Tuesday, 12 March 2019

Cyber Security - Famous Hackers

Cyber Security - Famous Hackers

Jonathan James

          Jonathan James was an American hacker, known as the first juvenile sent to prison for cyber crime in United States. He was born on December 12, 1983. He enjoyed using computers since he was 6 years old. When he was in high school, he used to delete Windows from his home computer to install Linux on it. In 1999, Jonathan at the age of 15 managed to break NASA security and accessed 13 computers. With these computers he had stolen software and information worth $ 1.7 million. It causes  a 21-day shutdown of NASA computers that supports the international space station. This cost them $ 41,000 in repairs and losses. Jonathan was known on the internet as “C0mrade”.

           Later it would be discovered that ‘C0mrade’ stolen the source code that controlled critical elements of survival within the International Space Station. According to NASA, this software helps to control temperature and humidity within the ISS, as well as some other important elements of the physical environment. Because of the above, NASA made the decision to turn off everything and rewrite part of the source code, to reinforce the security of their software. Since he was under 18, sent to Alabama Juvenile Correctional Center for a period of 6 months. By August 1999, he breached the systems of the telecommunications company BellSouth, the Marshall Space Flight Center in Huntsville, Alabama, and the Miami-Dade school system. Later, intruded into Department of Defense of the United States in the Pentagon. He become the first person in the world to crack the DOD by entering the Defense Threat Reduction Agency (DTRA) system. He found a backdoor on one of the servers, where he installed a sniffer that allowed him to spy on thousands of calls and messages that allowed him to obtain usernames and passwords that gave him access to 10 military computers.
               On January 17, 2007, one of the largest computer attacks in the United States were released. It was initiated by Albert Gonzalez. During the investigations, the names of several hackers who would have collaborated with González, were related with Jonathan James. Even his family member can’t find a connection or clues to Jonathan’s collaboration in the attack. On May 18, 2008, Jonathan, 25, was found dead in his house with a self-inflicted gunshot wound on the head. Jonathan wrote in his suicide note, "I have no faith in the 'justice' system. I honestly, honestly had nothing to do with TJX. Perhaps my actions today, and this letter, will send a stronger message to the public. Either way, I have lost control over this situation, and this is my only way to regain control."

Albert Gonzalez                                                 

                 Albert Gonzalez is an American  hacker and a cyber criminal who is accused for the theft of credit and ATM card numbers with a group of hackers named as ShadowCrew group. Around 4,000 people were registered with the Shadowcrew.com website. Once registered, they could buy stolen account numbers and other objects of identity theft like passports, drivers’ licenses, Social Security cards, credit cards, debit cards, birth certificates, college student identification cards, and health insurance cards. The investigators believed that up to $4.3 million was stolen credit /debit card numbers, as ShadowCrew shared its information with other groups like Carderplanet and Darkprofits. Later, he hacked TJX Companies, in which 45.6 million credit and debit card numbers were stolen over an 18-month period ending in 2007, which is greater than 2005 breach of 40 million records at CardSystems Solutions. He was known as “soupnazi” in the internet which became a secret service informant after he was arrested for hacking.

             In September 2007, About 5,000 card numbers were stolen. Fraudulent transactions of $600,000 were reported on 675 of the cards in total. Gonzalez was arrested on May 7, 2008 in room 1508 at the National Hotel in Miami Beach, Florida. The authorities seized $1.6 million in cash including $1.1 million buried in plastic bags in a three-foot drum in his parents' backyard, his laptops and a compact Glock pistol. In addition to this cash, they seized Gonzalez's Miami condominium, a BMW car, a Glock 27 firearm, a currency counter, a Tiffany diamond ring given to his former fiance and three Rolex watches that Gonzalez gave to his father and others as gifts. He was taken to the Metropolitan Detention Center in Brooklyn, where he started heartland payment system hack. In Heartland attack, 130 million card numbers were stolen. Around $12.6 million is lost in the attack including legal fees. Gonzalez named the scheme as “Operation Get Rich or Die Tryin”. Using SQL injection, this famous hacker and his team created backdoors in several corporate networks and stole an estimated $256 million from TJX alone. The 20 years of prison for the largest computer-crime till date in United States for hacking or identity-theft. Gonzalez was also fined $25,000. Later, he regrets his crime and said “I blame nobody but myself”. He helped US government to find other hackers.
           According to the New York Daily News, Gonzalez, dubbed "soupnazi," got his start as the "troubled pack leader of computer nerds" at his Miami high school. He eventually became active on criminal commerce site Shadowcrew.com and was considered one of its best hackers and moderators. At 22, Gonzalez was arrested in New York for debit card fraud related to stealing data from millions of card accounts. To avoid jail time, he became an informant for the Secret Service, ultimately helping indict dozens of Shadowcrew members.
              During his time as a paid informant, Gonzalez, along with a group of accomplices, continued his criminal activities and stole more than 180 million payment card accounts from companies including OfficeMax, Dave and Buster's and Boston Market. The New York Times Magazine notes that Gonzalez's 2005 attack on US retailer TJX was the first serial data breach of credit information. Using SQL injection, this famous hacker and his team created back doors in several corporate networks and stole an estimated $256 million from TJX alone. During his sentencing in 2015, the federal prosecutor called Gonzalez's human victimization "unparalleled."

Thursday, 21 February 2019

Hacking - Types of Hackers


        
Welcome back to yet another post on Cyber Security Hacking-Types of Hacking . In the last post we read about Cyber Security - Elements Overview. If you did not come across that post yet please https://creocyber.blogspot.com/2019/02/cyber-security-elements.html to read that.

          Hacking is an attempt of finding and exploiting a weakness in a system or in a network to gain unauthorized access to data and system resources. It can also refer to non-malicious activities or unauthorized intrusion into the information systems/networks by compromising the security. The person who engaged in hacking activities is known as a hacker.


Types of Hackers

          Hackers can be of different categories such as white hat, black hat and grey hat, based on their intent of hacking a system. These different terms come from old Spaghetti Westerns, where the bad guy wears a black cowboy hat and a good guy wears a white hat.


White Hat Hackers


          White Hat Hackers, also known as Ethical Hackers are the cyber security experts who helps the Government Organizations by performing penetration testing and identifying loopholes in a system or a network. They never intent to harm a system or a network, rather they try to find vulnerabilities in a computer or a network as a part of penetration testing and vulnerability assessments and help you to remove virus and malware from your system.
       Ethical Hacking is legal and it is one of the demanding jobs in the IT industry. There are numerous companies that hire ethical hackers for penetration testing and vulnerability assessments.


Black Hat Hackers


           Black Hat Hackers , also known as a cracker, are those who you should be worried off. They hack your computer in order to gain unauthorized access to a system and harm its operations or steal sensitive information. These hackers look for vulnerabilities in victim PCs, organizations or bank systems. Using some loopholes they may hack into your network and get access to your personal, business and financial information.
            Black Hat Hacking is illegal because of its bad intent which includes stealing corporate data, violating privacy, damaging the systems, blocking network communication, etc.


Grey Hat Hackers


            Grey Hat Hackers are a combination of both black hat and white hat hackers. They exploit a security weakness in a computer system or a network without the owner’s permission or knowledge for their fun, not for malicious intent.
        Their main intention is to bring the weakness to the attention of the owners and getting appreciation or a little bounty from  the owners.


Miscellaneous Hackers


         Apart from the above well-known classes of hackers, we have the following categories of hackers based on what they hack and how they do it –


Red Hat Hackers    

     

          Red Hat Hackers are again a combination of both black hat and white hat hackers. They are hacking Government agencies, top-secret information hubs, and generally anything that falls under the category of sensitive information. They launch a series of cyber attacks and malware to crash the whole system.


Script Kiddies                

        

           A Script Kiddie is a non-expert who breaks into computer or network by using automated tools developed by others, usually with little understanding of the underlying concept, hence the term Kiddie. They perform hacking to gain attention or to impress their friends. The attacks by script kiddies might result in DoS/DDoS attacks.


Blue Hat Hackers  


           A Blue Hat Hackers are a person outside computer security consulting firm. They used to bug-test a system prior to its launch. They look for loopholes that can be exploited and try to close these gaps. Microsoft also uses the term BlueHat to represent a series of security briefing events. Blue hat hackers are similar to script kiddie whose aim is to take revenge on someone who makes them angry. They may  use simple cyber attacks like flooding your IP with overloaded packets which will result in DoS.


Elite Hackers    


           Elite Hacker is the term utilized by the community in identifying those individuals who are deemed to be as experts in their line of work. These people are the “cutting edge” of both the computer and network industry. Newly discovered exploits will circulate among these hackers.
              Elites are commonly recognized as the “innovators” or those who took part in the primal years of hacking with utmost skillset.


Neophyte   


        A neophyte, is a person who is new to hacking or phreaking and with no knowledge or experience of the workings of technology and hacking. These hackers are also known as noob, or newbie or Green Hat Hackers. These Green Hat Hackers have a desire to become full-blown hackers and they are very curious to learn new things. They can be identified by their spark to grow and learn more about the hacking trade.


Hacktivist    

                         

          A hacker who utilizes technology to announce a social, ideological, religious, or political message is known as Hacktivist. In general, hacktivist is an online version of an activist which involves website defacement or denial of service attacks. They think that they can bring about social changes and often hack government and organizations to gain attention or share their displeasure over opposing their line of thought.


Monday, 11 February 2019

Cyber Security - Elements


Welcome back to yet another post on Cyber Security – Elements Overview. In the last post we read about Cyber Security History. If you did not come across that post yet please click to the link https://creocyber.blogspot.com/2019/02/cyber-security-history-explained.html to read that.

What are the Elements of Computer Security?
The computer security can able to detect and prevent attacks and it can recover. If the data or information is breached or any disruption occurs then there comes the concept of computer security.
The three main elements of computer security are
·         Confidentiality
·         Integrity
·         Availability

Confidentiality

Confidentiality is protecting your private information from being accessed by unauthorized users. It can be ensured by using role-based security techniques to ensure user or viewer authorization (data access levels may be assigned to a specific department) or access controls that ensure user actions which remains within their roles (for example, define user to read but not write data).

Example in real life: When two people are communicating with one another via an encrypted email. The two people should know their decryption keys of each other and they can read the email by entering decryption keys into the email program. Here, there is a chance for an intruder  to know decryption keys, by this confidentiality of that email reduces.

Integrity

       Integrity ensures that stored data are accurate and contain no unauthorized modifications. Generally, Integrity is composed of two sub-elements they are
·     Data-integrity: There should not be any modification to the content of the data.
·  Authentication: It is a security measure designed to establish the validity of a transmission or message for verifying an individual’s authorization to receive specific categories of information. Authenticity involves checking the credentials of the users who is going to transact with the system. A better form of authenticity is biometrics, because it depends on the user’s physical and biological features. The PKI (Public Key Infrastructure) authentication method uses digital certificates to prove user identity.

Example in real life: In an Online Banking, if it is possible to modify a fund transfer message passing between you and your banking website. The attacker may hijack the transfer and steal the  funds by altering the account number of the recipient of the funds and redirect it into attacker’s own bank account number. Ensuring the integrity of this type of messages is vital to any security system.

Availability

Availability refers to the ability to access information or resources whenever needed in a specified location and in the correct format. When a computer system cannot deliver information efficiently, then availability is compromised. Data availability can be ensured by its storage.Nowadays denying access to the data has become a common attack. Non-repudiation means that the parties involved in a transaction cannot deny their role with data transmission or reception.

Example in real life: When you want to send money through e-banking, but it is impossible to access it because the hacker has compromised a web server of a bank and put it down. 




Tuesday, 5 February 2019

Cyber Security - History Explained


Welcome to my new post on the Cyber Security - History Explained

What is Cyber Security?

            Computer Security is commonly known as Cyber Security. Cyber Security is a process of detecting and preventing any unauthorized use of your Internet connected systems, including hardware, software and your personal data. It can recover the device, network or a source code from any kind of Cyberattack. Cyberattacks are an evolving danger to the organization, employees, and customers. It may be designed to access or destroy sensitive data or to extort money. They can even destroy businesses and damage people’s lives. It is designed to maintain the confidentiality, integrity and availability of the data. Cybersecurity strategies may include identity management, risk management and incident management.


What is Cyberspace?

            Cyberspace is a worldwide network of computers and the equipment that helps to connect them through an electronic medium. It forms a global computer network to facilitate online communications. Its design is free and open to the public. Cyberspace is becoming a dangerous place for all organizations or an individual to protect their data. It allows users to share information, interact, swap ideas, play games, engage in discussions or social forums, conduct business and create intuitive media, among many other activities. In 1984, the term cyberspace was introduced by William Gibson in his book, “Neuromancer.” Cyberspace's core feature is an interactive and virtual environment for a broad range of participants.

History of Cyber Security

The history  of cyber security started with a research project. Bob Thomas is the one who realized that it is possible for a computer program to move across a network, leaving a small trial wherever it goes. Bob designed a program named Creeper, it can able to travel between Tenex terminals on the early ARPANET, printing the message “I’m The Creeper: Catch Me If You Can”. Later, Ray Tomlinson the one who invented email saw bob’s idea. He modified the program and made it self-replicating, which is the first worm. Again he came up with another program named Reaper, the first antivirus software which would chase Creeper and delete it.

In late 1988, Robert Morris came up with an idea that he wanted to gauge the size of the internet. To do this, he wrote a code designed to propagate across networks, infiltrate Unix terminals with a known bug, and then copy itself. Robert Morris became the first person successfully charged under the Computer Fraud and Abuse Act. This act leads to the formation of the Computer Emergency Response Team, which functions as a nonprofit research center for systemic issues that might affect the internet as a whole.

Morris worm is the start of everything. After the Morris worm, viruses started getting deadlier and deadlier, affecting more and more systems. Then there is a rise of Antivirus as a commodity. In 1989,   the first dedicated antivirus company was released. Later, the worm took advantage of the sendmail function in Unix, which was originally created by Ray Tomlinson. In other words, the world’s first famous virus took at advantage of the first virus author’s most famous creation.

It’s interesting to look back from where we are now, in an era of ransomware, fileless malware, and nation-state attacks.

Why Cyber Security is needed?

The use of Cyber Security can help prevent Cyberattacks, data breaches and identity theft and can aid in risk management. When an organization has a depth knowledge of network security and an effective incident response plan, it is better able to prevent and mitigate these attacks. For example, end user protection defends information, and it can guard against loss or theft while scanning computers for malicious code.

Nowadays advisory organizations are promoting a proactive and adaptive approach. The National Institute of Standards and Technology issued updated guidelines in its risk assessment framework  for continuous monitoring and real-time assessments. US president Donald Trump issued an executive order mandating that federal agencies adopt the NIST Cyber Security Framework (NIST CSF) in May 2017. Version 1.1 of the framework for Improving Critical Infrastructure was released in April 2018.

Cyber Security - Famous Hackers

Cyber Security - Famous Hackers Jonathan James           Jonathan James was an American hacker, known as the first juvenile sent to ...