Thursday, February 2, 2012

NASA, Pentagon Hacker TinKode Arrested in Romania



Police in Romania said they have nabbed the notorious hacker TinKode, who is known for breaking into U.S. government and military Web sites and exposing security shortfalls in their systems.

The accused hacker, Razvan Manole Cernaianu, accessed high profile computer systems without authorization, including those belonging to the Pentagon and NASA, then posted evidence of his attacks online, the Romanian Directorate for Investigating Organized Crime and Terrorism, said in a statement Tuesday. Cernaianu, a 20 year-old IT student from Timisoara, Romania, broke into servers belonging to the U.S. Army and stole confidential information, which he published on his blog, authorities said.
He also posted a video on his blog demonstrating an attack he carried out against the U.S. government, and created and offered for sale a computer program used to hack Web sites. Through his exploits, Cernaianu blocked access to systems and seriously disabled their proper functioning, authorities said.


Graham Cluley, senior technology consultant at security firm Sophos, said in a blog post Tuesday that TinKode often published information online about security flaws in the systems he hacked. The hacker was likely seeking bragging rights, rather than financial gains, Cluley added.

"In my estimation over the last few years TinKode's motivation has been more about mischief-making than the more malicious attacks we often see, fueled by a desire for publicity via his active Twitter and Facebook accounts," Cluley wrote. "Perhaps now is a good time to remind everyone who thinks it's cool or amusing to expose an organization’s weak security that hacking into a site is still a crime, regardless of what your incentive may be."

Romanian authorities said the FBI and NASA took part in the investigation. TinKode also previously claimed credit for an attack against the Web site for Britain's Royal Navy.







Source

Monday, January 30, 2012

Hacking Seen as Rising Risk With Car Electronics

Drivers can talk with each other via Bluetooth phone connections, ask their cars for directions and dial up satellite radio. The same cars use electronic components to signal the gas pedal to accelerate and control stability.
What increasingly worries scientists is that entertainment computers could be manipulated to tell the safety computers what to do.
“There clearly is a vulnerability,” said Adrian Lund, president of the Insurance Institute for Highway Safety, based in Arlington, Va. “All these electronics we’re bringing into cars seem to exacerbate that.”
A National Academy of Sciences panel, including Lund, elevated the concerns in a report Jan. 18 reviewing U.S. regulators’ work in finding the cause of unintended acceleration in Toyota Motor Corp. vehicles.
While safety and entertainment systems are intended to be separate, “it is not evident that this separation has been adequately designed for cybersecurity concerns,” the academy wrote. It agreed with U.S. regulators who said they found no evidence the Toyota incidents were caused by faulty electronics.
Automotive engineers at a conference in Washington last week said they aren’t immediately concerned that a hacker will take over a car and drive it off a bridge. Instead, they said, they want to help automakers spot vulnerabilities while they’re hypothetical and ease fears of consumers who are already familiar with cyberattacks in other areas.

Listening In

Car thieves could exploit security weaknesses to remotely open and start a car, or a spy could listen to conversations inside a car, Stefan Savage, a University of California-San Diego computer science professor, said in a telephone interview. He co-authored a paper last year after discovering ways to hack into cars.
Any electronic system in a car from brakes to radios is a potential target for hackers, said Andre Weimerskirch, chief executive officer of Escrypt, a closely held security company in Ann Arbor, Michigan, with automotive clients. While the risk is hypothetical so far, automakers and regulators need to address it now, he said in telephone interview.
“Once you have access through the infotainment system, the question is could a hacker get access to the safety-critical components,” Weimerskirch said.
Weimerskirch spoke last week in Washington at the annual conference of SAE International, a group of automotive engineers whose members are helping draft an industry standard for car electronics.

Fast-Moving Technology

Savage and co-author Tadayoshi Kohno, from the University of Washington, found vulnerabilities in telematics systems, which make the connections between cars and mobile communications. They also successfully inserted an infected CD into a car’s compact-disc player and directed it to control safety systems. They aren’t aware of any real-world examples of car hacking.
“The issue for the industry and for the government is that you’re one really bad situation away from it becoming a thing that people think about,” Savage said. “Much better to try to address it early.”
The U.S. National Highway Traffic Safety Administration, which regulates automotive safety, needs better expertise in vehicle electronics, the science panel’s report concluded after studying the agency’s response to the Toyota incidents.
“This technology is changing so fast that NHTSA needs to make sure they can keep up,” Lund said.

Standards, Research

NHTSA is researching auto cybersecurity, Lynda Tran, an agency spokeswoman, said in an e-mail.
“The agency recognizes there are potential vulnerabilities, especially those related to future connected vehicles, that need to be fully understood and addressed,” she said. “NHTSA has been conducting exploratory research and is now planning further efforts that would evaluate the vulnerabilities and possible counter-measures on an industrywide basis,” including more research and evaluation.
Both SAE and the United States Council for Automotive Research, whose members include General Motors Co. (GM), Ford Motor Co. (F) and Chrysler Group LLC, have groups working on engineering standards aimed at cybersecurity.
Unlike automotive standards that specify performance minimums, a security standard would have to specify what systems shouldn’t do, Savage said, such as not allowing a CD to send signals to the brakes. Improving electronic security in cars takes a combination of hardware, software and more personal expertise, he said.

Potential Sales

“The knowledge how to do it is known, but it’s not a market where you have off-the-shelf products,” Weimerskirch said.
The cost to automakers and their suppliers will depend on the model of car and level of desired protection, he said. It’s unlikely car companies will offer special security systems as an option because automakers wouldn’t want to imply that customers would need to buy something to protect their cars, Savage said.
“It sends the wrong message,” he said.
Coverity Inc., based in San Francisco, and Hewlett-Packard Co. (HPQ)’s Fortify unit are among the companies that may gain sales to manufacturers, Weimerskirch said. Computer security companies such as McAfee Inc., a unit of Intel Corp. (INTC), might also try to sell automotive-security products, he said. A spokesman for McAfee didn’t immediately respond to a phone call seeking comment.

Industry Has Time

Escrypt, which gets about 50 percent of its revenue from automotive work, hopes to profit as well, Weimerskirch said, declining to disclose which automakers employ the company.
The one comfort for automakers rushing to address cybersecurity concerns may be that it takes a great deal of effort to hack a car, Savage said. He worked with a team on his research for more than a year.
“The average person, they’re much more likely to get their car stolen in the traditional way and the average person is not concerned about somebody bugging their car,” he said. “That’s a big advantage that the industry has and it gives them time.”


Source

Sunday, February 14, 2010

TCS site hacked; domain name put up for sale

9th Feb 2010.

MUMBAI/KOLKATA: India’s biggest software exporter Tata Consultancy Services (TCS) became a victim of cyber attack on Sunday, after the company’s
website was hacked and the domain name was put up for sale.

While in the recent past, hackers have attacked top government websites, including telecom regulator’s trai.gov.in, this is the first time a large IT company’s website has been hacked.

The company’s official website www.tcs.com displayed the message ‘this domain name is for sale’ for nearly three hours, before the portal was restored by around 7 am.

When contacted by ET, a TCS spokesman said the attacks happened at the domain name registrar’s end, which is Network Solutions in this case. Network Solutions is one of the top five domain name registrars on internet, managing almost 6.4 million domains.

Source

Saturday, April 18, 2009

LHC restart gets reset to June 2009

_45214859_hadron466pa
The £5bn Large Hadron Collider (LHC) is intended to smash protons - one of the building blocks of matter - into each other.

The world's most powerful particle accelerator will go live again in June 2009 at the earliest, after a shutdown in September 2008. The European Organization for Nuclear Research (CERN) thought it would only be out of action until November but the damage was worse than expected. CERN also said that repairing the Large Hadron Collider (LHC) will cost up to €16.6 million or US$21 million.

The European Organization for Nuclear Research (CERN), which runs the Large Hadron Collider, previously suggested that the apparatus would be restarted in April 2009, following maintenance. However, it emerged that June would be the earliest possible date for operations to resume fully.

The LHC is housed in a 17-mile-long circular tunnel nestled beneath the Swiss-French border in the Alps. It is designed to shoot streams of particles around the tunnel in opposing directions, smashing them into each other and thereby hopefully discovering more about the origin and nature of matter and the universe.

The particle beams are held on their paths by dipole magnets and focused by quadrupole magnets. These magnets are made of a superconducting material that needs to be cooled by liquid helium to a temperature of 1.9 kelvins (3.4 degrees Fahrenheit), if it is to avoid overheating and exploding.

The LHC was successfully turned on in September 2008, but little more than a week later, an electrical fault caused a helium leak that necessitated the complete shutdown of the machine.



This week, details began to emerge about the cost of the necessary repairs and the likely resumption date for the LHC. Repair time aside, the process will also be slowed down by the fact that the LHC needs to be out of service throughout winter; as it uses a tremendous amount of electricity, CERN cannot risk power issues at a time when citizens' homes need to be heated.

"We already said the bare minimum (repair time) included two months to warm up the sector (from its cryogenic state)," a CERN representative. "It became clear that there was no way of doing that before we shut down the accelerator complex for winter, anyway, so that puts the earliest possible date (for the refreezing of the LHC to start) in May. When we start up our accelerator complex, getting it up and running again takes a few weeks, so that takes you into June 2009."

CERN said the glitch and resulting shutdown had been educational, as "markers" had been identified that show when such an incident is likely to occur.

"Those markers would have allowed us to stop (the LHC before the helium leak), had we known where to look," the representative said. "We're building in additional monitoring and protection systems to make sure this kind of incident won't happen again, and this will take time."


"We expect that the repairs and the (installation of additional monitoring systems) will cost us between 10 million and 20 million Swiss francs ($8.4 million to $16.8 million)," CERN's spokesperson said. However, because the repairs will eat into CERN's supply of spare parts for the LHC, a second phase of the resumption operation will involve buying more spares, thereby raising the total costs further.

The costs for repairing the LHC and buying new spares would be "accommodated within CERN's annual budget," the spokesperson said, and the organization would not be requesting additional funds from European member states for those purposes.

Fundamental questions

The LHC was built to smash protons together at huge speeds, recreating conditions moments after the Big Bang, and scientists hope it will shed light on fundamental questions in physics.

The fault occurred just nine days after it was turned on with Cern blaming the shutdown on the failure of a single, badly soldered electrical connection in one of its super-cooled magnet sections.



The collider operates at temperatures colder than outer space for maximum efficiency and experts needed to gradually warm the damaged section to assess it.

"Now the sector is warm so they are able to go in and physically look at each of the interconnections," Mr Gillies told Associated Press.

The cost of the work will fall within the Cern's existing budget.

Dr Lyn Evans, the Welsh-born project director has called the collider "a discovery machine, the most sophisticated scientific instrument of our time."

Thursday, March 26, 2009

Wireless Power

Suntower


Physicist Marin Soljacic is working toward a world of wireless electricity.

In the late 19th century, the realization that electricity could be coaxed to light up a bulb prompted a mad dash to determine the best way to distribute it. At the head of the pack was inventor Nikola Tesla, who had a grand scheme to beam elec­tricity around the world. Having difficulty imagining a vast infrastructure of wires extending into every city, building, and room, Tesla figured that wireless was the way to go. He drew up plans for a tower, about 57 meters tall, that he claimed would transmit power to points kilometers away, and even started to build one on Long Island. Though his team did some tests, funding ran out before the tower was completed. The promise of airborne power faded rapidly as the industrial world proved willing to wire up.

Then, a few years ago, Marin Soljačić, an assistant professor of physics at MIT, was dragged out of bed by the insistent beeping of a cell phone. "This one didn't want to stop until you plugged it in for charging," says Soljačić. In his exhausted state, he wished the phone would just begin charging itself as soon as it was brought into the house.

So Soljačić started searching for ways to transmit power wirelessly. Instead of pursuing a long-distance scheme like Tesla's, he decided to look for midrange power transmission methods that could charge--or even power--portabl­e devices such as cell phones, PDAs, and laptops. He considered using radio waves, which effectively send information through the air, but found that most of their energy would be lost in space. More-targeted methods like lasers require a clear line of sight--and could have harmful effects on anything in their way. So Soljačić sought a method that was both efficient--able to directly power receivers without dissipating energy to the surrounding­s--and safe.

He eventually landed on the phenome­non of resonant coupling, in which two objects tuned to the same frequency exchange energy strongly but interact only weakly with other objects. A classic example is a set of wine glasses, each filled to a different level so that it vibrates at a different sound frequency. If a singer hits a pitch that matches the frequency of one glass, the glass might absorb so much acoustic energy that it will shatter; the other glasses remain unaffected.

Soljačić found magnetic resonance a promising means of electricity transfer because magnetic fields travel freely through air yet have little effect on the environment or, at the appropriate frequencies, on living beings. Working with MIT physics professors John Joannopoulos and Peter Fisher and three students, he devised a simple setup that wirelessly powered a 60-watt light bulb.

The researchers built two resonant copper coils and hung them from the ceiling, about two meters apart. When they plugged one coil into the wall, alternating current flowed through it, creating a magnetic field. The second coil, tuned to the same frequency and hooked to a light bulb, reso­nated with the magnetic field, generating an electric current that lit up the bulb--even with a thin wall between the coils.

So far, the most effective setup consists of 60-centimeter copper coils and a 10-megahertz magnetic field; this transfers power over a distance of two meters with about 50 percent efficiency. The team is looking at silver and other materials to decrease coil size and boost efficiency. "While ideally it would be nice to have efficiencies at 100 percent, realistically, 70 to 80 percent could be possible for a typical application," says Soljačić.



Wireless Light

Marin Soljačić and colleagues used magnetic resonance coupling to power a 60-watt light bulb. Tuned to the same frequency, two 60-centimeter copper coils can transmit electricity over a distance of two meters, through the air and around an obstacle.

1. Resonant copper coil attached to frequency converter and plugged into outlet
2. Wall outlet
3. Obstacle
4. Resonant copper coil attached to light bulb

Other means of recharging batteries without cords are emerging. Startups such as Powercast, Fulton Innovation, and WildCharge have begun marketing adapters and pads that allow consumers to wirelessly recharge cell phones, MP3 players, and other devices at home or, in some cases, in the car. But Soljačić's technique differs from these approaches in that it might one day enable devices to recharge automatically, without the use of pads, whenever they come within range of a wireless transmitter.

The MIT work has attracted the attention of consumer-electronics companies and the auto industry. The U.S. Department of Defense, which is funding the research, hopes it will also give soldiers a way to automatically recharge batteries. However, Soljačić remains tight-lipped about possible industry collaborations.

"In today's battery-operated world, there are so many potential applications where this might be useful," he says. "It's a powerful concept."

Wednesday, March 25, 2009

Intel Releases Draft USB 3.0 Spec

usb-3_0

Intel has released part of the draft specification for USB 3.0, a move that could speed up the release of the next-generation data transfer standard.

The Extensible Host Controller Interface (xHCI) draft specification revision 0.9 is available under royalty free licensing terms to all USB 3.0 Promoter Group members, and AMD, Dell, Microsoft and NEC were among those to back the move, according to Intel.

USB 3.0 -- also known as SuperSpeed USB -- is expected to enable transfer speeds of up to 4.8Gbps, a significant leap from the 480Mbps supported by the current USB 2.0 spec.



"The future of computing and consumer devices is increasingly visual and bandwidth intensive," said Phil Eisler, corporate vice president at Intel rival AMD.

"Lifestyles filled with [high-definition] media and digital audio demand quick and universal data transfer. USB 3.0 is an answer to the future bandwidth need of the PC platform. AMD believes strongly in open industry standards, and therefore is supporting a common xHCI specification."

Intel said it expects to release a revised xHCI 0.95 specification in the fourth quarter, and the technology should become widely available in 2010.

usb3

The chip giant announced plans to release more details on the USB 3.0 spec earlier this year.

In June, Intel spokesman Nick Knupffer said on his blog: "The sooner USB 3.0 hits the market, the sooner all you readers will be flooding your devices and hard drives with insanely large files requiring masses amounts of computational resources, improving your lives, and making you pleased that you bought a quad-core processor."

Source

Hacking with a Pringles tube

_1860241_pringle-isec300
A crisp can is an effective tool for curious hackers

Empty cans of Pringles crisps could be helping malicious hackers spot wireless networks that are open to attack.

Security company i-sec has demonstrated that a directional antenna made with a Pringles can significantly improves the chances of finding the wireless computer networks being used in London's financial district.

An informal survey carried out by i-sec using the homemade antenna has found that over two-thirds of networks were doing nothing to protect themselves.

The security firm said all the companies at risk could easily thwart anyone that wanted to find and penetrate their network by making a few simple changes to the hardware used to build the wireless networks.

Hack here

In November last year BBC News Online was shown just how easy it is to find and gain information about wireless networks.

These networks are rapidly becoming popular because they are cheap, easy to set up and replace the unsightly cables that many companies have used to link PCs together into networks.

But the convenience of using radio waves to transfer data between machines is not without its risks.

Many curious hackers have started carrying out so-called war-driving expeditions.

US security expert Peter Shipley invented the practice. It involves driving around an area using a laptop fitted with a wireless network card to find and map out the networks.

Crisp signal

_36202803_pringles150
Pringles tube works as an antenna

Wireless, or WiFi, networks have an encryption system built in, but it is not turned on when the basic hardware of the network is set up.

"People have made these antenna out of Pringles tubes, coffee cans and even old satellite dishes"
Geoff Davis, i-sec


Geoff Davies, managing director of i-sec, said its informal survey revealed that 67% of the networks it found had this encryption system turned off.

"Many companies are going out and buying a wireless access point to see what it can do," said Mr Davies. "The problem is that they have opened a great big back door into their network."

He said that i-sec had boosted the chance of spotting networks by converting an empty can of Pringles into a directional, or Yagi, antenna. Plans to make such an antenna first appeared on the net last year.

Properly made, such an antenna can boost signal strengths by up to 15 decibels, vastly aiding the discovery of wireless networks.

Potential for havoc

In one 30-minute journey using the Pringles can antenna, witnessed by BBC News Online, i-sec managed to find almost 60 wireless networks.

"Those doing [war-driving] are not necessarily looking to take down corporate networks, they are looking to use corporate bandwidth," said Mr Davies.

"But if they are doing that then someone with more nefarious purpose could wreak havoc."

Mr Davies said that a few basic steps such as changing default names, moving wireless access points to the centre of a building and switching off the networks' broadcast functions could help significantly improve the security of these systems.