Home » Security » Recent Articles:

TSA Data Analyst Planned Cyber Attack

March 13, 2010 Security, crime 1 Comment

A former Transportation Security Administration contractor is being charged in Colorado for allegedly injecting malicious code into a government network used for screening airport security workers and others.

The malicious code, a logic bomb installed last October, was designed to cause damage and disrupt data on servers on an undisclosed date but was caught by other workers before it delivered its payload.

denver airport security

denver airport security

Douglas James Duchak, 46, had worked as a data analyst at the TSA’s Colorado Springs Operations Center, or CSOC, since 2004. The CSOC is used to vet people who have “access to sensitive information and secure areas of the nation’s transportation network,” according to the indictment. A source involved in the case said this involved screening of both passengers and workers at airports and other transportation facilities.

He pleaded not guilty in a Denver federal court on Wednesday and was released on a $25,000 unsecured bond. The indictment did not say whether the malware was crafted to erase or alter data, or simply disable servers.

The CSOC network stores updated information from the government’s terrorist watchlist as well as criminal histories from the U.S. Marshal’s Service Warrant Information Network.

Duchak’s job was to update the CSOC database as new information arrived from these two sources. But on Oct. 15, he was given two weeks’ notice that his job would be terminated.

About a week later, on Oct. 22, Duchak allegedly transmitted the malicious code onto a CSOC server that stored data from the U.S. Marshal’s Service, according to the indictment (.pdf). The next day, he allegedly loaded malicious code to a server containing the Terrorist Screening Database. The source involved in the case said the servers “are part of the system that contains the no-fly list” and added that the code, if it had gone undetected, could have traveled to a facility in another state that uses a similar computer system.

Duchak has been charged in the U.S. District of Colorado with two counts of attempting to cause damage to a protected computer. If convicted, he faces a possible prison sentence of 10 years and a $250,000 fine for each count.

Duchak’s attorney, David Lindsey, disputes the government’s charges and says that the system Duchak worked on was a beta system used for testing statistical analyses.

“It wasn’t connected to anything that had to do with security,” Lindsey said. “Before anything he had his hands on left, it went to another system before it got into any live system that did screening. As I understand it, it is a system that does statistical analyses on the systems that are up and running. And when the tests are run, those are done at one level and then [go to] a second level and then at a final level before the analyses are verified and passed onto anything you would call a live system.”

Lindsey said the CSOC servers that were allegedly targeted for sabotage were used for screening workers primarily and were only “remotely, remotely” related to passenger screening, though he could not elaborate.

“The government has been very misleading in the indictment and press release as to any potential harm [this might have caused] to the public,” he said, adding that the alleged malware was not a virus and will ultimately be shown to have been “nothing.”

Lindsey said that his client was not given a clear answer about why he was let go from his job.

Biggest Threat to an Open Internet: U.S. Intelligence Community

The biggest threat to the open internet is not Chinese government hackers or greedy anti-net-neutrality ISPs, it’s Michael McConnell, the former director of national intelligence.

mcconnell DNI

McConnell

McConnell’s not dangerous because he knows anything about SQL injection hacks, but because he knows about social engineering. He’s the nice-seeming guy who’s willing and able to use fear-mongering to manipulate the federal bureaucracy for his own ends, while coming off like a straight shooter to those who are not in the know.

When he was head of the country’s national intelligence, he scared President Bush with visions of e-doom, prompting the president to sign a comprehensive secret order that unleashed tens of billions of dollars into the military’s black budget so they could start making firewalls and building malware into military equipment.

And now McConnell is back in civilian life as a vice president at the secretive defense contracting giant Booz Allen Hamilton. He’s out in front of Congress and the media, peddling the same Cybaremaggedon! gloom.

And now he says we need to re-engineer the internet.

We need to develop an early-warning system to monitor cyberspace, identify intrusions and locate the source of attacks with a trail of evidence that can support diplomatic, military and legal options — and we must be able to do this in milliseconds. More specifically, we need to re-engineer the Internet to make attribution, geo-location, intelligence analysis and impact assessment — who did it, from where, why and what was the result — more manageable. The technologies are already available from public and private sources and can be further developed if we have the will to build them into our systems and to work with our allies and trading partners so they will do the same.

Re-read that sentence. He’s talking about changing the internet to make everything anyone does on the net traceable and geo-located so the National Security Agency can pinpoint users and their computers for retaliation if the U.S. government doesn’t like what’s written in an e-mail, what search terms were used, what movies were downloaded. Or the tech could be useful if a computer got hijacked without your knowledge and used as part of a botnet.

The Washington Post gave McConnell free space to declare that we are losing some sort of cyberwar. He argues that the country needs to get a Cold War strategy, one complete with the online equivalent of ICBMs and Eisenhower-era, secret-codenamed projects. Google’s allegation that Chinese hackers infiltrated its Gmail servers and targeted Chinese dissidents proves the United States is “losing” the cyberwar, according to McConnell.

But that’s not warfare. That’s espionage.

McConnell’s op-ed then pointed to breathless stories in The Washington Post and The Wall Street Journal about thousands of malware infections from the well-known Zeus virus. He intimated that the nation’s citizens and corporations were under unstoppable attack by this so-called new breed of hacker malware. … Continue Reading

Pentagon, DHS Turn Up Media Hype

February 24, 2010 Security, terrorism 1 Comment

Napolitano

On Issues of Domestic Terrorism and Cyber Security we have seen a rash of blatant over the top Pentagon fed news pieces and headlines into the main stream media with in this last week.

For example on Monday Department of Homeland Security (DHS) Janet Napolitano said that  “She is afraid of Americans” announcing that Domestic Terrorism is the Homelands Chief threat to the security of the United States.

Every major news outlet and the local networks in the nation ran unthinkingly with the Headline:

Homeland Chief: Domestic extremism is top concern

See headline search results:

“The government is just starting to confront this reality and does not have a good handle on how to prevent someone from becoming a violent extremist, she said.

In the last year, Napolitano said, she’s witnessed a movement from international extremism to domestic extremism – cases in which Americans radicalized and decided to plot attacks against the country.

“What really is it that draws a young person being raised in the United States to want to go and be at a camp in Yemen and then come back to the United States with the idea of committing harm within the United States?” Napolitano asked without citing specific cases. “Where in that person’s formulation is there an opportunity to break that cycle?”

The DHS head embarrassingly cites the accused “underwear bomber” Umar Farouk Abdulmutallab, who according to witnesses was lead onto the plan by a sharply dressed accomplice who turned out to be an intelligence operative part of a larger operation according to a Detroit Newspaper.

“Patrick F. Kennedy, an undersecretary for management at the State Department, said Abdulmutallab’s visa wasn’t taken away because intelligence officials asked his agency not to deny a visa to the suspected terrorist over concerns that a denial would’ve foiled a larger investigation into Al-Qaeda threats against the United States.

“Revocation action would’ve disclosed what they were doing,” Kennedy said in testimony before the House Committee on Homeland Security. Allowing Adbulmutallab to keep the visa increased chances federal investigators would be able to get closer to apprehending the terror network he is accused of working with, “rather than simply knocking out one solider in that effort.”

Underwear Bomber

Yet despite this statement on record from Mr. Kennedy before the House Committee on Homeland Security, DHS upgrades their threat assessment on the American public over that of the international threat of Al-Qaeda.
It shows that DHS is intent on demonizing Americans in a fear campaign rather than a fact campaign, and the headlines reflect it. Most Americans are to busy working 2-3 jobs and have their hands around the remote control of their T.V. rather than a finger on an AR-15 or a detonator.
The obvious incident to cite would be the airplane Joe Stack piloted  into the IRS building in Austin, Texas this last week. This is strangely absent from Napolitano’s list of examples during this meeting even after Mr. Stack’s own daughter called him a Hero, for this desperate act that  caused his death and one other.
Maybe they foresee Joe 6-pack angrily getting off the couch due to economic fall out in the near future is the real cause for DHS alarm.
CNN Fakes Media Cyber-War
Another example of the Pentagon take over of the media, would be the fake cyber-terror broadcast done by CNN recently in which they acted out the scenario of hackers taking down the entire electrical grid of the nation on live television.

It has been reported that bloggers and media pieces have been purchased by the U.S. government to help shape our perspectives in regards to domestic terrorism. This time taking it one step further they simply bought out an entire network news broadcast from CNN to fear-monger the Nation with.

Amusingly enough it turns out it is ‘fear and hype’ that even the Pope seemingly has had a hard time buying into by criticizing the use of body scanners recently.

Massive Cyber Attacks Uncovered

February 19, 2010 Security, Technology 1 Comment

More than 75,000 computer systems at nearly 2,500 companies in the United States and around the world have been hacked in what appears to be one of the largest and most sophisticated attacks by cyber criminals discovered to date, according to a northern Virginia security firm.

The attack, which began in late 2008 and was discovered last month, targeted proprietary corporate data, e-mails, credit-card transaction data and login credentials at companies in the health and technology industries in 196 countries, according to Herndon-based NetWitness.

News of the attack follows reports last month that the computer networks at Google and more than 30 other large financial, energy, defense, technology and media firms had been compromised. Google said the attack on its system originated in China.

This latest attack does not appear to be linked to the Google intrusion, said Amit Yoran, NetWitness’s chief executive. But it is significant, he said, in its scale and in its apparent demonstration that the criminal groups’ sophistication in cyberattacks is approaching that of nation states such as China and Russia.

The attack also highlights the inability of the private sector — including industries that would be expected to employ the most sophisticated cyber defenses — to protect itself.

“The traditional security approaches of intrusion-detection systems and anti-virus software are by definition inadequate for these types of sophisticated threats,” Yoran said. “The things that we — industry — have been doing for the past 20 years are ineffective with attacks like this. That’s the story.”

The intrusion, first reported on the Wall Street Journal’s Web site, was detected Jan. 26 by NetWitness engineer Alex Cox. He discovered the intrusion, dubbed the Kneber bot, being run by a ring based in Eastern Europe operating through at least 20 command and control servers worldwide.

The hackers lured unsuspecting employees at targeted firms to download infected software from sites controlled by the hackers, or baited them into opening e-mails containing the infected attachments, Yoran said. The malicious software, or “bots,” enabled the attackers to commandeer users’ computers, scrape them for log-in credentials and passwords — including to online banking and social networking sites — and then exploit that data to hack into the systems of other users, Yoran said. The number of penetrated systems grew exponentially, he said.

“Because they’re using multiple bots and very sophisticated command and control methods, once they’re in the system, even if you whack the command and control servers, it’s difficult to rid them of the ability to control the users’ computers,” Yoran said.

The malware had the ability to target any information the attackers wanted, including file-sharing sites for sensitive corporate documents, according to NetWitness.

Login credentials have monetary value in the criminal underground, experts said. A damage assessment for the firms is underway, Yoran said. NetWitness has been working with firms to help them mitigate the damage.

Among the companies hit were Cardinal Health, located in Dublin, Ohio, and Merck, according to the Wall Street Journal. A spokesman for Cardinal said the firm removed the infected computers as soon as the breach was found.

Also affected were educational institutions, energy firms, financial companies and Internet service providers. Ten government agencies were penetrated, none in the national security area, NetWitness said.

The systems penetrated were mostly in the United States, Saudi Arabia, Egypt, Turkey and Mexico, the firm said.

China’s Computer Equipment Threat

February 8, 2010 Security, Technology No Comments

Suspicions about China slipping eavesdropping technology into computer exports have been around for years. But the recent spying attacks, attributed to China, on Google and other Internet companies have revived the hardware spying concerns. An IT World blogger suggests the gear can’t be trusted, noting that it wouldn’t be hard to add security holes to the firmware of Chinese-made USB memory sticks, computers, hard drives, and cameras. He also implies that running automatic checks for data of interest in the compromised gear would not be difficult.” The blog post mentions Ken Thompson’s admission in 1983 that he had put a backdoor into the Unix C compiler; he laid out the details in the 1983 Turing Award lecture, Reflections On Trusting Trust: “The moral is obvious. You can’t trust code that you did not totally create yourself. (Especially code from companies that employ people like me.) No amount of source-level verification or scrutiny will protect you from using untrusted code. In demonstrating the possibility of this kind of attack, I picked on the C compiler. I could have picked on any program-handling program such as an assembler, a loader, or even hardware microcode. As the level of program gets lower, these bugs will be harder and harder to detect. A well installed microcode bug will be almost impossible to detect.”

Recent Comments

Tags

Disclosure

Get the Flash Player to see the wordTube Media Player.

Top Security Gear



Nitro-Pak Emergency Preparedness Center

World's Most Secure USB Drive
IronKey 8GB S200 Basic USB 2.0 Flash Drive

Polls

Does the "War" on Drugs Cause More Problems than it Solves?

View Results

Loading ... Loading ...
  • TSA Behavior Detection at Super Bowl
    tsa behavior detection officer


    Record Budget For Black Projects in 2010
    pentagon-seal


    KGB Technology Detects Impending Disease
    kgb-medical-device2


    Anti-Terror Training for Boy Scouts
    boy-scouts-train-for-anti-terror


    U.S. Developing Mind Reading Technology
    mind-reading-technology