Showing posts with label SECURITY NEWS. Show all posts
Showing posts with label SECURITY NEWS. Show all posts

Friday, June 25, 2010

A to Z of online piracy

LONDON, England (CNN) -- If mention of The Pirate Bay conjures up images of parrots, peg legs and planks, or geeky jargon like BitTorrent and jailbreak leaves you all at sea, this handy A-Z will help you navigate the choppy waters of the online piracy debate.

"X-Men Origins: Wolverine," starring Hugh Jackman, was downloaded over a million times after being leaked in early April.

"X-Men Origins: Wolverine," starring Hugh Jackman, was downloaded over a million times after being leaked in early April.

The Screening Room's indispensable lexicon of online piracy will teach you cracking from key generators: You'll never again be caught out wondering how "X-Men Origins: Wolverine" fits into warez.



A is for anti-piracy
Efforts to prevent the illegal transfer and use of copyrighted material -- often spearheaded by corporate associations like the Motion Picture Association of America (MPAA) -- using a variety of digital rights management (DRM) tools like encryption, product keys and serial numbers. Technologically often a step or two behind the pirates, the entertainment industry will sue for breach of copyright.

B is for Bill Gates
As early as 1976, Gates wrote an open letter saying that software piracy could be a problem. Ironically, he has since said that Microsoft actually benefited from piracy in China, where over 90 percent of computers use Windows, most copies of which are pirated. The widespread use of Microsoft's operating system has enabled the software giant to gain pole position in the fast-growing market.

C is for cracking
Modifying software to remove copy protection -- one of the technologies companies use to prevent unauthorized reproduction of media -- to enable the illegal duplication and proliferation of pirated material on disks and online. Mostly done by hackers, not usually for money but to gain respect within the hacker community.

D is for digital rights management (DRM)
Access-control technologies used by manufacturers. Most pirating technology is created to circumvent various types of DRM in order to share copyrighted material online. Apple rid its iTunes library of DRM in early April, but is charging users 30 cents per song to upgrade to DRM-free tracks.

E is for encryption
Originally used by militaries to protect secret message transmissions, encryption allows a user to transform and "lock" information that, upon transfer, can only be opened by a person who has the right "key." Encryption software is one of many anti-piracy measures designed to prevent the spread of copying and transferring copyrighted material.

F is for Free Culture movement
Led by Harvard law professor Lawrence Lessig, the movement believes restrictive copyright laws are strangling humanity's creativity. Under Lessig's "Creative Commons" organization, the movement is advocating for the free copying and modification of creative works -- and rejecting what they perceive to be the culturally oppressive "permission culture" of copyright and intellectual property.

G is for Global Software Piracy
This report by the Business Software Alliance suggested that 35 percent of software installed on PCs worldwide in 2006 was pirated.

H is for hackers
Hackers "wiped," or erased, all the data from the Recording Industry Association of America's (RIAA) Web site in 2008. The incident, which exposed serious flaws in the RIAA's web security, was an embarrassment for the group, which represents the recording industry of the United States.

I is for International Federation of the Phonographic Industry (IFPI)

According to the IFPI's 2008 Digital Music Report, up to 80 percent of data traffic via Internet service providers (ISPs) is involved in the illegal transfer of pirated material.

J is for jailbreak
Mostly commonly associated with the iPhone, it is the practice of downloading illicit software designed to bypass digital rights management, allowing people to upload pirated versions of official iPhone applications for free and use them on their phones.

K is for key generators
Small programs found on pirate sites that allow users to crack open key-locked software like Microsoft Office or Adobe Photoshop by generating valid serial numbers for pirated copies of software that would otherwise only be included with legitimately purchased copies.

L is for Limewire
One of the oldest and most popular peer-to-peer (P2P) file sharing clients, Limewire is a free program used to search for and download pirated content. The program has been accused of having massive security gaps and an abundance of "malware" files, which contain computer viruses that infect users' computers upon completion of a download.

M is for Metallica
The first major band to sue for online music piracy in 2000, Metallica sued file-sharing service, Napster and three U.S. universities for enabling illegal downloading of copyrighted content. The case, which saw the rock group harshly criticized by many of its fans, was eventually settled out of court when Napster agreed to block illegal downloads of the band's songs.

N is for Napster
Online music-sharing service created by a college student in Boston in 1999, which spearheaded the widespread illegal copying and transferring of MP3 music files. A judge shut down the service in 2001. Napster has since relaunched as a legitimate monthly subscription music site.

O is for organized crime
International recording industry organization, IFPI and Interpol say there are links between online piracy and organized crime and terrorism, citing examples from South America to South Africa and Eastern Europe to East Asia.

P is for P2P
More than 20 times as much music is exchanged on peer-to-peer networks as is legally purchased, the Economist magazine wrote in 2008. BitTorrent is a growing P2P technology that allows the rapid downloading of large, multi-gigabyte files.

Q is for quality
According to a survey by the auditor Ernst and Young in India, 66 percent of people believe pirated content is of an inferior quality to the original, but 89 percent say they've used pirated music or films anyway.

R is for R4 card
A $30 Nintendo DS cartridge that can be loaded with hundreds of free, pirated Nintendo games, the R4 card is cheaper than the store price of many single authentic games.

S is for Sweden
Prosecutors in the country filed suit against The Pirate Bay Web site earlier this year for "promoting other people's infringement of copyright laws." Dubbed the "Internet piracy trial of the decade" by UK newspaper The Times, the verdict against the site will have massive implications for the future of online file-sharing, but The Pirate Bay's founders plan to appeal and have previously said that the site will stay up and running.

T is for The Pirate Bay
A very popular file-sharing Web site primarily used as a linking site to find and download pirated movies, music, video games, applications and more. It tracks BitTorrents -- file sharing protocols that enable big, fast file transfers. The Pirate Bay's founders have constantly argued that the Web site does not violate copyright law because the site does not host any copyrighted material, but simply provides a service by indexing the BitTorrents.

U is for Usenet.com

Regarded as a source of much pirated material, this bulletin board site is being sued by the RIAA. Unlike The Pirate Bay, Usenet allows paying customers to download files in a way that is nearly impossible to track. But, like the Swedish site, Usenet has had to defend itself from charges that it encourages its users to violate copyright law.

V is for video games
The Entertainment Software Association says the industry loses $3 billion annually to online piracy.

W is for "Warez"
Slang for any movies, music, applications or any other materials being traded in violation of copyright law.

X is for "X-Men Origins: Wolverine"
A version of the upcoming blockbuster leaked online in March this year, the film has already been downloaded over a million times. The FBI says it is investigating the source of the leak, and the film's star Hugh Jackman has spoken out, calling the leak "a serious crime," and "heartbreaking."

Y is for YouTube
The ubiquitous video site has been sued by major companies like Viacom for publishing and proliferating unauthorized video content online. YouTube has responded by removing copyrighted content, but popular clips of television programs are often reposted by users as soon as they are taken down.

Z is for Zune
Microsoft's answer to the iPod plans to make its entire catalogue of music DRM-free, which will make it even easier to copy and share copyrighted music.

iPad phishing scams still going strong

iPad's instant popularity is - by now - the stuff of legends, and the possibility of receiving it as a reward for being a BETA tester, participating in a survey or any similar low-effort-great-reward type of scheme, still hasn't lost its allure.

If it had, we wouldn't be seeing messages such as these on Facebook (or, for that matter, anywhere on the Internet):


The shortened link takes the naive user to a page that says that 5,000 BETA testers for the iPad are wanted, and that after testing the device for 2 months, the testers will get to keep it as payment/reward for their trouble.

To be a part of this testing group, the victim needs only to apply by sharing their contact information and the key (i.e. the password) to their email account:


Zscaler warns that if the victims fail to realize that this last request doesn't seem quite right, they will be falling pray to a well known group of scammers who have a history of using the iPad lure in order to phish for user credentials.

Wednesday, July 22, 2009

The Latest Facebook Western Union Scam

Read here for the latest variation on the 419 scam, utilized through chat on hijacked Facebook accounts, as detailed by the famous Meng Wong, author of the SPF specand other helpful technologies.

Wong includes a full transcript of a chat with a "friend" of his who tells him that he is traveling in London, was robbed at gunpoint and needs Wong to wire him money. Wong is not fooled for a second and plays with the guy, even sending him the URL toa TechCrunch story picked up by the Washington Post about this exact scam.

In the end Wong gets him to view a URL on one of his servers; then from the logs he pulls out the address of the scammer, a Nigerian address. The very least you can say about the Nigerian address is that it's not in London.

All of this proves the general rule that identity is a fuzzy thing on the Internet. Even when you have an established relationship with someone through an online channel you need to be skeptical of everything you see, especially when patterns of behavior change.

Monday, July 20, 2009

The Month of Twitter Bugs

About 3 years ago there were a series of vulnerability research campaigns for various targets: the Month of Apple Bugs, the Month of PHP Bugs, the Month of Kernel Bugs...

Aviv Raff is a pen-testing veteran of the Month of Browser Bugs. Now he has proposed bringing the bug-month method into the modern era with...

July 2009 will be the Month of Twitter Bugs—this sounds like it will be heavy with cross-site scripting problems of the sort Raff has blogged on recently.

The bugs will focus on the Twitter API and third party sloppy use of it. Raff will warn these services in advance and give them time to fix their problems before he parades them in public. He adds that bugs of this sort are common on Web 2.0 mashup sites. Perhaps it takes something like this to raise awareness of a problem.

Wednesday, July 15, 2009

IronKey S200 Line Achieves Unique Federal Certification


ronKey's new S200 line of secure Flash drives has been certified by the government to meet the stringent requirements of FIPS 140-2, Security Level 3. Government agencies can purchase only security products that receive FIPS certification from the National Institute of Standards and Technology (NIST). Level 3 certification means NIST has verified that in addition to meeting the requirements for Level 2, the product is both tamper-proof and tamper-evident. According to IronKey, no other USB Flash drive has received this certification.

Level 3 certification is more commonly reached by larger-scale devices. According to Scott Crawford, research director for the security practice at Enterprise Management Associates, "FIPS 140-2, Level 3 is most often associated with devices such as high-confidence security hardware typically found in the data center. To have implemented this in a USB form factor is a noteworthy achievement."



The existing IronKey product line is extremely tough, both cryptographically and physically. It has a crypto-chip built in and is designed to withstand traumatic events that would destroy most USB drives. Any attempt to attack its components results in electronic self-destruction. The IronKey Personal includes a built-in password manager and secure browser with anonymizing capability.

The S200 line can automatically lock down AutoRun to protect against worms such as Conficker. An option to open in read-only mode prevents malware on infected host systems from migrating to the IronKey. The Enterprise edition can be configured to unlock only inside the trusted network. And an optional anti-malware scanner (powered by McAfee) keeps the device malware-free.

This new edition also expands the range of USB drive capacities offered, including 16GB and 32GB. IronKey VP John Jefferies pointed out that with that much space, available users could put an entire virtualized PC on the IronKey. In that case the host computer would be little more than a docking station supplying network connection, keyboard, and display.

PCMag will evaluate the device when it becomes available in early August. Prices will vary by capacity; a 1GB unit will cost $79 and a 16GB unit will be $299.

Norton 2010 Beta Benchmarks

AV-Test.org, an independent test lab in Germany has been feeding us test results for the emerging 2010 generation of anti-malware products. Previously we have reported results from them for Panda and Kaspersky. Today they gave us results for the public beta versions of Norton Antivirus 2010 and Norton Internet Security 2010.

The Norton Antivirus 2010 beta may be obtainedhere.


They tested the products in 32-bit US English versions on Windows XP SP3 and Vista SP1. All tests were performed on July 6, which is worth noting since Symantec, like everyone these days, is adding "in the cloud" detection for parts of their service. AV-Test says that the latest available AV updates were from July 1, although that doesn't seem to have mattered much.

As with the other products, they tested against the 05/2009 WildList and select malware from older releases for a total of 3,194 samples that are confirmed malicious and widespread, and tested these both on-access and with the on-demand scanner. Norton 2010 found and removed all of these easily. They tested NAV2010 on XP with a larger set of about 680,000 samples. It detected 99.5% of these and registered no false positives.

They tested behavior-based detected using very new samples. Norton found 80% of these, which AV-Test calls an excellent result.

Tests of detection and cleaning of an already-infected PC proceeded well, removing all components, including registry keys, which many programs leave behind. System performance was also good.

AV-Test only tested the classic anti-malware functions described above. Norton Internet Security does much more, but they have not yet tested the newer functions. The test methodology used may be found here.

Symantec products have a history of performing well on AV-Test testing, which speaks well of them.