Wednesday, April 28, 2010

SKMM terima 165 aduan terhadap laman web

KUALA LUMPUR 28 April - Suruhanjaya Komunikasi dan Multimedia (SKMM) menerima 165 aduan dalam tempoh Januari hingga Mac tahun ini berhubung kandungan laman web atau blog yang melakukan pelbagai kesalahan di bawah Akta Komunikasi dan Multimedia (AKM) 1998.

Timbalan Menteri Penerangan Komunikasi dan Kebudayaan, Datuk Joseph Salang Gandum berkata, daripada jumlah tersebut, 90 aduan adalah bagi kandungan lucah, 72 kandungan bersifat mengancam atau jelik dan tiga aduan bagi kandungan berunsur palsu.

"Bagi kandungan bersifat lucah, tindakan siasatan dan sekatan akan dilakukan.

"Selain itu, laporan penyalahgunaan juga akan dihantar kepada moderator laman-laman web sosial seperti Facebook, blogspot dan YouTube," katanya ketika menjawab soalan Datuk Zaitun Mat di Dewan Negara hari ini yang bertanyakan jumlah aduan yang diterima SKMM berhubung kandungan laman web atau blog mengikut AKM 1998.

Katanya, bagi kandungan bersifat mengancam dan jelik serta kandungan palsu pula, nasihat dan amaran akan dikenakan oleh SKMM kepada pemilik laman-laman berkenaan dan sekiranya cukup bukti bagi mensabitkan kesalahan, pendakwaan boleh dikenakan terhadap pihak tersebut.

Menjawab soalan tambahan Fatimah Hamat yang ingin tahu langkah kerajaan dalam menangani laman web lucah yang mudah dilayari di kafe siber, Joseph Salang berkata,SKMM setakat ini telah menutup serta-merta 81 laman web yang didapati menerapkan unsur lucah seperti menyediakan video aksi lucah dan perkongsian cerita lucah dengan teman berbual.

"Ada antara laman web sosial yang turut mengandungi elemen lucah walaupun telah mendapat aduan tetapi tidak dapat diambil tindakan memandangkan moderator laman web tersebut mendapati ia dianggap tidak lucah disebabkan oleh faktor budaya negara masing-masing," katanya. - BERNAMA

Sumber Capaian : http://www.utusan.com.my/utusan/info.asp?y=2010&dt=0429&pub=Utusan_Malaysia&sec=Dalam_Negeri&pg=dn_19.htm

Google dedah program keselamatan palsu

SAN FRANCISCO 28 April - Google semalam berkata, program keselamatan palsu yang menjangkiti komputer kini merupakan ancaman dalam talian yang semakin berleluasa, dengan penggodam memperdaya pengguna untuk memasukkan kod perosak.

Satu analisis ke atas 240 juta laman web oleh gergasi Internet ini sejak 13 bulan lalu mendedahkan bahawa program antivirus palsu merupakan 15 peratus daripada perisian perosak yang dikesan.

"Ancaman antivirus palsu semakin meningkat. Jelas terdapat trend peningkatan dalam jumlah domain antivirus palsu yang ditemui setiap minggu," demikian menurut Google.

Penyebar program palsu ini menggodam laman web dengan menakut-nakutkan pengguna melalui mesej pop-up yang memberi amaran imbasan menemui perisian perosak dalam komputer.

Penipuan berlanjutan dengan penjualan program yang didakwa membantu menyelesaikan masalah tetapi sebenarnya 'menanam' kod perosak dalam komputer terlibat.

Transaksi sedemikian juga berisiko menyebabkan kebocoran maklumat kad kredit ke tangan penjenayah Internet.

Lebih mengejutkan, ramai mangsa terpedaya dan membayar untuk mendapatkan antivirus palsu. - AFP

Apa yang lebih teruk, ia biasanya dicampurkan dengan perisian perosak lain yang kekal di dalam komputer sama ada bayaran dibuat atau tidak," kata Google.

Google kini mengemaskini peralatan untuk menapis laman web berisiko dan penggodam biasanya akan bertindak menukar tempat dari satu nama domain ke domain lain. - AFP


sumber : http://www.utusan.com.my/utusan/info.asp?y=2010&dt=0429&pub=Utusan_Malaysia&sec=Luar_Negara&pg=lu_09.htm


Monday, April 26, 2010

Mobile Phone Hacking for £1000

Nigel Stanley By: Nigel Stanley, Practice Leader - IT Security, Bloor Research
Published: 21st April 2010
Copyright Bloor Research © 2010


History was made the other evening when the UK's three wannabe prime ministers took centre stage for a TV debate. This was the culmination of weeks of rehearsals, practice runs and body language training.

But what if I then tell you that every mobile phone call made by one of the campaign teams preparing for this TV event was secretly recorded and analysed, enabling their rival to understand everything from the campaign strategy through to the likely rebuttal to a particular question?

Illegal? Of course. Farfetched? No longer.

The past few months has seen the mobile phone industry thrown into turmoil as the computer hacking community has carried out successful attacks against mobile phone call security. I wrote an article about such a hack a while back, but at that point it remained a theory rather than a practical way to listen into mobile phone calls.

In this article I commented that the best way of getting access to mobile phone calls was to setup a fake base station, something that has historically been difficult and expensive. Little did I know that within 4 months we would have a practical mobile phone hacking kit, using off the shelf equipment and a fake base station, for around £1000. Not only that but the software needed to run the hack is available as a neatly packaged CD—free of charge.

There is even a video demonstration of the hack available here

Government agencies have had capabilities to listen into mobile phone calls for years, by tapping the insecure and unencrypted landlines that run from cellular base stations back to the exchanges and beyond. This new hack is different as it enables a criminal to set up a false mobile phone base station, capturing all phone calls within the vicinity, at very low cost.

It relies on a feature of mobile phones that forces them to automatically link into the closest base station to conserve their battery power. By setting up a false base station close to your intended target, hackers can capture the victim's phone signals. This type of intercept tool, called an IMSI catcher, has been around for a number of years but only available to approved government agencies and at a cost of hundreds of thousands of pounds.

Now a standard PC running the OpenBTS software GSM base station, an Asterisk PBX to link calls into the public phone network and a software defined radio receiver black box is all you need to capture these same phone calls.

For many people the only risk of their mobile phone conversation being intercepted was when they decided to bellow into their phone on a crowded train. Now we all need to face the fact that our calls can be intercepted with little effort.

Those that use mobile phones believing they are secure should think again, be they wannabe prime ministers, captains of industry or anyone else who shares confidential information via the mobile phone.


credit to : http://www.it-director.com/business/security/content.php?cid=12039

Wednesday, March 31, 2010

Conficker Infection

Thanks to Joe Stewart from SecureWorks for his awesome work.

Check for Infection


Introduction

Conficker, also known as Downup, Downandup, Conflicker, and Kido, is a computer worm that surfaced November 21st, 2008 with Conficker.A and targets the Microsoft Windows operating system. The worm exploits a known vulnerability (MS08-067) in the Windows Server service used by Windows 2000, Windows XP, Windows Vista, Windows Server 2003, Windows Server 2008, and Windows 7 Beta. The latest variant (Conficker.C) will begin checking for a payload to download on March 31st, 2009. Conficker.A and Conficker.B variants continue to check for payloads each with a distinct domain generation algorithm.
Operation

The Conficker worm spreads itself primarily through a buffer overflow vulnerability in the Server Service on Windows computers. The worm uses a specially crafted RPC request to execute code on the target computer.

When executed on a computer, Conficker disables a number of system services such as Windows Automatic Update, Windows Security Center, Windows Defender and Windows Error Reporting.

It receives further instructions by connecting to a server or peer and receiving a binary update. The instructions it receives may include to propagate, gather personal information and to download and install additional malware onto the victim's computer. The worm also attaches itself to certain Windows processes such as svchost.exe, explorer.exe and services.exe.

The worm seems to implement some of the ideas presented by Fucs, Paes de Barros e Pereira at the Blackhat Briefings Europe 2007, specifically: digitally signed additional payload, use of PRNG for communication and P2P communication.
Payload

The "A" and "B" variants of Conficker will create an HTTP server and open a random port between 1024 and 10000. If the remote machine is exploited successfully, the victim will connect back to the HTTP server and download a worm copy. It will also reset System Restore points, and download files to the target computer.
Symptoms of infection

* Account lockout policies being reset automatically.
* Certain Microsoft Windows services such as Automatic Updates, BITS, Windows Defender, and Error Reporting Services are automatically disabled.
* Domain controllers respond slowly to client requests.
* System network gets unusually congested. This can be checked with network traffic chart on Windows Task Manager.
* On websites related to antivirus software, Windows system updates cannot be accessed.
* Launches a brute force attack against administrator passwords to help it spread through ADMIN$ shares, making choice of sensible passwords advisable.
* Port 445/TCP scanning (A/B)
* Multicast UPnP requests
* High-port TCP and UDP P2P Activity
* Abnormal DNS lookup activty

Impact

Experts say it is the worst infection since the SQL Slammer. Estimates of the number of computers infected range from almost 9 million PCs to 15 million computers, however a conservative minimum estimate is more like 3 million which is more than enough to cause great harm.

Another anti-virus software vendor, Panda Security, reported that of the 2 million computers analyzed through ActiveScan, around 115,000 (6%) were infected with this malware.

The potential scale of infection is large because 30 percent of Windows computers do not have the Microsoft Windows patch released in October 2008 to block this vulnerability.

The U.K. Ministry of Defence reported that some of its major systems and desktops were infected. The worm has spread across administrative offices, NavyStar/N* desktops aboard various Royal Navy warships and Royal Navy submarines, and Hospitals across the city of Sheffield reported infection of over 800 computers.

On February 1, 2009, Schools in the town of Rochdale, England were infected. The virus spread to 13 schools estimated to have infected 7,500 computers.

On February 13, the Bundeswehr reported that some hundred of their computers were infected.

On March 27, 2009, the British Director of Parliamentary ICT released a (leaked) memo stating that the House of Commons computer network has been infected with the virus and called for all people who have access the network to use caution and to not connect any unauthorized equipment to the network.
Response

On February 12, 2009, Microsoft announced the formation of a technology industry collaboration to combat the effects of Conficker. Organizations involved in this collaborative effort include Microsoft, Afilias, ICANN, Neustar, Verisign, CNNIC, Public Internet Registry, Global Domains International, Inc., M1D Global, AOL, Symantec, F-Secure, ISC, researchers from Georgia Tech, The Shadowserver Foundation, Arbor Networks and Support Intelligence.

As of February 13, 2009, Microsoft is offering a $250,000 USD reward for information leading to the arrest and conviction of the criminals behind the creation and/or distribution of Conficker.
Patching and removal

On 15 October 2008 Microsoft released a patch (MS08-067) to fix the vulnerability. Removal tools are available from Microsoft, BitDefender, ESET, Symantec, Sophos, and Kaspersky Lab, while McAfee and AVG can remove it with an on-demand scan. While Microsoft has released patches for the later Windows XP Service Packs 2 and 3 and Windows 2000 SP4 and Vista, it has not released any patch for Windows XP Service Pack 1 or earlier versions (excluding Windows 2000 SP4), as the support period for these service packs has expired. Since the virus can spread via USB drives that trigger AutoRun, disabling the AutoRun feature for external media (through modifying the Windows Registry) is recommended. However the United States Computer Emergency Readiness Team describe Microsoft's guidelines on disabling Autorun as being "not fully effective," and they provide their own guides. Microsoft has released a removal guide for the worm via the Microsoft website.

Also, on March 16, 2009, BitDefender released an updated tool to remove the already famous Downadup/Conficker worm on a new domain that has not been blocked by the malicious computer code at a website called "bdtools.net", it also comes as a separate installer dedicated to network administrators. In this way, the scanner can be dispatched throughout networks in order to remotely scan and disinfect workstations.

Refer to Wikipedia for reference URLs http://en.wikipedia.org/wiki/Conficker

Text adapted from Wikipedia: All text on this page is available under the terms of the GNU Free Documentation License

Source : http://www.confickerworkinggroup.org/wiki/

Check for infection : http://www.confickerworkinggroup.org/infection_test/cfeyechart.html

Credit to : http://www.confickerworkinggroup.org/wiki/

Sunday, March 28, 2010

Ramai tak peka risiko jenayah siber

Oleh Suzan Ahmad
suzan@bharian.com.my
2010/03/28
Pengguna internet hari ini turut jadi mangsa peras ugut, bunuh

KECANGGIHAN teknologi bukan sekadar memudahkan urusan seharian, ia turut membawa kesan yang perlu dibayar dengan harga mahal.
Tidak ramai tahu perbandingan nisbah kebarangkalian jenayah siber kini pada tahap 1:5 berbanding jenayah pecah rumah hanya 1:30. Sememangnya membimbangkan, namun ia tidak diberikan perhatian sepatutnya atas alasan kita tidak melihat penjenayah siber. Tanpa kita sedar peningkatan mendadak jumlah pengguna ruang siber yang berinteraksi di laman sosial seperti Facebook, Friendster dan Twitter sebenarnya antara punca meningkatkan lagi risiko menjadi mangsa jenayah siber.

Mengikut statistik Symantec Norton Security Response, syarikat yang menawarkan perlindungan, penyimpanan dan pengurusan sistem penyelesaian komputer global, jenayah siber berlaku setiap 0.25 saat di seluruh dunia yang meliputi peras ugut, ancaman virus, angkara penggodam, phising, jangkitan anti-spyware dan malware.

Pengguna ruang siber kini bergantung kepada teknologi untuk membolehkan mereka berkongsi fail, foto dan muzik pada bila-bila masa daripada sebarang alat telekomunikasi.

Masalah mula timbul apabila kecenderungan pengguna mengejar kepantasan teknologi siber tidak setara dengan kesedaran untuk melindunginya daripada diceroboh penjenayah siber.
Kelemahan ini ditambah dengan jangkaan peningkatan penggunaan smartphone yang menguasai hampir separuh jualan telefon mudah alih dunia seperti Android, iPhone dan iPad pada 2013.

Hakikatnya, dalam masa empat minit saja selepas dihubungkan ke internet, sebuah komputer peribadi yang tidak berperisai akan dijangkiti virus dengan mudah.
Malah, setiap tiga saat pengguna laman siber akan hilang kata laluan, maklumat kad kredit, maklumat bank dan pelbagai maklumat lain.

Ketua Perniagaan Norton (Rantau Asia Selatan), Effendy Ibrahim, berkata pemantauan aktiviti internet yang dilakukan baru-baru ini menyerlahkan, dalam masa 24 jam selepas kejadian tsunami di Chile dan gempa bumi di Haiti, pelbagai laman web bertujuan mengutip derma dibangunkan, sedangkan laman web ini mengandungi banyak perisian palsu yang cuba memporak-perandakan dan mencuri data peribadi pengguna ruang siber.

“Insiden terbaru berlaku di Jakarta, Indonesia dan masih dalam siasatan membabitkan seorang gadis yang berkenalan dengan seorang lelaki di Facebook diajak bertemu atas alasan lelaki itu sakit tenat.

“Atas dasar simpati, gadis itu bersetuju dan pergi ke tempat yang dijanjikan. Malangnya selepas gagal memperkosanya, dia membunuh gadis itu.

“Dek ghairah dan mudahnya mendapat ramai kawan tanpa perlu bertentang mata di laman sosial, ternyata menarik pengguna ruang siber untuk terus berkomunikasi menggunakan pengantara ini sehingga terlalu selesa dan percaya untuk berkongsi maklumat peribadi, foto, video dan data,” katanya yang mengakui pengguna internet lebih ramai kawan di laman sosial berbanding di alam nyata.

Sementara itu, Ketua Perbankan Virtual Maybank, Choong Wai Hong, berkata 1,200 kes penipuan perbankan internet dikesan dalam tempoh Januari hingga Jun tahun lalu yang merangkumi 0.003 peratus daripada jumlah nilai transaksi membabitkan RM348.5 bilion, membabitkan kerugian RM1 juta.

Beliau berkata, walaupun peratusan kerugian masih rendah berbanding jenayah kewangan lain, ancaman itu tidak harus dipandang rendah.

“Kita perlu melihatnya dari perspektif lebih meluas dengan bilangan pelanggan perbankan internet semakin meningkat, oleh itu kami perlu mengimbanginya dengan menjadi lebih peka kepada segala bentuk ancaman,” katanya.

Mengikut pengalaman Maybank, katanya, 72 peratus jenayah siber yang dilapor membabitkan kecuaian pelanggan seperti mendedahkan kata laluan dan maklumat peribadi secara sedar.

Untuk mengatasinya, Maybank menjalin usaha sama dengan firma keselamatan bagi mengesan secara proaktif serta menangani kes penipuan, menjalin kerjasama rapat sesama bank, meningkatkan perkhidmatan keselamatan dan bekerjasama dengan polis, selain menganjurkan kempen kesedaran awam.

Cybersecurity, agensi di bawah Kementerian Sains, Teknologi dan Inovasi mengakui isu keselamatan yang dihadapi pengguna komputer dan internet meningkat berikutan penggunaan teknologi jalur lebar yang bertambah.

“Lebih 700 kes dilaporkan kepada Cyber999 sehingga Februari tahun ini manakala sepanjang tahun lalu mencecah 3,600 kes,” kata Ketua Pusat Bantuan Tindak Balas Kecemasan Komputer MyCert dan Cyber999, Adli Abdul Wahid.

Beliau berkata, dalam tempoh tiga bulan, MyCert mengesan 75 serangan virus melalui komputer atau e-mel. Walaupun jumlah itu mungkin kecil, impak buruknya mampu menjangkiti 1.6 juta komputer di Malaysia.

INFO
Jenayah siber

# Nisbah kebarangkalian jenayah siber kini pada tahap 1:5 berbanding jenayah pecah rumah hanya 1:30.

# Jenayah siber berlaku setiap 0.25 saat di seluruh dunia yang meliputi peras ugut, ancaman virus, angkara penggodam, phising, jangkitan anti-spyware dan malware.

# Setiap tiga saat pengguna laman siber akan hilang kata laluan, maklumat kad kredit, maklumat bank dan pelbagai maklumat lain.

# 1,200 kes penipuan perbankan internet dikesan dalam tempoh Januari hingga Jun tahun lalu yang merangkumi 0.003 peratus daripada jumlah nilai transaksi membabitkan RM348.5 bilion, membabitkan kerugian RM1 juta.

Sumber : http://www.bharian.com.my/bharian/articles/Ramaitakpekarisikojenayahsiber/Article

Kredit : http://www.bharian.com.my/

Monday, March 22, 2010

Research reveals 1 in 4 children have tried hacking

19 March 2010

A study just published claims to show that, although 78% of children knowing that hacking it is wrong, one in four of them have tried hacking into other people's Facebook accounts.

The survey, from Tufin Technologies, says that 47% of those admitting Facebook hacking guilt are girls. The study of 1000 youngsters from London and 150 from Cumbria found that, although 27% were doing so from the relatively safe confines of their bedrooms, 22% are using internet cafes and 21% are hacking from school. Interestingly, 19% of respondents to the survey also said they had used a friend's computer to hack.

The most common reason was for fun (46%); however, 21% aimed to cause disruption and a resourceful 20% thought they could generate an income from the activity. A small minority (5%) said they were switching to the dark side as a career move.

The survey, which was undertaken in conjunction with Cumbria Constabulary, found that a good third of respondents had fallen victim to hackery, having had their Facebook or email accounts broken into without authorisation.

Researchers also found that Cumbrian children with hacking habits were much younger than their city counterparts, with 78% having done so before their 13th birthday – in London 44% were under 16, with only 16% of these yet to enter their teens.

Delving into the survey results reveals that 27% of the kids who were hacking admitted they were caught. 82%, meanwhile, confessed that hacking wasn't actually that easy in practice, and a commendable 70% labelled the practice as uncool.

Stuart Hyde, deputy chief constable with Cumbria Constabulary, said that what this survey highlights is that hacking into personal online accounts, whether email or Facebook, can be child's play if users do not protect their own passwords.

"It illustrates the importance of keeping your passwords strong, secure and changing them regularly to help protect your accounts from unscrupulous people of all ages", he said.

"We live in a world where social networking, email and the internet are embedded into our every day lives from a far younger age, so early education is essential to ensure young people know the devastating consequences this activity can have", he added.

Only 53% of the children surveyed felt that hacking was illegal, which shows there is a real need to educate youngsters to the dangers, both so they are deterred from trying it and also so they know how to protect their own accounts.

Commenting on the results, Reuven Harrison, CTO of Tufin Technologies, said that one of the most worrying statistics from this survey is the staggering numbers of kids that are successful and the ages involved. "Hacking has changed a lot in the past few years from the curiosity or fun factor to now making serious money or causing havoc in the corporate environment", he said.

"Our job as IT security professionals is to stop hackers in their tracks and that means educating the kids, as the police have said, at a very young age", he added.


source of news : http://www.infosecurity-magazine.com/view/8208/research-reveals-1-in-4-children-have-tried-hacking/

credit to : www.infosecurity-magazine.com