Archive for 2011/10/11
The infosec industry needs to move beyond “faith-based security” to an evidence-based approach that takes ideas from battlefield combat if corporations are ever to get ahead of hackers and keep security spending down to manageable levels
Posted: 2011/10/11 in Education / Awareness, New Business ModelsWal-Mart And Facebook To Serve Up Local Offer
Posted: 2011/10/11 in Education / Awareness, New Business ModelsRSA chief says two groups for SecurID breach
Posted: 2011/10/11 in Cybercrime, Education / Awareness, Stats / reportsA2B Internet to sue Spamhaus for extortion. Spamhaus accused of threatening A2B and its customers with “Denial of Service” attacks if A2B would refrain from taking action against “Pirate Bay and WikiLeaks hoster” Cyberbunker / CB3ROB
Posted: 2011/10/11 in Education / Awareness, Litigation, Stats / reportsAccording to the Webwereld.nl article this is what happened:
- A2B Internet is hosting Cyberbunker/CB3ROB via a customer: colocated host Datahouse;
- Cyberbunker/CB3ROB is believed to be hosting ThePirateBay.org and WikiLeaks.org using servers of Datahouse (which in turn is using the services of A2B Internet);
- According to A2B Internet, one IP address within Cyberbunker/CB3ROB’s IP range may have been used for SPAM distribution;
- In relation to that spam activity, Spamhaus asked A2B Internet to block all traffic related to Cyberbunker/CB3ROB;
- A2B Internet refused as it believed that request to be disproportionate;
- Spamhaus then blacklisted all IP ranges belonging to A2B Internet (rather than Cyberbunker/CB3ROB);
- This disrupted the services of all of the customers of A2B Internet;
- A2B Internet gave in to the pressure and has stopped “advertising” the IP range of Cyberbunker/CB3ROB;
- A2B Internet will now go and sue Spamhaus
Spamhaus Managing Director Steve Linford states that the rules and procedures of Spamhaus have been the same for the past 10 years. Whenever upstream providers are aware of spamming activities or are actively supporting the work of spammers they will be blacklisted too. “Arguing that appearing on an SBL list is the same as extortion is pretty much the same as arguing that you’re being extorted by a restaurant because they are not allowing you in because they feel you’re not dressed appropriately.”
Dutch language news article:
http://webwereld.nl/nieuws/108204/isp-doet-aangifte-tegen-spamhaus-wegens-afpersing.html
See also:
Pictures And Video From Within The Spanish Hideout Of Cyberbunker Operator Sven Olaf Kamphuis
http://vrritti.com/2013/04/28/pictures-and-video-from-within-the-spanish-hideout-of-cyberbunker-operator-sven-olaf-kamphuis/
Cyberbunker Operator And DDOS Suspect Sven Olaf Kamphuis Operated From Bunker In Spain As Well As His Mobile “Hacker Van”
http://vrritti.com/2013/04/28/cyberbunker-operator-and-ddos-suspect-sven-olaf-kamphuis-operated-from-bunker-in-spain-as-well-as-his-mobile-hacker-van/
Cyberbunker Operator And Alleged Spamhaus DOS Attacker Sven Olaf Kamphuis Arrested In Spain
http://vrritti.com/2013/04/26/cyberbunker-operator-and-alleged-spamhaus-dos-attacker-sven-olaf-kamphuis-arrested-in-spain/
“It was all Photoshop,” says Guido Blaauw (aka Rik van Esser?), of Bunkerinfra Datacenters (aka Cyberbunker), and Kamphuis fled to Spain
http://vrritti.com/2013/04/08/it-was-all-photoshop-says-guido-blaauw-aka-rik-van-esser-of-bunkerinfra-datacenters-aka-cyberbunker-and-kamphuis-fled-to-spain/
It seems clear that the CB3ROB network hijacked one (or more) of the IP addresses of Spamhaus, and installed a DNS server there which incorrectly returns positive results to every query (Cyberbunker)
http://vrritti.com/2013/03/30/it-seems-clear-that-the-cb3rob-network-hijacked-one-or-more-of-the-ip-addresses-of-spamhaus-and-installed-a-dns-server-there-which-incorrectly-returns-positive-results-to-every-query-cyberbunker/
“Yo anons, we could use a little help in shutting down illegal slander and blackmail censorship project ‘spamhaus.org,’” Cyberbunker’s Sven Kamphuis wrote on his Facebook wall March 23
http://vrritti.com/2013/03/30/yo-anons-we-could-use-a-little-help-in-shutting-down-illegal-slander-and-blackmail-censorship-project-spamhaus-org-cyberbunkers-sven-kamphuis-wrote-on-his-facebook-wal/
Current owner of “NATO bunker” – Bunkerinfra Datacenters – states that “Cyberbunker” and Sven Olaf Kamphuis have left the building
http://vrritti.com/2013/03/29/current-owner-of-nato-bunker-bunkerinfra-datacenters-states-that-cyberbunker-and-sven-olaf-kamphuis-have-left-the-building/
Let’s start with some truth. The “Cyberbunker attack” did reach upwards of 300 Gb/sec and is the largest recorded DDoS to date
http://vrritti.com/2013/03/29/lets-start-with-some-truth-the-cyberbunker-attack-did-reach-upwards-of-300-gbsec-and-is-the-largest-recorded-ddos-to-date/
The Cyberbunker Revisited: The American Dream, Swindlers, Aliases, Big Money, Fraud, Dope, Governments And…Terrorists?
http://vrritti.com/2013/03/29/the-cyberbunker-revisited-the-american-dream-swindlers-aliases-big-money-fraud-dope-governments-and-terrorists/
In Spamhaus’s view, cb3rob is the worst spam ISP in the world (Cyberbunker)
http://vrritti.com/2013/03/29/in-spamhauss-view-cb3rob-is-the-worst-spam-isp-in-the-world-cyberbunker/
How Spamhaus’ attackers turned DNS into a weapon of mass destruction (Cyberbunker)
http://vrritti.com/2013/03/29/how-spamhaus-attackers-turned-dns-into-a-weapon-of-mass-destruction-cyberbunker/
Cloudflare reveals details of ‘world’s biggest’ cyber attack (Cyberbunker)
http://vrritti.com/2013/03/28/cloudflare-reveals-details-of-worlds-biggest-cyber-attack-cyberbunker/
Blast From The Past: “I guess all I can say is I’ll take what I can get” (Cyberbunker, Sven Olaf Kamphuis, CB3ROB, XTC, Porn, Pirate Bay, WikiLeaks, Fake WHOIS, Leaked Prefix, IP Tunnel)
http://vrritti.com/2013/03/28/blast-from-the-past-i-guess-all-i-can-say-is-ill-take-what-i-can-get-cyberbunker-sven-olaf-kamphuis-cb3rob-xtc-porn-pirate-bay-wikileaks-fake-whois-leaked-prefix-ip-tunnel/
The sheer scale of the attack by Cyberbunker is having an impact on services like Netflix and could eventually affect banking, email and other systems
http://vrritti.com/2013/03/28/the-sheer-scale-of-the-attack-by-cyberbunker-is-having-an-impact-on-services-like-netflix-and-could-eventually-affect-banking-email-and-other-systems/
Cyberbunker’s Sven Olaf Kamphuis To SpiegelOnline: “I brought in a few of my customers (…) and then it all started”
http://vrritti.com/2013/03/28/cyberbunkers-sven-olaf-kamphuis-to-spiegelonline-i-brought-in-a-few-of-my-customers-and-then-it-all-started/
Five national cyber-police-forces are investigating the unprecedented Denial of Service attacks by Cyberbunker
http://vrritti.com/2013/03/28/five-national-cyber-police-forces-are-investigating-the-unprecedented-denial-of-service-attacks-by-cyberbunker/
Cyberbunker’s Sven Olaf Kamphuis: “They (SpamHaus) Think That They Are In Charge On The Internet, But WE Are In Charge”
http://vrritti.com/2013/03/28/cyberbunkers-sven-olaf-kamphuis-they-spamhaus-think-that-they-are-in-charge-on-the-internet-but-we-are-in-charge/
Has Cyberbunker Launched The Largest Publicly Announced DDoS Attack In The History Of The Internet?
http://vrritti.com/2013/03/27/has-cyberbunker-launched-the-largest-publicly-announced-ddos-attack-in-the-history-of-the-internet/
A2B Internet to sue Spamhaus for extortion. Spamhaus accused of threatening A2B and its customers with “Denial of Service” attacks if A2B would refrain from taking action against “Pirate Bay and WikiLeaks hoster” Cyberbunker / CB3ROB
http://vrritti.com/2011/10/11/a2b-internet-to-sue-spamhaus-for-extortion-spamhaus-accused-of-threatening-a2b-and-its-customers-with-denial-of-service-attacks-if-a2b-would-refrain-from-taking-action-against-pirate-bay-and-wi/
Will ISP ‘Child Protection’ Website Filtering Hit File-Sharing Sites?
Posted: 2011/10/11 in Blocking, Education / Awareness, FilteringDutch Government Bought German Spying Trojan From Developer DigiTask
Posted: 2011/10/11 in Education / Awareness, Network Security, Privacy / Data Protection, Public PolicySome European Union politicians have already begun raising questions about the use of DigiTask’s software in various EU member states.
English language news article:
http://www.dw-world.de/dw/article/0,,15453150,00.html
Dutch language news article:
http://www.security.nl/artikel/38803/1/Nederlandse_politie_kocht_Duitse_spionagesoftware.html
Previously:
Bavarian Minister of Interior Joachim Herrmann Admits That His Government Used Spying Trojan Developed By DigiTask And Exposed by Chaos Computer Club
http://vrritti.com/2011/10/11/bavarian-minister-of-interior-joachim-herrmann-admits-that-his-government-used-spying-trojan-developed-by-digitask-and-exposed-by-chaos-computer-club/
Dutch Political Party Democrats 66: Collecting society BUMA/STEMRA needs to be regulated by a new ‘Super Authority’
Posted: 2011/10/11 in Education / Awareness, New Business Models, Public PolicyExisting provisions for checks and balances are insufficient. New ‘Super Authority’ will combine the Dutch Telecom Regulator OPTA, The Dutch Consumer Authority and The Netherlands Authority for Consumers and Markets. It will be better suited to check the practices of the collecting society BUMA/STEMRA.
Dutch language news articles:
http://tweakers.net/nieuws/77325/d66-buma-stemra-moet-onder-toezicht-van-superautoriteit-vallen.html
http://www.volkskrant.nl/vk/nl/3380/muziek/article/detail/2962754/2011/10/11/NMa-moet-toezicht-houden-op-Buma-Stemra.dhtml
Bavarian Minister of Interior Joachim Herrmann Admits That His Government Used Spying Trojan Developed By DigiTask And Exposed by Chaos Computer Club
Posted: 2011/10/11 in Cybercrime, Education / Awareness, Enforcement, Network Security, Privacy / Data Protection, Public PolicyThe malware called ’0zapftis’ or ‘R2D2′ is capable of:
- eavesdropping on Skype conversations
- stealing passwords
- circumventing encryption tools such as TrueCrypt (probably by using a keylogger which keeps track of keystrokes)
- taking screenshots
- recording audio
According to the Bavarian police the tool has been used in accordance with the law and that certain functionalities had been disabled, all of which is contradicting the findings of the Chaos Computer Club.
Dutch language news article:
http://www.security.nl/artikel/38792/1/Duitse_politie-spyware_omzeilt_TrueCrypt.html
German language news article:
http://www.spiegel.de/netzwelt/netzpolitik/0,1518,790960,00.html
Previously:
German government accused of spying on citizens with state-sponsored Trojan
http://vrritti.com/2011/10/09/german-government-accused-of-spying-on-citizens-with-state-sponsored-trojan/
André Rieu walking the red carpet in Mexico thanks to piracy
Posted: 2011/10/11 in Education / Awareness, New Business ModelsEverybody in Mexico knows Rieu thanks to the illegal sales of his CDs at numerous markets in Mexico.
This has resulted in skyrocketing sales of tickets to his concerts:
50,000 tickets sold for Mexico City, 13,500 tickets sold for Guadelajara and another 5,000 for Monterrey.
Rieu says that Mexico does have laws against piracy but that people see it as a sport to try and circumvent them, to a certain extent. “I’m not afraid for piracy, my audience will rather go and buy the real thing anyway.”
Currently Rieu is at the top of the Mexican charts in relation to his DVD “Fiesta Mexicana.” He is also ranked as first, fifth and ninth in the top ten list of most popular CDs ever sold.
Dutch language news article:
http://www.telegraaf.nl/filmenuitgaan/muziek/10701547/__Piraterij_rode_loper_Rieu__.html?p=28,1
New anti-piracy strategy: James told TorrentFreak that after the first couple of levels, gamers found themselves dumped out and directed to a website containing a questionnaire
Posted: 2011/10/11 in Education / Awareness, Illegal File Sharing, New Business Models, Stats / reportsIt asked why people illegally download, which torrent and DDL sites they use, how much data they download per month, what content people download (with a focus on PC games) and what, if any, anonymity services they use.
A whole section of the questionnaire was dedicated to DRM systems such as SecuROM, Steam, and solutions from EA and Ubisoft. Vigilant also asked respondents if they were planning on buying the game when it came out officially and how much they would pay for it – the average (including nearly 24% of respondents who indicated they had already pre-ordered at the full price) was $28.00.
The whole point of the experiment, James says, was to get pirates to download a free trial of a game and then go on to buy the full product through a yet-to-be-created distribution system. He apologized for having to do that by tricking pirates into a ‘fake’ download and went out of his way to say that he wishes to embrace file-sharers, not treat them as enemies.
More:
http://torrentfreak.com/anti-piracy-company-pirates-deus-ex-in-controversial-experiment-111010/
Extraordinary claims require extraordinary evidence. Esteemed scientist and science communicator Carl Sagan reminded us of that throughout his career, but the message didn’t sink in at some newdesks
Posted: 2011/10/11 in Education / AwarenessAll you have to do is track the news of the “kraken” to see that recycling press releases often counts for “science news” right now. Jeanna Bryner of LiveScience swallowed the big squid story whole and had her version regurgitated at FOX and CBS News. Dean Praetorius of the Huffington Post, Houston Chronicle’s “Sci Guy” Eric Berger, and TG Daily’s Kate Taylor also took the bait. Who could resist a sensational, super-sized squid? Only Cyriaque Lamar of io9 sounded a minor note of skepticism — “But the possibility of finding that which is essentially a gargantuan mollusk’s macaroni illustration?”, Lamar wrote, “That’s the kind of glorious crazy you hope is reality.” Leave it to science bloggers like PZ Myers to point out how ridiculous this media feeding frenzy is.
But what really kills me about this story is the fact that no reporter went to get a second opinion. Each and every story appears to be based directly off the press release and uses quotes directly from that document. No outside expert was contacted for another opinion in any of the stories — standard practice in science journalism — and, frankly, all the stories reek of churnalism.
More:
http://www.wired.com/wiredscience/2011/10/the-giant-prehistoric-squid-that-ate-common-sense/