Pink Floyd star David Gilmour joins fight to halt extradition to US of hacker Gary McKinnon

This isn’t really security news. But I am a big Dave Gilmour fan and I love UFO stories so this is a great story for me.  As far as Gary McKinnon’s actions, I believe if NASA had UFO information they would most likely bury it.  But again hacking is still illegal.

Speaking of mysteries, does anyone remember this Floyd mystery?

~~Dave

PS.. If Mr Gilmour by chance reads this, I am free to jam whenever you are :)

Musicians from such diverse groups as Pink Floyd and Boyzone have joined forces in a last-ditch campaign to halt the extradition to the US of north London computer hacker Gary McKinnon.

The family and friends of McKinnon, who has Asperger’s syndrome, are hoping that a campaign also supported by well-known names including Terry Waite, Boris Johnson, Sting, Lord Carlile and Jane Asher, will finally bear fruit.

Next month, McKinnon is due to have what is likely to be his final legal appearance in a judicial review over the decision of home secretary,Jacqui Smith, to send him to stand trial in the US for hacking into the US defence department and Nasa computer systems in a search for evidence about UFOs.

An earlier judicial review ruled that Smith had failed to take adequate consideration of evidence of McKinnon’s medical condition. If McKinnon failed in this bid for a reconsideration of the extradition decision, he could be sent immediately for trial in the US and face a lengthy jail sentence.

To help the case, Graham Nash has authorised a reworking of his song Chicago, written when he was part of Crosby, Stills and Nash in the wake of the violent 1968 Democratic party convention in Chicago and the subsequent trial of the so-called Chicago Seven.

David Gilmour, the Pink Floyd musician and political activist, has agreed to produce a fresh recording of the song to publicise McKinnon’s plight.

Boyzone singer Keith Duffy has also expressed his support for McKinnon. “As the parent of a child with autism I know only too well that getting support at the right time can be crucial,” said Duffy

http://www.guardian.co.uk/uk/2009/may/25/gary-mckinnon-extradition-pink-floyd-hacker-us

Anti-Virus Sites have XSS vulnerabilties??

XSS flaws found in sites of multiple anti-virus firms

Dirty half-dozen

Security researchers have revealed that the websites of no less than six anti-virus firms are vulnerable to cross-site scripting flaws, of a type that might lend themselves to phishing attacks.

Some of the firms involved have admitted problems, while others say the issues raised have either already been fixed or are erroneous.

Nemesis, a gang of programmers and security bods that work mostly in chat room software development, reckons the sites of Symantec, Kaspersky, Eset (Nod32), AVG, F-secure and Trend Micro are all vulnerable, one way or another. The group has posted screen shots to back up its claims in an advisory here.

El Reg contacted the six firms involved on Monday evening, some of who have already got back to us. We’ll add statements from the others as and when they become available.

  • Trend Micro said the flaw highlighted by Nemesis is on a part of its site which is outsourced. The firm added that the flaw was in the process of getting fixed.
  • Eset said the site with the alleged flaw, eset.co.il, was run by its Israeli distributor. “The iFrame injection has been removed from eset.co.il and today (Tuesday) the site will be deeply scanned to fix all other possible vulnerabilities,” it said in a statement.
  • Symantec said the reported vulnerability on its site was discovered and fixed last month. “Symantec was notified of a reported security vulnerability on a webpage within Symantec’s website back in April,” a spokeswoman explained. “Upon notification of the potential vulnerability, Symantec immediately conducted comprehensive testing and fixed the vulnerability. Symantec takes the security of its website very seriously and can confirm that no company or customer information was exposed.”
  • AVG said there wasn’t any problem with its site. “We’ve investigated the issue as raised by The Register, and we can report that there is no vulnerability on the AVG website. We’re always looking at potential security issues – and extra ways to keep our customers’ data secure. As an internet security company, we often find that we come under attack from the bad guys.”

Broadly speaking the cross-site scripting flaws detailed by the Nemesis make it possible to present rogue iFrames from third-party servers as if they came from the sites of security vendors a surfer might be visiting. This type of vulnerability therefore lends itself to attacks that rely on impersonation, such as phishing. XSS flaws, more generally, also pose cookie stealing and other risks.

This class of vulnerability has popped up on the website of security firms over recent months. Most notable Romanian hacking group HackersBlog exposed XSS flaws on the websites of Kaspersky, BitDefender, F-Secure and Symantec in a two month campaign before the group got bored and disbanded in late March 2009.

Other incidents of similar problems on the websites of McAfee and Symantec have cropped up since to the point where its tempting to think that the problem has become endemic.

In other security-related news, AVG released a fix for a vulnerability involving how its software processes Zip files. An advisory on the flaw, discovered by security researcher Thierry Zoller, can be found here. ®

US Power Infrastructure at risk of an attack

WASHINGTON — Cyberspies have penetrated the U.S. electrical grid and left behind software programs that could be used to disrupt the system, according to current and former national-security officials.

The spies came from China, Russia and other countries, these officials said, and were believed to be on a mission to navigate the U.S. electrical system and its controls. The intruders haven’t sought to damage the power grid or other key infrastructure, but officials warned they could try during a crisis or war.

“The Chinese have attempted to map our infrastructure, such as the electrical grid,” said a senior intelligence official. “So have the Russians.”

The espionage appeared pervasive across the U.S. and doesn’t target a particular company or region, said a former Department of Homeland Security official. “There are intrusions, and they are growing,” the former official said, referring to electrical systems. “There were a lot last year.”

Many of the intrusions were detected not by the companies in charge of the infrastructure but by U.S. intelligence agencies, officials said. Intelligence officials worry about cyber attackers taking control of electrical facilities, a nuclear power plant or financial networks via the Internet.

Authorities investigating the intrusions have found software tools left behind that could be used to destroy infrastructure components, the senior intelligence official said. He added, “If we go to war with them, they will try to turn them on.”

Officials said water, sewage and other infrastructure systems also were at risk.

“Over the past several years, we have seen cyberattacks against critical infrastructures abroad, and many of our own infrastructures are as vulnerable as their foreign counterparts,” Director of National Intelligence Dennis Blair recently told lawmakers. “A number of nations, including Russia and China, can disrupt elements of the U.S. information infrastructure.”

Officials cautioned that the motivation of the cyberspies wasn’t well understood, and they don’t see an immediate danger. China, for example, has little incentive to disrupt the U.S. economy because it relies on American consumers and holds U.S. government debt.

But protecting the electrical grid and other infrastructure is a key part of the Obama administration’s cybersecurity review, which is to be completed next week. Under the Bush administration, Congress approved $17 billion in secret funds to protect government networks, according to people familiar with the budget. The Obama administration is weighing whether to expand the program to address vulnerabilities in private computer networks, which would cost billions of dollars more. A senior Pentagon official said Tuesday the Pentagon has spent $100 million in the past six months repairing cyber damage.

Overseas examples show the potential havoc. In 2000, a disgruntled employee rigged a computerized control system at a water-treatment plant in Australia, releasing more than 200,000 gallons of sewage into parks, rivers and the grounds of a Hyatt hotel.

Last year, a senior Central Intelligence Agency official, Tom Donohue, told a meeting of utility company representatives in New Orleans that a cyberattack had taken out power equipment in multiple regions outside the U.S. The outage was followed with extortion demands, he said.

The U.S. electrical grid comprises three separate electric networks, covering the East, the West and Texas. Each includes many thousands of miles of transmission lines, power plants and substations. The flow of power is controlled by local utilities or regional transmission organizations. The growing reliance of utilities on Internet-based communication has increased the vulnerability of control systems to spies and hackers, according to government reports.

[Chart]

The sophistication of the U.S. intrusions — which extend beyond electric to other key infrastructure systems — suggests that China and Russia are mainly responsible, according to intelligence officials and cybersecurity specialists. While terrorist groups could develop the ability to penetrate U.S. infrastructure, they don’t appear to have yet mounted attacks, these officials say.

It is nearly impossible to know whether or not an attack is government-sponsored because of the difficulty in tracking true identities in cyberspace. U.S. officials said investigators have followed electronic trails of stolen data to China and Russia.

Russian and Chinese officials have denied any wrongdoing. “These are pure speculations,” said Yevgeniy Khorishko, a spokesman at the Russian Embassy. “Russia has nothing to do with the cyberattacks on the U.S. infrastructure, or on any infrastructure in any other country in the world.”

A spokesman for the Chinese Embassy in Washington, Wang Baodong, said the Chinese government “resolutely oppose[s] any crime, including hacking, that destroys the Internet or computer network” and has laws barring the practice. China was ready to cooperate with other countries to counter such attacks, he said, and added that “some people overseas with Cold War mentality are indulged in fabricating the sheer lies of the so-called cyberspies in China.”

Utilities are reluctant to speak about the dangers. “Much of what we’ve done, we can’t talk about,” said Ray Dotter, a spokesman at PJM Interconnection LLC, which coordinates the movement of wholesale electricity in 13 states and the District of Columbia. He said the organization has beefed up its security, in conformance with federal standards.

In January 2008, the Federal Energy Regulatory Commission approved new protection measures that required improvements in the security of computer servers and better plans for handling attacks.

Last week, Senate Democrats introduced a proposal that would require all critical infrastructure companies to meet new cybersecurity standards and grant the president emergency powers over control of the grid systems and other infrastructure.

Specialists at the U.S. Cyber Consequences Unit, a nonprofit research institute, said attack programs search for openings in a network, much as a thief tests locks on doors. Once inside, these programs and their human controllers can acquire the same access and powers as a systems administrator.

NERC Letter

The North American Electric Reliability Corporation on Tuesday warned its members that not all of them appear to be adhering to cybersecuirty requirements. Read the letter.

The White House review of cybersecurity programs is studying ways to shield the electrical grid from such attacks, said James Lewis, who directed a study for the Center for Strategic and International Studies and has met with White House reviewers.

The reliability of the grid is ultimately the responsibility of the North American Electric Reliability Corp., an independent standards-setting organization overseen by the Federal Energy Regulatory Commission.

The NERC set standards last year requiring companies to designate “critical cyber assets.” Companies, for example, must check the backgrounds of employees and install firewalls to separate administrative networks from those that control electricity flow. The group will begin auditing compliance in July.

—Rebecca Smith contributed to this article

http://online.wsj.com/article/SB123914805204099085.html

Ghost in the Hack

Looks like the Chinese are still aggresively attacking anyone and everyone – Dave

 

Computer hackers based in China built up a network of compromised computers in the offices of the Dalai Lama and many other national government offices and organisations around the world, Canadian computer security researchers have revealed.

The network, nicknamed GhostNet, included over 1295 computers belonging to the Tibetan Government in Exile, embassies belonging to countries including India, South Korea and Germany, the Association of Southeast Asian Nations, and the Asian Development Bank.

The investigation was carried out by Information Warfare Monitor (IWM) – an organisation formed by Canadian think tank, the Secdev Group – and a laboratory at the Munk Centre for International Studies, University of Toronto.

Email lure

IWM hacked into the control servers running GhostNet, using information gleaned by University of Cambridge computer scientists Ross Anderson and Shishir Nagaraja, who last year cleaned up computers from the Dalai Lama’s office that had been infected with malicious software, nicknamed malware.

IWM say it is unclear whether the attacks were carried out with the support of the Chinese government, or whether they were the work of isolated hackers. The Chinese government has denied all involvement.

GhostNet is run from 10 servers, IWM says. Most of them are in China – at Hainan, Guangdong, Jiangsu and Sichuan – while two others are in Hong Kong and the mainland United States.

The network uses a Trojan, a program that seems innocuous to the computer user but, when run, a hidden part of it causes harm or allows outside access to a machine. In this case, emails were used to spread the Trojan – called gh0st RAT – either by sending the malware as an attachment or by using a web link to direct a person to a site where it was downloaded.

Targeted attacks

The emails seem to have been carefully crafted to maximise the chances of someone installing the Trojan. For example, the Dalai Lama’s office was infected after a member of staff opened an email that apparently came from the email address “campaigns@freetibet.org” and downloaded a Microsoft Word document that appeared to relate to Tibetan independence.

In recent years, security services have frequently blamed cyber attacks on other governments, although comprehensive proof of their being used in such a way has not been made public. The Pentagon is now investing in greater cyber-defences for the US, while the UN recently added cyber weapons to the list of those considered by its body that advises on weapons of mass destruction.

As a sign of the shifting face of war, NATO last year opened its first “cyber defence centre”, dedicated to protecting its member nations from such attacks

Read more at http://www.newscientist.com/article/dn16862-chinese-spy-network-infiltrated-embassies-worldwide.html