<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; russian-hackers</title>
	<atom:link href="http://www.darknet.org.uk/tag/russian-hackers/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>TJX Hacker Albert &#8220;Segvec&#8221; Gonzalez Indicted By Federal Grand Jury</title>
		<link>http://www.darknet.org.uk/2009/08/tjx-hacker-albert-segvec-gonzalez-indicted-by-federal-grand-jury/</link>
		<comments>http://www.darknet.org.uk/2009/08/tjx-hacker-albert-segvec-gonzalez-indicted-by-federal-grand-jury/#comments</comments>
		<pubDate>Tue, 25 Aug 2009 08:34:03 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[General Hacking]]></category>
		<category><![CDATA[Legal Issues]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[albert gonzalez]]></category>
		<category><![CDATA[credit card hacker]]></category>
		<category><![CDATA[credit-card-fraud]]></category>
		<category><![CDATA[data-security]]></category>
		<category><![CDATA[data-theft]]></category>
		<category><![CDATA[hacking tjx]]></category>
		<category><![CDATA[russian-hackers]]></category>
		<category><![CDATA[segvec]]></category>
		<category><![CDATA[stealing credit cards]]></category>
		<category><![CDATA[tjx]]></category>
		<category><![CDATA[tjx hack]]></category>
		<category><![CDATA[tjx hacker]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2039</guid>
		<description><![CDATA[We&#8217;ve been following the whole TJX saga for quite some time now since way back in September 2007 when the hack became public as the Largest Breach of Customer Data in U.S. History and in August 2008 when the TJX Credit Card Hackers Got Busted. The legal system has ticked along and now they have [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>We&#8217;ve been following the whole <a href="http://www.darknet.org.uk/tag/tjx/">TJX</a> saga for quite some time now since way back in September 2007 when the hack became public as the <a href="http://www.darknet.org.uk/2007/09/tjx-tj-maxx-and-marshall%e2%80%99s-largest-breach-of-customer-data-in-us-history/">Largest Breach of Customer Data in U.S. History</a> and in August 2008 when the <a href="http://www.darknet.org.uk/2008/08/tjx-credit-card-hackers-busted-largest-us-data-breach/">TJX Credit Card Hackers Got Busted</a>.</p>
<p>The legal system has ticked along and now they have to stand up for their charges, which are spiraling as more and more cases are linked to them.</p>
<blockquote><p>Albert “Segvec” Gonzalez has been indicted by a federal grand jury in New Jersey — along with two unnamed Russian conspirators — on charges of hacking into Heartland Payment Systems, the New Jersey-based card processing company, as well as Hannaford Brothers, 7-Eleven and two unnamed national retailers, according to the indictment unsealed Monday. Gonzalez, a former Secret Service informant, is already awaiting trial over his involvement in the TJX hack.</p>
<p>According to the court document, <a href="http://www.wired.com/images_blogs/threatlevel/2009/08/gonzalez.pdf">the hackers allegedly stole more than 130 million credit and debit card numbers</a> (.pdf) from Heartland and Hannaford combined. Prosecutors say they believe these breaches constitute the largest data-breach and identity-theft case ever prosecuted in the United States. They’re investigating other breaches and have not ruled out Gonzalez’s involvement in even more intrusions.</p>
<p>“We’re not seeing a huge array of hackers capable of doing this, but rather a more select group, [and that] demonstrates that there is a level of sophistication involved in these hacks,” said Assistant U.S. Attorney Erez Liebermann of the Justice Department’s New Jersey district office.</p></blockquote>
<p>As with most things, 80% of the damage is done by 20% of the people. I&#8217;d say in this case it&#8217;s more like 98% of the damage is done by 2% of the hackers only a few of which ever get caught.</p>
<p>I think these guys just got too greedy and went after too many targets, but then their credit card theft ring  is called &#8220;Operation Get Rich or Die Tryin&#8221;. They aren&#8217;t likely to die, but they are likely to go down for a long time.</p>
<blockquote><p>But these are just the latest in a string of high-profile breaches that have been connected to Gonzalez. He and 10 others were charged in May and August 2008 with network intrusions into TJX, OfficeMax, Dave &#038; Busters restaurant chain and other companies. Jury selection is slated to begin Sept. 14 in one of those cases. With regard to the Heartland-Hannaford cases, Gonzalez and the two unnamed Russian hackers have been charged with one count of conspiracy to commit computer fraud and one count of conspiracy to commit wire fraud.</p>
<p>They each face a maximum penalty of five years in prison and a possible maximum fine of $250,000 on the computer-fraud count and an additional 30 years and $1 million fine on the wire-fraud count, or twice the amount they gained from the offense, whichever is greater.</p>
<p>Attorneys for Gonzalez were not available for comment.</p>
<p>According to the New Jersey indictment, Gonzalez, 28, and an uncharged conspirator identified only as “P.T.,” allegedly found their targets on a list of Fortune 500 companies and then did reconnaissance to determine the payment-processing systems they used and uncover vulnerabilities. The hackers used computers they leased or controlled in California, Illinois and New Jersey as well as in Latvia, Ukraine and the Netherlands to store malware, launch their attacks against the networks, and receive the stolen numbers.</p></blockquote>
<p>If you tally up all the counts that could be one hell of a sentence, especially with the 30 years for the wire-fraud tacked on. I guess if they ever manage to get out of prison, they might get to enjoy the millions they have stolen.</p>
<p>That is assuming they&#8217;ve laundered it and stashed it safely somewhere outside the jurisdiction of a US federal investigation.</p>
<p>Either way it&#8217;s an interesting case and I&#8217;m sure there will be more news about it.</p>
<p></p>
<p>Source: <a href="http://www.wired.com/threatlevel/2009/08/tjx-hacker-charged-with-heartland/">Wired</a> (<em>Thanks Navin</em>)</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=TJX+Hacker+Albert+%E2%80%9CSegvec%E2%80%9D+Gonzalez+Indicted+By+Federal+Grand+Jury+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2039+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/08/tjx-hacker-albert-segvec-gonzalez-indicted-by-federal-grand-jury/&amp;t=TJX+Hacker+Albert+%E2%80%9CSegvec%E2%80%9D+Gonzalez+Indicted+By+Federal+Grand+Jury" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/08/tjx-hacker-albert-segvec-gonzalez-indicted-by-federal-grand-jury/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/08/tjx-hacker-albert-segvec-gonzalez-indicted-by-federal-grand-jury/&amp;title=TJX+Hacker+Albert+%E2%80%9CSegvec%E2%80%9D+Gonzalez+Indicted+By+Federal+Grand+Jury" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/08/tjx-hacker-albert-segvec-gonzalez-indicted-by-federal-grand-jury/&amp;title=TJX+Hacker+Albert+%E2%80%9CSegvec%E2%80%9D+Gonzalez+Indicted+By+Federal+Grand+Jury" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/08/tjx-hacker-albert-segvec-gonzalez-indicted-by-federal-grand-jury/&amp;title=TJX+Hacker+Albert+%E2%80%9CSegvec%E2%80%9D+Gonzalez+Indicted+By+Federal+Grand+Jury" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/08/tjx-hacker-albert-segvec-gonzalez-indicted-by-federal-grand-jury/&amp;title=TJX+Hacker+Albert+%E2%80%9CSegvec%E2%80%9D+Gonzalez+Indicted+By+Federal+Grand+Jury" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F08%2Ftjx-hacker-albert-segvec-gonzalez-indicted-by-federal-grand-jury%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/08/tjx-hacker-albert-segvec-gonzalez-indicted-by-federal-grand-jury/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Russian Elcomsoft Finds Backdoor in Quicken Passwords</title>
		<link>http://www.darknet.org.uk/2007/08/russian-elcomsoft-finds-backdoor-in-quicken-passwords/</link>
		<comments>http://www.darknet.org.uk/2007/08/russian-elcomsoft-finds-backdoor-in-quicken-passwords/#comments</comments>
		<pubDate>Tue, 14 Aug 2007 07:33:18 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[General Hacking]]></category>
		<category><![CDATA[Password Cracking]]></category>
		<category><![CDATA[elcomsoft]]></category>
		<category><![CDATA[hacking-quicken]]></category>
		<category><![CDATA[quicken]]></category>
		<category><![CDATA[quicken-passwords]]></category>
		<category><![CDATA[russian-hackers]]></category>
		<category><![CDATA[software-application-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2007/08/russian-elcomsoft-finds-backdoor-in-quicken-passwords/</guid>
		<description><![CDATA[Elcomsoft is quite a well known firm when it comes to password &#8216;recovery&#8217;, I have used their products in the past when I was in a fix and I needed a password that had been, you know&#8230;lost. They rose to fame in 2001 after cracking Adobe&#8217;s eBook format. Recently they announced a fairly serious backdoor [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Elcomsoft is quite a well known firm when it comes to password <em>&#8216;recovery&#8217;</em>, I have used their products in the past when I was in a fix and I needed a password that had been, you know&#8230;lost.</p>
<p>They rose to fame in 2001 after cracking Adobe&#8217;s eBook format.</p>
<p>Recently they announced a fairly serious backdoor in Quicken product for accounting.</p>
<blockquote><p>A Russian firm that provides password-recovery services says it has found a backdoor in the encryption mechanism that Quicken uses to secure password-protected files, a feature that makes millions of users of the personal finance program more vulnerable to government spooks or other highly determined snoops.</p>
<p>Elcomsoft, which made waves in 2001 after it circulated software that circumvented digital rights management protections in Adobe&#8217;s eBooks, said the latest version of its Advanced Intuit Password Recovery product allows users to remove password protection from Quicken files.</p></blockquote>
<p>It&#8217;s a pretty serious case seen as though a lot of small and medium enterprises hold all of their accounting and payroll data in Quicken databases. It could lead to some serious theft, if Elcomsoft can work out the backdoor I&#8217;m sure the bad guys can too.</p>
<blockquote><p>According to a statement issued by Elcomsoft, Intuit since 2003 has secured password-protected Quicken files using &#8220;strong encryption&#8221; that for practical purposes makes brute-force attacks impossible. But Elcomsoft said the strong encryption is accompanied by a backdoor that lets Intuit unlock encrypted files using a 512-bit RSA key that until recently was known only to Intuit. The key enabled Intuit to deliver retrieval service for customers who could no longer remember their password.</p>
<p>&#8220;It is very unlikely that a casual hacker could have broken into Quicken&#8217;s password protection regimen,&#8221; Vladimir Katalov, Elcomsoft&#8217;s CEO, said in a statement. &#8220;Elcomsoft, a respected leader in the crypto community, needed to use its advanced decryption technology to uncover Intuit&#8217;s undocumented and well-hidden back door, and to successfully perform a factorization of their 512-bit RSA key.&#8221;</p></blockquote>
<p>The skeptics would indeed say the escrow or backdoor is there to allow Quicken to make more money from password recovery, the conspiracy theorists would say it&#8217;s there for FBI/CIA/Homeland access to people&#8217;s account.</p>
<p>I&#8217;m undecided personally.</p>
<p></p>
<p>Source: <a href="http://www.theregister.co.uk/2007/06/23/quicken_password_backdoor/">The Reg</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Russian+Elcomsoft+Finds+Backdoor+in+Quicken+Passwords+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D610+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2007/08/russian-elcomsoft-finds-backdoor-in-quicken-passwords/&amp;t=Russian+Elcomsoft+Finds+Backdoor+in+Quicken+Passwords" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2007/08/russian-elcomsoft-finds-backdoor-in-quicken-passwords/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2007/08/russian-elcomsoft-finds-backdoor-in-quicken-passwords/&amp;title=Russian+Elcomsoft+Finds+Backdoor+in+Quicken+Passwords" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2007/08/russian-elcomsoft-finds-backdoor-in-quicken-passwords/&amp;title=Russian+Elcomsoft+Finds+Backdoor+in+Quicken+Passwords" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2007/08/russian-elcomsoft-finds-backdoor-in-quicken-passwords/&amp;title=Russian+Elcomsoft+Finds+Backdoor+in+Quicken+Passwords" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2007/08/russian-elcomsoft-finds-backdoor-in-quicken-passwords/&amp;title=Russian+Elcomsoft+Finds+Backdoor+in+Quicken+Passwords" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2007%2F08%2Frussian-elcomsoft-finds-backdoor-in-quicken-passwords%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2007/08/russian-elcomsoft-finds-backdoor-in-quicken-passwords/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
	</channel>
</rss>

