Showing posts with label Cyber War and Cyber Terrorism. Show all posts
Showing posts with label Cyber War and Cyber Terrorism. Show all posts

Friday, January 20, 2012

Major Pakistani Mobile Site Hacked by zer0Freak &VipVince



A mobile site from Pakistan has been hacked by two web hackers, zer0Freak and VipVince, revealing almost 30,000+ personal phone numbers and countless personal messages from almost 27,000 users.
The website had 7000 users active everyday constantly sending SMS and socializing causing a 16000+ visits per day
The admin panel of the website recently had 3000 un-confirmed SMS and the administrator was to have had 10000+ contacts in his list.
VipVince and zer0Freak didn’t put too much effort into hacking the site, in fact, it took them less than 10 min to bypass and extract the databases
Vulnerability Status:
  • Type: Union Based WAF Bypassing SQL Injection
  • Website: www.smsfree.pk
  • Status: Unfixed
  • Researcher: VipVince& zer0Freak
Screenshots:
Admin Panel:




















Current Contacts of Administrator

Personal Messages and Contact Numbers Exposed:


Shoutouts:
Team Intra, Zer0Lulz
Submitted by:
Zer0Freak (http://www.zerofreak.blogspot.com)
CodeName: z3r0fr34k

VipVince ( Team Intra)
CodeName: VipVince

Source:- z3r0fr34k
Read More...

Tuesday, November 23, 2010

Where Are Hero Hackers?? Forgotten Hero Hackers By Cat Techie


What is the source of earning/income of all those notorious hackers. Read in next post with Cat Techie & Amarjit Singh

(Want to know where all these people have gone, what are they doing? what next..keep eying on this blog)

By Cat Techie

The day I started with my research I had to track down many hackers which was quite difficult task. During this journey I came across numerous new concept which no normal brain can even think of one of them was ‘Cyber War’. The first ideas that wallop my mind was this could be war between hackers from all countries. later as I started exploring I was jeopardize because I realised that virtual war is more harmful then any kind of physical war, There are highly talented hackers across the world who can be serious threat but also safety to government, economy and also infrastructure of respective countries. Till now except the ethical hacker no other hacker is known by their original names. all are coded with some different name or number, there is a great story behind these names, how these names came is existance and why they got these codes is yet another story to read. I am deffinately going to discuss about the same in near future. Cyber war was started by the Pakistani group of hackers named ‘paksbug’ which was maintained by zombie_ksa and his fellow team mates. Zombie_ksa is known to be one the highly talented hacker from Pakistan few of them mark him as a legend, his identity is still a mystery there are so many myths and rumors about this hacker. this arab hacker made his bench mark in hacking trends. I have special liking for this hacker for his uniqueness.

Amongst everybody, the major components or hackers of this group were ‘spoofer’, ‘Xoom-Xoom’, ‘big smoke’, and ‘cyber crime’ (these are substitute names given to them their real names you can get to read in Cyber terror book).


Due to the hatred for India this group started posting nude pictures of Indian girls in their community more over the Indian god were abused which was no longer tolerated by the Indian hacker. To retaliate and express disagreement Indian hackers also formed a group which was named as ICW i.e., Indian Cyber Warrior the founder of these group were Rascle (Gaurav Singh), Sai Satish, and Smart(keval) . Later so many people became members of this group, they started attacking pak cyber space but never wrote anything ill or against their almighty god, neither insulted any gender. This gave rise in the defacement of the sites from both the countries. With the growing hatred towards each other this lead to the formation of two more new groups that was PCA the founder of this group was Harun from Pakistan. Now there is one more PCA founded by .

After this there are a serias of hackers came in existance, now a days the hackers mashroomed like anything. there is one more hacker Cyber swati, how this hacker got indian name and what is his background..read in cyber terror.

One fine day both the opponent groups realised that only defacement is not the solution so the graph of hacking came down and thus here this phase was ended with the signs of maturity. But was this an end??? NO.

This time it was a quite a major issue. After few months a guy named ‘Xoom-Xoom’ regenerate the conflict by hacking our prime minister site ‘Manmohan Singh.org’ cyber war was revived but this time ICW did not retaliate May be it was the question of their ego. Hackers are known to maintain their principles and so they do not wish to go against.By then ICW and paksbug were only two active groups. This was the time where zombie realised his skill and gradually he started hacking bigger sites like national internet back bone of morocco then google.co.in, and hotmail.ug. He almost ended up hacking all the sites of Uganda and stopped attacking India. So as ICW was dead by that time.Injector, Sai satish one of the most legendary hacker known for his integrity gave up, and every one went their way. Today they all are working in different IT companies.

Indishell was the group formed and the founder by ‘hack my PC’ who was basically from London. The major platform of the group was patriotism. He trained many ordinary minds to expert hacking. Patriotism of this group was immense and was intensely mounting day by day.
What ‘Xoom-Xoom’did he ignored everything and in addition to this he ramdomly started defacing sites. Mean while another group was formed by some Pakistani hackers named ‘pak hackers’ the founder of these group called himself as a ‘spider’ who was from Afghanistan, he is the leader of afghan cyber army ,once again filthy game of defacing came in full force.

Indian sites were above to hit the top, an avarage 25 sites a day was at the target of Pak hackers. Still the Indishell was quite, and they did not reciprocate but these was high time as the defacing Indian sites went beyond limit.Two new strong Indian hackers started retaliating pak hackers. They were M.XXX and silent poison. The new brilliant hacker was thrown at the battle to controll situations his name is c0de Breaker, who was trained by ‘hack my pc’ he was the new heir of Indishell. S
ilent poison approached c0de breaker for defacements in which nations pride was the most important topic, this is the phase where indishell came into highlight.One more group was formed and that was cyber hacker.net which was super monitored by a hacker called his partners in this group was net cracker, these was formed due to the disputes between shack and the member of pak hackers. Shak is heartthrob of young aspiring hackers of Pakistan as well as India.

These three groups were on the top on the list of cyber war. In this was indishell ended up by hacking cyber hacker.net. complete back up and old data was erased by indeshell so that there won’t be any chance of them coming back in existance. It’s still been three months no trace of these guys is been found. Now the only person left is shak and few others who knows the technique of SQL injection and Google hacking. None of these member were even partially related to ethical hacking.

The most undue advantage was taken by SQL attack was by shack and nut crackers now their target was common man, who regularly does net shopping. These hackers hacked credit cards by introducing server of Pakistan in Germany, later on even that was suspended because the bank of these credit cards started giving back to these hackers in strrn actions. But nobody could stop this hackers from committing crimes, once again they use to establish themselves with new servers and by hacking new credit cards.

What they were doing wasn’t sufficient so they started teaching credit card hacking through their websites and forums, after some time they had to close this due to the legal problem raised by banks...Pak police started clutching there hackers and illegally the institutions were getting operated behind the eyes of law. Indishell reported this to the CMO office. Unfortunately all the officer went blind folded. There was no other option for indeshell to wait for 14th august as it was Pakistan’s independence day. On that dayPakistani hackers defaced 18 Indian sites with abusive language, they abuse India and also insulted the lord ram by pasting his face to a dogs body. this went in to the nerves of Indian hackers specially Indishell . they answered them through Gang Bang and ICA came in action with the hackers like Mr.XXX, silent poison, Inex root, dark look, and code breaker himself. by that time indishell became a open door for every hacker around the world. ICA was started by lucky and silent poison then after indian hacker started joining their camp. here after so many things happened but wait for some time to read in details..

What is the source of earning/income of all those notorious hackers. Read in next post with Cat Techie & Amarjit Singh

(Want to know where all these people have gone, what are they doing? what next..keep eying on this blog)

---Like this post, Just leave a comment as your feedback. If you want us to post an article on some specific topic OR have a suggestions for us...you can also drop an email on amarjit@freehacking.net
Read More...

Monday, November 22, 2010

Cyber Terror & Cyber Terrorism: Attacks & Cases by Cat Techie


Article submitted by Cat Techie

The changing face of security threats must be understood by enterprises and consumers alike. We delve into the new risks they pose, just how vulnerable you are, and what can you do about it; along with useful advice for CIOs on enterprise security.

The president gets five threatening emails

Credit card numbers and other personal information peddling for less than a dollar a record Information stealing Trojan poses as Microsoft Windows patch Russia filters Internet traffic from Georgia: Google Earth being misused by militants in Gaza strip to launch attacks on Israel: HSBC loses disk containing details of around 400,000 customers.News like above is enough to send shivers down anyone's spine, be it an enterprise, individual, or the govt. But alas, it's all true. Increasingly, the news headlines everywhere are getting filled with security incidents that are more focused and malicious. It's no longer about a script-kiddie breaking into an organization's server just for kicks or to hack a website just to leave a funny message there. Security incidents the world over are being committed with a very clear and malicious objective, which could be financial gain, plan for a terrorist attack, or propaganda. In other words, security threats have really changed and taken a much more gruesome shape than you could ever imagine. It will only get worse in the future, so you have to be ready for it. Today, terror is everywhere, and there's a dire need to combat it at all levels. This special story from PCQuest will focus on various aspects of security, strategies to adopt, and tools to combat it. We'll focus on different kinds of security threats for different types of audience, along with the strategies and tools to combat them. We'll look at cyber-terrorism, what it means for different people, and how to combat it.

Just how vulnerable you are

Security incidents are different for different parts of the society, so measures taken to safeguard against them also have to be different. For enterprises, security could mean protecting critical information from getting stolen or preventing a virus from causing significant downtime. For an individual, security could mean preventing loss of personal information like credit card or bank account details. For the govt, security could mean ensuring that national secrets are well-guarded, senior leaders are protected, and citizens are safe. But before you can do that, you have to first understand the nature of security threats that you're most vulnerable to.
Enterprise security trends

If you feel your IT infrastructure is safe from any kind of security breaches, well think again. That's because there's no such thing as a boundary for your organization's network anymore, thanks to the growing number of mobile users and Internet based applications. Your users will need access to your network from everywhere, be it a hotel, cyber cafe, airport, or railway station. They will access it from all sorts of networks, putting far more stress on your network than ever before.There are many more entries to watch in the organization, many more end points to secure, and a lot more sensitivity towards protecting information theft.The other key trend is that security threats are no longer being carried out by college pass-outs wanting to bring down a website or portal just for kicks. Security attacks have now become more serious, and they're being conducted by people with a criminal bent of mind for information theft, financial gain, or other malicious reasons.There is of course, more malware than ever before. In fact, the amount of malware created last year was more than the combination of all malware ever created till date. This clearly indicates that with increasing penetration of the Internet, both the good as well as bad guys have better connectivity and reach.Last key trend in enterprise security is that today the focus of security threats is not just on the infrastructure. It's also on stealing information. So organizations must go beyond setting up firewalls, anti-virus, and anti-spam software.

Consumer security trends

If you think you're safe from prying eyes on the Internet, think again. Today, there are more bank accounts, credit cards and personal information available for purchase on the Internet than ever before, and you'll be shocked at the prices they sell them for (see table on previous page). Each record could be available for less than a dollar if purchased in bulk. Premium accounts, with higher bank balance or credit limit sell at higher prices.
Email tracing of Ahmedabad blasts

How Cyberoam and their technical support team helped to trace and identify the IP Address of Waghodia Dental Institute, Vadodara after the Ahmedabad bomb blast.

1. An email is sent to IndiaTV news channel giving some information on the blasts. From the email, police was able to track the sender's IP address which is traced to some web hosting company. The web hosting company finally traced the IP Address to Waghodia Dental Institute in Vadodara.
2. A Cyberoam device is installed at the institute. The support department of the institute is told to determine the exact computer from where the mail was sent.
3. The device is able to tell which websites were surfed at the time when the mail was sent.
4. From the websites, IP addresses of the same range were matched.
5. Finally the website is identified: abdultaiyeb.com. This was a web based proxy service that the terrorists used.
6. With the help of these reports, the IP Address of the computer from where this site was viewed is identified. Interestingly, the computer had a static IP address, and belonged to one of the institute's internal labs. 3. The police seized the computer for further investigation.

Credit card details can be stolen during online or offline transactions. Online, you might land up on a fake site, which cons you into shelving out the details. Or there could be an information stealing Trojan sitting on your machine. Offline, your credit card could get cloned at a restaurant or any other place. For instance, there are tiny credit card reading machines available, which a person could simply swipe your card on before swiping it on the actual terminal. And you thought that giving your credit card to the waiter in your favorite restaurant was safe!

Web 2.0 has been a boon for everyone, but it could become a bane if you're not careful. Just as you have access to so much information on the web, and so many social networking sites to interact on, so do the bad guys. So we all obviously know what that means! They can coordinate better and react more quickly to vulnerabilities.So while you're busy watching that YouTube video, a Trojan might be quietly be installing itself in your system, and bringing along its other friends like keyloggers, bots, etc. Rest as they say, is history.We all know the story of phishing emails pointing you to a fake website to extract your personal information. But now, things are taking a different turn. To take an example, suppose you receive an email pointing you to an 'interesting' website from where you could download some 'hot' pictures of a known celeb. But along with the picture, you end up downloading certain file infectors. These can then use your precious bandwidth to launch a deadly Denial of Service attack on other websites. So guess who'll get caught for doing this attack? You of course!Incidentally, what that means is that it's not just bank sites that are bieng faked. Any site that's not been hardened against vulnerabilities could get infected, causing you to download Trojans.

---Like this post, Just leave a comment as your feedback. If you want us to post an article on some specific topic OR have a suggestions for us...you can also drop an email on amarjit@freehacking.net
Read More...

Saturday, November 20, 2010

Fight Cyber Terrorism & Cyber Crime: New Laws Against Hackers in China


Fight Cyber Terrorism & Cyber Crime: New Laws Against Hackers in China

According to Gu Jian, Deputy Director of the Network Security Protection Bureau of the Ministry of Public Security (MPS), China is all set to fight against the hacking attacks as the government is drafting law governing the punishment of hackers and other cyber offences, as reported by ShanghaiDaily on November 11, 2010.

He further highlighted that presently, lawmakers are working on the judicial interpretations of the new law, which will be released by the end of 2010.

Gu stated that nearly 80% of the machines in China are facing the problem of botnet attacks, whereby hackers use malicious software to attack and compromise machines.

Remarkably, botnet can be defined as a network of systems that have had malware installed into them and are managed by cybercrooks, while the users are not aware of the computer hacking.

Disturbingly, according to a report released in earlier 2010 by the China National Computer Network Emergency Response Technical Team (CNCERT) revealed that 71% of the global botnets are placed in China. Of which, majority are administered by hackers of foreign origin.

Commenting on the finding, Gu stated that, China, a land of around 440 Million netizens is the key victim of cyber criminals, as reported by the web portal China on November 11, 2010. Gu also said that over 80% of the online attacks targeting China's government agencies official websites come from foreign locations.

Gu further highlighted that, to fight against overseas criminals, China has been making remarkable attempts to co-operate with overseas government agencies. Since 2004, China's public security departments have offered assistance to around 41 countries in 721 online criminal instances.

Until now, Chinese police have set up bilateral cooperation agreements with 30 nations including the United States, Germany, and the UK.

However, according to Gu, existing collaborations between various governments are far away from fighting against overseas cybercrimes.

Conclusively, Gu stated that late response is one of the major problems. Since 2009, China's police agents have asked for investigation assistance for 13 cybercrimes to the U.S. FBI (Federal Bureau of Investigation), including instances concerning fake bank website and child pornography. But, the Chinese police have not got any response till now.

SOURCE» SPAMfighter News

Fight Cyber Terrorism & Cyber Crime: New Laws Against Hackers in China

---Like this post, Just leave a comment as your feedback. If you want us to post an article on some specific topic OR have a suggestions for us...you can also drop an email on amarjit@freehacking.net
Read More...

Thursday, November 18, 2010

China’s Internet Hijacking Uncovered [CyberWar]



Cybercrime experts have found proof that China hijacked the Internet for 18 minutes last April. China absorbed 15% of the traffic from US military and civilian networks, as well as from other Western countries—a massive chunk. Nobody knows why.

On April 8, China Telecom's routers sent messages declaring that their network channels were the fastest available at that point. Since the traffic routing is based on trust between the world's telecommunication providers, other Internet routers redirected their traffic through China's network.

Security expert Dmitri Alperovitch—VP of threat research at McAfee—says that this happens "accidentally" a few times a year, but this time it was different: The China Telecom network absorbed all the data and returned it without any significant delay. Before, this kind of accident would have resulted in communication problems, which lead experts to believe this wasn't an accident but a deliberated attempt to capture as much data as possible.

As of why this happened, nobody knows. Alperovitch added that the Chinese could have captured and manipulated data passing through their network:

This is one of the biggest - if not the biggest hijacks - we have ever seen. What happened to the traffic while it was in China? No one knows. Imagine the capability and capacity that is built into their networks. I'm not sure there was anyone else in the world who could have taken on that much traffic without breaking a sweat.
While the US government says that this is not alarming, it's certainly puzzling. It doesn't make sense for China Telecom to act in this extraordinary way without an specific objective. Perhaps it wasn't a malicious move, but it certainly seems like a test to its network power. In any case, it seems like it can happen again at any time.

---Like this post, Just leave a comment as your feedback. If you want us to post an article on some specific topic OR have a suggestions for us...you can also drop an email on amarjit@freehacking.net
Read More...

Monday, November 15, 2010

Cyber War Sabotaging The System: Are We Ready??


Cyber War Sabotaging The System: Are We Ready??

Looking at the growing menace and to ‘try to excite student and create an interest in ethical hacking , Ankit fadiya a self proclaimed ethical hacker always speak about dearth of hackers in India. This claims remains till attracting students to his hacking seminars and classes. Irony is that so called branded hackers of my country are aware of the fact that According to Nasscom, India needs about 77,000 ethical hackers every year to fix the situation and we are not even producing half of them. There are cells where the Chinese government actually trains and operates cyber mercenaries who incessantly keep attacking Indian, American and Japanese websites mostly belonging to the governments and some even to the corporate. The question is here Including Mr fadia and Waghela and so many such ethical hacking classes are producing at least thousands hackers per year.

Here I am specifically talking about the so called hackers trained from classes by paying thousand of rupees for learn hacking courses. Lakhs of Untrained but truly professional hackers are lured in unwanted activities due to lack of opportunities. Why government never thought of providing them job opportunities by testing their skills. Why Fadia or whghelas never tried bringing in to government’s notice. If the undercover hackers start getting cover and jobs from Indian government I am sure the so called ethical hacking coaching may take back seat. They are producing craze, fancy and nothing but the noobs at the end. Young guys those who have done spending so many amounts such classes are not trained to find vulnerability; they are not even taught the basics of cyber security. I might have hundreds of such kids in my face book friends list, who seek help for over small issues like finding vulnerability, forget about patching or securing.
Another anniversary of one of the world’s worst terrorist attacks (9/11) went by bringing into sharp focus the still looming threat that countries of the world face as the tools of the terrorism trade continue to evolve. Even though explosives and jet-planes are not things of the past just yet when it comes to causing damage to enemy states, cyber warfare is a serious enough threat to be pegged as the number 3 priority in the Federal Bureau of Investigation (FBI)’s list even way back in 2002.Indian authorities, however, just don’t seem to get the seriousness of the situation, deploying far less than what is required to combat cyber-attacks. China is actually doing a great job when it comes to cyber security. They are far better prepared and equipped than our authorities are. We have very good cyber laws in our country. The only thing that’s terrible is the training that our personnel get. Cyber security is just not taken seriously enough. We have people from all over getting transferred to cyber security [departments] without formal training or with outdated knowledge.

Defacing websites is a fast growing sector in cybercrime. This ‘hacktivism’, or activism through hacking, is where hackers from not-so-friendly states deface important websites of another country to cause everything from diplomatic embarrassment to real damage to sensitive data. Hackers from Pakistan deface anything between 40 to 50 government and corporate websites every day. Indian hackers in response manage to hack in to be almost same. The fact remains that India is woefully ill-equipped to meet the kind of aggression that the country faces from its not-so-friendly nuclear-armed neighbors what exactly are ‘real threats’ a nation can face from cybercrime and terrorism? Apart from spies, hired cyber mercenaries, and criminal syndicates worming their way into government networks, are attempting to steal a nation’s most sensitive secrets. With the blindingly rapid growth of social media making it difficult to monitor content posted online, scheming terrorists are actually posting videos on how to build everything from backpack bombs to bio-weapons in addition to that identity-thefts, email spoofing, face book account hacking, sim card cloning, call spoofing, real and rapidly expanding, including the rise of extremist websites that recruit, radicalise, and incite violence. India’s provisions to deter cyber-attacks are woefully inadequate. Last year the U.S. suffered a loss of $3 trillion due to cybercrimes. At least we are not even close to experiencing that kind of damage, but we really are headed in that direction. Security breach has become small time game.

1. Second anniversary of one of the India’s worst terrorist attacks 26/11 yet remained unsolved. If we go little deep in history On June 12, 2009, US and Italian investigators arrested some persons on a charge of stealing phone services from phone companies around the world and using the illegal profits thus earned for funding terrorism.

2. They were accused of hacking phone lines and selling the phone services thus illegally obtained through call centers and via phone cards. It was stated by the investigators that many of the phone calls were made over lines owned by the AT&T Corp. While the AT&T was not hacked, 12 million minutes of its phone services valued at $55 million were allegedly stolen by the arrested persons.

3. The three hackers, who were indicted by a grand jury of New Jersey in the US on June 12, 2009, were residents of the Philippines. They were accused by the investigators of helping the Madina Trading Company of Brescia, Italy, in obtaining stolen phone lines for providing stolen phone services to the customers of the company in India, Pakistan, Afghanistan, Saudi Arabia and Egypt. The "Wall Street Journal" reported on June 13, 2009, that the Madina Trading Company, which paid the three hackers, also 'financed the communications of the terrorists" in the Mumbai 26/11 attacks.

4. According to the U.S. indictment, Mahmoud Nusier, 40, Paul Michael Kwan, 27, and Nancy Gomez, 24, residing in the Philippines, conspired to break into the phone systems of 2,500 entities in the U.S., Canada, Australia and Europe. The three hackers were arrested by the Philippines Police last year, but were released on bail. On getting information of their hacking into the phone systems of American companies, US authorities took up the investigation and have sought their extradition from the Filippino authorities. It is not known what action has been taken by the Filippino authorities on the extradition request from their US counterparts. the Filippino authorities alleged that Nusier, a Jordanian national, had links with Al Qaeda.

5. The Italian Police arrested on June 12, 2009, five Pakistani nationals during raids on 10 call centers suspected of involvement in the alleged conspiracy. Among those arrested were a husband-and-wife team who managed call centers in Brescia, Italy -- Mohammad Zamir, 40 years old, and Shabina Kanwal, 38. The indictment filed in the New Jersey court alleged that the Madina Trading Company is owned by one of the call-center operators involved in the alleged conspiracy. However, the owner of the company was not named.

6. Two employees of the same Madina Trading Company in Brescia ---- 60-year-old Mohammad Yaqub Janijua and his son 31-year-old Aamer Yaqub Janijua----- who were managing the company were arrested by the Italian authorities on November 21, 2009, on a charge of aiding and abetting international terrorism as well as illegal financial activity.

7. According to Stefano Fonzi, the head of the anti-terrorism police of Brescia, on November 25, 2008, they sent money using a stolen identity to a U.S. company to activate an Internet phone account used by the terrorists involved in the 26/11 terrorist attacks in Mumbai. The funds were transferred under the identity of another Pakistani who had never been to Italy and was not involved in the attacks, Fonzi said. His identity was probably stolen when he used another money transfer agency in Pakistan. The order to open the account that allowed the attackers to communicate during the attack came from two men in Pakistan. The Italian Police said the identities of these Pakistanis had been intimated to the Pakistani authorities.

8. The transfer of the money by the Mumbai conspirators through the Madina Trading Company had come to the notice of the Federal Bureau of Investigation and the Indian authorities shortly after the 26/11 attacks, but the manager of the company and his son could not be arrested immediately by the Italian authorities as they had fled Italy----reportedly to Pakistan. They were arrested when they returned to Italy. If it is correct that they had fled to Pakistan, it is not clear why they were not arrested by the Pakistani authorities.

9.The investigation into the activities of the Madina Trading Company bring out the involvement of members of the Pakistani diasporas in the West in the sale of stolen phone services and the use of such companies by terrorist organizations based in Pakistan such as the Lashkar-e-Toiba (LET). These organisations seem to have an up-to-date database of Pakistani-owned or run companies which could be used for facilitating terrorist attacks. Another example is India and Pakistan engaging in a cyber protest caused by national and ethnic difference. After a cease-fire in the Kashmir Valley hackers took it upon themselves to continue the hostilities. In 2000, pro-Pakistan hackers defaced more than 500 Indian web sites. Conversely, only one known Pakistani site was hacked by the Indians. ... The group G-Force Pakistan was the most active group claiming involvement in the events. This still continues, every day hundred of websites of both the countries are hacked (defaced) by hackers. God knows the fate of 26/11, there are peace talks going on in hacker’s forums, but nothing is predictable. So the future isn't just about physical attacks on the infrastructure but it’s also matter of concern on security threat to nation. The problem isn't just restricted to terrorism. There are a variety of attackers that can attack the networks including criminals and hackers. Attacks are getting more sophisticated, costly, and greater in number and the numbers of attacks are going up significantly. Attacks can come through a number of different sectors of the economy, before they reach national defence systems. That requires the office to identify the vulnerabilities in critical systems not just on defence, but in banking or finance and in other sectors too. We should not just look at industries and government sectors, but also home users and small businesses, because of the "always on" phenomena. It’s high time we need a quick response system which includes contingency planning and information sharing, as well as continuity and recovery. No country can stand alone on cyberspace security because of globalisation of markets and telecomms systems worldwide.

(The views expressed by the author in the blog are her own, but deffinately not imposed on anyone if you do not agree pleas feel free to leave your openion, in comments )

---Like this post, Just leave a comment as your feedback. If you want us to post an article on some specific topic OR have a suggestions for us...you can also drop an email on amarjit@freehacking.net
Read More...

Criminals on Facebook Friend List: By Vaidehi Sachin AKA Cat Techie, Author of Book Cyber Terror


Criminals on Facebook Friend List: By Vaidehi Sachin AKA Cat Techie, Author of Book Cyber Terror


Dear friends I never thought my book ‘Cyber Terror’ would ever have this kind of investigative story in it. One Pakistani Hacker (Mastermind) with multiple identities, one video upload, a few negligible activities, one cell phone number and one target the other side face book admin, three countries intelligence, every crime has traces and every Mastermind has one bad day. Nothing is beyond Law, The whole story started on 16th October 2pm, I am a damn fool, whose faith was betrayed and would have never regained on a journey across the hacker’s world if few hackers and my co writer, few face book friends, one journalist and some agencies wouldn’t have helped me tracing them.. Being well educated, deeply spiritual, and by the evil of social networking what I have gone through these days was horrible. My enthusiasm turns to disillusionment: my life drained out of me, faith, betrayals, bad words, violence and pretentions and wearied insecurity of a hacker, who has in-depth knowledge and potentials of web world and cyber crime. Man with tremendous brains and meager earnings, wanted to do big landed frustrated doing crime, his exploits, his coding, his way of hacking and over and above the skills of social engineering he uses are undoubtedly amazing. He has his group of small time hackers.

It’s been a long struggle. Why he came my way, how he made perfect strategy to harass me? His Kashmir links, his probes in my personal life. A terrorist who is heartless? Made me scapegoat, Social networking is an invention that has the Internet still at the edge of its seat due to its popularity with people. This is mostly because it really is for the people. Bringing every kind of social group together in one place and letting them interact is really a big thing indeed. Everything about it lies on the advantages and disadvantages of social networking and what it can do for you or what it takes from you never know. Definitely, it's cheaper to use online social networking for both personal and business use because most of it is usually free. While personal use is rather simple for anyone, the business functions are underestimated by many. In a social networking site, you can scout out potential customers and target markets with just a few clicks and keystrokes, adding a boost to your usual advertisements and promotional strategies. It lets you learn about their likes and dislikes, which is tremendous. If you want to fine tune your business, then this is the way to go, whether on a budget or not.

You definitely can gain so many things, earlier for an investigative journalist like me has to make tremendous efforts to work on story but now internet has given us a new platform, this builds confidence if you can connect to them on both a personal and professional level. Despite having to do a bit of work, it definitely pays off as you can be tapped for an offer if someone catches wind of your products or services. As long as you don't pursue them too aggressively, you will do well here.

You are friends with people who have other friends, and so on. There is potential in such a common situation. By using a social networking site, you can do what you can and get connected with these people to form a web of connections that can give you leverage if you play your cards right. As long as you give as well as you receive, then they will most likely stick with you. These connections are definitely valuable in the long run. That definitely sounds enticing. However, what about the disadvantages though? You are putting out information about your name, location, age, gender, and many other types of information that you may not want to let others know. Most people would say be careful, but no one can be certain at any given time. As long as people can know who you exactly are, then some can find ways to do you in. There is a potential for failure of security in any context. While many sites apply certain measures to keep any of these cases of harassment, cyber-stalking, online scams, and identity theft to an absolute minimum, you still may never know. If this is not your kind of thing then it would just be a waste of time for you. The key to social networking is that it is supposed to be fun, whether you are just doing it for kicks or clicking around for certain purposes. That should be reasonable enough for anyone, but there are those people who don't see the point. For them, it can be a disadvantage. Now there is something to really think about. Nothing is without a blemish, but those of this type of networking shouldn't really be that much of a concern regarding your safety. As long as you go along without making big mistakes, then it is all good.

One man with multiple identities, few fellow hackers, so many ids, and one pretends to be dumb and other sound IT and cyber security expert, every one plays perfect role and drags the target to that particular window..Yes they are player..Great player.. Great social engineering, Each move was calculative like chess.. One makers comments at his wall and other replies to it like fool, one again comments like a ruler of security system and then one of his own fake id comments at it like a dumb hacker, all this is done by one person and fools like us fall prey to these tricks and land in that wall commenting at their statements and this makes you adding them as friends. These few names are part of every hacker’s friend list, there are another type of people in this community as yesterday I posted on a few walls That “DON’T BELIEVE IN RUMORS- LAST NIGHT WHEN I WAS CHATTING WITH MY LITTLE HACKER FRIEND, HE SURPRISED ME SAYING, “DIDI DON’T CHAT WITH EVERY PAKISTAN HACKER BECAUSE SOME OF THEM ARE HERE ON BEHALF OF FIA”. AND HE WAS ASKED TO SPREAD THAT NEWS IN COMMUNITY. No intelligence agency has time or concern to vigil your activities. Believe me you all are victims of Someone’s social engineering skills.

The poor little hacker was harassed by that hacker who used him to spread the rumors and threatened to an extent that he disabled his account itself, I never mentioned any name but the culprit reached to his target, Poor little boy tried doing well any landed as victim of circumstances and deactivates his account.

See how crime and criminal make their way in your life quite unknowingly. To site another example, you all must be aware of Unix Root a good source of news portal which gained mileage popularity in no time. This portal has given good jolt to existing news blogs. The girl gave good show maintaining this portal, but some so called custodians of news blogs tried their level best putting pressure on her, URDU Hackers, some face book groups, some face book friends every one pounced at her. Reason no one knows. I don’t think this news portal has ever harmed anyone.

Last night I was not in good state of mind because I lost my grandmother who was the only family member left with me. But the night was much darker, these so called groups of hackers were tried penetrating me with their modus operand, initially I pleaded, I cried, I even begged to stop because they were very close to my heart, I couldn’t take that emotional jolt. It took time for me to digest that my friend is dealing with me with multiple ids just to cripple me. He randomly took me for granted. Some of my friends have witnessed amazing thing on face book window. I salute my Indian hackers, at least they are not into these kinds of cheap traits unfortunately they were also used as the gate ways to these people’s activities. Code breaker, dark look, and entire indishell group has focus, they know why and what are they doing. I am not endorsing their misdeeds but yes whatever they are doing at least doing with some ethics. This group will always remain in good books of any Indian. There are few very good Pakistani hackers, their behaviors, conduct, their vision is clean and they are the only few examples of Pak-hacking sect or community.

My dear friends I don’t know why, who and where is the next victim but they are very much active, and they are none other than your face book friends. I can say be careful. Record each suspicious activity, I had to record it because I am writing book and as you all know we are filming the same. Don’t forget to read how I traced them, how crime leaves traces over the period of time. What is needed is just patience and determination to clutch the culprit.

Now you must be having big question.. what was the intention of that hacker to harrasse me? why are they not nabbed? Why I have not disclosed their names?

Only thing I can say wait and watch…khel abhi
baki hai mere dost...

---Like this post, Just leave a comment as your feedback. If you want us to post an article on some specific topic OR have a suggestions for us...you can also drop an email on amarjit@freehacking.net
Read More...

WAKE UP HACKERS - CYBER TERROR



By Vaidehi Sachin

I've been using Facebook for less than a year. It's been mainly used as a communication tool with friends and family and acquaintances. Facebook is a good way to keep in touch and see what everyone else is doing. Photos and videos can be uploaded and shared for everyone to see. There are privacy settings that users can control, but it's still possible for a security breach. While a new era of technological fascination and social networking is upon us, the debate rages on amongst all those who have utilized the service(s) of either Facebook or MySpace, or, perhaps, BOTH. Even though charts and graphs depict the increasing popularity of Facebook's service(s), Face book captivating the hearts and minds of a massive, influential population. For me earlier it was just a space to understand the people related to the subject I was working on. Then this space became my community, my family out of family. Believe it or not when you are on face book surrounded by your friends you are out of tensions, you forget yourself for a while.

Recently I finished writing first volume of cyber terror; this is in addition to the same books second volume. You will be amazed to read this edition I have added my chapters where you can see the real faces of some hackers perhaps who might have dreamt of. I have added chapters on Khantastic HaXor( over rated but bad hacker), Cyber swati ( little deliv), SHAK, Haroon (ruled once), and many more such good bad and ugly hackers of India as well as Pakistan and Globelly. You will definitely love to read my date with Kevin, a guru of social engineering. WE have done intense research over many hidden faces which you may not even know.

Now when I think of Cyber War, Cyber terrorism I laugh at myself, the illusionary world and false assumptions which i was living with has flopped me over night. I was forced to change my thought process and went rear to reality. The cyber war which you experience in day to day life with all these kid hackers defacing pages is nothing but child’s play, these so called exploits, shell uploading, harming sites, web hacking, binding virus, ohhhhhhhh! It’s just nothing. A dumb ass like me who possess an average intellect can also learn this internet game in no time. Cyber war has began in internal level, where the hackers are ruling your embassies, your security systems, they are eyeing on your moves, your thoughts, your national planning, and arms defense and ammunitions, NASA, they are there where you never thought of. it something like this

CONFIDENTIAL MOS T IMMEDIATE No.140 16/10/2010- UTS.II Ministry of Home Affairs Governme nt of India **** North Block, New Delhi- 110001 Dated the 24th **, **** To 1. Secretary (Services), Gove rnment of NCT of Delhi, Delhi Secretariat, I.P.Estate, New Delhi. 2. Chief Secretary, Andam an & Nicobar Islands Admn, Port Blair.

They know the moves, promotions, changes in departments everything working in embassies. Core networks what the target is what hacking, and that is the beginning of CYBER WAR.
The hacking which you do focusing on website , it’s not hacking my dear friends it is just destroying some ones source of earning. You are playing your wasted games at the cost of an innocent citizen’s site. Let it be Indian, or Pakistani or of any other country.

Recently when I heard vishal thappar of GEO TV anchor saying on national television... about Pakistani collabaration with Chinese hackers ...omg I felt like rolling down, I am sure even pak hackers must have seen this standup comedy. Irony is that we media take all authority in hand and make such foolishstatements as if we know the world.

My dear readers I am talking about the conflicts not talking about technology and hacking, its outdated subject. It’s not who’s against who, it’s just why against why? Every government of the world has some agenda and they are working on it. ..Period. Like USA, Israel, India Pakistan china Russia everyone is doing their bit to be the rule writer that’s it. Each government is assigning these jobs to hackers, again Hackers not website defacers and facebook and msn ones.
Want to know more read CYBER TERROR……………

In next post which is part of this book read my first love on Face book, my close friend creating fake ID the dog techie for wrong reasons, people playing with my emotions, how and why one misunderstood? So much about my facebook family, my first defacement…using facebook wright from hell ..and so much part by part here itself..........

---Like this post, Just leave a comment as your feedback. If you want us to post an article on some specific topic OR have a suggestions for us...you can also drop an email on amarjit@freehacking.net
Read More...

Saturday, November 13, 2010

Cyber Criminals Are Also Human: Cyber Terrorists are People Too



In my openion, the Cyber security is a human problem, but not a technology problem. Sure it manifests itself through technology, but unless, and until you realise that humans are at the heart of it, you are never going to crack it.

What does this mean? It means we doesn’t just hire computer geeks — not just brought electronic engineers and computer scientists — But better is to hires human scientists and even sociologists..BUT WHY??? Because We can’t claim to understand the system we are trying to tackle until we understand the human component & that should be very obvious.

People in the cybersecurity “community” view the world from their own view point. They simply step out of from the anglo-centric view of the world. They Have to think about how people’s geographies and their cultures interact with the system.

For the term “cyberspace”, it is one of the geometry, a boundary or a perimeter & it leads us to thinking about perimeter defense also. Here we need to defend our perimeter against the bad guys. Keep the bad guys out. Perimeter defense is not going to lead to perfect defense, and limiting access to the networks certainly might work, but taken to the limit.

The history of computer security is one of huge gaping holes — maybe it’s time to have another think about this.

---Like this post, Just leave a comment as your feedback. If you want us to post an article on some specific topic OR have a suggestions for us...you can also drop an email on amarjit@freehacking.net
Read More...

Thursday, November 11, 2010

SPECIAL REPORT: Bruce Schneier on the future of IT security



A security guru has debunked cyber war and cyber terrorism myths.

The threats of cyber war and cyber terrorism have been grossly exaggerated and are hindering a real understanding of risks on the internet, one of the world’s leading information security experts has said. Bruce Schneier, the author and security technologist who is also chief security technology officer with BT, was speaking in Dublin yesterday at an event held by the Irish Institute for European Affairs (IIEA).

Schneier referred to the denial of service attack in Latvia in 2007, which brought down several government services for a time, and said it was most likely the first such cyber war attack against a state. However, he pointed out that just one person was convicted – an ethnic Russian living in Latvia who was apparently angered by the authorities’ decision to remove some statues dating from the Communist era.

“It could well be that the first cyber war was perpetuated by an annoyed, disaffected youth,” said Schneier. From a technical point of view, the incident was no different to a regular cyber crime tactic. “Estonia was a regular denial of service attack – it just happened to be against a country instead of Amazon.”

Similar attacks took place against systems in Georgia the following year, just before Russian forces invaded, but Schneier warned against opting for obvious conclusions. “We don’t know if it was government sanctioned or just activists playing politics,” he said.

Even technology security experts can’t agree on what constitutes cyber war, he said, “One of the problems we have is there is no good definition of what war looks like in cyber space … we don’t know when it starts or what a war looks like when it’s over.” Schneier posited that it’s a rhetorical war, like the war on crime or the war on terror, and remarked on the irony that the term is quickly applied to situations where no war exists, and not where it does. “It’s dangerous to apply the term war without knowing what’s going on.”

Schneier was similarly sceptical about the word cyber terrorism, calling it a media myth. Attacking the Stock Exchange or on a mobile phone network does not put people’s lives at risk and would not spread mass panic that a real terrorist attack would, he said. “I don’t like the term terrorism applied in places where it doesn’t belong.”

“There’s a lot of politics in cyber war, and this is where we have to watch language,” he added. “Using the war metaphor reinforces the notion that we are helpless. It’s immediately evocative. If I say ‘cyber war’ to a politician, he’ll get it. The message will be wrong, but he’ll get it.”

The Stuxnet worm
Schneier turned his attention to the Stuxnet worm, the subject of much security industry speculation since its discovery earlier this year. A combination of multiple threats, it is malicious and designed to attack a certain type of industrial control system, which led to speculation that it may have been targeting a power plant or nuclear facility in Iran.

Experts estimate that several years went into writing the code and it attacks previously unknown vulnerabilities. “We do know that Stuxnet is not a criminal worm because criminal worms try to steal money,” said Schneier. “The people who designed this knew what they were doing.” However, he said for all Stuxnet’s detailed design, it would probably do nothing. “Is this an act of war? If indeed the result was sabotage of a nuclear power plant, in the real world that would probably be an act of war, but we don’t know who wrote it,” said Schneier.

Absent a motive and identity, it’s hard to police cyber attacks under any kind of legal framework, he added. “The two things we don’t know are who’s attacking and why.” Discovering the real origin of attacks is difficult, which leaves the issue of reprisal completely open to question, said Schneier. “Cyber attacks don’t come with a return address. If a group wants to frame Russia (for an attack), this isn’t hard. You never know when your trace ends. I can trace attacks back to computers, but the link from computer to chair is very difficult.”

Cyber war treaties
The fact the US has a cyber command is a good idea and Schneier encouraged more debate around the issue. “Now is the time to think of cyber war treaties. The last thing we want is a cyber war arms race,” he said. While he claimed not to have answers for all the questions, he said they were worth asking in the context of a broad discussion on the subject. A cyber war treaty might include agreements that no civilians are to be targeted in any action between rival states. “Is it OK to create official Trojans and keep them in your back pocket until there’s a cyber war? It’s like stockpiling weapons,” he added.

Similarly, Schneier welcomed the kind of cyber war incident reponse test conducted this week by the EU. “It’s a good idea. The US does this all the time. There’s nothing bad in practising, simulating and training.”

Discussing these issues without resorting to hype makes sense because they will become increasingly relevant, said Schneier. “As more of our lives, economy and infrastructure move into cyber space, cyber space becomes a more attractive target. While the hype doesn’t serve us well, we should start talking about these things, we should start knowing what cyber war and cyber peace is so we can have less of one and more of the other.”

At the same time as the recent domestic unrest in Greece, some hacking was spotted in that country. The nature of the web means activism is amplified, even if it is only carried out by one person. Schneier likened it to the assassination of Archduke Ferdinand – the act of a single individual was the catalyst that pushed Europe into the First World War. “Cyberspace is a place where a disaffected person can magnify their message,” he said.

“I think the real threat is cyber crime and that is what we should be concerned about,” he said, calling on all nation states to be prepared for cyber attacks, whatever form they may take. “Every country needs some kind of CERT (computer emergency response team), and some kind of police investigative powers.”

---Like this post, Just leave a comment as your feedback. If you want us to post an article on some specific topic OR have a suggestions for us...you can also drop an email on amarjit@freehacking.net
Read More...

Wednesday, November 10, 2010

Cyberwar & Cyber Terrorism: How to Guard?? By Dr. Ravi Bhatia



By Dr. Ravi Bhatia

E-Mail-ravipbhatia28@rediffmail.com

The world-wide web or the internet has become an omnipresent presence in the contemporary world. From sending and receiving messages to accessing services such as banking, booking rail or air tickets, to trading shares on stock exchanges, more and more people inhabit cyberspace with the aid of a computer. Science fiction writer William Gibson coined this term, which indicated his vision of a global computer network linking people, machines and sources of information throughout the world. Anyone could navigate through this virtual space and use this facility freely for learning, sending and receiving messages and photos and other visual materials.

Large computer systems connected to internet and local intranets have also become indispensable in defence services, atomic energy establishments or space research organisations such as ISRO for launching satellites or rockets or in other similar sensitive areas. These organisations connect through complicated computer systems called servers and specialised, sophisticated software for operational processes that need utmost security for safe keeping and analysis of data and computer operations.

Satellites, whether meteorological or scientific, are launched and maintained by advanced computer programming. Data received from them also need sophisticated handling for analysis and dissemination. Because of these universal applications of computers and their control systems and servers, a new danger lurks behind these large computer systems.

Serious threat exists when military, scientific or bank servers are hacked by so called computer viruses also called malicious software or malware. This term signifies the penetration of individual or institutional computer systems by viruses with malicious intent. Here the entire operations of these organisations whose servers have been hacked are at risk. Sometimes the danger is more acute as the systems are completely disturbed or destroyed.

Cyberwars

The targets of malware on computer systems can be civil or military. Civilian targets could be gas or oil refineries, disruption of banking and stock exchange operations, jamming communication networks such as telephones, disabling websites and disruption of online reservation systems of air and rail.

The penetration of malaware into military or defence systems has a very sinister design. By means of hacking military or service servers, a terrorist organisation can wage war or destroy the military operations of a target of their choice. Several terrorist operations can be undertaken by this means. It could mean steering computer controlled helicopters to a different destinations, destruction of military or weather satellites, penetration of nuclear facilities with an intent to dame, dislocation of military operations.

Military warfare hacking computers and introduction of malware is often called cyberwar. Modern warfare is heavily dependent on remaining in contact between the commander of a military operation and the soldiers and officers in the forward lines as well as stationed elsewhere. The commander collects information from the forward and other lines, analyses it and then gives appropriate directions to all the military personnel in that operation. Collecting, sharing information, and giving directions is done through internet and intranet networks. If this system is hacked the military force becomes lost or goes blind. It does not know what to do and how to act. The aerial layers of the military command – helicopters, warplanes also become dysfunctional and confused. Thus when the military command’s network is hacked, the whole capability of a military unit is reduced if not totally destroyed.

What would be the impact of a cyberwar? According to Richard Clarke in charge of counter terrorism and cyber security in USA, this would lead to a catastrophic breakdown of systems that we swear by within a very short period of time with damage to of oil refineries, air traffic control systems, derailing of mass rapid transport systems, orbiting satellites spinning out of control, among others. These events would lead further to other breakdowns of transportation of food supplies and other essential commodities. The impact could be as devastating as that of a nuclear war.

A recent case of a software bomb called Stuxnet was reported in the Times of India, designed to penetrate Iran’s nuclear facilities in order to sabotage them. This has been achieved by producing a malware that is able to recognise a specific nuclear facility’s control network in order to destroy or paralyse it. The same newspaper reported on 27th September that Iran admitted to 30,000 computers having been affected by Stuxnet but denied that their first nuclear plant at Bushehr was affected. Iran maintained that the main systems at this power plant were not affected and computer programmes were running normally.

Guarding against cyber terrorism

Terrorists can pose serious dangers by resorting to cyber war tools. Modern countries must guard against these hazards. Whether or not an actual terrorist organisation engages in cyber terrorism, we must protect ourselves from its potential danger. Countries like USA, Russia, UK and others are aware of these dangers. They have set up various command posts to remain alert and take precautionary steps to prevent these types of risks and if something actually happens how to take prompt remedial action.

What can India do to ward off similar cyber attacks on its critical computer systems belonging to military, space research, nuclear facilities etc?

This is a complicated and a very sensitive area where not too much information is available.

However some of the basic steps that are needed to protect the country from this type of cyber attack are briefly presented below:

1. Recognition of the dangers of cyber attacks.

2. Design of computer security architecture to prevent infection of computer systems from malware viruses.

3. Training of relevant computer and military experts.

4. Setting up of a joint command directly under the Prime Minister or the National Security Agency.

The system of prevention of neutralisation or destruction or military computer systems and network is a very complex, sensitive and secret operation. But it is important to realise the inherent danger of cyberwars and take whatever preventive steps possible.

Dr Ravi Bhatia is an educationists and peace researcher based in Delhi

---Like this post, Just leave a comment as your feedback. If you want us to post an article on some specific topic OR have a suggestions for us...you can also drop an email on amarjit@freehacking.net
Read More...

Cyber Threat Facing the UK Says Defence Minister



Nick Harvey has emphasised the cyber threat facing the UK, saying it is "a matter of time" before terrorists use it as a method of attack.

In a speech in London, the armed forces minister warned that, in the wrong hands, a laptop could be as effective a weapon as a cruise missile.

He also set out how the government planned to use cyberspace to help the military fight the wars of the future.

All parties see cyber warfare as one of the UK's biggest emerging threats.

In the government's recent national security strategy, cyber security, alongside terrorism and a flu pandemic, was identified as a "tier one" threat to the UK - meaning the government was giving highest priority to these issues.

'Top threat'

It will spend £650m over the next four years on a National Cyber Security Programme, aimed at protecting individuals and the national infrastructure from hostile computer attacks.

However, Labour says the plans are a "reheated" version of its own approach while critics say government efforts are disjointed and officials are not taking advantage of external expertise.

Mr Harvey told Chatham House that the consequences of a cyber attack against the country's critical infrastructure could be "catastrophic".

"The fact that cyber security has been identified as one of the top national security threats for the UK over the next five years indicates both the likelihood of such an attack and the level of impact," he said.

"It can only be a matter of time before terrorists begin to use cyber space more systematically, not just as a tool for their own organisation, but as a method of attack," he said.

The public should not just focus on the threats posed by cyberspace as the government was still excited about the way the internet and digital technology enables people to expand their horizons and express their freedoms.

Warnings

But he said governments across the world would have to establish laws governing cyberspace and how it is used, in accordance with existing legal frameworks.

BBC defence correspondent Jonathan Beale said Mr Harvey had spelt out his belief that the threat was real and the government must work with industry and academia to combat it.

So far the focus has been on the threats posed to the UK, he said, rather than how Britain could use cyber warfare to enhance its conventional military capabilities.

There have been warnings from ministers and security chiefs about the threat in recent weeks.

Last month, the head of GCHQ, Iain Lobben, said 1,000 malicious e-mails a month were being targeted at government computer networks.

In a rare public appearance, the intelligence agency's director said the UK's critical infrastructure, such as power grids and emergency services, faced a "real and credible" threat of cyber attack.

---Like this post, Just leave a comment as your feedback. If you want us to post an article on some specific topic OR have a suggestions for us...you can also drop an email on amarjit@freehacking.net
Read More...

US Department of Defense Takes Steps to Defend Air Force Cyber Property



By Ian Graham
Emerging Media, Defense Media Activity

WASHINGTON, Nov. 9, 2010 – Computer networks can do a lot of things. They can turn your neighbor’s kid into a viral video phenomenon, they can let you know you’re about to miss your connection in Atlanta, and they can be a line of defense in protecting national assets.

Maj. Gen. Michael J. Basla, vice commander of Air Force Space Command at Peterson Air Force Base, Colo., is concerned with the latter.

In a “DOD Live” bloggers roundtable yesterday, Basla discussed the Air Force’s cyberspace mission, cybersecurity and the training and education the Air Force is providing to airmen in the field.

Basla said the Air Force’s mission emphasizes mission assurance: how to conduct operations in, to and from cyberspace and how to react as quickly as possible to emerging threats.

“There’s a great threat to American security out there in the cyberspace domain, and it's real, it's significant, it's persistent, and we are under attack every day,” Basla said. “The defense of our networks is essential for us to conduct all kinds of day-to-day activities -- in the commercial sector, in the public sector, in the military sector.

“So the Department of Defense recognized this,” he continued, “and as the Department of Defense does, they said we need to have a capability organic to our Department of Defense so that we could carry out anything our government might ask us to do in the defense of our networks.”

The general said the Air Force looked at its core capabilities -- related to speed, access and distance –- and determined how to best meet the Defense Department’s requirement to defeat threats from cyberspace. That starts with teaching new officers and enlisted airmen how to fight on the digital battlefield, Basla said.

The Air Force is reconciling that need with the requirements of the job. Basla said 100 percent of the service’s original cyberspace officers had to have technical degrees before being admitted to the cybersecurity program. Now, only about 80 percent need them.

“We wanted to have tech, math, science, and engineering degrees, but we were advised that there are some folks that could come from the social sciences that could contribute -- you know, something about looking at the problem a little differently,” he said. “So we've allowed for some exceptions.”

Interest in the field has increased generally, he said, because the young people enlisting and enrolling at the Air Force Academy have grown up with computers, at least in their schools.

“There's a great deal of interest, I will tell you, and that's the encouraging thing,” he said. Potential cyber airmen “want to understand what their responsibilities will be, and how they can get involved,” he added. “And so I'm encouraged about that.”

Part of his encouragement is related to the prevalence of computing –- though most recruits come to the Air Force with working knowledge of computer systems, many don’t understand the risks associated, such as phishing scams and virus attacks. Basic training at Lackland Air Force Base in Texas now includes two sections on being a good “cyber wingman” and taking care of the network, and the Air Force Academy now offers a cybersecurity major.

“It's hands-on lab work. It's ‘red versus blue forces’ exercises. It is instruction. It is classroom work,” he said.
The increased capabilities, though, come with an increased demand for people. The Air Force plans to bring in 220 people under a new Air Force specialty code, and Air Force schools will graduate another 50 cyber specialists yearly.

“As I talk to the folks in the field and we get feedback from the combatant commands that are now starting to understand that cyberspace brings another aspect of warfighting capability to the fight, some of the things that we are hearing are that we want more of these,” he said.

Integrating the new specialty -- a consolidation of 11 other specialties including airfield systems maintainers, network operators and information managers -- into planning and execution cycles still a work in progress, Basla said. He pointed out that the cyber field has two sides.

“When you look inside of that specialty -- and certainly that specialty includes these ‘3-Deltas’ -- there are two pieces to that picture,” he said. “The one piece is the technical experts who help develop and create and sustain that cyberspace domain that we've been talking about. And then there's another component of that picture that are the operators that operate inside that domain that was just created.”

One group is made up of people who are facilitators and maintainers of networks, he explained, and the other is made up of those with operational capabilities.

He said today’s problems regarding network operations and security are drastically different from those of the past, and that creates the need for both operators and facilitators. In the past, a blinking light meant a network interruption needed fixing. Now, that blinking light could signify an attack, rather than the need for a routine repair.

“Today, the operator must say first, ‘Is there some adversary that is getting into my networks that is trying to interrupt my mission assurance capabilities?’ So that's the difference, and we need both,” he said.

---Like this post, Just leave a comment as your feedback. If you want us to post an article on some specific topic OR have a suggestions for us...you can also drop an email on amarjit@freehacking.net
Read More...