Internet Anthropologist Think Tank

  • Search our BLOG


  • HOME
    Terrorist Names SEARCH:
    Loading

    Tuesday, October 14, 2008

    Cyber crooks scared


    Paradigm Intel: Hackers
    By Barb; Internet Anthropologist Think Tank
    Oct 14,08

    Cyber crooks scared, weeping in their beer.
    In the next few months we will see mass arrests of cyber crooks around the globe.

    As DarkMarket.ws turned honey pot bares fruit.

    Hackers retreating, scrubbing drives, getting off the net and on the run.
    Many are collectiong evidence on others as a bargining chips to plead for lower or no sentenances.
    Hackers don't do well in prison.

    Project DarkMarker will put a nice dent into ID theft, and may provide some good leads into RBN.

    For the past two years the FBI has been logging thousands of IPs of rhackers, cc theives, and buyers.
    The site offered a quality control fuction. A chance to check the quality of your product, and get a rating
    for the quality of your stolen cretdit card numbers stc, so the FBI has a sample / Evidence of most transactions. The would even boot off crooks with fake cc numbers.

    Barb


    Like Shadowcrew and earlier sites, DarkMarket lets buyers and sellers of stolen identities and credit card data meet and do business, in an entrepreneurial, peer-reviewed environment. Products for sale run the gamut from specialized hardware, to electronic banking logins collected from phishing attacks, stolen personal data needed to assume a consumer's identity ("full infos") and credit card magstripe swipes ("dumps), which are used to produce counterfeit cards. Vendors are encouraged to submit their goods for review before offering them for sale.

    Dejected denizens of the forum absorbed Tuesday's news with disappointment. "I was waiting for this, the worst news of them all," wrote a poster called Ms. Gold. "I don't really know what to say nor am I in your shoes to give a real view. There must be another solution to the problem. Do we just let them win?"

    "Now it would be too difficult to conduct business," wrote Iceburg. "Darkmarket was our bridge to business and if that bridge is broken than business is broken ... Long live carding and cashing. Short live all the RATS and FBI and all stupid secret agencies who are not just ruining our lives and families but they are destroying everything we left behind!"

    DarkMarket has enjoyed a solid reputation among users for effectively weeding out "rippers" who steal from other crooks.

    XXXXXXXXXXXXXXXXXXX

    UPDATE:

     the FBI reports that, for the first time ever, revenues from cybercrime have exceeded drug trafficking as the most lucrative illegal global business, estimated at reaping in more than $1 trillion annually in illegal profits. ....Cybercrime Inc. Keeps Growing

    In August, 11 defendants were formally charged in last year's high-profile T.J. Maxx data breach in which more than 45 million accounts were compromised over a couple of years. The defendants included three U.S. citizens as well as citizens of the Ukraine, Estonia, Belarus and the People's Republic of China. What's become clear to investigators and security experts alike is that organizations perpetrating these kinds of attacks are not only increasingly global, they're becoming nimbler, smarter and more efficient at wreaking havoc on company networks and profiting from their illegal activities. They have names like the Russian Business Network, Gray Pigeons, and Honkers Union of China. And they're growing—in numbers, power and reach.

    "What we've seen is really a deep stratification of electronic crime into a growing, prosperous and responsive economy, with a number of specialty organizations, syndication and deepening organization of peers, both within a vertical skillset and across the entire enterprise of electronic crime," said Peter Cassidy, secretary general of the Anti-Phishing Working Group, a nonprofit organization dedicated to counteracting cybercrime. "Increasingly, we see this is turning into big business."........

    Scott Henderson, a former U.S. military intelligence analyst with a specialty in the Chinese cyberthreat, said that there are about 280,000 to 300,000 individual hackers in China belonging to about 250 cybercrime organizations.

    SOURCE:

    XXXXXXXXXXXXXXXXXXXXXXXXXXXXX

    Quality Assurance in Malware 

    Surprisingly, while opportunistic cybercriminals have long embraced themalware as a service model, and are offering managed lower detection rate services for a customer's malware, or DIY ones where the customer can take advantage ofpopular tools ported to the Web, others are still trying to innovate at a faddish market niche - multiple offline AV scanners tools aiming to ensure that their malware doesn't end up in the hands of vendors/researchers.



    [multiple_offline_av_scanners.bmp]

    SOURCE:

    Does your malware pass these scanners?

    Barb.

    RBN Russian Business Net, aka FBS are not scared. World Bank Under Cyber Siege ...

    1. Internet Anthropologist Think Tank: Terrorists: Credit Card Fraud ...

      It reported the arrest of four men on charges of debit and credit card fraud for possessing numerous gift cards containing bank account and debit ...
      warintel.blogspot.com/2008/02/terrorists-credit-card-fraud-quiet.html
    2. Internet Anthropologist Think Tank: Credit Cards threat to GWOT ...

      Credit Cards and Terrorists By Dennis Lormel counterterrorism Blog As Imam Samudra sits on death row in Indonesia nearing his execution date for ...
      warintel.blogspot.com/2008/01/credit-cards-threat-to-national.html
    3. Internet Anthropologist Think Tank: CREDIT CARD CO. :CRIMINALS Banks ...

      May 2, 2008 ... Federal regulators are moving ahead with new rules to stop "unfair and deceptive " practices involving credit cards and bank overdraft fees. ...

    1. Internet Anthropologist Think Tank: Major banks, telecos top lead in ID theft...

      Mar 4, 2008 ... The study, Measuring Identity Theft at Top Banks , found that the Bank ...The profit the banks make from ID theft, is the only motivation I ...
      warintel.blogspot.com/2008/03/major-banks-telecos-top-identity-theft.html
    2. Internet Anthropologist Think Tank: Terrorists: Credit Card Fraud ...

      February 28, 2008 09:39 AM Link XXXXXXXXXXXXXXXXXXXXXXXXX The paradigm of this article is FALSE: ID THEFT AND CREDIT CARD FRAUD CAN BE STOPPED: ...

      There is a codependency between Banks and Cyber Criminals, Banks ( Credit Card Co. ) maintain it is not there job to stop ID theft, and the Banks profit from ID theft.
      But other Companys using the CC co. data can stop the ID theft, more criminal errors and ommissions by the Banking Indrustry.
      Barb

    Labels: , , , , , , ,

    Terrorist Names SEARCH:
    Loading

    Thursday, June 12, 2008

    Feds wrong paradigm.

    Top Spook: Facebookers, Gamers May Be Unfit to Spy.

    By Noah Shachtman EmailJune 12, 2008 | 11:16:00 AM
    .....................
    The Office of the Director of National Intelligence (ODNI) -- which, in theory, oversees all of the country's intelligence services -- is looking to launch a series of research studies into "cyber-behavior." Because what wannabe spooks do on-line should play "an important part" in the "process for granting security clearances for personnel working in national security positions." Suspect activities include "social network usage," "compulsive internet use," "distribution of pirated materials," and "on-line contact with foreign nationals."

    The first step is to get a "better understanding" of "which specific cyber-behaviors are normative, acceptable, or favorable as well as identifying those that may be associated with risky or problematic cyber behavior within the workplace."

    ...................................................


    Areas of potential interest include, but are not limited to: social network usage; disclosure of information in computer-mediated activities; extent of on-line contact with foreign nationals; cyber behavior that suggests an unwillingness to abide by rules; compulsive internet use; involvement in computer groups (especially those allied to stigmatized practices); providing false information within computer-mediated communications about oneself or others; procurement and distribution of pirated materials; engaging in deviant cyber-behaviors with the intention of causing harm to others including "hacking" and sabotage.

    SOURCE:

    XXXXXXXXXXXXXXXXXXXXXX

    If Wired has this right, it is an example of the Paradigm prevalent across the board in Federal
    agencys and an example of why al Qaeda is setting the Internet Paradigm that is eating US militarys lucnch on the Internet, recruiting, funding, hacking, C2, etc.

    Blocking someones security clearance for file sharing is like telling someone they can't become Police officers because they J-walk.
    ( I never file share for security reasons, but file sharing is almost a right of passage for adolescents. )

    "Areas of potential interest include, but are not limited to: social network usage; disclosure of information in computer-mediated activities; extent of on-line contact with foreign nationals; cyber behavior that suggests an unwillingness to abide by rules;"

    I hope Wired has this part wrong, but it sounds like these activities pre-employment show a disposition towards an unwillingness to abide by the rules.

    This thinking precludes the type of personalities best suited to WWW Intelligence work.

    On my staff of "cyber warriors" they must follow rules we set down. Or we bounce them.

    But I want out of the box thinkers, troops that can easily bond with strangers, huge social networks, connected, and the more foreign contacts the better.

    Defining hacking as deviant cyber-behavior, is an acknowledgment of the fear the Feds feel towards the Internet. The Feds don't rule the WWW and want to cut all risks.
    And an acknowledgment they fear they can't control a hacker.

    This is equalivant to the Revolutionary war Military refusing anyone who has hunted with a long distance rifle, and classifying this type of hunting as "deviant hunting-behavior".

    Criminal sanctions preclude us from hacking, but hackers , espically your own ar not to be feared. One must take certian security precautions. The computer you deal with hackers from
    can't have classified info on it, print it , then rescan ot into classified computers, they have not found a way to transmit a virus by paper yet.

    In order to attract the best talent to the WWW war effort, and the Air Force now says the WWW qualifies as a domain, ( and is on the FAST track for WWW dominance ) the Government needs to be embracing hackers, and learning to control them. Bust the violators, and shelter and nurture the hackers willing to come across from the dark side.

    I wonder what would have happened in the Revolutionary WAR if anyone who had fired a Kentucky long rifile was disqualified from serving? For "deviant hunting-behavior".

    Gerald
    Anthropologist

    The Chinese Government has access to a pool of 11,000 Chinese civilian hackers.
    Chinese hackers responsible for '88 per cent of attacks'
    BCS, UK -Jun 3, 2008
    News stories: 1,118 for chinese hackers.




    Zemanta Pixie

    Labels: , , ,

    Terrorist Names SEARCH:
    Loading

    Thursday, May 29, 2008

    RUMINT, China


    This just in: Authorities in three West European countries have arrested ten individuals whom they believe to have links to Islamic Extremist factions in Uzbekistan. It is reported that those arrested were obtaining funding for a militant group within Uzbekistan that allegedly has ties with al-Qaida.

    Yuldeshev and his Uzbeks are going to be trouble, many are Russian Army trained, very disciplined and they play rough. Rumors are that the Chinese are terrified of them regarding the Olympics, talk of a dirty bomb there. The Uzbeks would do it and they have all the access they need with the Tibetans

    SOURCED Co C.

    xxxxxxxxxxxxxxxxxx

    Excerpts:
    China's Cyber Militia

    by Shane Harris

    One prominent expert told National Journal he believes that China's People's Liberation Army played a role in the power outages. Tim Bennett, the former president of the Cyber Security Industry Alliance, a leading trade group, said that U.S. intelligence officials have told him that the PLA in 2003 gained access to a network that controlled electric power systems serving the northeastern United States. The intelligence officials said that forensic analysis had confirmed the source, Bennett said. "They said that, with confidence, it had been traced back to the PLA." These officials believe that the intrusion may have precipitated the largest blackout in North American history, which occurred in August of that year. A 9,300-square-mile area, touching Michigan, Ohio, New York, and parts of Canada, lost power; an estimated 50 million people were affected.....There has never been an official U.S. government assertion of Chinese involvement in the outage, but intelligence and other government officials contacted for this story did not explicitly rule out a Chinese role. One security analyst in the private sector with close ties to the intelligence community said that some senior intelligence officials believe that China played a role in the 2003 blackout that is still not fully understood.
    ..............

    The Central Intelligence Agency's chief cyber-security officer, Tom Donahue, said that hackers had breached the computer systems of utility companies outside the United States and that they had even demanded ransom. Donahue spoke at a January gathering in New Orleans of security executives from government agencies and some of the nation's largest utility and energy companies. He said he suspected that some of the hackers had inside knowledge of the utility systems and that in at least one case, an intrusion caused a power outage that affected multiple cities. The CIA didn't know who launched the attacks or why, Donahue said, "but all involved intrusions through the Internet."

    ......................
    "Cyber-networks are the new frontier of counterintelligence," Brenner emphasized. "If you can steal information or disrupt an organization by attacking its networks remotely, why go to the trouble of running a spy?"

    Stephen Spoonamore, CEO of Cybrinth, a cyber-security firm that works for government and corporate clients, said that Chinese hackers attempt to map the IT networks of his clients on a daily basis. He said that executives from three Fortune 500 companies, all clients, had document-stealing code planted in their computers while traveling in China, the same fate that befell Gutierrez.


    .................

    Private Sector Foot-Dragging

    There is little indication that cyber-intrusions, however menacing, have severely impaired government operations for very long. So why are so many officials increasingly sounding the alarm about network attacks, Chinese hacking and espionage, and the advent of cyberwar?

    Part of the answer lies in officials’ most recent appraisals of the cyber-threat. They cite evidence that attacks are increasing in volume and appear engineered more to cause real harm than sporadic inconvenience. Without naming China, Robert Jamison, the top cyber-security official at DHS, told reporters at a March briefing, “We’re concerned that the intrusions are more frequent, and they’re more targeted, and they’re more sophisticated.”

    “In terms of breaches within government systems, it’s something that has happened quite a bit over the last six, seven years,” says Shannon Kellogg, the director of information-security policy for EMC Corp., which owns RSA, a top cyber-security research firm. “But the scale of these types of breaches and attacks seems to have increased substantially.”

    Government officials are more concerned now than in recent years about the private sector’s inability, or unwillingness, to stop these pervasive attacks. When Donahue, the CIA cyber-security officer, warned the gathering in New Orleans about foreign hackings of power plants, some saw it as a direct challenge to American companies.


    .......................

    The Air Force is in the process of setting up a Cyberspace Command, headed by a two-star general and comprising about 160 individuals assigned to a handful of bases. As Wired noted in a recent profile, Cyberspace Command "is dedicated to the proposition that the next war will be fought in the electromagnetic spectrum and that computers are military weapons." The Air Force has launched a TV ad campaign to drum up support for the new command, and to call attention to cyberwar. "You used to need an army to wage a war," a narrator in the TV spot declares. "Now all you need is an Internet connection."


    SOURCED: MUCH MORE:

    xxxxxxxxxxxxxxxxx

    Internet Anthropologist cyber team has pointed out that the WWW is currently at risk.

    And emailed DHS's NICC information on a new NEW VECTOR EXPLOIT.
    and have yet to hear back from them, " it " can walk thru all current security programs and Vista isn't even a constraint, nor are MACs.

    Our sources place the number of Chinese hackers in the 11,000 range.

    Paradigm Intel indicates we are in the middle of a massive invisible infection, motive unknown.
    To see the evidence on your PC down load "Haute secure".
    ( we have no connection to this compan.)


    Gerald
    Internet Anthropologist, ad Magnum

    .


    xxxxxxxxxxxx

    Chinese perspective (w/corrections ) American Economy


    China's actions should trigger SEC. Investigation Insider Trading...


    China hackers penetrate Pentagon ...


    China blackmailing USA, China ...



    Beijing will not do Anything against Iran's Interests

    Pearl Harbor of cyber war

    China is presenting some NEW dangerous paradigm threats in asymmetrical warfare.
    ( and don't forget space weapons, and their new supersonic evasive missiles, ie aircraft carriers )

    Labels: , , , ,

    Terrorist Names SEARCH:
    Loading

    Saturday, January 19, 2008

    Hackers are not YOU.


    from a password protected forum:

    The Turks are teaching hacking, the RATs.

    xxxxxxxxxxxxxxxxx


    Welcome to Palestine forums Hacker regret Forum currently closed

    للصيانة والتطوير Maintenance and development

    سنعود قريبا We will return soon

    والعذر منكم جميعا علي أي تأخير أو أزعاج The excuse you all for any delay or inconvenience

    ooops sorry...

    xxxxxxxxxxxxxxxxxxxxxxxxxx

    al Jinan planning a comeback. New secret web page.

    We don't think so.

    xxxxxxxxxxxxxxxxxxxxx


    Ongoing more to come.

    Gerald

    .

    Labels: , , , ,

    Terrorist Names SEARCH:
    Loading

    Saturday, January 05, 2008

    Hackers and forum





    # Section applications programmes encrypted encryption special versions special
    # مــــنــــتـــدى اخــــتــــراق الايــــمـــيـــل Forum penetrate email
    #

    * قـسـم خــــاص لأســئــلـــة الأعــضـــاء واسـتـفـسـاراـتـهـم حـــول الاخـــتـــراق A special section of questions and requests for information about members penetration

    # مــــنــــتــــدى اخــــتـــراق الاجـــهـــزة Forum penetrating devices
    #

    * قـسـم خــــاص لأســئــلـــة الأعــضـــاء واسـتـفـسـاراـتـهـم حـــول الاخـــتـــراق A special section of questions and requests for information about members penetration
    * الـبـرامـج الـــمــشـــفــرة والــحـــصـــريــة Encrypted programmes and exclusive

    # مــــنـــتــــدى اخـــتـــراق الــمـــواقع والـــمــنـــتـــديـــات Forum penetrate sites and forums
    #

    * قـسـم خــــاص لأســئــلـــة الأعــضـــاء واسـتـفـسـاراـتـهـم حـــول الاخـــتـــراق A special section of questions and requests for information about members penetration
    * ::Local Root Exploit :: :: Local Root Exploit::

    # قــســـم أخـــتــــراق شــبــكـــات الــويــرلــــس & LAN Section penetrate networks Aloyrls & LAN
    # مــنـــتــدى انـــــجــــازات الـــهـــكر Forum achievements Alhecr
    #

    * قسم أدوات و اندكسات الاختراق Tools section and penetration Andquisat
    * مكتبة الثغرات Library gaps

    # مـــنــــتـــــدى اخـــــتــــراق الـــــجــــوال Forum mobile penetration
    # مـــنـــتـــدى اخــــتــــراق الـــمحـــادثـــة Forum penetrate conversation
    # منتدى تعليم الهكر Education Forum Alhecr
    # قسم الدورات الاحترافية Section professional courses
    # قسم تعليم الاختراق بالفيديو Education Section breakthrough video
    # قسم E-book Section E-book
    #

    * قسم الطلبات Section applications

    # مـــنــــتـــــدى الـــــفـــايــــروســــات Forum VIRUSES



    The West has an advantage, in technological abilities, an attempt to close this gap, with forums like this.

    Bill



    From hacked site:


    .

    Labels: , ,

    Terrorist Names SEARCH:
    Loading

    Friday, December 07, 2007

    Islamic Hackers, Hacker ALERT


    CLICKETY, click......





    New wana be Islamic Hackers:
    "SecurityGhost" started the group:

    EVIDENCE:
    Man power & Time allowing we have been notifying site owners with in 5 min. after defacement.
    Mostly kiddy scripts.
    They have been down loading scripts, one of ours.

    They have defaced about a dozen web sites, no damage but they seem to be working towards more deviltry.

    He works with and is training these guys:
    :: GreetZ To:: EmBrAtOuR , Syntax(U)err , Weebi , VerY SecreT , ShoOtR , Mishal , Mr.Max , NouR iCE EmBrAtOuR, Syntax (U) err, Weebi, VerY SecreT, ShoOtR, Mishal, Mr.Max, NouR iCE مـــتــكـــي وراء الــشــمــس ,V4 Crackers , C0bra Hacker The strategy behind the sun, V4 Crackers, C0bra Hacker

    He is associated with these IP's.:

    Our info on him from our CI section :
    Location
    Riyadh, Ar Riyad, Saudi Arabia ,
    IP 's
    (212¸71¸37¸68:40191),
    (212¸71¸37¸67:49986),
    (212¸71¸37¸66:47849),
    (89¸4¸109¸112:2706)
    Language
    PC: ar-sa (Arabic/Saudi Arabia)
    Browser
    used by recipient: Moz/4.0 (MSIE 7.0; WinNT 5.1; .NET CLR 2.0.50727)

    AND
    212¸71¸32¸84:58699

    Language PC: en-us (English/United States)

    UPDATE: They have seen this page visited on Dec 10 2007 4:56:53 pm, (National Engineering Services)....http://nesma.net.sa/...( We should have some names soon).

    They is small stuff now but he will grow and branch out, and is training others.

    Today they defaced: 12.07.07
    http://www.wildcat-rally.co.uk/
    http://www.efdx.com/
    UPDATE following site not hacked, it is just information of a hacked site, sorry.
    http://72.14.209.104/search?q=cache:http%3A//whois.domaintools.com/syrianchristian.com

    Contact:Email: Barb.andrews at Gmail.com


    Gerald

    "CYBER ALERT" OTHER Islamofascist head HACKER ...BURNED


    UPDATE: 12.18.07
    Upon review we over classified this situation, Terrorist maybe to strong a word, as defacing and the text involved would only indicate sympathizers. G.


    UPDATE: 1.1.08
    He's at it again, but alone now, he has defaced 2 more sites, actually only one, they were waiting and put the site right back up 3 min after it was defaced.
    What needs to be done?
    YOUR not listening...
    How about some computer problems???

    Gerald

    .
    .

    Labels: , , , , , ,

    Terrorist Names SEARCH:
    Loading

    Saturday, October 06, 2007

    People's Information Warfare

    Friday, October 05, 2007

    Dancho

    People's Information Warfare Concept

    Malicious Culture of Participation

    DoS battle stations operational in the name of the "Please, input your cause". Preventing a malware infection in order to limit the possibility for the host to become part of a botnet that will later one start a large scale DDoS attack is such a rational thinking that information warriors truly understanding what information warfare is all about, tend to undermine. The recently discussed "people's information warfare" concept highlighting China's growing interest in the idea, is a great example of a culture of participation orbiting around hacktivism cause, a culture we've also seen in many other hacktivism tensions in the past, and will continue to see in the future. The entire concept is relying on the fact that the collective bandwidth of people voluntarily "donating" it, is far more efficient from a "malicious economies of scale" perspective, compared to for instance the botnet masters having to create the botnet by infecting users in one way or another. Moreover, empowering an average Internet user with diversified DoS capabilities is directly increasing the nation's asymmetric warfare capabilities in an event of a hacktivism war.

    Furthermore, the majority of DoS or DDoS flooding tools have a relatively high detection rate, but when people want to use them, they'll simply turn off their anti virus software, the one they use to prevent malware infections, but in a "people's information warfare" they can go as far as consciously becoming a part of a hacktivism centered botnet. Take this DoS tool featured in the screenshot for instance, it has a high detection rate only if the anti virus software is running, but in situation where a "malicious culture of participation" is the desired outcome it doesn't really matter. Donating their bandwidth and pretending to be malware infected is far more dangerous than botnet masters acquiring DDoS capability by figuring out how to infect the massess. It's one thing to operate a botnet and direct it to attack a certain site, and entirely another to be infected with a malware that's DDoS-ing the site, a situation where you become an "awakened and fully conscious zombie host".

    Examples of the "People's Information Warfare Concept" :

    - During the China/U.S hacktivism tensions in 2001 over the death of a Chinese pilot crashing into an AWACS, Chinese hacktivists released mail bombers with pre-defined U.S government and military emails to be attacked, thus taking advantage of the people's information warfare concept

    - The release of the Muhammad cartoons had its old-school hacktivism effect, namely mass defacements of Danish sites courtesy of Muslim hacktivists to achieve a decent PSYOPS effect online and in real-life

    - The Israel vs Palestine Cyberwars is a great example of how DIY web site defacement tools were released from both sites which resulted in a web vulnerabilities audit of the entire web space they were interested in defacing to spread hacktivism propaganda

    - Cyber jihadists taking advantage of the "people's information warfare" concept by syndicating a list of sites to be attacked from a central location, and promoting the use of a Arabic themed DoS tool against "infidel" supporting sites

    - What exactly happened during Russia's and Estonia's hacktivism tensions? The voting poll that is still available indicates that people believe it was botnet masters with radical nationalism modes of thinking. But judging from the publicly obtainable stats, ICMP often comes in the form of primitive DIY DoS tools compared to the more advanced attacks for instance. Collectivist societies do not need coordination because they know everyone else will do it one way or another.

    Power to the people.
    posted by Dancho Danchev @ Friday, October 05, 2007

    xxxxxxxxxxxxxxxxx

    This New application for new group, civilian irregular defense

    Threat to entire WWW

    al-jinan..org, was a dos attack group, whom we have drove underground.
    They are using an off the shelf program now to in-effectively attack a few sites,
    their members download a program to perform group DOS attacks.
    We continue to track and get members arrested,

    Gerald

    Labels: , , , , ,

    Terrorist Names SEARCH:
    Loading

    Monday, September 24, 2007

    Chinese Hackers in USA Gov PC's

    Chinese Hackers

    By GORDON G. CHANG
    September 14, 2007


    On Wednesday, wire services reported that a senior Chinese official charged foreign intelligence services of causing "massive and shocking" damage to his country through computer espionage.

    A vice minister of the Information Industry, Lou Qinjian, did not identify any culprit by name, but he did state that 80% of the computers used in the attacks were based in America. Beijing's accusation came suspiciously only after months of reports of Chinese hacking into Western government information systems.

    President Bush had been expected to raise the issue with his Chinese counterpart, Hu Jintao, during their 90-minute meeting in Sydney last Thursday. The two leaders had time to discuss a wide range of topics, including China's role in Sudan and Iran. They even found a few moments for a friendly chat about next summer's Olympics.

    Mr. Bush, however, was not anxious to talk about the recent Chinese hacker attacks against U.S. government networks. The Pentagon suspects that China's People's Liberation Army successfully penetrated an unclassified computer system serving the office of Defense Secretary Gates this June.

    The system was shut down after the perpetrators had obtained information, some of it sensitive. The Pentagon attack followed ones last year in July on the Commerce Department's Bureau of Industry and Security, in November on the Naval War College, and in December on the National Defense University. In the spring of last year, China accessed State Department computers and installed backdoors in networks to siphon off information on China and North Korea.

    Read the rest:

    Labels: , , ,

    Terrorist Names SEARCH:
    Loading

    Saturday, September 22, 2007

    Hacker Hunters cira 2001

    AND THIS WAS 6 YEARS AGO, MANY INTEL SERVICES USE MANY POSSE's NOW, HUNTING INTERNET JAHIDISTS.

    Tens of thousands of computers containing now-dormant Leaves worms await instructions from their master. Should they ever again awaken, a posse will be waiting.

    Wednesday, June 20, 2001
    6:30 a.m.
    FBI Headquarters,
    Washington

    After 23 years as a CIA analyst, having briefed the president and his team on every conceivable threat to national security, Bob Gerber was scared. More scared than he'd been in a long time.

    Holed up in his cramped, 11th floor office on a stark, colorless hallway at FBI headquarters in Washington, Gerber's stomach turned as he took his first look at a new enemy.

    Gerber was a hunter, one of the government's best. These days, he was hunting worms, malicious computer programs let loose into the wild of the Internet by some of computerdom's most brilliant hackers. Two months earlier Gerber, 56, had left his job at the CIA, where he helped write the president's daily intelligence briefing, to head the analysis and warning division at the FBI's National Infrastructure Protection Center. There, he and his crew of more than 60 tracked worms, viruses and other computer evils, as well as the hackers who create them. Both threatened daily to shut down the engines of modern life - electrical power grids, the banking system, water treatment facilities, the World Wide Web.

    Worms were the most vicious new beasts to stalk the Internet. But Gerber had never seen a worm quite like the one he confronted that sweltering Wednesday morning in June.

    It was named Leaves after "w32.leave. worm," the poisonous file it implanted in unsuspecting computers. Like all worms, Leaves bored through cyberspace, probing Internet connections for holes in personal computers or Web servers. It slithered inside the machines and spewed venomous strings of data that threw its victims into electronic shock.

    Leaves was hardly the first worm to infest the Internet. In fact, the pests became so common in 2001, that security cognoscenti dubbed it the "Year of the Worm." Worms wrought all sorts of damage. They forced computers to delete critical files or erase entire programs. They also allowed hackers to steal personal information from computers' memories. Once they infested their victims, worms made clones, then used their hosts as launching pads for more worms, whose numbers grew exponentially.

    In 2000, Gerber and his team began battling a new species of even more virulent super worms. Rather than devour computers' innards, these worms hijacked their victims' controls, rendering them powerless zombies. With a gang of zombies at his command, the creator of a superworm could mob a Web site or computer system, flooding it with bogus electronic transmissions until it drowned in the data torrent.

    In the spring of 2000, Gerber's colleagues took on a 15-year-old hacker who called himself Mafiaboy. The teenager turned his zombies loose on World Wide Web giants Amazon.com, eBay and Yahoo!, launching what is called a distributed denial of service attack that shut down business at the sites for five hours. It cost shareholders and the companies billions and shocked the Web world.

    But compared with the Leaves worm, Mafiaboy's creation was a larva. Gerber's best analysts had worked late into the night trying to make sense of a sample of Leaves captured by worm watchers at the SANS Institute, a computer research center in Bethesda, Md. They let Leaves infect a computer, and then they watched how it behaved. What Gerber saw fascinated and appalled him.

    Leaves was a zombie maker on steroids. It searched out computers already wounded by another Internet scourge called a Trojan, which installs back doors in the machines. Leaves used a Trojan called SubSeven as its entrance. Once transformed, the zombies awaited orders. To communicate with them, Leaves' creator ordered his zombies to rendezvous online through Internet Relay Chat channels. He also told them to visit certain Web sites and download encrypted information to receive instructions on what to do next. No one knew who was controlling the zombies, from where or why.

    More:

    Labels: , , , ,

    Terrorist Names SEARCH:
    Loading

    Saturday, September 15, 2007

    moqawmh.com DOWN



    moqawmh.com DOWN,
    WE FORTOLD THIS LAST WEEK or before?

    G

    They are back, hmmmm...

    Oh and from Moqawmh:

    Quote"
    A statement on the re-opening
    A statement on the re-opening A statement on the re-opening
    الموقع الرسمي للجيش الإسلامي في العراق The official website of the Islamic Army in Iraq
    The official website of the Islamic Army in Iraq The official website of the Islamic Army in Iraq
    الحمد لله رب العالمين القوي العزيز Praise be to Allah strong Aziz
    Praise be to God, Lord of the Worlds strong Aziz Praise be to God, Lord of the Worlds strong Aziz
    وأفضل الصلاة وأتم التسليم على نبي الهدى نبي الملحمة ، وعلى آله وصحبه أجمعين The best prayers and fully recognizing the prophet Huda epic prophet, his family and companions
    The best prayer and fully recognized the prophet Huda prophet saga, and his family and companions The best prayer and fully recognized the prophet Huda prophet saga, and his family and companions
    أما بعد .. After ..
    As yet. As yet.
    فقد منّ الله على اخوانكم في القسم الفني لمؤسسة البراق الاعلامية من اعادة افتتاح الموقع الرسمي للجيش الإسلامي في العراق بعد اغلاقه لمدة ثلاثة ايام حيث تعرض لهجمة شرسة من قبل اعداء الله . May God on your brothers in the technical section of the media institution go from re-opening the official website of the Islamic Army in Iraq after closure for three days where he was a fierce attack by the enemies of God.
    The God of your brothers in the technical section of the Wall information from re-opening the official website of the Islamic Army in Iraq after they closed for three days, where he was subjected to a fierce attack by the enemies of God. The God of your brothers in the technical section of the Wall information from re-opening the official website of the Islamic Army in Iraq after they closed for three days, where he was subjected to a fierce attack by the enemies of God.
    و نسأل الله أن يمكننا من رفع مكانة الجهاد و توعية المسلمين لأهميته، و نعاهده ما استطعنا على أن نبقى العين الصادقة على ملحمة الجهاد في أرض الرافدين. And ask God to enable us to raise the status of the Muslim Jihad and awareness of its importance, and Naahdeh we have to keep on eye sincere epic Jihad in the land of the Rafidain.
    And ask God to enable us to raise the status of Jihad and awareness of the importance of Muslims, and Nahid what we have been able to remain true to the epic eye Jihad in the land of Iraq.
    و نذكر اخواننا الموحدين بعنوان الموقع : And remember our brothers Single site entitled:
    And remember our brothers Single site entitled : And remember our brothers Single site entitled:
    iaisite.org Iaisite.org
    iaisite.info Iaisite.info
    كما و يسرّ المؤسسة أن تستقبل مشاركات و مواضيع الإخوة من تحليلات و مقالات و دراسات و تراجم حول أحوال الجهاد في بلاد الرافدين عبر معرف “مؤسسة البراق الإعلامية” في منتدى البراق Also, the Foundation is pleased to receive participants and themes of brotherhood and analysis articles and studies and biographies about the conditions of Jihad in the Rafidain across the country defined "media institution go" forum Shiner ( close quote )"

    Now how did they do that?
    Must be a new server.

    G

    Labels: , ,

    Terrorist Names SEARCH:
    Loading

    Thursday, September 06, 2007

    Wanta read Iran's embassy EMAIL


    "I'm not going to call the president of Iran and tell him that I got access to all their embassies. I'm DEranged, not suicidal! He has bombs and stuff…"

    Could these email accounts be accessed globally and if yes why? For instance, could Uzbekistan's embassy in London successfully login into Uzbekistan's embassy in Moscow, and even worse, could a host not belonging to the embassy's network access these mailboxes for flexibility?

    So somebody has read all their emails, hmmm why would anyone want to do that?

    More, hat tip Dancho Danchev.

    Labels: , , ,

    Terrorist Names SEARCH:
    Loading

    Monday, July 30, 2007

    al Qaeda 's IT mentors/advisers in India


    al Qaeda 's IT mentors/advisers seem to be in India, we are monitoring 4 people.

    People of interest, in supporting al Qaeda's wana bee hackers.

    Current efforts involve tracking connections between these persons.

    And developing evidence and proofs. BREAKING...

    Gerald

    Labels: , , ,

    Terrorist Names SEARCH:
    Loading

    Saturday, June 23, 2007

    Rusty at mypetjawa does it again

    Rusty at mypetjawa does it again. http://mypetjawa.mu.nu
    In his war against terrorist sites he
    continues to bring sucessful pressure against the terrorist
    hosting services.

    His most recent involves the
    http://mypetjawa.mu.nu/archives/188231.php

    Seems again he is having some sucess:

    I have nothing to do with the CIPDTF - here we go again…

    As you can read from My Pet Jawa, Howie's Moisture Farm and The Dread Pundit Bluto, some stupid spammer has apparently taken upon himself to promote the increasingly dubious prose of the CIPDTF. As I am providing anonymous hosting services to the CIPDTF, I am as usually taking some heat for anything related to them. So once again I have some explaining to do. The few last times I had to do that chore the controversy involved mostly French speakers so I wrote my CIPDTF disclaimers in my French speaking blog. Now it seems that time has come to make things clear in English too…

    It is really a pity that I have to add another categorical denial to the already thickening pile, but here it is… Once again I want to make clear that I have never participated directly or indirectly in the content of the CIPDTF nor in any action aimed at promoting it by any means, especially the obnoxious and illegal ones.

    In the name of the freedom of speech that was under very strong pressure during the heights of the Ivorian civil war, I am providing free anonymous hosting services to an Ivorian collective. My contact with that collective goes through a person I know under the pseudonym "Jacques Koulibaly". I handle hosting services and that is all - I have nothing whatsoever to do with contents, nor with the actions of the CIPDTF or its sympathisers.

    With the Ivorian crisis settling down, maybe the time for the CIPDTF's radical, provocative and plain bizarre humor has passed. That is my opinion, but that is not my problem. The CIPDTF is becoming ever stranger, I believe that the quality of its publications has sharply declined and my problem is that I wish to make clear that I am not associated with the CIPDTF in any way.

    As you may know I am an extremely patient person and I will remain faithful to my past commitment to provide hosting unless unethical content appears on the site. But I am quite fed up with issuing disclaimers. So as a first step in making the demarcation of responsibilities more clear I have asked the CIPDTF to register their own domain name.

    In fact I asked them long ago, but I did not follow up. Lending a sub-domain to those impecuniary people was supposed to be a temporary measure but I let it go on way past its expiration date. So two weeks ago I gave them a deadline : register your own domain before the 14th July or I shall discontinue hosting your site. The recents events reported by the aforementioned blogs have only confirmed my determination on this matter.

    I hope that my position is now clearer for everyone involved. If you have any questions please do not hesitate to ask them here so that the debate can enlighten everyone.


    http://serendipity.ruwenzori.net/

    http://tinyurl.com/2egsfv

    Gerald

    Labels: , , ,

    Terrorist Names SEARCH:
    Loading

    Saturday, June 02, 2007

    Server in Iran compromised

    who??

    Server in Iran compromised.
    Who is launching the scan? Is it a random script kiddie or maybe a bot farm, using the Iranian server?
    A sophisticated attacker may actually use some simple "script kiddie" tools first, in order to hide out in the noise of bot probes. What computers are they taking over?
    And port 5900 (VNC) appears to be the main attack method.


    Discovered Targets: 1867
    First Reported: 2007-05-11
    Most Recent Report: 2007-05-02
    It is a "Ministry of Jahad" server....
    Whom is using this Iranian server?
    Whom are they attacking?
    How many more Iranian servers penetrated?

    Breaking:

    Gerald

    Labels: , , , ,

    Terrorist Names SEARCH:
    Loading

    Wednesday, May 23, 2007

    HACKERtrackers

    Terrorist Names SEARCH:
    Loading

    Sunday, May 20, 2007

    Hack3r Track3r vid

    Flektor: RULE YOUR MEDIA

    Labels: , , ,

    Terrorist Names SEARCH:
    Loading

    Wednesday, May 02, 2007

    EXCLUSIVE: Update:" Hack of Jihadist DOS program."

    From previous post:
    USA's MILITARY's CYBERFORCES STRAPPED

    My off the record sources told me James Manning from Earthlink Inc. could help me with this story.
    I showed this Email to James Manning, Senior Threat Analyst, EarthLink, Inc.

    Copy of email I recieved:

    start start start

    "On 4/28/07, XXXXXX wrote:........Private sector Sources have seen an exploit within the Hackers DOS programs allowing an authority to monitor and track the wanabe Jihadist hackers back to their nest right around their proxys.

    While the flaw doesn't allow access to root, it has lead to a collection of VERY interesting IP addresses,

    In the silver dos program the login authentication routine for the program does not properly sanitize entered information or the credentials that are transmitted, opening the MySQL database and PHP scripts to compromise, xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

    in turn putting all login data and ongoing user xxxxxxxxxxxxxxxxxx activity that the database stores opening it to the authority. Also the transmission of login data is not properly encoded or encrypted and someone xxxxxxxxxxxxxxxx using the proper packet sniffer captured login packets and stole and recorded the users login data.

    This means that an "authority" has captured this data and they have isolated the true location and have a record of them logging in and engaging in "terrorist activities".

    There is a fake email associated with this el_fatak@hotmail.com, which they are back tracking.

    A privacy vulnerability exists in the applications interaction xxxxxxxxxxxxxxx with the Windows firewall and how it authorizes itself for use. One of the methods is xxxxxxxxxxxx value to the ProxyEnable key in the registry xxxxxxxxxxx. If you are using a proxy for any purpose but especially for anonymity, the xxxxxxxxxxxxxxxxxxxxxxxxxx of this registry key will temporally disable your proxy and leave your raw IP visible.

    The ones that track back to Internet cafes, the security cams, available on the Internet are used to collect photos of the "terrorist hackers"

    The IP's have been collected and processed. Their is nothing the terrorists can do but wait for the knock.

    After analyzing that program and data someone worked with two pro-Muslim, Christian sites and just recently worked with the Radio Vatican site informing them of impending attacks and who and where the attackers are..

    .They monitor their program and activities then proactively notify and work with target sites to mitigate any potential outages and loss. Eventually they will take down the program distributors and users, PRISON or worse.

    The wanabe jihadist have exposed their entire network, IPs, passwords, Emails, even some photos. Just a matter of time. Nice work fascists hackers.

    They know about the exploit which is why membership is currently almost dead, and they go begging.

    MORE: turning the Snort 2.6.1 DCE/RPC flaw into a working exploit. http://www.securityfocus.com/bid/22616"

    end end end

    James while "on the RECORD " said: " he could confirm parts of it.", went off record, and refused to talk anymore about it on the record.

    Islamofacsists top hackers, known:

    croconile ( owner, programer, el_fatak@hotmail.com )
    some of his Hacking activity by Croconile: [Open in new window]
    "stoshhar" knows who he is too, he was showing off for him.


    الناصر العربى

    ابن مكة

    طلب

    ms

    engomar

    123

    شام الإسلام

    المظلوم

    عبدالقادر أبوعلي

    عبووود

    أحمد


    stealthbattle

    ibrahim_annahda

    ghost_212

    More BREAKING:

    GERALD

    Labels: , , , ,