Wednesday, October 7, 2009

Scammers Exploit Public Lists of Hijacked Hotmail Passwords


Scammers have grabbed the Hotmail passwords that leaked to the Web and are using them in a plot involving a fake Chinese electronics seller to bilk users out of cash and their credit card information, a security researcher said today.

"We've seen a 30% to 40% increase in these types of spam messages in the last several days," said Patrik Runald, senior manager of Websense's security research team. "By 'these types of spam,' I mean messages that are advertising great consumer electronics bargains, such as cameras and computers."

The messages shill for a fake electronics retailer in China, and provide a link to its site, said Runald, who added that the ensuing domain looks legitimate enough but is simply a front. "They're offering great deals -- MacBook Pros going for $700, when they really cost $1,200 or $1,500," he said of the bogus retailer.

Consumers duped by the scam have reported on Web forums that they never received the goods they ordered. "There are tons of people posting this," claimed Runald. "But it's just a scam. Not only are they out the money they paid [for the non-existing items], but the scammers have their credit card number, their mailing address and everything else they need to make other purchases with the card."

The link to the Hotmail passwords is circumstantial, admitted Runald, but still credible.

"The increase in spam started as these lists became public knowledge," said Runald, who speculated that the scammers had simply taken advantage of the work of other criminals, grabbing the account information from the Web and then using those compromised accounts to send spam. "Since the lists made it into the public domain, they've been piggybacking," he said, of the scammers.

Another clue that hints at a connection between the spam spike and the hijacked Hotmail passwords is the claim consumers have made that they bit on the bogus China retailer scam because they'd received the messages from friends.

"They're saying that they received these messages from friends," said Runald, "but when they get in touch with that friend, he says 'I lost my account details' in the recent phishing attack. So it makes perfect sense that there's a connection."

New York Times

Citing cybercrime, FBI director doesn't bank online


IDG News Service - The head of the U.S. Federal Bureau of Investigation has stopped banking online after nearly falling for a phishing attempt.

FBI Director Robert Mueller said he recently came "just a few clicks away from falling into a classic Internet phishing scam" after receiving an e-mail that appeared to be from his bank.

"It looked pretty legitimate," Mueller said Wednesday in a speech at San Francisco's Commonwealth Club. "They had mimicked the e-mails that the bank would ordinarily send out to its customers; they'd mimicked them very well."

In phishing scams, criminals send spam e-mails to their victims, hoping to trick them into entering sensitive information such as usernames and passwords at fake Web sites.

Though he stopped before handing over any sensitive information, the incident put an end to Mueller's online banking.

"After changing our passwords, I tried to pass the incident off to my wife ... as a teachable moment," he said. "To which she deftly replied, 'Well, it is not my teachable moment. However, it is our money. No more Internet banking for you."

Mueller said he considers online banking "very safe" but that "just in my household, we don't use it."

Phishing has evolved into a big problem, not just for banks, but for online retailers and even providers of consumer Web applications such as Facebook and Yahoo.

In June -- the latest month for which figures are available -- the Anti-Phishing Working Group counted nearly 50,000 active phishing Web sites, the second-highest number it has ever recorded.

Late last week, criminals posted tens of thousands of passwords belonging to Microsoft Live Hotmail, Gmail, and Yahoo accounts online. They are all thought to have been stolen via phishing.

Computer World

FBI smashes US-Egypt cyber 'phishing' ring


LOS ANGELES — Investigators in the United States and Egypt have smashed a computer "phishing" identity theft scam described as the biggest cyber-crime investigation in US history, officials said Wednesday.

The Federal Bureau of Investigation said 33 people were arrested across the United States early Wednesday while authorities in Egypt charged 47 more people linked to the scam.

A total of 53 suspects were named in connection with the scam in a federal grand jury indictment, the FBI said.

Authorities said the sophisticated identity theft network had gathered information from thousands of victims which was used to defraud American banks.

Wednesday's arrests were the culmination of a two-year probe involving US and Egyptian officials dubbed "Operation Phish Phry."

The investigation was described in statement as the largest cybercrime investigation to date in the United States.

A series of raids early Wednesday resulted in arrests in California, Nevada and North Carolina.

A 51-count US indictment accuses all defendants with conspiracy to commit wire fraud and bank fraud while various defendants are charged with aggravated identity theft and conspiracy to commit computer fraud.

"The sophistication with which Phish Phry defendants operated represents an evolving and troubling paradigm in the way identity theft is now committed," FBI Los Angeles acting assistant director Keith Bolcar said.

"Criminally savvy groups recruit here and abroad to pool tactics and skills necessary to commit organized theft facilitated by the computer, including hacking, fraud and identity theft, with a common greed and shared willingness to victimize Americans."

According to an unsealed indictment, Egyptian-based hackers obtained bank account numbers and personal information from bank customers through phishing, and then hacked into accounts at two unidentified banks.

Once compromised accounts had been accessed, hackers in Egypt contacted conspirators based in the United States via text messages, phone calls and Internet chatrooms to arrange transfer of cash to fraudulent accounts.

"This international phishing ring had a significant impact on two banks and caused huge headaches for hundreds, perhaps thousands, of bank customers," acting US Attorney George Cardona said in a statement.

The investigation comes hard on the heels of a security breach targeting thousands of Microsoft Hotmail accounts.

Cyber-crooks evidently used "phishing" tactics to dupe users of Microsoft's free Web-based email service into revealing account and access information, according to the US technology giant.

AFP

Tuesday, October 6, 2009

Windows Attack Code Out, but Not Being Used



It has been a week since hackers released software that could be used to attack a flaw in Windows Vista and Server 2008, but Microsoft and security companies say that criminals haven't done much with the attack.

Late Monday, Microsoft said it hadn't seen any attacks that used the vulnerability, an analysis that was echoed by security companies such as SecureWorks, Symantec and Verisign's iDefense unit.

While criminals jumped on a similar flaw a year ago, using it in widespread attacks that ultimately forced Microsoft to rush out a security patch ahead of its monthly set of security updates, that hasn't happened with this latest bug, which lies in the SMB v2 software used by Vista and Server 2008 to do file-and-printer sharing.

SecureWorks researcher Bow Sineath said today that there are several reasons why this latest attack has not been picked up. The main reason is probably that the Metasploit code doesn't work as reliably as last year's MS08-067 attack, and often causes the computer to simply crash instead of running the hacker's software.

SMB v2 is typically blocked at the firewall, and it does not ship with Windows XP, meaning that the Metasploit attack will not work on the majority of PCs. Vista, the only Windows client that is vulnerable to the attack, is used on about 19% of computers that surf the Web, according to Web analytics firm Net Applications. Windows XP runs on 72% of PCs.

Because of these factors, the SMB v2 flaw is simply not "all that popular of a target," Sineath said.

Last week, Dave Aitel, CEO of security tool vendor Immunity, predicted that Microsoft would not need to patch the bug ahead of its scheduled Oct. 13 security patch date.

The Metasploit attack makes certain assumptions about the computer's memory that allow it to work in certain hardware configurations, but in many situations, it simply doesn't work, Aitel said.

"I asked the Immunity team to take a look into the new exploit to assess whether Microsoft would patch the SMB v2 bug early, and our initial assessment is 'No, they will not,'" he wrote in a discussion list post last Tuesday. "Working around this issue in the current public exploit is probably two weeks of work. At that point, we're nearing Microsoft Tuesday and the need for an out-of-band patch is moot."

The Metasploit team is still working on its attack, however. On Sunday, Metasploit posted details of a new way of exploiting the bug and said it was working on a module that takes advantage of this so-called trampoline technique.

If the trampoline method works and makes the Metasploit attack more reliable, criminals are likely to start using it, SecureWorks said.

Computer World

Hackers hook Web email users with "phishing" scams


SAN FRANCISCO — Google and Yahoo! on Tuesday joined a growing roster of Web-based email service providers with users duped by hackers into betraying passwords to accounts.

A day after Microsoft blocked access to thousands of Hotmail accounts in response to hackers plundering password information and posting it online, the list of victims was growing to include users of an array of email services.

"We recently became aware of a phishing scheme through which hackers gained user credentials for Web-based mail accounts including a small number of Gmail accounts," Google said in response to an AFP inquiry.

"As soon as we learned of the attack, we forced password resets on the affected accounts. We will continue to force password resets on additional accounts if we become aware of them."

Cyber-crooks evidently used "phishing" tactics to trick users of free Web-based email service into revealing account and access information.

"We are aware that a limited number of Yahoo! IDs may have been made public," Yahoo! said in a statement to AFP. "Online scams and phishing attacks are an ongoing and industry-wide issue."

Time Warner subsidiary AOL, in response to an AFP inquiry, said it is "closely monitoring the situation."

"Our guidance to users is to keep your wits about you: do not click on live links, or insert any details into input fields in emails, pop-ups or Web pages if you are not sure where they come from."

Microsoft said Monday that it learned of the latest problem during the weekend after Hotmail account information of "several thousand" users, many of them reportedly in Europe, was posted at a website.

The unconfirmed list of Hotmail accounts compromised by "phishing" has grown into the tens of thousands.

"We are aware that some Windows Live Hotmail customers' credentials were acquired illegally by a phishing scheme and exposed on a website," Microsoft said. "We have taken measures to block access to all of the accounts that were exposed and have resources in place to help those users reclaim their accounts."

Phishing is an Internet bane and involves using what hackers refer to as "social engineering" to trick people into revealing information online or downloading malicious software onto computers.

Phishing tactics include sending people tainted email attachments that promise enticing content such as sexy photos of celebrities and luring people to bogus log-in pages that are convincing replicas of legitimate websites.

Microsoft, Google, and Yahoo! stressed that hackers did not breach their databases, but rather email users were conned into revealing information.

"Phishing is an industry-wide problem... exercise extreme caution when opening unsolicited attachments and links from both known and unknown sources, and install and regularly update anti-virus software," Microsoft said.

Google advises Gmail users not to "click through" on warnings browsers may raise about certificates nor sign in at Web addresses that don't start with google.com/accounts.

Web-based email users who suspect their accounts have been compromised should change passwords and check to make certain any secondary email or texting options in accounts have not been changed.

"We encourage users to be very careful when asked to share their personal information," Google said.

The email service providers urged people to visit pages at their websites with advice and tools for protecting accounts.

AFP

Monday, October 5, 2009

Hackers expose slew of Hotmail acount passwords


SAN FRANCISCO — Microsoft blocked access to thousands of Hotmail accounts in response to hackers plundering password information and posting it online.

Cyber-crooks evidently used "phishing" tactics to dupe users of Microsoft's free Web-based email service into revealing account and access information, according to the US technology giant.

"We are aware that some Windows Live Hotmail customers' credentials were acquired illegally by a phishing scheme and exposed on a website," Microsoft said in response to an AFP inquiry.

"We have taken measures to block access to all of the accounts that were exposed and have resources in place to help those users reclaim their accounts."

Microsoft said it learned of the problem during the weekend after Hotmail account information of "several thousand" users, many of them reportedly in Europe, was posted at a website.

Phishing is an Internet bane and involves using what hackers refer to as "social engineering" to trick people into revealing information online or downloading malicious software onto computers.

Phishing tactics include sending people tainted email attachments that promise enticing content such as sexy photos of celebrities and luring people to bogus log-in pages that are convincing replicas of legitimate websites.

"This was not a breach of internal Microsoft data," the Redmond, Washington-based technology firm said.

"Phishing is an industry-wide problem ... exercise extreme caution when opening unsolicited attachments and links from both known and unknown sources, and install and regularly update anti-virus software."

Microsoft is also advising Hotmail users to change their account passwords every 90 days

AFP

World War III Could Be Fought on Internet, Says ITU Head


Threats of cyberwar and a story of real violence rubbed shoulders at a news conference to mark the opening of the ITU Telecom World exhibition and forum in Geneva on Monday.

"The next world war could begin in cyberspace," warned Hamadoun Touré, secretary general of the International Telecommunication Union, the United Nations agency that organized the event.

The beginnings of such an unconventional war could be out of the control of conventional diplomacy, he said, because in cyberspace "there is no such thing as a superpower: Every citizen is a superpower." With an army of "bots," or compromised computers, at their command, almost anyone could wield great power in a virtual battle, as a number of recent denial-of-service attacks against targets around the world have shown.

"We know from conventional wars that the best way to win is not to start," Touré said.

That's why the ITU is pushing an ambitious worldwide program for cybersecurity and peace.

"By the end of next year, we will broker a global agreement with every country to protect its citizens online, not to harbor cyberterrorists, and not to start an online attack," he said.

U.N. Secretary General Ban Ki-moon began by expressing his sorrow at news of an all-too-real attack, the suicide bombing earlier in the day of the Islamabad, Afghanistan, office of the U.N. Food and Agriculture Organization, which left several people dead.

Returning to the theme of the conference, he highlighted "a world divided," those with access to information on one side, and those without on the other.

Encouraging the participation of "our youth, drivers of innovation and change," is vital if those divisions are to be eradicated, he said.

Investment in infrastructure and services must be encouraged too in order to eliminate the technology divide -- but the motive should be profit, not charity, Touré said.

"In our strategy of connecting the world, we have no need for charity: It's pure business. If you have the right business plan, you will have investment," he said.

The telecommunications industry will always have investment, because it's a profitable industry, he said.

That's turning out to be the case in Rwanda, said President Paul Kagame, where state infrastructure projects have attracted investment from Chinese network equipment manufacturers.

"The availability of capital for everything is getting more and more scarce, but in our country there is a strong partnership between public and private sectors," he said.

China continues to invest internationally, despite the impact of the global economic crisis and the attraction of the untapped potential of its home market, said Wang Jianzhou, chairman and chief executive officer of China Mobile, also present at the news conference.

"We have still got challenges from the international financial crisis," he said. In the company's home market, revenue from international calls is down 20 percent because of a reduction in tourism and manufacturing exports, he said.

PC World