The John Batchelor Show

Podcasts

Lessons Learned from the Hacking: "Black Hole Exploit Kit"

| 0 Comments
The black hole discovered in the galaxy NGC 3842 dwarfs our Solar System.  

blackhole_v2.jpg

The JBS site was hacked and malware was distributed on it sometime very early Friday morning, January 27.  My thanks to my web colleagues who have cleaned out the hack attackers and their malware (the site is acceptable again to the Google watchtowers) and taught me what took the site down from Friday 27 until Sunday 29 January.  I learn the that method of attack was a relatively new malware weapon system (dating from December 2011) called the  "Black Hole Exploit Kit. (BEP)"  The suspects may well be Russian hackers, who are always perfecting their code to avoid detection by the defense systems.  The entry method is the old-fashioned phising, that is inserting a false link in the posts that let the BEP enter the site.   I learn from the "Imperva Data Security Blog" that this new BEP is able to avoid detection up to 70% of the time:

What's New?
The new black hole exploit kit has been out and we've had a chance to deconstruct it.  Before we get super geeky, some general observations about the innovation in this kit:

  • Malware developers continue to use the latest tools to encrypt their malware to evade anti-virus (AV) software.  As usual, the encryption signature is new, avoiding AV--our analysis showed that 70 percent of AV software would miss this altogether.  This serves as a not-so-gentle reminder the fundamental problem with signature based AV--it changes every week with the use of a new encryption algorithm.  
  • Hackers are deploying resiliency.  In the past, we've seen hackers deploy a single exploit server.  In this case, there were four that could be redirected if any of the URLs was taken down.

What are BEPs?
An exploit kit, a browser exploit pack (BEP) is a toolkit that automates the exploitation of client side vulnerabilities. 

The toolkit is a bundle of PHP and HTML files with a list of exploit files (including JAVA, PDF, Browsers, Adobe Flash Player ...etc) designed to target the operating system, browser or other client side application.  Toolkits are usually heavily obfuscated using some known or unknown obfuscation and crypto algorithms tools to avoid detection by anti-virus vendors.  

Black hole is yet another web exploit kit developed by Russian hackers. Blackhole is a very powerful kit with a number of recent exploits including Java and Adobe PDF exploits. One blog published (with updates) a great overview of the most known exploit packs. 



Koobfaced Gang.  

koob-popup.jpg
I also learn that there are a host of suspects, though the Imperva blogger aims his remarks at the Russians.  My conversation with Misha Glenny teaches me (author: Darkmarket: Cyberthieves, Cybercops and You, Knopf 2012) that the phishing attacks are well-known to a variety of hackers, from Odessa to Petersburg to Berlin to San Francisco.  I have covered a number of these issues recently.  Most readily, I spoke to the NYT Riva Richmond a week ago, Friday 20 January, about the Petersburg-based Russian hackers called the "Koobfaced Gang," who are regarded as especially successful.  They used to employ Facebook to attack and steal by using phony vendors (no delivery) or selling their power to redirect traffic to fraudsters.  A member of the Koobfaced Gang posted the picture to to left  to Foursquare, which included the coordinates on an accompanying map.  Bold and trite, by Misha Glenny has taught me that the Russia hackers know they are safe in Russia as long as they do not mess with Russian based sites.  Facebook is said to have made it no longer worth their while, and they have gone elsewhere.  Perhaps it was the Koobfaced Gang just swinging by to leave a calling card.  What is odd about the attack is that it is a major weapon system, newly developed and most effective so far against lots of guardians.  My site is non-commercial: no cash, no credit cards, no passwords, nothing to steal or exploit or manipulate.  It is a bookish record of the show's ceaseless conversation with authors, professors, journalists, editorial writers and think-tankers.  What use a BEP?

So Many Villains, So Little Time.    

We did entertain the possibility of the China geniuses, since Gordon Chang sits with me as co-host each Wednesday, and he was mostly rewarded for his diligence in criticizing the China Communist Party's bullies and bosses by having the People's Daily declare him an "enemy of the state."  Then too Malcolm Hoenlein and I sit together each Thursday and speak roughly of the Tehran Twelvers and their stooges.  China and Iran both have their share of clever hackers.  



 
black exploit kit.jpg





Enhanced by Zemanta

True Virtual Dotcom Crime Reports

| 4 Comments
 



Screen shot 2012-01-24 at 12.50.37 PM.png
Wonderful to see my colleague Simon Constable featured in this web report (Simon on the WSJ newsroom floor noting the CofD3 stats) constructed by the infamous web buccaneer Kim Dotcom, the impressario of the pirate site MegaUload. It is a pleasure to see that Mr. Dotcom now only surfs the web, he can play the web to championship level. The detention will slow the results, and we can assume someone has now passed Megaracer. Still, a grand record, and all the sweeter because of the allegation that Mr. Dotcom cheated the system to run up his kill records -- just like Captain Kirk fixing the computer simulation at Star Fleet Academy to win the Kobayashi Maru scenario). (Mention also that Dotcom has a rep in the gamer world as a vindictive sore loser: surprise!)  I have tried to manage the Xbox controls. It requires eye-hand coordination beyond the reach of a middle-aged dad.  Am seeking Misha Glenny to follow up on the MegaUpload case, the new new world of virtual piracy.  Below find the report from Auckland, New Zealand on the indictment of Mr. Dotcom (aka Kim Schmitz) and colleagues, in addition to a glimpse of their automobile park and former rented mansion.


  
Enhanced by Zemanta

"The Senator" Gone

| 13 Comments

CFR Theme Park and the GOP

| 22 Comments
ObamaCFR.jpg

John Bolton, AEI, endorses Mitt Romney in a matter of fact presentation of why the US has stumbled badly with the Obama administration's unusual clumsiness. Speak to John Bolton routinely, and over the last years we have catalogued the arrogance and indifference of POTUS foreign policy, from the Mideast delusions of making peace with the gangsters of Hamas to the passivity in the face of Tehran and Pyongyang aggression. John Bolton is a leading candidate for StateSec in a Romney administration, and his endorsement has much weight in the posh CFR theme park (below). Also, the Bolton measure is a direction for the GOP that will provide a sharp contrast with the Obama administration the next ten months. The just revealed episode of the IRGC harassing the USS New Orleans at the Hormuz Strait (January 6) and the same game against a Coast Guard cutter east of Kuwait City (Jan 6) point to a building Gulf crisis. John Bolton doubts that POTUS Obama has the talent, boldness or desire to solve the rogue threats. Bolton mentions that the Bin Laden op was the result of ten years of search and destroy, and that Obama was at the end of a long chain of decisions. Tehran requires statecraft, not generic electioneering to a timid, downcast citizenry.




counfor.gif

Enhanced by Zemanta

DPRK Cult Opera Themes

| 5 Comments

 


New video from North Korea, DPRK, starring Kim Jong Un playing his father in the walk-and-talk-with-the-bosses scenes that serve as a regime opera. The many faces of military cadres is the best evidence available of who is in charge of the  Kim cult.  What is striking is how closely KJU imitates his father's casual haberdashery and regal gestures, as if he is trying out for the role of Big Kim.  Are they now experimenting with doubles and triples in the same rolly-polly format, so that they can send KJU on secret missions while his doubles hold court for cameras?  This is bizarre discovery.  The PRC and its PLA cadres are held in check by the play-acting of these unusually dim-witted actors on a stage of severe depravity (famine as a weapon is commonplace in DPRK).  KJU is a stooge to stooges.  The KJU cult development proceeds in a separate reality to ours, a parallel performance, and it is testing the audience (us) to learn if the cult is satisfactory.  This may be the best version we will ever get of what the planet would look like if the junta opera cults ever achieved their goals of conquest.  For now, it is as if there are cult theme parks, in Tehran, in Pyongyang, in Damascus, in Harare and so forth, where the melodramas struggle in their central casting roles.

Screen shot 2012-01-10 at 12.09.06 PM.png

Screen shot 2012-01-10 at 12.08.24 PM.png
  
Enhanced by Zemanta

Who owned the Titanic?

| 4 Comments
 


the-funeral-of-john-jacob-astor-iv-who-died-in-the-sinking-of-the-titanic-new-york-may-4-1912.jpg
The White Star Line was built by the self-made Liverpool sharpie Thomas Ismay from the remains of a failed line that sent immigrants out to Australia in the mid 19th Century. Ismay made the move from sail to steam and launched larger and larger ships until he was well capitalized enough to build twin behemoths, Titanic and Olympic. By then, Thomas Ismay had lost control of the original company to the sharholders of International Mercantile Maritime (IMM) which was controlled by the significant presence of J.P. Morgan. Thomas Ismay's son Bruce Ismay (below) was the president of the Line, and, at 49, world prominent after 80 crossings of the Atlantic in his duties, Bruce Ismay was onboard the Titanic along with the stunningly weatlhy John Jacob Astor IV (then 47, a $100 Billionaire by today's collar) for the maiden voyage. I learn from Frances Wilson's new book, "How to Survive the Titanic: the Sinking of J Bruce Ismay," that Ismay chose to put himself into one of the last lifeboats lowered from B Deck.   The New York papers were immediately convinced that Ismay was a coward and rat, and the Congressional inquiry in the Ritz that followed within days put Ismay on the stand as if he was the criminal of the event.  The English press lords were sympathetic to Ismay and protected him when he arrived back in London for a British inquiry of what was in effect an American company's conduct.  Ismay spent the remainder of his life in seclusion, indifferent or deaf to the accusations that he left his post as owner of the ship.  The auction in New York is unlikely to offer any artifact that connects to the Ismay scandal.  It will show lots of evidence of the 400 first-class passengers on board.  However the White Star Line was built on the fact that it made money on the third-class passengers, and that Ismay's great genius was to build giant floating bins to take advantage of the immigrant push to America after the Civil War.  Note that Astor's body was recovered (funeral left), with a surprising amount of personal paraphernalia (below) that illustrates how the richest of men lived and died one century ago: Astor is said to have placed his 19 year-old bride (after a scandalous divorce to his children's mother) in a lifeboat, and then to have boosted two children into place beside her.  The anecdotes of Astor's conduct as the ship sank made him an immediate hero to the press.

CLOTHING - Blue serge suit; blue handkerchief with "A.V."; belt with gold buckle; brown boots with red rubber soles; brown flannel shirt; "J.J.A." on back of collar.
EFFECTS - Gold watch; cuff links, gold with diamond; diamond ring with three stones; £225 in English notes; $2440 in notes; £5 in gold; 7s. in silver; 5 ten franc pieces; gold pencil; pocketbook.
  
ismay.jpg

Enhanced by Zemanta

Apple Harvest of the Late 20th

| 20 Comments



Apple's success derives from the simple fact that the Facebook generation has grown up alongside the single-minded product line. The video above connects to the first 25 years of Apple, 1976-2000, when it was a cluttered, self-centered cult, imitating grown-up office environments without direction or success.  After 1984, it did manage to put its sealed, peculiarly boxy, toylike Macintoshes into numerous primary and secondary schools.  I watched as my children were trained in a so-called computer lab with rows of Macs, simple, icon-based, hard to break, easy to learn.  No laptop to speak of in the Apple line until the late 90s. What was happening?  Conditioning.  These years, Apple promotes itself as a software company. The IPhone dominates the streets and subways of NY in the hands of the young and no longer young. I favor the notion that what Steve Jobs and Apple achieved was to listen to the practical needs of the Millenniums, who are restless, connected, socially skilled, and relentless consumers of cultural intelligence. Apple did not get out front. Apple developed a product line from what was extant, and then it connected the products to each other.  Apple responded to the least among the consumers, the children who couldn't choose their own products but who lived with what their parents and school boards considered child appropriate, the 1-20 year-olds of 1999, who are the dominant players of the next business cycle.  Apple didn't sell the young; it harvested them.

apple-campus-overhead-sketch.png
Enhanced by Zemanta