Showing posts with label hacking back. Show all posts
Showing posts with label hacking back. Show all posts

Wednesday, April 3, 2013

Hacking Back: Why security is important, even for hackers committing felonies (from XyliBox)

If you are going to steal credit card numbers and offer them on your site, try and at least secure admin panel (and the overall site itself) sufficiently that so the email addresses and passwords of your users are not easily accessed. The excerpt below is from Xylibox; the full post can be found here re: VMAdumps - a huge hat tip to XyliBox.

Also, note that Cybercrime Review is merely reporting what has already been published; we in no way condoned this illegal activity, participated in it, supported it, or encouraged it. However, this is the epitome of "hacking back" and why a lot of people have recently argued for it. Our summation post on hacking back can be found here: Hacking Back - are you authorized?

Definitions:
Dumps = credit card dumps
Track1/Track2 = different types of CC information - Track 1 contains more information
Dumps can be written to credit cards via black market devices, and then used to commit fraud in-store
Fullz - CC data + full biographical data - can be used to complete full ID theft (filing fraudulent taxes, opening up additional credit card accounts, etc.)

********************************************************************************
The Details:
Another carder shop, similar to dumpslogs, they sell track2.
vmadumps.cc - 80.82.64.21
Registrant Contact:
none
onofrio castaldi ()
Fax:
via DOMENICO CUCCHIARI nr.60
rome, rome 00159
IT
Creation date: 20 Sep 2012 10:20:00
Expiration date: 20 Sep 2013 07:20:00
And the goods offered on the site vmadumps.cc:


Noticing lax security:

Some weird urls: 
vmadumps.cc/Mail.php
vmadumps.cc/activ.php
vmadumps.cc/PEAR.php
lol:

Fruits of the hack back:
Credit cards being offered:

admins:
Clients:

And the kicker:
3k clients, i've broke ~55% of passwords with a simple brute force and a basic dictionary.You want a copy ? oh... ok.(link excluded)
PHP+SQL, tracks2 and credit cards are not included of courseHappy hunting.

Wednesday, March 13, 2013

Video from House Judiciary Committee’s Subcommittee on Crime, Terrorism, Homeland Security and Investigations re: CFAA

The video of the hearing today can be seen here. It includes commentary from Orin Kerr regarding the Nosal holding of the 9th Circuit and his recommendation that Congress act to amend the CFAA to clarify the ambiguity in the statute regarding "unauthorized access" and "exceeds authorized access" which has led to a circuit split on the statute's reach.

There is also an interesting discussion about hacking back.

Here is a link to the House Judiciary Committee's page with materials about the hearing: "Investigating and Prosecuting 21st Century Cyber Threats"

Wednesday, February 13, 2013

Tidbits: Executive Order on Cybersecurity; CISPA redux; NPR discussion of "hacking back"

President Obama's Executive Order on Cybersecurity

President Obama, in his SOTU speech last night, explicitly mentioned cybersecurity and the need for more action on protecting the nation on that front (through information sharing, etc.). The President's Executive Order can be found here: Executive Order -- Improving Critical Infrastructure Cybersecurity. The Presidential Policy Directive associated with the Executive Order (PPD-21) can be found here: PRESIDENTIAL POLICY DIRECTIVE/PPD-21.

I think it is too early to tell the impact that the Executive Order will have, but overall, I do not think it is close to an overreach. Jody Westby at Forbes disagrees: Obama's Cybersecurity Action Reaches Too Far. For another take on the EO (from Information Week), see: White House Cybersecurity Executive Order: What It Means

The Re-introduction of the Cyber Intelligence Sharing and Protection Act

As expected:
Chairman Mike Rogers and Ranking Member C.A. Dutch Ruppersberger re-introduced H.R. 624, the Cyber Intelligence and Sharing Protection Act, their bipartisan cyber threat information sharing legislation, to help American businesses better protect their computer networks and corporate trade secrets from advanced cyber attacks.   The bill that was introduced today is identical to the “Cyber Intelligence Sharing and Protection Act” (H.R. 3523) that passed the House by a strong bipartisan vote of 248-168 in April 2012.
The full text of the bill can be found here: CISPA 2013 - H.R. 624

For some varying perspectives on CISPA, see:

Controversial cyber bill CISPA returns to Congress for debate, same as before - The Verge

Lawmakers: CISPA Will Help Battle Cyber Attacks From China, Iran - PC Magazine

Congress Is Trying to Kill Internet Privacy Again - Rolling Stone

NPR Discusses Hacking Back

NPR recently had a discussion about "hacking back," or more euphemistically, "proactive response" to cyberattacks; the story can be found here (with a link to the audio): Victims Of Cyberattacks Get Proactive Against Intruders 

I found a particular section in the article about hacking back to be telling of the legal implications of such tactics:
A turn toward more aggressive actions against cyberattackers, however, could be risky. Because the source of a cyberattack is often hard to identify, counterattacking is not always well-advised. 
"I will guarantee you there will be lots of mistakes made," said Rep. Mike Rogers of Michigan, chairman of the House Permanent Select Committee on Intelligence, speaking at a recent cybersecurity conference at George Washington University. "I worry about the private sector engaging in offensive [activities] ... because a lot of things are going to go wrong." 
Companies that want to go on the offense against their cyber-adversaries need to consider the legal risks such actions would involve. 
"I have only found one or two lawyers ... who have said, 'Let's consider pursuing some kind of offensive response,' " says Richard Bejtlich, chief security officer at Mandiant, a cyber-consultancy. "The corporate legal structure is very conservative when it comes to what we can allow someone to do."

My previous summation/aggregation of articles regarding the legality of hacking back can be found here: Hacking Back: are you authorized?


Wednesday, October 31, 2012

Forget the theoretical - what hacking back looks like in the real world

There have been many posts and links on Cybercrime Review discussing the legal implications of hacking back - see my collection of those posts, here: Hacking Back - are you authorized?  A discussion of whether it's an invitation to federal prison or a justified reaction/strategy?. What is lost in these discussions is a strong foothold in real world examples. Well, now we have a recent, real life "hack back" to look upon - the Republic of Georgia's counter-espionage hack of a supposed Russian perpetrator who was propagating malware for the purposes of espionage against Georgia. This is a must read.

Here's the story from IT world: Irked by cyberspying, Georgia outs Russia-based hacker -- with photos

And here is the Georgia CERT report: CYBER ESPIONAGE -- Against Georgian Government - (Georbot Botnet)

A quick summary for those who don't want to follow the links -- Georgia had been getting attacked and mined for information from a botnet, and this included infiltration of government entities. Fed up with this, the Georgian government decided to take action:  (taken from a ZDNET article about the same):
In order to lay the bait after the attacks increased in severity over the course of 2011, Georgia allowed a computer to be infected on purpose. Placing a ZIP archive named "Georgian-Nato Agreement," once opened, the investigator's own malware was installed. 
While the alleged hacker was being photographed, his computer was rapidly mined for sensitive documents. One Word document contained instructions on who and how to hack particular targets; as well as website registration data linked to an address within Russia.
As mentioned above, there are pictures of the Russian hacker in the report - part of the malware the hacker had been propagating (against Georgia) enabled webcams and took photographs. Georgia CERT experienced sweet revenge when this functionality was turned on the hacker himself.

Does this example change your opinion of "hacking back?"