09 August 2012

Cyberwar: A Gaussian Flame Sweeping Through Middle Eastern Banks

Computer malware "Flame" and a new addition "Gauss" have been detected targeting bank accounts at several banks in Lebanon. They appear to be seeking out log-in credentials, which would allow outsiders to spy on account activity -- and even manipulate accounts and account transfers, if desired. It is likely that Lebanese banks are only the tip of the iceberg, however.

Russia's Kasperky labs -- closely tied to Putin's Kremlin -- have been unable to crack the encryption for the Gauss malware.
“When you look at Stuxnet and DuQu, they were obviously single-goal operations. But here I think what you see is a broader operation happening all in one,” says Roel Schouwenberg, senior researcher at Kaspersky Lab.

The researchers don’t know if the attackers used the bank component in Gauss simply to spy on account transactions, or to steal money from targets. But given that the malware was almost certainly created by nation-state actors, its goal is likely not to steal for economic gain, but rather for counterintelligence purposes. Its aim, for instance, might be to monitor and trace the source of funding going to individuals or groups, or to sabotage political or other efforts by draining money from their accounts.

While the banking component adds a new element to state-sponsored malware, the mysterious payload may prove to be the most interesting part of Gauss, since this part of the malware has been carefully encrypted by the attackers and so far remains uncracked by Kaspersky.

The payload appears to be highly targeted against machines that have a specific configuration — a configuration used to generate a key that unlocks the encryption. So far the researchers have been unable to determine what configuration generates the key. They’re asking for assistance from any cryptographers who might be able to help crack the code.

According to Kaspersky, Gauss appears to have been created sometime in mid-2011 and was first deployed in September or October of last year, around the same time that DuQu was uncovered by researchers in Hungary. DuQu was an espionage tool discovered on machines in Iran, Sudan, and other countries around August 2011 and was designed to steal documents and other data from machines. Stuxnet and DuQu appeared to have been built on the same framework, using identical parts and using similar techniques. Flame and Stuxnet also shared a component, and now Flame and Gauss have been found to be using similar code as well.

Kaspersky discovered Gauss only this last June, while looking for variants of Flame.

...Like Flame, Gauss is modular, so that new functionality can be swapped in and out, depending on the needs of the attackers. To date, only a few modules have been uncovered — these are designed to steal browser cookies and passwords, harvest system configuration data including information about the BIOS and CMOS RAM, infect USB sticks, enumerate the content of drives and folders, and to steal banking credentials as well as account information for social networking accounts, e-mail and instant messaging.

Gauss also installs a custom font called Palida Narrow, the purpose of which is not known. The use of a custom font designed by the malware authors is reminiscent of DuQu, which used a font called Dexter fabricated by its creators to exploit victim machines. Kaspersky has found no malicious code in the Palida Narrow font files and has no idea why it’s in the code, though the font contains Western, Baltic and Turkish symbols.

Gauss’s primary module, which Kaspersky refers to as the mother ship, appears to have been named after German mathematician Johann Carl Friedrich Gauss. Other modules of the malware appear to have been named after mathematicians Joseph-Louis Legrange and Kurt Godel. The Gauss module is about 200K in size. With all of the plugins found so far, Gauss measures 2MB, much smaller than the 20MB Flame with all of its modules. Researchers do not yet know yet how the main Gauss module first gets onto systems, but once on a system, it injects into the browser in order to steal cookies and passwords. Another module loads an exploit onto any USB sticks inserted into the system thereafter. The exploit dropped to the USB stick is the same .lnk exploit that Stuxnet used to spread to systems. Microsoft has since patched the .lnk exploit, so it’s unclear if the .lnk module that Gauss uses has been successful in infecting systems. Once an infected USB stick is inserted into another system, it has two roles – to gather configuration information about the system and to deliver the encrypted payload.

The configuration data it collects includes information about the operating system, network interfaces and SQL servers. It stores this data in a hidden file on the USB stick. When the USB stick is later inserted into another system that has the main Gauss module installed on it and that is connected to the internet, that stored configuration data is sent to the attacker’s command-and-control servers. The USB exploit is set to gather data only from 30 machines, after which it deletes itself from the USB stick.

Schoewenberg says the USB module appears to be aimed at bridging an airgap and getting the payload onto systems that are not connected to the internet, as it had been used previously to get Stuxnet onto industrial control systems in Iran that were not connected to the internet. _Wired
More at the linked story above.

More background on Flame

Development timeline linking Stuxnet and Flame

Middle East cyberwar is not all one-sided

Computer network intrusion, data collection, and disruption, are all part of a modern nation's arsenal. Russian and Chinese hackers and info-spies have been among the most malicious and destructive, penetrating the highest levels of governmental networks in Europe, North America, and Oceania.

The reason that Flame, Stuxnet, Duqu, Gauss, etc. are receiving so much media attention is that these infowar tools are the most sophisticated of which the public have been made aware. Thus far.

One thing's not in contention. Kaspersky and Symantec each are convinced that Stuxnet and Flame were built by different teams.

There's little to no similarity between the two pieces of malware.

"Stuxnet and Duqu were created on the same [development] platform, but they have nothing in common with Flame," said Schouwenberg. "There's absolutely nothing in common. Stuxnet/Duqu and Flame use completely different development philosophies." _Source
Clearly the electronic commons has been breached and exposed to anyone clever enough to graze them. The physical commons has, of course, long since been breached.

Members of the Society for Creative Apocalyptology are taught how to avoid the "commons" when necessary. And how to deal with the risks of the commons when necessary.

Labels:

Bookmark and Share

29 May 2012

Flame Malware Burns Information Systems Across MENA

From Iran to Sudan, computer systems across MENA (Middle East North Africa) are being infected by Flame, a huge and powerful type of spyware, of unknown origin. Flame seeks out hidden information inside targeted systems, and transmits it to command and control centres outside the countries targeted.

Russia's Kaspersky Lab discovered the sophisticated virus while following a request by the United Nations to look into reports that Iranian Oil Ministry and Oil Company computers may have been infected by a new, unknown virus.
A massive, highly sophisticated piece of malware has been newly found infecting systems in Iran and elsewhere and is believed to be part of a well-coordinated, ongoing, state-run cyberespionage operation.

The malware, discovered by Russia-based anti-virus firm Kaspersky Lab, is an espionage toolkit that has been infecting targeted systems in Iran, Lebanon, Syria, Sudan, the Israeli Occupied Territories and other countries in the Middle East and North Africa for at least two years.

...Early analysis of Flame by the Lab indicates that it's designed primarily to spy on the users of infected computers and steal data from them, including documents, recorded conversations and keystrokes. It also opens a backdoor to infected systems to allow the attackers to tweak the toolkit and add new functionality.

The malware, which is 20 megabytes when all of its modules are installed, contains multiple libraries, SQLite3 databases, various levels of encryption -- some strong, some weak -- and 20 plug-ins that can be swapped in and out to provide various functionality for the attackers. It even contains some code that is written in the LUA programming language -- an uncommon choice for malware.

...Gostev says that because of its size and complexity, complete analysis of the code may take years.

"It took us half-a-year to analyse Stuxnet," he said. "This is 20-times more complicated. It will take us 10 years to fully understand everything." _Wired.co.uk
Read the full article linked above for more information.

While the author of the article speculates that "Flame" may have been written by the same authors as Stuxnet and Duqu, Al Fin analysts suspect that the three viruses were each written by distinct groups of malware creators.

It is likely that Stuxnet was a joint project of US and Israeli spy agencies. Duqu is more likely to be the product of Chinese malware labs. Flame is probably either a Russian or a Chinese project.

Expect such spyware to increase in sophistication over time, as the war of the codes intensifies.

And just wait until nano-ware -- entire mobile computer and telecom systems which can be transported and placed virtually anywhere in a covert manner -- becomes more prominent. Interesting times.

Labels:

Bookmark and Share

19 March 2012

DuQu Undressed? Mystery Computer Language Revealed

DuQu, an espionage tool that followed in the wake of the infamous Stuxnet code, had been analyzed extensively since its discovery last year. But one part of the code remained a mystery – an essential component of the malware that communicates with command-and-control servers and has the ability to download additional payload modules and execute them on infected machines.

Kaspersky researchers were unable to determine the language in which the communication module was written and published a blog post asking programmers for help. Identification of the language would help them build a profile of DuQu’s authors. _Wired
While other parts of DuQu were written in the C++ programming language and were compiled with Microsoft’s Visual C++ 2008, this part was not. Kaspersky also ruled out Objective C, Java, Python, Ada, Lua or many other languages they knew.

Most commenters who wrote in response to Kaspersky’s plea thought the code was a variant of LISP, but the reader who led them in the right direction was a commenter who identified himself as Igor Skochinsky and wrote in a thread posted to Reddit.com that he was certain the code was generated with the Microsoft Visual Studio Compiler and offered some cogent reasons why he believed this. Two other people who sent Kaspersky direct emails made crucial contributions when they suggested that the code appeared to be generated from a custom object-oriented C dialect — referred to as OO C — using special extensions.

This led the researchers to test various combinations of compiler and source codes over a few days until they found the right combination that produced binary that matched the style in DuQu.

The magic combination was C code compiled with Microsoft Visual Studio Compiler 2008 using options 01 and Ob1 in the compiler to keep the code small.

“Visual C can optimize for speed and it can optimize for size, or it can do some kind of balance between the two,” says Costin Raiu, director of Kaspersky’s Global Research and Analysis Team. “But they wanted obviously the smallest possible size of code” to get it onto victim machines via an exploit.

...The use of object-oriented C to write the event-driven code in DuQu reveals something about the programmers who coded this part of DuQu – they were probably old-school coders, Kaspersky’s researchers say. The programming style is uncommon for malware and is more commonly found in professionally-produced commercial software created ten years ago, Raiu says. The techniques make DuQu stand out “like a gem [from] the large mass of ‘dumb’ malicious program we normally see,” the Kaspersky researchers note.

...DuQu’s programmers might have chosen C because they wanted to make sure that their code could be compiled with any compiler on any platform, suggesting they were thinking ahead to other ways in which their code might be used.

...when you create such a complex espionage tool, you take into account that maybe some day you will run it on servers, maybe you will want to run it on mobile phones or God knows what other devices, so you just want to make sure your code will work everywhere.... _Wired
Small, clean, and versatile...it requires a lot of work and patience to reach the optimal approach to creating such a tool as Duqu. We seem to be looking at professional programmers with experience and savvy. But one can find such programmers in most countries of Europe, North America, East or South Asia, or Oceania.

To narrow the field, one must look at the apparent targets of a particular weapon. Judging by the apparent targets of Duqu so far, China is the best guess for the originators and ongoing master controllers of Duqu.

Labels:

Bookmark and Share

12 March 2012

Et Tu, Duqu?

Duqu, a trojan of unknown purpose spread by tainted Microsoft Word files, is supposedly the follow up to the Stuxnet worm, the self-replicating USB-stick-distributed malware that wrecked 400 uranium centrifuges with overspeed commands at Iran's Natanz nuclear fuel enrichment facility in 2010. Duqu is a remote access trojan (a RAT) and is waiting on instructions from a remote commander to activate it and tell it which files to steal, corrupt or run.

Stuxnet and Duqu are thought to have come from the same programming teams because they share whole chunks of code.... In a section of the malware called 'payload dll', and sandwiched between regular C++ code, there's a mysterious section written in an unknown programming language. "It's definitely not C++, Objective C, Java, Python, Ada, Lua or many other languages we have checked," says Soumenov. If it is a customised language that might very well need the support and resources of a nation state's security apparatus.

One of the strongest hints in the comments thread suggests that the language may be a variant of the AI programming language LISP, while another says the code looks like it might hail from a version of C++ for old IBM System/38 (from 1978) computers. They suggest the IBM-alike code may give Duqu a robust TCP/IP internet connection for receiving its malicious commands. _NewScientist
Duqu Spread

Here are a few conclusions that experts have arrived at regarding Duqu (excerpted and edited):
  • It is obvious that every single Duqu incident is unique with its own unique files using different names and checksums;
  • Duqu is used for targeted attacks with carefully selected victims (The term APT has been used to describe this, but I don’t like this expression and prefer not to use it);
  • We know that there are at least 13 different driver files (and we have only 6 of them);
    We haven’t found any ‘keylogger’ module usage. Either it has never been used in this particular set of incidents, or it has been encrypted, or it has been deleted from the systems;
  • Analysis of driver igdkmd16b.sys shows that there is a new encryption key, which means that existing detection methods of known PNF files (main DLL) are useless. It is obvious that the DLL is differently encoded in every single attack. Existing detection methods from the majority of AV vendors are able to successfully detect Duqu drivers. But it is almost 100% certain that the main DLL component (PNF) will go undetected.
  • Duqu is a multifunctional framework which is able to work with any number of any modules. Duqu is highly customizable and universal;
  • The main library (PNF) is able (export 5) to fully reconfigure and reinstall the package. It is able to install drivers and create additional components, record everything in the registry, etc. It means that if there is a connection to active the C&C and commands, then Duqu’s infrastructure on a particular system might be changed completely;
_Securenet
The fact that part of Duqu is written in an unknown programming language, suggests that the coders may just bet getting started, and are conducting something of an experiment in advanced remote command and control of computing systems.

Duqu code is being shared among a large number of persons and institutions interested in computer security and hacking. Symantec is among the companies that are tracking Duqu:
Symantec Corp. (SYMC) is among the firms tracking Duqu. Interestingly, they make some statements about the worm's origin which seemingly exonerate the U.S. from Stuxnet suspicions. Symantec states that the Duqu authors must have either been given code by the Stuxnet authors, have stolen the code from the Stuxnet authors, or are themselves the Stuxnet authors.

Symantec's Kevin Haley comments to Reuters, "We believe it is the latter."

The sophistication of this worm suggests that if the U.S. didn't have a hand in crafting it, that China or Russia perhaps did. A command and control server was found to be hosted in Belgium, but it's rather unlikely that the attackers chose their home nation to host the attacking platform.

China -- a cyber-superpower and notorious aggressor -- is thought to maintain a repository of unpublished vulnerabilities on platforms such as Windows, Linux, and OS X, waiting to exploit them when the need arises.

Nine international organizations have found their systems compromised. The compromised nations in these victim organizations are:
Organization A - France, Netherlands, Switzerland, Ukraine
Organization B - India
Organization C - Iran
Organization D - Iran
Organization E - Sudan
Organization F - Vietnam
Other researchers report that systems in the United Kingdom, Austria, Hungary, and Indonesia were infected. _DailyTech
No one is coming forward to admit having composed Duqu or Stuxnet. It is not clear that the two worms were disseminated by the same entities, since Stuxnet appears to have been aimed at Iran's nuclear projects, while Duqu may well be a copycat which is evolving beyond the abilities of its predecessor.

Labels: , ,

Bookmark and Share

20 November 2011

Is This the Super-Spy We've Been Waiting For?

While this diminutive computer-in-a-thumb-drive bears no resemblance to Daniel Craig, Pierce Brosnan, much less Sean Connery, it is capable of snooping and extracting information with the best of them.
Image Source

Norwegian company FXI Technologies showed off an amazing USB stick-sized portable computer prototype on Friday, Nov. 18. Code-named Cotton Candy because its 21 gram weight is the same as a bag of the confection, the tiny PC enables what its inventor calls "any-screen computing": the ability to turn any TV, laptop, phone, tablet, or set-top box into a dumb terminal for its Android-powered operating system.
Packed in its tiny body is a dual-core 1.2-GHz Samsung Exynos ARM CPU (the same processor as in the Galaxy S II), 802.11n Wi-Fi, Bluetooth, HDMI-out and even a microSD card slot for memory.

...When you plug the Cotton Candy into a Mac or PC, the Windows or OS X operating system recognizes it as a USB drive. You can then launch the software and run the Cotton Candy's Android environment in a secure window while you use your desktop OS outside the window. You can even transfer files between your notebook's native OS and the Cotton Candy's Android environment by dragging them off or on the USB stick's memory.

...Because the Cotton Candy is a full-fledged computer, it should be able to plug into a USB hub and connect directly to a monitor, keyboard, and mouse to launch its OS. Offices or schools could set up docking terminals to support users who carry it in their pockets.
Cotton Candy's purpose is to provide a computing experience that users can carry with them and replicate anywhere they go. Imagine walking into an Internet cafe or a business center, popping your Cotton Candy into a USB port, and having your own operating system and applications take over the device. _FoxNews
Indeed. Or imagine walking into a rival corporation's headquarters, and covertly plugging a pre-programmed spy thumb computer into the rival network. Within seconds it could be relaying sensitive information wirelessly, while covertly taking over the network and all its resources.

Something similar may have happened with the Stuxnet worm in Iran, but using a simple USB drive. Imagine how much more you could do with a powerful computer that just resembles a USB drive?

In reality, this is just a waystation along the road to nano-sized spy computers capable of invisibly flying through the doors and windows of buildings, or hitching a ride on the soles of shoes just about anywhere. Entire swarms of such nanocomputers could meet at a pre-arranged time and place, taking over in a very short time whatever network-controlled resources they were targeting.

Do you want to shut down a city's water supply? What about its electricity grid, or its cell phone networks? Consider disrupting the traffic light network, or sending a barrage of false fire and security alarms to police and fire departments, as a diversion from what you actually have planned?

You see there is no need to bomb a country that depends upon a "smart grid" or embedded networks. Just take over the networks that control the grid, the water supply, communications, and government agencies. If you do it anonymously enough, your adversary or target will be vulnerable to your next move, without even understanding who was behind the disruption.

The only defense against this type of inevitable attack, is redundant systems. Look around you, to see what organisations are developing redundant systems to deal with this type of certain attack. Even more importantly: What redundant systems have you developed for yourself and your company or household?

Update: Russian hackers destroy part of the water system of Springfield, Illinois using remote hacking techniques. The onslaught has just begun.

New Update 1 Dec 2011: It appears that the Springfield, Illinois water pump burnout was caused by normal wear and tear. The "false alarm" claim of Russian hacking was caused by a routine monitoring call from Russia the owner of the American company that provides advanced networking for the Springfield plant. The owner happened to be on vacation in Russia when he received a call that there may be a problem with the plant. He made a routine remote log-in to the network using his credentials, from his Russian location. A few months later, a pump burned out. Now you know the rest of the story.

Labels: ,

Bookmark and Share

21 February 2011

Night Dragon Hack-Attacks Connected to Industrial Accidents?

We hear about industrial accidents and explosions all the time. Here is a recent example from Turkey:
At least seven people were killed and 34 injured Thursday in an apparent accidental explosion at a factory in Turkey's capital Ankara, media reports said.

The death toll was likely to rise because several people were still believed to be buried under the rubble left by the explosion....The powerful explosion is believed to have been caused by a worker's mishandling of oxygen tanks at the factory, which employed at least 80 people in manufacturing hydraulic machinery. _MAC
But such accidents begin to take on new possible meanings as knowledge about the Chinese "Night Dragon" intrusions and the Stuxnet worm become more widely known. The Stuxnet worm took control of target machines in Iranian uranium enrichment facilities, causing them to behave erratically and destroy themselves. The Chinese Night Dragon attacks and intrusions are likewise capable of taking control of target machines:
...a [Chinese] company that, according to the company’s advertisements, provides “Hosted Servers in the U.S. with no records kept” for as little as 68 RMB (US$10) per year for 100 MB of space. The company’s U.S.-based leased servers have been used to host the zwShell C&C application that controlled machines across the victim companies.

...McAfee has determined that all of the identified data exfiltration activity occurred from Beijing-based IP addresses and operated inside the victim companies weekdays from 9:00 a.m. to 5:00 p.m. Beijing time, which also suggests that the involved individuals were “company men” working on a regular job, rather than freelance or unprofessional hackers. In addition, the attackers employed hacking tools of Chinese origin and that are prevalent on Chinese underground hacking forums. These included Hookmsgina and WinlogonHack, tools that intercept Windows logon requests and hijack usernames and passwords. _Forbes
The targets of Night Dragon included oil & gas companies which operate refineries -- refineries that are subject to exploding if their controls malfunction. The same is true for many chemical plants, and other types of industrial plants. Machinery at most modern factories is networked, to allow for highly automated operation. Anyone who can hack into the network and take control of the machines can also take control of the destiny of that plant.

Industrial work is already extremely hazardous, as jobs go. But in the highly-networked age, where sensitive machinery is controlled remotely via the net, there is one more hazard to worry about.

As Obama and his allies press for a highly networked "smart grid" which is meant to grow more reliant on inherently unreliable wind power, the hazards for society at large only grow larger.

Labels: , , ,

Bookmark and Share

10 February 2011

What's In It for China?

According to the report, the intruders used widely available attack methods known as SQL injection and spear phishing to compromise their targets. Once they gained access to computers on internal company networks, they would install remote administration software that gave them complete control of those systems. That made it possible for the intruders to search for documents as well as stage attacks on other computers connected to corporate networks.

In addition to their parallels to the Google attacks of last year, the intrusions resembled a Chinese-based electronic espionage network that was found in 2009 and named GhostNet. In that case, researchers at the Munk Center for International Studies at the University of Toronto uncovered an elaborate network aimed at government computers as well as those of nongovernmental organizations like the office of the Dalai Lama. The researchers concluded that the control servers of the attack system were based on the island of Hainan, which is part of China. _NYT
It is bad enough that tin-pot oil dictatorships such as Venezuela and Russa systematically lure international oil&gas companies into partnerships -- only to nationalise all of the multinational's in-country assets. Over and over again. Now China has been caught red-handed attempting to use computer hacking tools to disrupt multinational oil & gas operations. What is in it for the Chinese?
At least five multinational oil and gas companies suffered computer network intrusions from a persistent group of computer hackers based in China, according to a report released Wednesday night by a Silicon Valley computer security firm.

...Operating from what was a base apparently in Beijing, the intruders established control servers in the United States and Netherlands to break into computers in Kazakhstan, Taiwan, Greece and the United States, according to a report, “Global Energy Cyberattacks: ‘Night Dragon.’ ”

The focus of the intrusions was on oil and gas field production systems as well as financial documents related to field exploration and bidding for new oil and gas leases, according to the report. The attackers also stole information related to industrial control systems, the researchers noted, but no efforts to tamper with these systems were observed.

McAfee executives declined to name the victim companies, citing nondisclosure agreements it signed before being hired to patch the vulnerabilities revealed by the intrusions. Last year, when Google announced that intellectual property had been stolen by Chinese intruders, it expressed frustration that while it had observed break-ins at a variety of other United States companies, virtually none of the other companies were willing to acknowledge that they had been compromised. _NYT

The opportunities for western oil&gas companies seem to be expanding almost exponentially, given new drilling and exploration techniques. Oil & gas production in the US and elsewhere around the world are set to rise as a result, with much growth in exploration and production sectors.

What can China expect to gain from disrupting western and multinational oil & gas enterprises? Is is nothing more than a show of force projection, far beyond Chinese borders? Is it a warning? Or is it rehearsal and preparation for a more integrated effort to disrupt western energy supplies and critical information systems?

China is known for its industrial sabotage, its product counterfeiting, its outright theft of technologies from partners, and its iron-fisted control over information sources and expression inside its borders. Is China experimenting with similar exertion of control over global information streamways, with a hoped-for domination over energy, financial, information, and political flow of data?

Clearly, with China one must never let down his guard.

Cross-posted to Al Fin Energy

More: Brian Wang looks at China's ambitious plans for innovative -- perhaps technologically revolutionary -- change over the next decade. According to Brian, "Special emphasis is on four key areas, namely space science, information technology, energy and health." In addition, China is looking at US$ 1.5 trillion in investments into other potentially disruptive technologies.

The western world runs on high-speed information. Were China to learn to tap into, control, or largely disrupt the massive flow of information which forms the foundation of modern western prosperity, the entire global future would be up for grabs.

Labels: , , , ,

Bookmark and Share

28 November 2010

"Stuxnet Can't Hurt Us," Says Iranian Government

According to a report by the International Atomic Energy Agency, Iran has been forced to suspend activity on enriching uranium because of “technical problems” that are bedeviling thousands of centrifuges at its Natanz nuclear reactor. _TNA

Fueling of the reactor was delayed in recent months by what Iran called a small leak in a storage pool and not by the Stuxnet computer worm, allegedly designed to sabatoge Iran's nuclear power program, as is widely believed. _jta
Iran has adamantly stated that its nuclear program has not been hit by the bug. But in doing so it has backhandedly confirmed that its nuclear facilities were compromised. _FoxNews


Map: Ebequity
The sophisticated Stuxnet computer worm has the uncanny ability to "worm" its way into sensitive computer systems, then interferes with commands to motor controllers for centrifuges involved in uranium enrichment. Iran denies that its nuclear enrichment operations were negatively impacted by Stuxnet, but:
Experts dissecting the computer worm suspected of being aimed at Iran’s nuclear program have determined that it was precisely calibrated in a way that could send nuclear centrifuges wildly out of control.

Their conclusion, while not definitive, begins to clear some of the fog around the Stuxnet worm, a malicious program detected earlier this year on computers, primarily in Iran but also India, Indonesia and other countries. _NYT

Experts have examined the worm's code and come to some interesting conclusions about how the intruder works:
Here's how it worked, according to experts who have examined the worm:

--The nuclear facility in Iran runs an “air gap” security system, meaning it has no connections to the Web, making it secure from outside penetration. Stuxnet was designed and sent into the area around Iran's Natanz nuclear power plant -- just how may never be known -- to infect a number of computers on the assumption that someone working in the plant would take work home on a flash drive, acquire the worm and then bring it back to the plant.

--Once the worm was inside the plant, the next step was to get the computer system there to trust it and allow it into the system. That was accomplished because the worm contained a “digital certificate” stolen from JMicron, a large company in an industrial park in Taiwan. (When the worm was later discovered it quickly replaced the original digital certificate with another certificate, also stolen from another company, Realtek, a few doors down in the same industrial park in Taiwan.)

--Once allowed entry, the worm contained four “Zero Day” elements in its first target, the Windows 7 operating system that controlled the overall operation of the plant. Zero Day elements are rare and extremely valuable vulnerabilities in a computer system that can be exploited only once. Two of the vulnerabilities were known, but the other two had never been discovered. Experts say no hacker would waste Zero Days in that manner.

--After penetrating the Windows 7 operating system, the code then targeted the “frequency converters” that ran the centrifuges. To do that it used specifications from the manufacturers of the converters. One was Vacon, a Finnish Company, and the other Fararo Paya, an Iranian company. What surprises experts at this step is that the Iranian company was so secret that not even the IAEA knew about it.

--The worm also knew that the complex control system that ran the centrifuges was built by Siemens, the German manufacturer, and -- remarkably -- how that system worked as well and how to mask its activities from it.

--Masking itself from the plant's security and other systems, the worm then ordered the centrifuges to rotate extremely fast, and then to slow down precipitously. This damaged the converter, the centrifuges and the bearings, and it corrupted the uranium in the tubes. It also left Iranian nuclear engineers wondering what was wrong, as computer checks showed no malfunctions in the operating system.

Estimates are that this went on for more than a year, leaving the Iranian program in chaos. And as it did, the worm grew and adapted throughout the system. As new worms entered the system, they would meet and adapt and become increasingly sophisticated.

During this time the worms reported back to two servers that had to be run by intelligence agencies, one in Denmark and one in Malaysia. The servers monitored the worms and were shut down once the worm had infiltrated Natanz. Efforts to find those servers since then have yielded no results.

This went on until June of last year, when a Belarusan company working on the Iranian power plant in Beshehr discovered it in one of its machines. It quickly put out a notice on a Web network monitored by computer security experts around the world. _FoxNews
It is apparent to Al Fin security analysts, that Stuxnet is the work of agencies within the Israeli government. It is extremely likely that the Iranians are lying through their teeth in regard to the damage that the worm did to their nuclear enrichment programs.

Imagine that instead of computer worms, the Stuxnet ensemble had been a set of nanotechnological infiltrators, capable of imitating desert dust, bunker concrete, or pipeline insulation. Propelled by blowing winds, flowing water, on the soles of shoes, or inside the lungs of workers -- essentially unstoppable by most modern security systems. Such a suite of nanotech infiltrators could not only install computer worms into virtually any system, they could insert targeted explosive devices to disrupt communications, convey poisonous substances into ventilation or water systems, or travel in a target's circulatory system to cerebral arterioles, where they do whatever damage they are programmed to do.

We see that deep underground bunkers are essentially naked to the newer and more clever tools of saboutage. How much more exposed are government and industrial centers on the surface.

The world is entering a new age of advanced espionage and covert destruction. Stuxnet can be seen as an early warning of the type of destructive tools which are coming soon, out of the djinn's bottle. Once released from their container, they cannot be returned safely.

Update 29 Nov 2010: Someone was unwilling to wait for advances in nanotechnological espionage and saboutage. Bombers-on-motorcycles used magnetic-attachable bombs on automobiles to attack two Iranian nuclear scientists (killing one and injuring the other) in Tehran. One of the scientists, at least may have been involved in trying to counter the effects of the Stuxnet worm on Iran's nuclear facilities (see comments).

Labels: , ,

Bookmark and Share

06 October 2010

The Unutterable Stupidity of Obama's "Smart Grid"

President Barack Obama’s talk about the need for a “smart grid” sounds, well, smart...As currently envisaged, however, it’s a dangerously dumb idea. _SciAm
President Obama tends to be attracted to ideas that sound good on the surface, but which are incredibly stupid and destructive at their core. The so-called "smart grid" is yet one more in a long line of such stupid and destructive ideas coming from the Obama White House.
The problem is cybersecurity. Achieving greater efficiency and control requires hooking almost every aspect of the electricity grid up to the Internet—from the smart meter that will go into each home to the power transmission lines themselves. Connecting what are now isolated systems to the Internet will make it possible to gain access to remote sites through the use of modems, wireless networks, and both private and public networks. And yet little is being done to make it all secure.

The grid is already more open to cyberattacks than it was just a few years ago. The federal government has catalogued tens of thousands of reported vulnerabilities in the 200,000-plus miles of high-voltage transmission lines, thousands of generation plants and millions of digital controls. Utilities and private power firms have failed to install patches in security software against malware threats. Information about vendors, user names and passwords has gone unsecured. Logon information is sometimes unencrypted. Some crucial systems allow unlimited entry attempts from outside.

As the power industry continues to invest in information technology, these vulnerabilities will only get worse. Smart meters with designated public IP addresses may be susceptible to denial of service attacks, in which the devices are overwhelmed with spurious requests—the same kind of attacks now made on Web sites. Such an attack could result in loss of communication between the utility and meters—and the subsequent denial of power to your home or business.

The smart grid would also provide hackers with a potential source of private information to steal. Just as they use phishing attacks to elicit passwords, credit-card numbers and other data stored on home computers, hackers could find ways of intercepting customer data from smart meters. A sophisticated burglar might use these data to figure out when you’re away on vacation, the better to rob your house.

Customer data could also give hackers a way to bring down the grid. Smart meters injected with malware, for instance, could disrupt the grid just as networks of PC botnets—home computers hijacked by viruses—now disrupt the Internet. A network of drone smart meters could cause a swath of the grid to power down, throwing off the grid’s electrical load. The imbalance would send large flows of electricity back to generators, severely damaging them or even blowing them up. _SciAm

The integrated electronics in the "smart grid" will also make the Obama Grid more prone to devastating damage from an EMP attack or a solar storm.

In uncertain economic times such as the current Obama Depression, it makes more sense to toughen the power grid to make it more resistant to hacking and the various forms of catastrophic failure. Instead, it seems almost as if the Obama regime wants to make the US more vulnerable, rather than less.

cross-posted to Al Fin Energy

Labels: , , , ,

Bookmark and Share

05 April 2010

"Smart Grid" An Open Door to Hacker Mischief

With the best of intentions, US residential, commercial, and industrial users of electric power are being pushed into an extremely vulnerable situation. With the installation of a "smart meter", your home immediately becomes vulnerable to a malicious hacking attack. Not only could your power be shut off by hackers, but your power use records could be manipulated at will.

Hacking the smart grid is a snap!
Once hackers have access to smart meter codes and programming, they can "talk" to all meters of the same brand over the network. In one simulation, Davis proved that malware set to self-replicate could shut down power for 15,000 homes in 24 hours.

The threat is not just to your home, or to 15,000 homes. The threat is to the entire grid, via self-propagating computer worms that could initiate a cascading power failure over large areas of North America.
Researchers have previously warned that allowing network access to the home opens up a host of security issues. Last year, security firm IOActive found flaws in a smart-meter device that allowed its researchers to insert code into one device and have it spread to others--essentially, injecting a computer worm into a local power network.

"If you could get that meter to talk to its neighbors and those to talk to their neighbors, you could conceptually tell them to turn off and cause a fairly broad power outage," Shaw says. _TR


Chinese spy-hackers have been busy at work, devising ways of breaking into the US power grid's most vulnerable points. The new "smart grid" will only make it easier for them to access every weak area.

Normally, a nation's government would not be so eager to make its citizens and economy so vulnerable to an overseas threat such as Chinese power-hackers. In the case of the Obama-Pelosi reich, however, one can never be sure of the underlying motive. We would like to think the best of our leaders, but the track record of Obama-Pelosi suggests that the current regime is not necessarily looking out for the best interests of North Americans without close O-P connections.

Cross-posted at Al Fin Energy

Labels: , , ,

Bookmark and Share

08 November 2009

The "Smart Grid" is an Invitation to Cyber-Sabotage

Obama's much-lauded "smart grid" is one of the most idiotic policy plans of an administration that has launched almost nothing but idiotic policy plans. The smart grid would involve putting virtually every aspect of the US power grid under central computer control -- exactly the type of computer control that could be hacked by Chinese and Russian saboteurs working out of government offices in Beijing and Moscow. CBS' 60 Minutes presented a feature on the vulnerability of the US to cyber-attack by overseas saboteurs on Sunday night. From the financial system to the power grid to oil refineries and water treatment plants, anything that is controlled over the network can be sabotaged the same way.
A group of scientists and engineers at the Department of Energy facility wanted to see if they could physically blow up and permanently disable a 27-ton power generator using the Internet.

"If you can hack into that control system, you can instruct the machine to tear itself apart. And that's what the Aurora test was. And if you've seen the video, it's kind of interesting, 'cause the machine starts to shudder. You know, it's clearly shaking. And smoke starts to come out. It destroys itself," Jim Lewis explained.

Asked what the real-world consequences of this would be, Lewis said, "The big generators that we depend on for electrical power are one, expensive, two, no longer made in the U.S., and three, require a lead time of three or four months to order them. So, it's not like if we break one, we can go down to the hardware store and get a replacement. If somebody really thought about this, they could knock a generator out, they could knock a power plant out for months. And that's the real consequence." __60 Minutes
Al Fin has looked at what would happen if the power grid went down after an EMP attack. But it is plain that it isn't necessary to conduct an EMP attack to shut down the grid. If Obama is successful in implementing his "smart grid" plan on the US grid, clever hackers could do the job as well.

If you knock large sections of the US power grid out for several months, the devastation that would follow would be far worse than the damage the US has suffered from any war -- including the US Civil War.

The "smart grid" only makes the US far more vulnerable to attack. But then, that is not the only Obama policy that makes the US more vulnerable to outside attack, is it? If you look at the entirety of the Obama proposals and policies, domestic and foreign, it should be obvious that the end result of almost every one of them, is increased debt and vulnerability with virtually no benefit to the US.

When did the US become such a masochistic nation?

Labels: , ,

Bookmark and Share

25 January 2008

China: Scratching its Way to the Top by Industrial Espionage, Counterfeiting, Reverse Engineering, Spying, Cheating, Bluffing . . . .

China poses as a rising star in the world of commerce, industry, technology and science. But China's recent stock market scare reveals how closely China's success hangs upon financial and technological achievements in the west. If China were unable to steal, counterfeit, pirate, and reverse-engineer superior achievements of technology and science in the west, how many decades behind the west would China be?
The government believes that, in the next few years, China will surpass South Korea in technical abilities, and Germany in GDP. While China is still a minor player in the world of military high tech, the government is putting lots of money and effort into changing this. Expensive, and long term, efforts are being made to produce high tech items like jet engines, missiles and military electronics. At the current rate of progress, Chinese military technology will match that of the United States in a decade or so.
Strategy Page

In a mad rush to surpass the west, China is poisoning its air and water, destroying and depleting its topsoil, stealing from its trading partners, sending poisoned toys,food,and other merchandise overseas, misrepresenting the size and health of its banks and state enterprises, and becoming the world's leading destructive state computer hacker and possible currency counterfeiter (via N. Korea).
...there is a long record in China of sending government-directed missions overseas to buy or shamelessly steal the best civil and military technology available, reverse engineer it, and build an industrial complex that supports the growth of China as a commercial and military power....The allegations against Chen Jin, of Jiaotong University in Shanghai, are an example of the entrepreneurial approach people take toward industrial espionage and intellectual property theft in China. Chen returned to China after earning a Ph.D. at the University of Texas at Austin. In 2003, China treated Chen like a national hero for inventing China's first signal processing microchip. Last week, Jiaotong University dismissed him, and Chen stands accused of hiring flocks of migrant workers with good manual dexterity and great eyesight to scratch the name "Motorola" off chips and etch in the name of Chen's company, "Hanxin."
Source

Is the government involved in Chinese counterfeiting? What do you think?
The second point is equally important. The piracy and counterfeiting that exists in China is largely the result of a tacit government policy to allow such practices to flourish. China has a relatively comprehensive set of antipiracy statutes on its books. However, little or no enforcement exists, and what fines and punishments do exist serve as only weak deterrents.

The reason for China's tacit sanctioning of widespread counterfeiting and piracy is that the Chinese government is well aware of two things. Counterfeit and pirated goods sold domestically help keep inflation low, and selling these goods internationally creates jobs and export revenues.___Source



Some of the counterfeit exports being sent overseas from China present a significant hazard to the end users.
Counterfeit high-tech items are a growing business, and a growing danger. In addition to computer gear, auto and aircraft components are also being faked. Some aircraft and auto accidents have been traced to the fakes, which makes it a public safety issue. But with the Department of Defense installing counterfeit computer components, it becomes a national security issue. There's also the fear that the Chinese, or some other hostile nation, might get their hands on real computer components, and replace some of the chips with modified ones that will make government networks easier to hack. Yes, it just gets worse.
Strategy Page

China is destabilizing the world's security.
China’s goal is to dominate in all sectors – from the lowest, most labor-intensive sectors to the highest and most advanced technological sectors – as quickly as possible. To accomplish these goals, China must have access to advanced technology. FDI gives China this access. Once the advanced technology is introduced into China, China gains access to the technology. Some of this access is lawful, but much of it is through unauthorized copying, theft, and counterfeiting, all of which allows China to obtain technology transfer without the payment of fees.___Source
China's recent moves into the third world, including Africa, should raise eybrows--particularly regarding the tendency of Chinese consumer exports to be poisoned.

The upcoming Beijing Olympics are a source of pride for the Chinese CCP, but amid all the other illegitimacies, is China hosting a counterfeit Olympics? There is significant international concern over the safety of food and water to be provided by the host country for Olympic athletes and guests. I wonder if the Chinese people themselves are wondering about the future safety of Chinese food and water? No, they're too busy worrying about the present.


China wants to be taken seriously by everyone, including the world's superpower. To accomplish this, China intends to gouge, steal, lie, cheat, copy, counterfeit, hack, intimidate, subvert, proliferate nukes, reverse engineer, spy, and bluster its way to the top.

In the process of its grand strategy, China's people and environment are being poisoned, while the world's environment is sullied. China's pro-proliferation policies and close friendships with state sponsors of terrorism such as Iran and Venezuela, suggests long term plans to destabilize the islands of prosperity within both the developed and developing worlds.

Nothing about the method of China's rise suggests the intent to become a responsible world co-citizen. Nothing indicates a will to create a better world, with prosperity and security for all. Instead we see a Chinese CCP hell-bent to achieve superiority and hegemony in every area--while destroying its own ecology and the ecologies of East Asia. There is nothing admirable or encouraging about China's gutter tactics, its quasi-criminal methods of achievement.

We will see how long the civilised world can ignore China's criminal underworld nature, and what the consequences will be for having ingnored it from the days of Bush I, Bill Clinton, to the present.

Labels: , ,

Bookmark and Share
Older Posts
Al Fin Main Page
Enter your Email


Powered by FeedBlitz
Google
WWW AL FIN

Powered by
Blogger

``