<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; computer-hacking</title>
	<atom:link href="http://www.darknet.org.uk/tag/computer-hacking/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Most Damaging Computer Attacks Rely on Stolen Logins</title>
		<link>http://www.darknet.org.uk/2006/09/most-damaging-computer-attacks-rely-on-stolen-logins/</link>
		<comments>http://www.darknet.org.uk/2006/09/most-damaging-computer-attacks-rely-on-stolen-logins/#comments</comments>
		<pubDate>Sun, 24 Sep 2006 18:33:07 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[General Hacking]]></category>
		<category><![CDATA[computer-attacks]]></category>
		<category><![CDATA[computer-hacking]]></category>
		<category><![CDATA[computer-security]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[Password Cracking]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[stolen-logins]]></category>
		<category><![CDATA[weak-passwords]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/09/most-damaging-computer-attacks-rely-on-stolen-logins/</guid>
		<description><![CDATA[A sterling case for two factor authentication if I ever saw one. The rule is use two of the 3 methods of authentication, if possible use all 3. What you have (A USB key or Token) What you are (Biometrics &#8211; Fingerprint or Iris scan) What you know (A password or passphrase) More than 8 [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>A sterling case for two factor authentication if I ever saw one.</p>
<p>The rule is use two of the 3 methods of authentication, if possible use all 3.</p>
<ol>
<li>What you have (A USB key or Token)</li>
<li>What you are (Biometrics &#8211; Fingerprint or Iris scan)</li>
<li>What you know (A password or passphrase)</li>
</ol>
<blockquote><p> More than 8 out of every 10 computer attacks against businesses could be stopped if enterprises checked the identity of not only the user, but also the machine logging onto its network, a report released Monday claimed.</p>
<p>The study, conducted by a California research firm and paid for by BIOS maker Phoenix Technologies, used data from cases prosecuted by federal authorities between 1999 and 2006 to reach its conclusions.</p>
<p>&#8220;We wanted to get an honest viewpoint that wasn&#8217;t opinion- or survey-based,&#8221; said Dirck Schou, the senior director of security solutions at Phoenix. The problem with acquiring data on computer attacks, including the amount of damage done, is that companies are often hesitant to admit to a breach. &#8220;That&#8217;s the beauty of this [data],&#8221; said Schou. &#8220;It&#8217;s only looking at those who have actually suffered an attack.&#8221; </p></blockquote>
<p>Their point of view is implementing checking of the physical machine, or perhaps logically checking that it should be part of the network? Some unique ID for each machine generated from hashes of the parts perhaps.</p>
<blockquote><p>According to the report, attacks based on logging in with stolen or hijacked credentials cost businesses far more, on average, than the typical worm or virus assault. When a privileged account is penetrated by an unauthorized user, the average damage runs to $1.5 million, the report said. The average cost from a single virus attack was much smaller: under $2,400.</p>
<p>&#8220;Cyber criminals who accessed privileged accounts obtained IDs and passwords through many means,&#8221; the report said. &#8220;Network sniffing, use of password cracking programs, and collusion with insiders. It was also common for employees to share their IDs and passwords with coworkers who later left the organization and used that knowledge to gain access.&#8221; </p></blockquote>
<p>All common and fairly easy methods, perhaps it&#8217;s time people really took some effort to understand information security and the issues at hand.</p>
<p></p>
<p>Source: <a href="http://www.informationweek.com/news/showArticle.jhtml?articleID=192300841">Information Week</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Most+Damaging+Computer+Attacks+Rely+on+Stolen+Logins+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D324+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/09/most-damaging-computer-attacks-rely-on-stolen-logins/&amp;t=Most+Damaging+Computer+Attacks+Rely+on+Stolen+Logins" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/09/most-damaging-computer-attacks-rely-on-stolen-logins/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/09/most-damaging-computer-attacks-rely-on-stolen-logins/&amp;title=Most+Damaging+Computer+Attacks+Rely+on+Stolen+Logins" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/09/most-damaging-computer-attacks-rely-on-stolen-logins/&amp;title=Most+Damaging+Computer+Attacks+Rely+on+Stolen+Logins" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/09/most-damaging-computer-attacks-rely-on-stolen-logins/&amp;title=Most+Damaging+Computer+Attacks+Rely+on+Stolen+Logins" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/09/most-damaging-computer-attacks-rely-on-stolen-logins/&amp;title=Most+Damaging+Computer+Attacks+Rely+on+Stolen+Logins" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F09%2Fmost-damaging-computer-attacks-rely-on-stolen-logins%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/09/most-damaging-computer-attacks-rely-on-stolen-logins/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Moving Ahead in the War Against Botnets</title>
		<link>http://www.darknet.org.uk/2006/09/moving-ahead-in-the-war-against-botnets/</link>
		<comments>http://www.darknet.org.uk/2006/09/moving-ahead-in-the-war-against-botnets/#comments</comments>
		<pubDate>Tue, 12 Sep 2006 09:20:10 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[bots]]></category>
		<category><![CDATA[computer-hacking]]></category>
		<category><![CDATA[darknet]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[viruses]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/09/moving-ahead-in-the-war-against-botnets/</guid>
		<description><![CDATA[This effort started quite a long time ago, I was just checking up to see how they were getting on, but there&#8217;s not much news of their progress. perating under the theory that if you kill the head, the body will follow, a group of high-profile security researchers is ramping up efforts to find and [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>This effort started quite a long time ago, I was just checking up to see how they were getting on, but there&#8217;s not much news of their progress.</p>
<blockquote><p>perating under the theory that if you kill the head, the body will follow, a group of high-profile security researchers is ramping up efforts to find and disable the command-and-control infrastructure that powers millions of zombie drone machines, or bots, hijacked by malicious hackers.</p>
<p>The idea is to open up a new reporting mechanism for ISPs and IT administrators to report botnet activity, especially the C&#038;C (command-and-control) system that remotely sends instructions to botnets.</p>
<p>A botnet, which is short for &#8220;robot network,&#8221; is a collection of broadband-enabled computers that have been commandeered by hackers for use in spam runs, distributed denial-of-service attacks or malware installation. </p></blockquote>
<p>Botnets are often used in script kiddy DDoS wars or more commonly nowadays for Eastern block extortion scandals. &#8220;Pay us $xxxx or we will take down your site&#8221; this of course is especially effective against sites such as online Casinos which do their business solely through their websites.</p>
<blockquote><p>Evron, who serves as the Israeli CERT manager and is a leader in many global Internet security efforts, said the group includes representatives from anti-virus vendors, ISPs, law enforcement, educational institutions and dynamic DNS providers internationally.</p>
<p>Over the last year, the group has done its work quietly on closed, invite-only mailing lists. Now, Evron has launched a public, open mailing list to enlist the general public to help report botnet C&#038;C servers.</p>
<p>The new mailing list will serve as a place to discuss detection techniques, report botnets, pass information to the relevant private groups and automatically notify the relevant ISPs of command-and-control sightings. </p></blockquote>
<p>It is true hackers code for cash nowdays, not for anarchy or chaos, money can be made being an online hitman and extortion has moved from physical beatings to online terrorism.</p>
<blockquote><p>Websense&#8217;s Hubbard agrees there&#8217;s no silver bullet to solve the problem. &#8220;We&#8217;re seeing a major crossover,&#8221; he said. &#8220;Bots are now coming with keyloggers. We&#8217;re seeing botnets being used in conjunction with phishing attacks. The effort has to get buy-in from everyone, including law enforcement authorities, ISPs, dynamic DNS providers and the general public.</p>
<p>&#8220;I don&#8217;t think we&#8217;ll ever shut down botnets. The problem is just going to change with time,&#8221; Hubbard added. &#8220;The techniques are becoming better and more sophisticated as we come out with new defense techniques. We&#8217;re just trying to slow them down, really.&#8221; </p></blockquote>
<p>I do agree, but it&#8217;s good to see efforts being made, the main counter of course is always education, remove the ignorance of PC owners and OS developers and there will be no botnets any more..but well that would be an ideal world wouldn&#8217;t it?</p>
<p><a href="http://www.whitestar.linuxbox.org/mailman/listinfo/botnets">Botnets mailing list</a></p>
<p>Darknet also reported on <a href="http://www.darknet.org.uk/2006/06/shadowserver-battles-the-botnets/">Shadowserver Battling the Botnets</a>.</p>
<p></p>
<p>Source: <a href="http://www.eweek.com/article2/0,1895,1933210,00.asp">Eweek</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Moving+Ahead+in+the+War+Against+Botnets+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D90+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/09/moving-ahead-in-the-war-against-botnets/&amp;t=Moving+Ahead+in+the+War+Against+Botnets" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/09/moving-ahead-in-the-war-against-botnets/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/09/moving-ahead-in-the-war-against-botnets/&amp;title=Moving+Ahead+in+the+War+Against+Botnets" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/09/moving-ahead-in-the-war-against-botnets/&amp;title=Moving+Ahead+in+the+War+Against+Botnets" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/09/moving-ahead-in-the-war-against-botnets/&amp;title=Moving+Ahead+in+the+War+Against+Botnets" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/09/moving-ahead-in-the-war-against-botnets/&amp;title=Moving+Ahead+in+the+War+Against+Botnets" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F09%2Fmoving-ahead-in-the-war-against-botnets%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/09/moving-ahead-in-the-war-against-botnets/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Next Up &#8211; Hacking Nuclear Powerstations!</title>
		<link>http://www.darknet.org.uk/2006/07/next-up-hacking-nuclear-powerstations/</link>
		<comments>http://www.darknet.org.uk/2006/07/next-up-hacking-nuclear-powerstations/#comments</comments>
		<pubDate>Mon, 10 Jul 2006 10:53:15 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[General News]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[computer-hacking]]></category>
		<category><![CDATA[darknet]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[national-security]]></category>
		<category><![CDATA[network-security]]></category>
		<category><![CDATA[nuclear-power]]></category>
		<category><![CDATA[power-station-hacking]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/07/next-up-hacking-nuclear-powerstations/</guid>
		<description><![CDATA[Now this is a scary though, with the digitisation of the old analogue power stations and the accidental cross-over of networks (as we&#8217;ve seen before) people could soon be hacking nuclear power station control systems.. he nuclear power industry is going digital &#8212; replacing mechanical systems with more efficient, networked computer-controls. If that makes you [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Now this is a scary though, with the digitisation of the old analogue power stations and the accidental cross-over of networks (as we&#8217;ve seen before) people could soon be hacking nuclear power station control systems..</p>
<blockquote><p>he nuclear power industry is going digital &#8212; replacing mechanical systems with more efficient, networked computer-controls.</p>
<p>If that makes you nervous in a season-four-of-24 kinda way, you&#8217;re not alone. Last week, the US Nuclear Regulatory Commission voted unanimously to add cyber security requirements to federal regulations governing nuclear power plant security. </p></blockquote>
<p>Scary eh? Something straight out of a sci-fi movie.</p>
<blockquote><p>The main concern is that the next generation of digital &#8220;instrumentation and control&#8221;, or I&#038;C, systems could all-too-easily wind up linked to company business networks, and, through them, the internet &#8212; all but guaranteeing they&#8217;d be hacked.</p>
<p>The risk was illustrated in 2003, when the Slammer worm penetrated a network at the idled Davis-Besse nuclear plant in Ohio, disabling a safety monitoring computer for nearly five hours. The worm snuck in through the energy company&#8217;s corporate network, over an unmonitored connection from a contractor&#8217;s private LAN.</p></blockquote>
<p>I think the whole world should be pretty nervous, don&#8217;t you?</p>
<blockquote><p>At an NRC security briefing last March, commissioner (and Los Alamos veteran) Peter Lyons commented he was &#8220;very, very nervous&#8221; about such interconnections. The exchange that follows shows how nervous nuclear-types are about sounding nervous. From the <a href="http://www.nrc.gov/reading-rm/doc-collections/commission/tr/2006/20060315.pdf">transcript</a> [PDF] </p></blockquote>
<p>Oh dear..</p>
<p></p>
<p>Source: <a href="http://blog.wired.com/27BStroke6/#1516283">Wired Blog</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Next+Up+%E2%80%93+Hacking+Nuclear+Powerstations%21+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D285+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/07/next-up-hacking-nuclear-powerstations/&amp;t=Next+Up+%E2%80%93+Hacking+Nuclear+Powerstations%21" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/07/next-up-hacking-nuclear-powerstations/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/07/next-up-hacking-nuclear-powerstations/&amp;title=Next+Up+%E2%80%93+Hacking+Nuclear+Powerstations%21" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/07/next-up-hacking-nuclear-powerstations/&amp;title=Next+Up+%E2%80%93+Hacking+Nuclear+Powerstations%21" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/07/next-up-hacking-nuclear-powerstations/&amp;title=Next+Up+%E2%80%93+Hacking+Nuclear+Powerstations%21" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/07/next-up-hacking-nuclear-powerstations/&amp;title=Next+Up+%E2%80%93+Hacking+Nuclear+Powerstations%21" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F07%2Fnext-up-hacking-nuclear-powerstations%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/07/next-up-hacking-nuclear-powerstations/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

