Dancho Danchev's Blog - Mind Streams of Information Security Knowledge

In the overwhelming sea of information, access to timely, insightful and independent open-source intelligence (OSINT) analyses is crucial for maintaining the necessary situational awareness to stay on the top of emerging security threats. This blog covers trends and fads, tactics and strategies, intersecting with third-party research, speculations and real-time CYBERINT assessments, all packed with sarcastic attitude

Wednesday, May 23, 2007

Counter Espionage Tips from the Cold War

There's nothing old-fashioned in short films like these representing possible techniques used by intelligence services while recruiting - "Cold War counter-spy instructional film created to convince government officials traveling with top secret info to watch their backs. Watch hapless G-men get seduced and setup for blackmail by treacherous Soviet she-spies"



And despite that today's perception of sexy she-spies has evolved proportionally with the technological advances in espionage, some of the tips are still emphasizing on the basics.
- May 23, 2007 No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Dancho Danchev
Independent Security Consultancy, Threat Intelligence Analysis (OSINT/Cyber Counter Intelligence) and Competitive Intelligence research on demand. Insightful, unbiased, and client-tailored assessments, neatly communicated in the form of interactive reports - because anticipating the emerging threatscape is what shapes the big picture at the end of the day. Approach me at dancho.danchev@hush.com

Tuesday, May 22, 2007

A Client Application for "Secure" E-banking?

This is perhaps the second product concept myopia right after the lie detection software for text comminations I come across to recently. Remember a previous post heading in the opposite direction, where a bank was trying to rebuild confidence in the most abused phishing medium - the email - to keep in touch with its customers? Here's another company that's betting on a third-party client application to solve the problem of secure E-banking totally falling victim in the secure channel communication myopia one that I think has nothing to do with reality when it comes to the success of phishing :

"Here’s how Armored Online works: A company, such as a financial institution or online retailer, offers a downloadable client to customers through its website. That client then gives the customer’s computer a secure channel with which to communicate and transact with the company. Its Java-based browser is locked down, meaning it won’t accept any plug-ins, like cookies used by criminals. What’s more, the client can only “talk” to the server at the bank or online store. “It’s like iTunes for banks,” Mr. Sowerby said."

The attack of the disabled cookies? Not really, so be realistic. Coming up with a third-party application as the cornerstone of E-banking security directly conflicts with E-banking's biggest benefit - flexibility due to the compatibility with the most popular browsers. So you'd rather focus on the current situation - Brandjacking instead of re-inventing the SSL wheel -- as a matter of fact the Gozi trojan and the Nuclear Grabber are quite comfortable with SSL as they bypass it entirely. Even worse, a trojanized copy of the program will emerge given it receives any acceptance at all. And if banks start embracing it -- don't -- we can easily start talking about DRM enabled E-banking where, both, banks and customers will turn into virtual hostages to a third-party application trying to reboot the market for anti-phishing services, totally forgetting the problem is not in the lack of unencrypted transactions as no one is sniffing the credentials, but pushing fake sites instead of letting customers pull the sites for themselves.

Don't disrupt in irrelevance.
- May 22, 2007 No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Dancho Danchev
Independent Security Consultancy, Threat Intelligence Analysis (OSINT/Cyber Counter Intelligence) and Competitive Intelligence research on demand. Insightful, unbiased, and client-tailored assessments, neatly communicated in the form of interactive reports - because anticipating the emerging threatscape is what shapes the big picture at the end of the day. Approach me at dancho.danchev@hush.com

A Malware Loader For Sale

Continuing the Shots from the Malicious Wild West series and the yet another malware tool in the wild posts, here’s a recently advertised malware loader. Polymorphism, built in packing functions and the ability to set an interval for loading yet another executable at a URL or a URL redirector, DIY firewalls unloading techniques, pretty much anything ugly is in place -- as usual. The loader's source code is currently available for $150, undetected bots go for $15 per piece. Malware on demand in principle, or malicious economies of scale?
- May 22, 2007 No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Dancho Danchev
Independent Security Consultancy, Threat Intelligence Analysis (OSINT/Cyber Counter Intelligence) and Competitive Intelligence research on demand. Insightful, unbiased, and client-tailored assessments, neatly communicated in the form of interactive reports - because anticipating the emerging threatscape is what shapes the big picture at the end of the day. Approach me at dancho.danchev@hush.com

Monday, May 21, 2007

MySpace's Sex Offenders Problem

MySpace, being one of the most popular social networking sites is always under fire on its efforts to combat known child offenders registering and using its database to find what they're looking for. The problem isn’t MySpace as a faciliator for such type of communications but the vast amounts of personal information -- future contact points -- kids publish about themselves online, not knowing that on the Internet anyone can be a dog and most importantly, parents loosing the emotional connection with their kids and making it easier for someone to break the ice and establish trust.

Several months ago, funded by nothing more but his common sense Kevin Poulsen gathered name data from the U.S public child offenders registry and found positive results with people -- thankfully -- stupid enough to use their real names. And while they wouldn't do it again the next time instead of making it easier to aggregate the data, a CAPTCHA to limit such automatic activities was implemented. Don't blame MySpace blame bureaucracy. Meanwhile, here's an article on U.S authorities demanding that MySpace provide data on identified and removed known child offenders -- they agreed :

"MySpace agreed Monday to provide the information to all states after some members of the group filed subpoenas or took other legal actions to demand it. The company said last week such efforts were required under the federal Electronic Communications Privacy Act before it could legally release the data."Different states are going about it different ways," said Noelle Talley, spokeswoman for Cooper, who filed a "civil investigative demand" for the information. Connecticut Attorney General Richard Blumenthal used a subpoena that "compels this information right away - within hours, not weeks, without delay - because it is vital to protecting children," he said."

If protecting children is vital, remove the CAPTCHA so everyone knowing how to aggregate and tweak the data will come up with far more sophisticated stats than the ones currently available. Actual results too. Next time it would become harder to track them, so don’t count on measures like these instead, ensure naughty conversations aren’t taking place at all. Makes me wonder one thing - should you be filtering known child offenders on the Internet perhaps a futile attempt given the pseudo-personalities they could establish, or at the ISP level and put them under surveillance right from the very beginning? Of course child offenders should not have unmonitored access to the Internet so rethink the basics.

Related posts:
Registered Sex Offenders on MySpace
IMSafer Now MySpace Compatible
- May 21, 2007 No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Dancho Danchev
Independent Security Consultancy, Threat Intelligence Analysis (OSINT/Cyber Counter Intelligence) and Competitive Intelligence research on demand. Insightful, unbiased, and client-tailored assessments, neatly communicated in the form of interactive reports - because anticipating the emerging threatscape is what shapes the big picture at the end of the day. Approach me at dancho.danchev@hush.com

Saturday, May 19, 2007

Tricking a Laptop's Fingerprint Authentication

The joys of fingerprint biometrics with a duplicate fingerprint of the original.

- May 19, 2007 No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Dancho Danchev
Independent Security Consultancy, Threat Intelligence Analysis (OSINT/Cyber Counter Intelligence) and Competitive Intelligence research on demand. Insightful, unbiased, and client-tailored assessments, neatly communicated in the form of interactive reports - because anticipating the emerging threatscape is what shapes the big picture at the end of the day. Approach me at dancho.danchev@hush.com

Friday, May 18, 2007

Commercializing Mobile Malware

Visionary enough, I predicted this over an year ago, and despite that for the time being there are only two publicly known pieces of mobile malware sending sms messages from the infected devices to premium numbers, it's an emerging trend for customers and mobile operators to keep an eye on :

"After installation, the Viver trojans immediately start sending SMS messages to premium-rate numbers. The messages are sent with proper international area codes, so they are able to reach the correct destination even when activated outside Russia. We've already seen for-profit malware in mobile devices: Wesber.A and Redbrowser are Java Midlet trojans that try to send messages to Russian premium-rate numbers. But these trojans require user acceptance per each message and are able to send messages correctly only inside Russia."

Some comments I made back then :

"The number and penetration of mobile devices greatly outpaces that of the PCs. Malware authors are actively experimenting and of course, progressing with their research on mobile malware. The growing monetization of mobile devices, that is generating revenues out of users and their veto power on certain occasions, would result in more development in this area by malicious authors. SPIM would also emerge with authors adapting their malware for gathering numbers. Mobile malware is also starting to carry malicious payload. Building awareness on the the issue, given the research already done by several vendors, would be a wise idea."

Something else to think about is related to Europe’s most recent mega-music event Eurovision and the sms voting power that, given enough infected mobile devices are in place the results could change pretty fast if you’re following my thoughts. Thankfully, compared to zombie networks making it possible to do intelligence and espionage tweaks given the large infected population, we still cannot talk about mobile botnets. The most juicy target for the time being however, remains the rise mobile banking.

Another comment I made a while ago :

"Malware authors indeed have financial incentives to futher continue recompling publicly available PoC mobile malware source code, and it's the purchasing/identification features phones, opening a car with an SMS, opening a door with an SMS, purchasing over an SMS or direct barcode scanning, mobile impersonation scams, harvesting phone numbers of infected victims, as well as unknowingly interacting with premium numbers are the things about to get directly abused -- efficiently and automatically."

Related posts:
Proof of Concept Symbian Malware Courtesy of the Academic World
Mobile Devices Hacking Through a Suitcase
- May 18, 2007 No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Dancho Danchev
Independent Security Consultancy, Threat Intelligence Analysis (OSINT/Cyber Counter Intelligence) and Competitive Intelligence research on demand. Insightful, unbiased, and client-tailored assessments, neatly communicated in the form of interactive reports - because anticipating the emerging threatscape is what shapes the big picture at the end of the day. Approach me at dancho.danchev@hush.com

Thursday, May 17, 2007

Yet Another Malware Cryptor In the Wild

Just stumbled upon a newly released cryptor in the wild, and as I pointed out in a previous post related to yet another cryptor, they're signature-based malware scanning's worst enemy. By the time AV vendors obtain a sample and analyze the routines they use, unless an IPS solution is in place, and end user friendly perimeter defense detecting the bot-ization of the host are in place - an infection occurs.

What's the big picture? It's launching a denial of service attack on anti virus vendors' labs in the form of distributing couple of hundred malware samples - future family members of a malware group. Polymorphism encrypting routines are nothing new, but with DIY cryptors in the wild the result can be quite successful even for copy cats:

"Another example is the Stration family of malware, responsible for worms and other forms of malware in late 2006. “Stration was changing so quickly—the encryption packaging, the compiler, everything. We saw up to 300 variants in a single day,” says Ron O’Brien, senior security analyst at anti-malware vendor Sophos."

File size: 4608 bytes
MD5: 406e3a1443ec617f2c968a957a460f10
SHA1: 187abe8cec588b53126afbe8e600379a3bac2321
- May 17, 2007 No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Dancho Danchev
Independent Security Consultancy, Threat Intelligence Analysis (OSINT/Cyber Counter Intelligence) and Competitive Intelligence research on demand. Insightful, unbiased, and client-tailored assessments, neatly communicated in the form of interactive reports - because anticipating the emerging threatscape is what shapes the big picture at the end of the day. Approach me at dancho.danchev@hush.com

Wednesday, May 16, 2007

Corporate Espionage Through Botnets

Following my previous post on OSINT Through Botnets, here's a company that's categorizing Fortune 500 companies whose networks are heavily polluted with malware infected hosts :

"Support Intelligence (SI), a network security company in San Francisco, has been running what it called "30 Days of Bots," featuring corporate networks infected with spam-churning bots. It began analyzing data in February, monitoring 10,000 domains that plow data into a trap much like a fishnet, except the intelligence in the data is designed to determine what information to keep by looking for spam. In total, SI analyzed traffic from more than 100 sources, including the aforementioned spam traps."

Considering the possibility for gathering open source intelligence through military and government infected PCs only, it is logical to conclude that a specific company can be targeted on the basis of the already infected hosts on its network as well. Think about it. For the time being, a botnet's master doesn't really care if it's a military or Fortune 500 company that's infected as long as spam, phishing and malware goes out of these hosts. But passive corporate espionage in the form of intercepting the traffic going out of a specific company's network shouldn't be excluded as an opportunity.
- May 16, 2007 No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Dancho Danchev
Independent Security Consultancy, Threat Intelligence Analysis (OSINT/Cyber Counter Intelligence) and Competitive Intelligence research on demand. Insightful, unbiased, and client-tailored assessments, neatly communicated in the form of interactive reports - because anticipating the emerging threatscape is what shapes the big picture at the end of the day. Approach me at dancho.danchev@hush.com

Visual Script Obfuscation

We often talk and deobfuscate scripts aiming to hide their real and often malicious intentions. But what if malicious attackers have become so efficient in their obfuscation, that they decide to show some JAPH style in order to make them harder to analyze by visually obfuscating the scripts as you can see here?
- May 16, 2007 No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Dancho Danchev
Independent Security Consultancy, Threat Intelligence Analysis (OSINT/Cyber Counter Intelligence) and Competitive Intelligence research on demand. Insightful, unbiased, and client-tailored assessments, neatly communicated in the form of interactive reports - because anticipating the emerging threatscape is what shapes the big picture at the end of the day. Approach me at dancho.danchev@hush.com

The Jihadist Security Encyclopedia

A month ago, the Media Jihad Battalion started distributing a 118 pages long encyclopedia on anything starting from secure communications to keywords not to search for as they'll raise an early warning system alarm. The front cover is so Blade's style, but the PSYOPS motive is highly influential. Here's a translated table of contents and the original version attached.
- May 16, 2007 No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Dancho Danchev
Independent Security Consultancy, Threat Intelligence Analysis (OSINT/Cyber Counter Intelligence) and Competitive Intelligence research on demand. Insightful, unbiased, and client-tailored assessments, neatly communicated in the form of interactive reports - because anticipating the emerging threatscape is what shapes the big picture at the end of the day. Approach me at dancho.danchev@hush.com

Sampling Jihadists' IPs

Great idea as a matter of fact :

"The following is based on an analysis of 4,593 IP addresses (1,452 unique IP addresses). The IPs were acquired from 19 of the more prominent of the Salafist/Jihadist forums, including both Arabic and non-Arabic forums, from 01 January through 30 April of this year."

Taking into consideration the per-country stats, do not exclude the logical possibility of IP cloaking while browsing these and also, the tiny number of intelligence and lone gunman info warriors gathering OSINT data. In another much more in-depth analysis on mapping the online jihad, the authors point out the emerging internationalization of jihad as well :

"The near exclusive use of the Arabic language in these significant jihadi websites likely accounts for the concentration of activity in the Middle East and North Africa. But with a reach to more than 40 countries, the virtual community within these ten influential sites assumes a global significance. The international jihadi movement's use of the internet to fuel the exchange of ideological expansion and its corresponding influx of support will increase the vulnerability of many countries to the appeal of extremism."

At least these organizations don't rely on setting up fake jihadist communities to come up with the sample data, but know exactly where to look for.
- May 16, 2007 No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Dancho Danchev
Independent Security Consultancy, Threat Intelligence Analysis (OSINT/Cyber Counter Intelligence) and Competitive Intelligence research on demand. Insightful, unbiased, and client-tailored assessments, neatly communicated in the form of interactive reports - because anticipating the emerging threatscape is what shapes the big picture at the end of the day. Approach me at dancho.danchev@hush.com

Monday, May 14, 2007

Mind Mapping Web 2.0 Threats

An informative, and for sure to be expanded mind map presenting various Web 2.0 threats courtesy of Mike Daw who by the way neatly integrated the anti virus detection results to his web backdoors compilation, I commented on in a previous post. Here are two more mind maps of Firefox security related tools, and the threats faced by mobile devices. A related post on the "wormability" of web application insecurities for everyone thinking flash worms.
- May 14, 2007 No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Dancho Danchev
Independent Security Consultancy, Threat Intelligence Analysis (OSINT/Cyber Counter Intelligence) and Competitive Intelligence research on demand. Insightful, unbiased, and client-tailored assessments, neatly communicated in the form of interactive reports - because anticipating the emerging threatscape is what shapes the big picture at the end of the day. Approach me at dancho.danchev@hush.com

XSS The Planet

Yet another initiative proving that major sites indeed suffer from XSS vulnerabilities in exactly the same fashion E-banking sites do. Perhaps the most interesting point regarding the list is that it's from 2005 and some of the sites still remain vulnerable but why is that? Lack of internal incentive programs to deal with the problem? Not getting the necessary attention given the rise of the lost laptop with unencrypted data issue? A lack of common sense is the best alternative for me. Consider the perspective - its like utilizing quantum encryption for the sake of protecting the confidentiality of your data but remaining vulnerable to wardriving attacks capable of obtaining the data in a pre-encryption stage, even on the fly. The encrypted data myopia is on the rise and it's the result of a yet another "stolen laptop news article" emphasizing on current and ignoring the emerging trends, namely, that a mobile workforce's improved productivity is proportional with the insecurities coming from storing sensitive data in a less controlled external environment. There's no point in implementing state-of-the-art technology when you haven't taken care of the basics, such as the ones that are so easy to exploit even a script kiddie can become the next pentagon hacker bruteforcing passwords on an unclassified system. And yes - trivial XSS ones too.

Currently active URLs on the list are the following:
Nortel.com
Federal Deposit Insurance Corporation
JC Penney
SonyStyle.com
D-Link.com
Poetry.com
- May 14, 2007 No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Dancho Danchev
Independent Security Consultancy, Threat Intelligence Analysis (OSINT/Cyber Counter Intelligence) and Competitive Intelligence research on demand. Insightful, unbiased, and client-tailored assessments, neatly communicated in the form of interactive reports - because anticipating the emerging threatscape is what shapes the big picture at the end of the day. Approach me at dancho.danchev@hush.com

Friday, May 11, 2007

Big Brother Awards 2007

I always liked the idea of emphasizing on the big picture when it comes to the worst privacy invadors on a worldwide basis compared to that of a particular country only. They are all interconnected to a certain extend, united under the umbrella of the common good which as a matter of fact won a golden boot in this year's Big Brother International Awards :

"PI's 'Big Brother Awards' have been running for nearly ten years, with events run in eighteen countries around the world. Government institutions and companies have been named and shamed as privacy invaders in a variety of countries and contexts. This year was the first time that Privacy International ran an international event to identify the greatest invaders around the world. The event was hosted by 'the pope', as presented by Simon Davies in full regalia. Previous hosts include 'Dr. Evil' and 'The Queen of England'."

Here are the winners in their categories :

Most invasive company - Choicepoint
Data aggregators and centralizing too much personal data in a single place makes it vulnerable even to pringles hacking attacks. Next year I'm sure Google's purchase of Doubleclick would get more attention

Worst Public Official - Stewart Baker
The way Microsoft and open source look awkward in a sentence in this very same way democracy looks awkward next to Russia

Most Heinous Government - The United Kingdom
Fully agree here. Twisting the common good is very marketable

Most Appalling Project or Technology - The International Civil Aviation Organization

I think the CCTV industry should have won here the rest are bureaucrats whose closed doors propositions later on face the public outbreak of how not to implement them. Anyway supply meets the demand for surveillance.

Lifetime Menace Award - The 'Common Good'
The main reason for the existence of today's intrusive surveillance technologies is the idea of the common good. We spy on you to protect you, we take away your civil liberties to protect you, and CCTV after CCTV you end up in a situation which can be best seen in the U.K

Related posts:
The Future of Privacy = don't over-empower the watchers!
Security vs Privacy or what's left from it
The Cell-phone Industry and Privacy Advocates VS Cell Phone Tracking
Afterlife Data Privacy
- May 11, 2007 No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Dancho Danchev
Independent Security Consultancy, Threat Intelligence Analysis (OSINT/Cyber Counter Intelligence) and Competitive Intelligence research on demand. Insightful, unbiased, and client-tailored assessments, neatly communicated in the form of interactive reports - because anticipating the emerging threatscape is what shapes the big picture at the end of the day. Approach me at dancho.danchev@hush.com

Thursday, May 10, 2007

Defeating Virtual Keyboards

To deal with the threat of keyloggers -- or to win time during te process of implementing two factor authentication and one-time-passwords-in-everything -- E-banking providers started introducing virtual keyboards as a pragmatic solution to the threat. Malicious attackers are anything but old-fashioned and this is a great example that insecurities are only a matter of perspective. To the E-banking providers who were aware that a static virtual keyboard would be much more easier to defeat, a randomized characters appearance came into play and so attackers adapted by first taking video sessions of the login process, and now turning each mouse click into a screenshot to come up with the accounting data in a PoC on Defeating Citibank Virtual Keyboard:

"Citibank Virtual Keyboard is a security enhancement for protecting from the key loggers. Using this virtual keyboard user can enter Card no and IPIN using mouse. This keyboard will display a keys in random position in a virtual keyboard on the screen where it makes little difficult for password capture. This only gives confidence for end user from key loggers not from other methods. Local attacker can use Win32 API’s to capture using screen shot method and obtain sensitive information including Credit Card/Debit Card (Suvidha Account), IPIN and misuse it."

From a malicious economies of scale perspective, these rather amateur techniques mean lack of efficiency compared to advanced tools suh as the Nuclear Grabber which I intend to cover in-depth in a future post from the Malicious Wild West series.
- May 10, 2007 No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Dancho Danchev
Independent Security Consultancy, Threat Intelligence Analysis (OSINT/Cyber Counter Intelligence) and Competitive Intelligence research on demand. Insightful, unbiased, and client-tailored assessments, neatly communicated in the form of interactive reports - because anticipating the emerging threatscape is what shapes the big picture at the end of the day. Approach me at dancho.danchev@hush.com

International Cryptography Regulations Map

Regulations on importing, exporting and using encryption greatly vary across the world. Bert-Jaap Koops came up with some informative maps highlighting the big picture :

"This is a graphic summary of the pertaining cryptography laws and regulations worldwide as outlined in the most recent version of my Crypto Law Survey. It shows the import controls, export controls, and domestic controls, according to the information available to me. Consult the corresponding entry in the Crypto Law Survey for the contents of the pertaining regulation in a particular country."

And here's a related post on a bureaucratic utopia, another one on bureaucracy vs reality when it comes to security, as well as famous cases related to criminals using encryption.
- May 10, 2007 No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Dancho Danchev
Independent Security Consultancy, Threat Intelligence Analysis (OSINT/Cyber Counter Intelligence) and Competitive Intelligence research on demand. Insightful, unbiased, and client-tailored assessments, neatly communicated in the form of interactive reports - because anticipating the emerging threatscape is what shapes the big picture at the end of the day. Approach me at dancho.danchev@hush.com

Disintermediating the Major Defense Contractors

Innovative and cost-effective altogether? Think SpaceShipOne, a commercial space ship that didn't come from a major defense contractor, not even NASA but from a competition won by a privately run company. How to disintermediate yet innovate? Become a venture capitalist, or an angel investor and optimistically hope the academic-to-commercialization process would happen with one of your investments. The DeVenCI project aims to connect sellers with buyers and seems like a sound short-term objectives oriented idea compared with In-Q-Tel the CIA's VC fund emphasizing on long-term R&D :

"Some companies have already profited from the program. In 2003, when DeVenCI was in its experimental phase, the Defense Information Systems Agency was looking for ways to protect computer networks. After speaking to several companies through DeVenCI and evaluating their technology, the agency wound up working with ArcSight, a software company based in Cupertino, Calif., which won $3.6 million in related contracts over the next few years, DeVenCI officials said. Mr. Novak of Novak Biddle said he brought with him to the March DeVenCI meeting two executives from a small start-up developing biometric technology that could be used for things like advanced fingerprinting or eye scans. Mr. Novak said the chief executive and chief technology officer from the Virginia company, which he declined to name for competitive reasons, gave a presentation to the roughly 50 assembled procurement agents."

Here's In-Q-Tel's investment portfolio so far -- Google used to be among them.

Related posts:
Insider Competition in the Defense Industry
Aha, a Backdoor!
Overachieving Technology Companies
- May 10, 2007 No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Dancho Danchev
Independent Security Consultancy, Threat Intelligence Analysis (OSINT/Cyber Counter Intelligence) and Competitive Intelligence research on demand. Insightful, unbiased, and client-tailored assessments, neatly communicated in the form of interactive reports - because anticipating the emerging threatscape is what shapes the big picture at the end of the day. Approach me at dancho.danchev@hush.com

Tuesday, May 08, 2007

DDoS on Demand VS DDoS Extortion

There were recent speculations on the decline of DDoS attacks, in respect to the lack of companies actually paying to extortion attacks and that it's supposedly not a cost effective approach for malicious attackers to use their botnets. Think again, as it's always a matter of a vendor's sensor network diversity, one that's also excluding targeting mom-and-pop web properties. Just because DDoS extortion may not be working, and I say may not be working because only a few companies would admit they have paid money given the simple math of losing revenues on an hourly basis and spending more on bandwidth and security consultancy than the money requested, DDoS on demand still remains a well developed underground business model. DDoS attacks may not be profitable for the attacker directly performing them, but remain profitable if he's getting paid to provide the service only. Here's an excerpt from my Future Trends of Malware (January, 2006) publication related to DDoS extortion :

"Now you should ask yourself, would total cost of ownership of the business, the costs of the bandwidth, the DDoS attack protection solution, or the botmaster’s deal with the devil style proposition can solve the situation. If you’re thinking big, each and every time an organization pays, it not only risks a repeated demand, but is also fueling the growth of the practice in itself – so don’t do it!"

I'm aware of an ironic situation where a small-biz client's web server started getting DDoS without any reason whatsoever. The first thing that came to my mind was that it's either a DDoS extortion, or a possible rival, so I asked whether or not they've received any extortion emails. They declined, and here comes the interesting part, two days later, the attacks stopped, and a letter arrived in the form of the following email - "We saw you ignored our first email so we had to demonstrate you the power of our attack, this is your second chance to bla bla bla". What happened, and why did they say no extortion emails were sent? Here comes the irony, in the spam folder of the publicly obtainable email account for the domain was the original extortion email, that got detected as a spam. Time for some cyber intelligence to assess their capacity.. Never comply with such letters, or they'll come back for more. By the way, ever thought of the DDoS extortion bluff?

Here's another excerpt on DDoS on demand :

"There’s a lot of demand for paying to teens to shut down your competitors and hoping they would go under the radar, and while ethics are excluded, given these get busted, they’ll be the first to forward the responsibility to the buyer of the service. There’s also a clear indication of market for such services, and sooner or later these individuals will improve their communication skills, thereby increasing the impact of these attacks. For instance, Jay Echouafni, CEO of TV retailer Orbit Communications, paid a group of botmasters to DDoS his competitors, where the outage costs were estimated at $2 million. Another case of DDoS on demand occurred in March, 2005, when the FBI arrested a 17 year old and a Michigan man for orchestrating a DdoS attack, again causing direct monetary loses. DDoS attacks, and the ease of gaining capability in this field are clearly increasing."

Unethical competitions would favor a service where a third party maintains the infrastructure, launches the attack, and for the safety of both parties, remain as anonymous as possible. Here' a related article at BBC News:

"We are seeing a lot of anti-competitive behaviour," he said. Mr Sop added that many more Asian targets were being hit by DDoS attacks - a region in which Symantec did not historically have a big presence. In Asia, he said, DDoS attacks were proving very popular with unscrupulous firms keen to get ahead of their rivals. "The really frightening thing is you can buy access to a botnet for a small amount of money and you can have you competitor down for a long time," he said."

I never actually enjoyed articles emphasizing on how Russian script kiddies are taking over the world given the idea of "outsourcing malicious services". So next time you see a DDoS attack coming from the Russian IP space against U.S companies, it could still be U.S based rivals that requested the attack on their U.S based competitors -- stereotypes keep you in the twilight zone.

Meanwhile, here's a proof hacktivism is still alive and fully operational as the Estonian Internet infrastructure's been recently under permanent DDoS attacks due to real-life tensions of removing a statue from the Soviet era. It wasn't Chinese Mao-ists that did it for sure, but the recent case is another proof that it's always about the money, as everyone not aware of different malicious attackers' motives is preaching. DDoS extortion isn't dead, it's just happening beneath the radar, as targets are picked up more appropriately balanced with less greed regarding this underground business model only.

UPDATE : More developments on the DDoS attacks in Estonia now combined with defacements, which I think was only a matter of time.

Related posts:
The Underground Economy's Supply of Goods
The War against botnets and DDoS attacks
Emerging DDoS Attack Trends
Korean Zombies Behind the Root Servers Attack
Hacktivism Tensions - Israel vs Palestine Cyberwars
- May 08, 2007 No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Dancho Danchev
Independent Security Consultancy, Threat Intelligence Analysis (OSINT/Cyber Counter Intelligence) and Competitive Intelligence research on demand. Insightful, unbiased, and client-tailored assessments, neatly communicated in the form of interactive reports - because anticipating the emerging threatscape is what shapes the big picture at the end of the day. Approach me at dancho.danchev@hush.com

Friday, May 04, 2007

A Chronology of a Bomb Plot

A very detailed overview of a bomb plot, especially the lines related to anything digital such as :

- "An e-mail sent from Mr. Khawaja to Mr. Khyam on Nov. 30, 2003, read: "It's not as easy as we thought it would be. We have to design the whole thing ourselves. "There are two parts to it, one transmitter and another receiver that will be at a distance of about 1 or 2km that will be attached to the wires and send out 5 volts down the line and then we get fireworks."

No details on whether or not the communication was encrypted, how it was decrypted -- indirectly through client side attacks for sure -- and was their communication on purposely intercepted or filtered though the noise with keywords such as transmitter, wires and fireworks.

- "Mr. Mahmood was working for the British gas company, Transco, and had stolen sensitive CD-ROMs from National Grid, a British utility, that detailed the layout of hundreds of kilometres of high-pressure gas pipelines in southeast England."

And the insider threat was just an overhyped threat with lack of statistical evidence of it happenning. Think twice. Don't dedicate efforts in ensuring such information never makes it out of the organization due to terrorist fears only, but consider the consequences of it getting into the wrong hands at the first place.

- "A notebook in the living room included references for books including The Virtue of Jihad, and Declaration of War."

Propaganda writings are easily obtainable online, which reminds me that monitoring them to the very last mile is worth the risk in order to further expand their network, of both, sites they visit and people they communicate with.

- "Downloaded on to his laptop was a computer file, The Mujahideen Explosive Handbook. It contained the exact recipe to build an ammonium nitrate bomb."

On purposely placed online DIY manuals can act as honeypots themselves. As we've already seen, counter-terrorism forces across the world are establishing such fake cyber jihad communities in order to lure and monitor wannabe jihadists. But monitoring who's obtaining the already hosted in the wild manuals, is far more beneficial than hoping someone will eventually fall a victim into your cyber trap.

In another related research by the RAND Corporation entitled "Exploring Terrorist Targeting Preferences" the authors try to come up with various scenarios on the process of prioritizing possible targets such as :

"the coercion hypothesis; the damage hypothesis; the rally hypothesis; and the franchise hypothesis. If Al-Qaeda directs the next attack the coercion and damage hypothesis, and, quite possibly both, are the most likely to influence the nature of the target.

Great psychological imagination applied in the paper, worth the read. From a statistical point of view, the probability of death due to a car accident is higher than that of a terrorist attack, so consider escaping the FUD related to terrorism that's streaming from your favorite TV channels in order to remain objective. The ugliest part of them all is that everyone's discussing the post-event actions taken, and no one is paying any attenting to the pre-event activities that made it possible, and with training camps under heavy fire, the digitalization of terrorist training is taking place.

And here's another great analysis, this time covering the process of how terrorists send money by combining anonymous Internet services in between mobile banking :

"Advanced mobile technology, cooperation between international mobile communications providers and international financial institutions and the lack of regulations make for a swift, cheap, mostly untraceable money transfer -- known as "m-payments" -- anywhere, anytime, by anyone with a mobile telephone."

Dare we say adaptive?
- May 04, 2007 No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Dancho Danchev
Independent Security Consultancy, Threat Intelligence Analysis (OSINT/Cyber Counter Intelligence) and Competitive Intelligence research on demand. Insightful, unbiased, and client-tailored assessments, neatly communicated in the form of interactive reports - because anticipating the emerging threatscape is what shapes the big picture at the end of the day. Approach me at dancho.danchev@hush.com

Winamp PoC Backdoor and a Zero Day

Listen to your infection? Not necessarily as this backdoor binds cmd.exe on port 24501, but needs to be socially engineered in the form of a plugin for Winamp. Code originally released in December, 2006, see attached screenshot. Not much of a fun here either, but as the folks at SANS point out Winamp doesn't play .MP4 files automatically from a web page, so no chance to have it embedded within popular sites and cause mass outbreaks as we saw it happen with the with ANI exploit code and the WMF one.

gen_wbkdr.dll
File size: 45056 bytes
MD5: 74d149f4a1f210ea41956af6ecedb96b
SHA1: 5a2e8d5727250a647ce44d00cf7446775e6cd7d5
- May 04, 2007 No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Dancho Danchev
Independent Security Consultancy, Threat Intelligence Analysis (OSINT/Cyber Counter Intelligence) and Competitive Intelligence research on demand. Insightful, unbiased, and client-tailored assessments, neatly communicated in the form of interactive reports - because anticipating the emerging threatscape is what shapes the big picture at the end of the day. Approach me at dancho.danchev@hush.com
Newer Posts Older Posts Home
Subscribe to: Comments (Atom)

About Me

My photo
Dancho Danchev
Independent Security Consultancy, Threat Intelligence Analysis (OSINT/Cyber Counter Intelligence) and Competitive Intelligence research on demand. Insightful, unbiased, and client-tailored assessments, neatly communicated in the form of interactive reports - because anticipating the emerging threatscape is what shapes the big picture at the end of the day. Approach me at dancho.danchev@hush.com
View my complete profile

Search This Blog

Subscribe to Dancho Danchev's Blog - Mind Streams of Information Security Knowledge

Subscribe To

Posts
Atom
Posts
All Comments
Atom
All Comments

Total Pageviews

Followers

Blog Archive

  • ▼  2026 (9)
    • ▼  March (1)
      • When Data Mining Conti Leaks Leads to Actual Binar...
    • ►  February (2)
    • ►  January (6)
  • ►  2025 (34)
    • ►  December (1)
    • ►  November (1)
    • ►  September (6)
    • ►  July (3)
    • ►  June (1)
    • ►  May (7)
    • ►  February (5)
    • ►  January (10)
  • ►  2024 (100)
    • ►  December (5)
    • ►  November (5)
    • ►  October (7)
    • ►  September (16)
    • ►  August (6)
    • ►  July (11)
    • ►  June (11)
    • ►  May (1)
    • ►  April (8)
    • ►  March (3)
    • ►  February (15)
    • ►  January (12)
  • ►  2023 (160)
    • ►  December (15)
    • ►  November (24)
    • ►  October (9)
    • ►  September (25)
    • ►  August (16)
    • ►  July (5)
    • ►  June (8)
    • ►  May (7)
    • ►  April (16)
    • ►  March (14)
    • ►  February (17)
    • ►  January (4)
  • ►  2022 (252)
    • ►  December (14)
    • ►  November (54)
    • ►  October (45)
    • ►  September (3)
    • ►  August (24)
    • ►  July (17)
    • ►  June (28)
    • ►  May (1)
    • ►  April (3)
    • ►  March (11)
    • ►  February (15)
    • ►  January (37)
  • ►  2021 (196)
    • ►  December (17)
    • ►  November (9)
    • ►  October (28)
    • ►  September (27)
    • ►  August (2)
    • ►  July (19)
    • ►  June (12)
    • ►  May (11)
    • ►  April (23)
    • ►  March (24)
    • ►  February (15)
    • ►  January (9)
  • ►  2020 (56)
    • ►  December (35)
    • ►  November (1)
    • ►  October (1)
    • ►  September (4)
    • ►  August (3)
    • ►  July (5)
    • ►  June (2)
    • ►  May (2)
    • ►  February (1)
    • ►  January (2)
  • ►  2019 (68)
    • ►  December (9)
    • ►  November (3)
    • ►  October (1)
    • ►  September (11)
    • ►  August (2)
    • ►  July (6)
    • ►  May (16)
    • ►  April (3)
    • ►  March (1)
    • ►  February (11)
    • ►  January (5)
  • ►  2018 (41)
    • ►  December (3)
    • ►  November (2)
    • ►  October (25)
    • ►  September (1)
    • ►  August (2)
    • ►  July (3)
    • ►  May (3)
    • ►  January (2)
  • ►  2017 (16)
    • ►  November (3)
    • ►  July (1)
    • ►  May (10)
    • ►  January (2)
  • ►  2016 (46)
    • ►  December (12)
    • ►  September (4)
    • ►  August (9)
    • ►  June (3)
    • ►  May (13)
    • ►  April (5)
  • ►  2015 (3)
    • ►  August (2)
    • ►  July (1)
  • ►  2014 (11)
    • ►  October (1)
    • ►  March (3)
    • ►  January (7)
  • ►  2013 (77)
    • ►  December (5)
    • ►  November (12)
    • ►  October (3)
    • ►  September (5)
    • ►  August (13)
    • ►  July (7)
    • ►  June (7)
    • ►  May (5)
    • ►  April (5)
    • ►  March (3)
    • ►  February (6)
    • ►  January (6)
  • ►  2012 (38)
    • ►  December (2)
    • ►  November (7)
    • ►  October (3)
    • ►  September (4)
    • ►  August (2)
    • ►  July (2)
    • ►  June (2)
    • ►  May (4)
    • ►  April (2)
    • ►  March (2)
    • ►  February (2)
    • ►  January (6)
  • ►  2011 (59)
    • ►  December (1)
    • ►  October (8)
    • ►  September (4)
    • ►  August (4)
    • ►  July (3)
    • ►  June (1)
    • ►  May (10)
    • ►  April (5)
    • ►  March (12)
    • ►  February (6)
    • ►  January (5)
  • ►  2010 (90)
    • ►  September (2)
    • ►  August (3)
    • ►  July (7)
    • ►  June (7)
    • ►  May (16)
    • ►  April (15)
    • ►  March (13)
    • ►  February (17)
    • ►  January (10)
  • ►  2009 (134)
    • ►  December (9)
    • ►  November (13)
    • ►  October (9)
    • ►  September (10)
    • ►  August (12)
    • ►  July (14)
    • ►  June (11)
    • ►  May (11)
    • ►  April (11)
    • ►  March (11)
    • ►  February (12)
    • ►  January (11)
  • ►  2008 (267)
    • ►  December (10)
    • ►  November (15)
    • ►  October (25)
    • ►  September (17)
    • ►  August (26)
    • ►  July (38)
    • ►  June (19)
    • ►  May (33)
    • ►  April (30)
    • ►  March (19)
    • ►  February (21)
    • ►  January (14)
  • ►  2007 (331)
    • ►  December (19)
    • ►  November (33)
    • ►  October (32)
    • ►  September (28)
    • ►  August (25)
    • ►  July (22)
    • ►  June (20)
    • ►  May (30)
    • ►  April (20)
    • ►  March (41)
    • ►  February (32)
    • ►  January (29)
  • ►  2006 (325)
    • ►  December (20)
    • ►  November (20)
    • ►  October (28)
    • ►  September (40)
    • ►  August (27)
    • ►  July (28)
    • ►  June (28)
    • ►  May (33)
    • ►  April (20)
    • ►  March (19)
    • ►  February (23)
    • ►  January (39)
  • ►  2005 (6)
    • ►  December (6)

Popular Posts

  • Exposing Bulgaria's Largest Data Leak - An OSINT Analysis
    I've recently came across to a news article detailing the recently leaked Bulgaria NAP records database and I decided to take a closer...
  • DDanchev is for Hire!
    Looking for a full time threat intelligence analyst, cybercrime researcher, or a security blogger? Approach me at dancho.danchev@hush...
  • Profiling a Currently Active Portfolio of High-Profile Cybercriminal Jabber and XMPP Accounts
    In a world dominated by fraudulent propositions it should be noted that Jabber and XMPP remain the primary secure communication channel f...
  • Historical OSINT - Google Docs Hosted Rogue Chrome Extension Serving Campaign Spotted in the Wild
    In, a, cybercrime, ecosystem, dominated, by, malicious, software, releases, cybercriminals, continue, actively, populating, their, botnet...
  • Exposing the Conti Ransomware Gang - An OSINT Analysis
    UPDATE: The following set of graphics aims to visualize the recently leaked Conti ransomware gang members conversations. UPDATE: The followi...
  • Historical OSINT - Massive Black Hat SEO Campaign, Spotted in the Wild, Serves Scareware
    In, a, cybercrime, ecosystem, dominated, by, hundreds, of, malicious, software, releases, cybercriminals, continue, actively, populating, th...
  • Historical OSINT - Hundreds of Malicious Web Sites Serve Client-Side Exploits, Lead to Rogue YouTube Video Players
    In, a, cybercrime, ecosystem, dominated, by, hundreds, of, malicious, software, releases, cybercriminals, continue, actively, populating, a,...
  • Historical OSINT - Malicious Malvertising Campaign, Spotted at FoxNews, Serves Scareware
    In, a, cybercrime, ecosystem, dominated, by, fraudulent, propositions, cybercriminals, continue, actively, populating, their, botnet's, ...
  • Historical OSINT - Rogue MyWebFace Application Serving Adware Spotted in the Wild
    In, a, cybercrime, ecosystem, dominated, by, malicious, software, releases, cybercriminals, continue, actively, populating, their, botnet...
  • Exposing a "Fast-Flux" Name Server Based Rogue Fraudulent and Malicious Online Infrastructure - An Analysis
    Dear blog readers, I've decided a diverse portfolio of fast flux name servers which basically act as a bulletproof botnet C&C commun...

Labels

  • 29A
  • 29A Virus Coding Group
  • 419 Scam
  • AbdAllah
  • Abdallah Internet Hizmetleri
  • Able Danger
  • Abuse Department
  • Active Security Monitor
  • Advance Fee Scam
  • Advanced Persistent Threat
  • Advertising
  • Adware
  • Affiliate Network
  • Ahmad Al Agha
  • Al Qaeda
  • Aleksandr Zhukov
  • Allied Group Inc
  • Amazon AWS
  • ANA Spoofer Project
  • Android
  • Anonymity
  • Anonymizer
  • Anonymous
  • Anonymous Hacking Collective
  • Anti-Phishing Group
  • Antivirus
  • Antivirus Signatures
  • Anton Nikolaevich Korotchenko
  • AOL
  • API
  • Apple
  • APT
  • Aqua ZeuS Gang
  • Armadillo Phone
  • Ashiyane Digital Security Team
  • ASProx
  • Astalavista
  • Astalavista Security Group
  • Astalavista.box.sk
  • ATM Skimmer
  • ATS
  • Australia
  • Authentication
  • Avalance Botnet
  • Avast
  • Background Check
  • BadB
  • Bahama Botnet
  • BakaSoftware
  • Bantu
  • BBC
  • Bebo
  • Bed Time Reading
  • Behrooz Kamalian
  • Best Practices
  • BGP
  • Big Brother
  • Bill Gates Botnet
  • Biography
  • Biometrics
  • Bitcoin
  • Bjorn Andreasson
  • Black Energy
  • Blackhat SEO
  • Blood and Honor
  • Blood and Honor Bulgaria
  • Boeing
  • Bogus Account
  • bother
  • Botners
  • Botnet
  • Botnets
  • Box.sk
  • Brian Krebs
  • Brute-Forcing
  • Bulgaria
  • Bulgaria Law Enforcement
  • Bulgarian Cyber Army
  • Bulgarian Cyber Army Hacking Group
  • Bullet Proof Hosting
  • Bust
  • C4I
  • CALEA
  • Caller ID
  • Caller ID Spoofer
  • Candid Wuest
  • CAPTCHA
  • Career Enrichment
  • Cash Transfers
  • CCTV
  • CDT
  • Cell Phone Monitoring
  • Cell Phone Surveillance
  • CellDEK
  • Censorship
  • Center for Democracy and Technology
  • CERT
  • Cheyenne Mountain Operations Center
  • China
  • China Eagle Union
  • CIA
  • CipherTrust
  • Classified Information
  • Client-Side Exploits
  • Client-Side Vulnerabilities
  • CNO
  • COCOM
  • Cold War
  • COMINT
  • Competitive Intelligence
  • Compliance
  • Computer Crime Survey
  • Computer Network Operation
  • Conficker
  • Confidential Connections
  • Conspiracy
  • Conspiracy Theory
  • Conti
  • Conti Ransomware
  • Conti Gang
  • Conti Ransomware
  • Conti Ransomware Gang
  • Cookies
  • CoolWebSearch
  • Corporate Risk Management
  • Counter Espionage
  • Counter Intelligence
  • Credit Cards
  • Crimeware
  • Critical Infrastructure
  • Crusade Affiliates
  • Crypters
  • Cryptography
  • Cryptome
  • Cryptoviral Extortion
  • CSIA
  • CVE
  • Cyber Attack
  • Cyber Espionage
  • Cyber Insurance
  • Cyber Jihad
  • Cyber Militia
  • Cyber Security Industry Alliance
  • Cyber Security Investment
  • Cyber Terrorism
  • Cyber Threat Actor Attribution Maltego Graphs
  • Cyber Warfare
  • Cyber Weapon
  • Cyber Weapons
  • CyberCamp 2016
  • Cybercrime
  • Cybercrime Ecosystem
  • Cybercrime Forum
  • Cybercrime Forum Data Set
  • Cybercrime Incident Response
  • Cybercrime Incident Response Maltego Graphs
  • Cybercrime Search Engine
  • Cybercriminal
  • Cyberpunk
  • Cyberspace
  • Cybertronics
  • Daniel Brandt
  • Dark Vader
  • Dark Forum
  • Dark Web
  • Dark Web Onion
  • Dark Web Search Engine
  • DarkComet RAT
  • Darkode
  • Darkode Forum Community
  • Data Acquisition
  • Data Breach
  • Data Center
  • Data Leak
  • Data Mining
  • David Endler
  • DCLeaks
  • DDoS
  • DDoS For Hire
  • Defense Complex
  • Delicious Information Warfare
  • Denmark
  • Department of Defense
  • DHS
  • DIA
  • Digital Armaments
  • Digital Forensics
  • Digital Rights
  • Dilbert
  • Distributed Computing
  • Distributed Computing Project
  • Distributed Project
  • DNS
  • DNS Changer
  • DoD
  • DoJ
  • DotCom
  • DreamHost
  • Dropbox
  • Durzhavna Sigurnost
  • DVD of the Weekend
  • E-Banking
  • E-Business
  • E-Commerce
  • E-Shop
  • Eavesdropping
  • Ebay
  • ECHELON
  • ECOFIN Projects
  • Economics
  • eID
  • Electric Universe
  • Electromagnetic Pulse Weapons
  • Electronic Banking
  • ELINT
  • Emotet
  • Emotet Botnet
  • EMP
  • Encrochat
  • Encrochat Database Leak
  • Encrypted Communication
  • Encrypted Phone
  • Encryption
  • Enigma
  • ENISA
  • Enki Bilal
  • Enron
  • Erasmus Bridge
  • Eric Goldman
  • Espionage
  • Espionage Movie
  • Evgeniy Mikhaylovich Bogachev
  • Exmanoize
  • Exploit Broker
  • Exploit Kit
  • Exploits
  • Eyeball Series
  • F-Secure
  • Facebook
  • Fake Account
  • Fake Adobe Flash Player
  • Fake Certificate
  • Fake Chrome Extension
  • Fake Chrome Update
  • Fake Code Signing Certificate
  • Fake Confirmed Facebook Friend Request Email
  • Fake Documents
  • Fake Facebook Appeal
  • Fake Facebook Notification
  • Fake Facebook Profile Spy Application
  • Fake Firefox Update
  • Fake Hosting Provider
  • Fake ID
  • Fake Internet Explorer Update
  • Fake Passport
  • Fake Personal ID
  • Fake Safari Update
  • Fake Security Software
  • Fake Tech Support Scam
  • Fake Utility Bill
  • Fake Video Codec
  • Fake Visa
  • Fake Visa Application
  • Fake Web Site
  • Fake Who's Viewed Your Facebook Profile Extension
  • Fake YouTube Player
  • Fast-Flux
  • FBI
  • FBI Most Wanted
  • FCC
  • FDIC
  • Financial Management
  • Firas Nur Al Din Dardar
  • FireEye
  • Flashpoint Intel
  • Foreign Influence Operations
  • Forensics
  • Forwarderz
  • FoxNews
  • Fraud
  • Free Speech
  • FSB
  • FTLog
  • FTLog Worm
  • Gartner
  • Gavril Danilkin
  • GazTranzitStroyInfo
  • GCHQ
  • GDBOP
  • Generation I
  • George Bush
  • Georgi Markov
  • Georgia
  • Germany
  • Gift Cards
  • GiveMeDB
  • Global Security Challenge
  • Goa Trance
  • GoDaddy
  • Google
  • Google Firebase
  • Google Ads
  • Google Docs
  • Google Earth
  • Google Groups
  • Google Hacking
  • Google Maps
  • Google Play
  • Google Store
  • Greece
  • Growth Hacker
  • GRU
  • Guccifer 2.0
  • GUI
  • Gumblar
  • Hacked Database
  • Hacked Web Site
  • Hacker
  • Hackers
  • Hacking
  • Hacking Book
  • Hacking Forum
  • Hacking Group
  • Hacking Groups
  • Hacking Tools
  • HackPhreak
  • HackPhreak Hacking Group
  • Hacktivism
  • Haiti
  • Hamas
  • Hezbollah
  • High Tech Brazil Hack Team
  • Hilary Kneber
  • HKLeaks
  • Home Molestation
  • Homebrew
  • Honeynet Project
  • Honker Union of China
  • HUMINT
  • ICBM
  • ID Theft
  • iDefense
  • Identity Theft
  • Illegal Arrest
  • Illegal Hosting
  • Illegal Restraint
  • IMINT
  • IMLogic
  • India
  • India Company
  • Indicator of Compromise
  • Information Operations
  • Information Security
  • Information Security Forum
  • Information Security Market
  • Information Warfare
  • Infrastructure Security
  • InFraud
  • InFraud Cybercrime Gang
  • InFraud Cybercrime Syndicate
  • InFraud Organization
  • InqTana Mac OS X Malware
  • Insider
  • Insider Monitoring
  • Insider Threat
  • Instant Messaging
  • Intellectual Property
  • Intelligence
  • Intelligence Agency
  • Intelligence Community
  • Internal Revenue Service
  • International Exploit Shop
  • Internet
  • Internet Censorship
  • Internet Economy
  • Internet Relay Chat
  • Investment Banking
  • IoC
  • IP Cloaking
  • IP Hiding
  • IP Spoofing
  • iPowerWeb
  • IPSec
  • IPv4
  • IPv6
  • Iran
  • Iran Election
  • Iran Election 2009
  • Iran Hacker Groups
  • Iran Hacking Groups
  • Iran Mabna Hackers
  • IRC
  • IRS
  • ISIS
  • Israel
  • Jabber
  • JabberZeuS
  • Javor Kolev
  • Jeffrey Carr
  • Joanna Rutkowska
  • Johannes Ullrich
  • John Young
  • K Rudolph
  • Kaseya
  • Kaseya Ransomware Attack
  • Katrina
  • Keylogger
  • KGB
  • Kidnapping
  • Koobface
  • Koobface Botnet
  • Korean Demilitarized Zone
  • KrotReal
  • Latest News Articles
  • Latvia
  • Law Enforcement
  • Lawful Interception
  • Leaks
  • Lenovo
  • Liberty Front Press Network
  • Lizamoon
  • Loads.cc
  • Localization
  • Location Tracking
  • Lockheed Martin
  • Logicube
  • Lone Gunmen
  • Lovely Horse
  • Lubyanka Square Headquarters
  • M4 Project
  • Mac OS X
  • Malicious Software
  • Maltego
  • Maltego Graphs
  • Malvertising
  • Malware
  • Malware Information Sharing Platform
  • Marketing
  • Mass Web Site Defacement
  • Mastercard
  • McAfee
  • MD5
  • Media Methane
  • Memoir
  • Metrics
  • Microsoft
  • Microsoft Live
  • Military Communications
  • Ministry of Interior
  • MISP
  • Missile Base
  • Mobile
  • Mobile Application
  • Mobile Communication Censorship
  • Mobile Internet
  • Mobile Location Tracking
  • Mobile Malware
  • Mobile Security
  • Mohammad Sagegh Ahmadzadegan
  • Money Laundering
  • Money Mule
  • Money Mule Recruitment
  • Monoculture
  • Morgan Stanley
  • Moses Staff
  • Most Wanted Cybercriminals
  • MSN
  • MSRC
  • MSRC Researcher Recognition Program
  • Muhammad Cartoons
  • MVR
  • MyWebFace
  • NASA
  • National Cyber Security Centre
  • National Security
  • Native Intelligence
  • NBC
  • NCSC
  • NetAssist LLC
  • NetCraft
  • Network Centric Warfare
  • Network Solutions
  • New Media
  • Nikolay Nedyalkov
  • Nikopol Trilogy
  • Nintendo
  • Nintendo DS
  • NordVPN
  • Norman Sandbox
  • North Korea
  • North Korea Missile Launch Pad
  • NSA
  • NSO Group
  • NSO Group Spyware
  • Nuclear Weapons
  • Nyxem
  • OEM
  • Offensive Cyber Warfare
  • OMEMO
  • Omerta
  • One-Time Password
  • One-Time Passwords In Everything
  • OneCare
  • Online Advertising
  • Online Fraud
  • Online Marketing
  • Online Propaganda Campaign
  • Online Scam
  • Open Source Malware
  • Operation EQUALIZER
  • Operation Uncle George
  • OPIE
  • OPSEC
  • Osama Bin Laden
  • OSINT
  • OSINT Training
  • OTC
  • OTP
  • Over-The-Counter
  • Packers
  • Parked Domains
  • Passwords
  • Pavlin Georgiev
  • Pay Per Install
  • PayPal
  • Perplex City
  • Persistent Cookies
  • Personal Career
  • Personal Data
  • Pharmaceutical Scams
  • Phileas Crawler
  • Phishing
  • Phishing Campaign
  • Phishing Domain Farm
  • Phishing Toolbar
  • PhishTube
  • Phreedom
  • Physical Security
  • Pinterest
  • Piracy
  • PlushForums
  • Podcast
  • Point of Sale Terrminal
  • Politics
  • PornTube
  • POS
  • Potentially Unwanted Application
  • PR
  • Press Coverage
  • Privacy
  • Project RAHAB
  • Prolexic
  • Protonmail
  • Proxy Service
  • Psychedelic Trance
  • PSYOPS
  • Psytrance
  • Psytrance Song of the Day
  • Qassam Cyber Fighters
  • Radicati Group
  • Ransomware
  • RAT
  • Ray Kurzweil
  • RBN
  • Reconnaissance Satellite
  • Red Joan
  • Regulation
  • Remote Access Tool
  • Reporters Without Borders
  • Return On Investment
  • Return On Security Investment
  • REvil Ransomware Group
  • Revolution in Militvry Affairs
  • RIPA
  • Risk Management
  • Rogue Account
  • Rogue Chrome Extension
  • Rogue Facebook Appeal
  • Rogue Security Software
  • Rogue Video Codec
  • Rogue YouTube Player
  • Rogueware
  • ROI
  • Roman Polesek
  • Root Server
  • Rootkit
  • ROSI
  • RSA
  • RSA Conference
  • Russia
  • Russia Small Group
  • Russian
  • Russian Bomber
  • Russian Business Network
  • Russian Submarine
  • Safe Harbor
  • Satellite Imagery
  • Satellite Jamming
  • Satellite SIGINT
  • Scam
  • Scams
  • Scandoo
  • ScanSafe
  • Scareware
  • Scientific Intelligence
  • Scribd
  • Search Engine
  • Search Engine Optimization
  • SEC
  • SecondEye Solutions
  • Secret Service
  • Secure Communication
  • SecureDrop
  • Securities and Exchange Commission
  • Security
  • Security Awareness
  • Security Book
  • Security Breach
  • Security Conference
  • Security Directory
  • Security Education
  • Security Event
  • Security Forum
  • Security Game
  • Security Industry
  • Security Interviews
  • Security Investment
  • Security Metrics
  • Security Podcast
  • Security Project
  • Security Research
  • Security Statistics
  • Security Training
  • Security Trends
  • Sensitive Information
  • SEO
  • Shadow Server
  • ShadowCrew
  • SIGINT
  • Silent Circle
  • Sipco Systems
  • SIPRNET
  • SITE Institute
  • SiteAdvisor
  • Skype
  • Sniffing
  • Social Engineering
  • Social Network Analysis
  • SocialMediaSystem
  • Software Piracy
  • Solarwinds
  • Song of the Day
  • Sophos
  • Soviet Union
  • Space Warfare
  • Space Weapons
  • Spam
  • Spam Campaign
  • Spam Operations
  • Spear Phishing
  • Spoofing
  • Sprott Asset Management
  • Spyware
  • SQL Injection
  • SSL
  • SSN
  • Stalkware
  • Starlight
  • Stealth Ideas Inc
  • Steganography
  • STIX
  • STIX2
  • Stolen Credit Card
  • Stolen Credit Cards
  • Stolen Gift Cards
  • Strider Crawler
  • Sub7
  • Suri Pluma
  • Surveillance
  • Swine Flu
  • Symantec
  • Symbian
  • Syria
  • Syrian Electronic Army
  • Syrian Embassy
  • Taia Global
  • TAN
  • TAXII
  • TDoS
  • Team Code Zero
  • Team Code Zero Hacking Group
  • Tech Support Scam
  • Technical Collection
  • Technical Mujahid
  • Telephony Denial of Service Attack
  • Terrorism
  • th3j35t3r
  • THAAD
  • The Bunker
  • The Immortals
  • The Lawnmower Man
  • The Outer Limits
  • Thought Leadership
  • Thousand Talents Program
  • Threat Intelligence
  • Threat Intelligence Feed
  • Threat Intelligence Report
  • TIA
  • Tipping Point
  • Top Secret Program
  • Tor
  • Tor Project
  • Torrent
  • TorrentReactor
  • Total Information Awareness
  • Travel Without Moving
  • TrendMicro
  • Trickbot
  • Trickbot Gang
  • Trickbot Malware
  • Trickbot Malware Gang
  • Trifinite Group
  • Trojan Horse
  • TROYAK-AS
  • Tutanota
  • Twitter
  • Two Factor Authentication
  • Two-Factor Authentication
  • Typosquatting
  • U.K National Cyber Security Centre
  • U.S Bureau of Engraving and Printing
  • U.S Cyber Command
  • U.S Driving License
  • U.S Elections
  • U.S Sanctions
  • U.S Secret Service
  • Underground Search Engine
  • United Kingdom
  • University ID Card
  • Vasil Moev Gachevski
  • Vault 7
  • VeriSign
  • Vertex Net Loader
  • Virtual Private Network
  • Virtual Reality
  • Virtual Reality Social Network
  • Virtual World
  • Virus
  • Virus for You
  • Virus Map
  • Virus Recovery Button
  • Viruses
  • VirusTotal
  • Visa
  • Visual Information System
  • Visualization
  • Void Balaur Malware Gang
  • VoIP
  • VPN
  • Vulnerabilities
  • Vulnerability Broker
  • War Driving
  • War Games
  • Weapon Systems
  • Web 2.0
  • Web Application Worm
  • Web Crawler
  • Web Inject
  • Web Proxy Service
  • Web Shells
  • Web Site Defacement
  • Web Site Defacement Groups
  • Webroot
  • WHGDG
  • WhoisXML API
  • WhoisXML API Jabber ZeuS Gang
  • Wireless
  • Wireless Hacking
  • Wireless Internet
  • Wiretapping
  • WMF Vulnerability
  • World Hacker Global Domination Group
  • X-Files
  • X-Tunnel
  • XMPP
  • XSS
  • Yahoo
  • Yaroslav Vasinskyi
  • Yavor Kolev
  • YouTube
  • ZDNet
  • ZDNet Zero Day Blog
  • Zero Day Exploit
  • Zero Day Initiative
  • Zerodium
  • ZeuS
  • Zombie Alert
  • Zone-H
  • Zotob
Clicky
Awesome Inc. theme. Powered by Blogger.