/018731.html InfoSec News: Researchers Uncover Security Vulnerabilities in Femtocell Technology: http://www.eweek.com/c/a/Security/Researchers-Uncover-Security-Vulnerabilities-in-Femtocell-Technology-760682/ <br /> By Brian Prince eWEEK.com 2010-02-01 <br /> Two Trustwave security consultants report they have uncovered hardware and software vulnerabilities in femtocell devices that can be used to [...] Oracle Hacker Gets The Last Word http://www.infosecnews.org/pipermail/isn/2010-February/018730.html InfoSec News: Oracle Hacker Gets The Last Word: http://www.forbes.com/2010/02/02/hacker-litchfield-ellison-technology-security-oracle.html <br /> By Andy Greenberg Forbes.com 02.02.10 <br /> ARLINGTON, Va. -- In 2001, Larry Ellison brashly proclaimed in a keynote speech at the computing conference Comdex that his database software was &quot;unbreakable. [...] At Black Hat, a search for the best response to China http://www.infosecnews.org/pipermail/isn/2010-February/018729.html InfoSec News: At Black Hat, a search for the best response to China: http://www.computerworld.com/s/article/9151018/At_Black_Hat_a_search_for_the_best_response_to_China_?taxonomyId=17 <br /> By Patrick Thibodeau Computerworld February 2, 2010 <br /> ARLINGTON, Va. -- Google's revelation last month that attacks out of China resulted in the theft of some of its data drew attention to the broader question at the Black Hat conference here over what can be done to the villains. <br /> Cyberattacks give rise to anger and a very human desire to strike back, but pursuing attackers in ways that matter isn't accomplishing much. The number of people who are arrested and convicted for any of the phishing attacks, intrusions and thefts is tiny. <br /> Several countries, Russia and China in particular, don't want to cooperate on cybersecurity enforcement, said Andrew Fried, a security researcher at the Internet Systems Consortium, a nonprofit group, and a former special agent at the U.S. Treasury Department. &quot;The reality is they don't want to do squat to help anybody,&quot; he said, on a panel at the cybersecurity conference today. <br /> After an attack, such as the China-Google incident, there's always interest in establishing &quot;attribution&quot; - identifying the source of the attack. But Jeff Moss, the founder of Black Hat and director of the conference, questioned whether too much emphasis is placed on that effort. Moss also serves on the Department of Homeland Security's security advisory council. <br /> &quot;We should be spending more energy on dealing with the containment of an attack, reducing the effects of an attack,&quot; Moss said. &quot;I don't think we will ever be able to stop the attack.&quot; <br /> [...] <br /> Accusations Fly Over Voice Encryption Hack http://www.infosecnews.org/pipermail/isn/2010-February/018728.html InfoSec News: Accusations Fly Over Voice Encryption Hack: http://www.csoonline.com/article/528418/Accusations_Fly_Over_Voice_Encryption_Hack <br /> By John E. Dunn CSO Online February 02, 2010 <br /> German encryption firm SecurStar has strenuously denied being behind an apparently independent test of voice encryption products that found many [...] Hacking for Fun and Profit in China's Underworld http://www.infosecnews.org/pipermail/isn/2010-February/018727.html InfoSec News: Hacking for Fun and Profit in China's Underworld: http://www.nytimes.com/2010/02/02/business/global/02hacker.html <br /> By David Barboza The New York Times February 1, 2010 <br /> CHANGSHA, China -- With a few quick keystrokes, a computer hacker who goes by the code name Majia calls up a screen displaying his latest victims. [...] Cyber threat growing at unprecedented rate, intell chief says http://www.infosecnews.org/pipermail/isn/2010-February/018726.html InfoSec News: Cyber threat growing at unprecedented rate, intell chief says: http://fcw.com/articles/2010/02/02/web--dni-cyber-threat-annual-assessment.aspx <br /> By Ben Bain FCW.com Feb 02, 2010 <br /> Malicious cyber activity is growing at an unprecedented rate, severely threatening the nation's public and private information infrastructure, [...] Homeland Security Plans Cybersecurity, Data Center Investments http://www.infosecnews.org/pipermail/isn/2010-February/018725.html InfoSec News: Homeland Security Plans Cybersecurity, Data Center Investments: http://www.informationweek.com/news/government/security/showArticle.jhtml?articleID=222600862 <br /> By Elizabeth Montalbano InformationWeek February 2, 2010 <br /> The Department of Homeland Security is looking to invest nearly $900 million in fiscal 2011 on technology projects that include bolstering [...] Most consumers reuse banking passwords on other sites http://www.infosecnews.org/pipermail/isn/2010-February/018724.html InfoSec News: Most consumers reuse banking passwords on other sites: http://www.theregister.co.uk/2010/02/02/e_banking_password_fail_survey/ <br /> By John Leyden The Register 2nd February 2010 <br /> The majority of online banking customers reuse their online-banking login credentials on other websites, according to a new survey on password insecurity. [...] THOTCON 0x1 - Chicago's Hacking Conference - Speakers/Talks/Tickets http://www.infosecnews.org/pipermail/isn/2010-February/018723.html InfoSec News: THOTCON 0x1 - Chicago's Hacking Conference - Speakers/Talks/Tickets: Forwarded from: c7five &lt;c7five (at) thotcon.org&gt; <br /> Hello InfoSec News subscribers and friends! <br /> There is a new hacking conference going on in Chicago this year. It is called THOTCON. The name is taken from THree-One-Two + CON. This is a non-profit, non-commercial event. [...]