In Through The Out Door

    Diving Through The Information Barrage

    Browsing Posts published in January, 2009

    Run Rabbit Run

    No comments

    Yes, the best analogy I have seen to date was presented by Justice Little, where he used rabbits running around a tree to describe monetary velocity, which is quite stagnant right now and the reason the Treasury and Fed are printing money left and right. here is how he describes it http://flmortgagereport.com/?p=1019

    cast-lead3.jpg

    A fairly active cyber militia within Israel wants you! These cyber activists (Help Israel Win) are actively recruiting pro-Israeli computer users to aide in their cyber attacks against Hamas websites. These efforts appear to date back to the very early days of the latest conflict in Gaza. The militia developed and is distributing a cyber weapon called “Patriot” that once installed turns the volunteer computer to be remotely controlled and used in a Distributed Denial of Service (DDoS) attack against targeted Hamas websites.

    As of late last week, the cyber militia said there were about 8,000 downloads of the cyber weapon. This is not just a hack package. The software includes the ability to remotely update the cyber weapon as well as an uninstaller that will remove the program once the conflict has ended.

    This is just one aspect of the growing cyber war. The DDoS coupled with a significant propaganda (PSYOPS) offensive has continued to intensify in the Israel/Gaza conflict. PSYOPS is commonly used to induce and/or reinforce attitudes and behaviors favorable to the desired objectives of those launching the psychological operations. There have been reports that the Israeli military is also using the good old phone system in their PSYOPS initiatives. There have been multiple reports that Palestinians have been receiving phone calls from the Israeli army warning them against dealing with or assisting Hamas. Numerous reports of web site defacement have echoed throughout the online world for weeks now. In fact, the Israeli military launched its own PSYOPS and became the first national army to set up an official YouTube channel featuring its own military videos.

    This is just the latest indicator of the new hybrid conflict engagement that combines bombs and bullets with bits and bytes. One thing is sure; the cyber war is heating up with multiple other countries getting involved.

    A cautionary note. Can someone else use the installed Patriot program? Yes – potentially. That being said, millions of computers have the same issue that are part of BotNets and the owners are totally unaware of that fact. Anyone who grants any type of remote access for maintenance, this type of activism or who knows what are placing themselves at risk.

    [From Israel's Looking for a Few Good Cybermen]

    Great entry in today’s SANS Internet Storm Center Handler’s Diary — How to suck at Information Security. Some of my favorite points include: ‘Assume the users will read the security policy because you’ve asked them to. Assume that policies don’t apply to executives. Make someone responsible for managing risk, but don’t give the person any power to make decisions. Expect end-users to forgo convenience in place of security. Hire somebody just because he or she has a lot of certifications. Expect your users to remember passwords without writing them down.’ Very entertaining and informative read with total of about 4 dozen points. Now if I could only find a way to get management to read it.

    [From How To Suck At Information Security ]

    Shutting down zero-day computer attacks could be carried out inexpensively by peer-to-peer software that shares information about anomalous behavior, say researchers at the University of California at Davis.The software would interact with existing personal firewalls and intrusion detection systems to gather data about anomalous behavior, says Senthil Cheetancheri, the lead researcher on the project he undertook as a grad student at UC Davis from 2004 to 2007. He now works for SonicWall.

    [From A Cheap, Distributed Zero-Day Defense? ]

    Cyber Espionage Targets Sensitive Data

    Bad Behavior has blocked 61 access attempts in the last 7 days.