Saturday, December 1, 2012

Crime and attacks are business that advertise

It seems that cyber crime does pay, or at least you can hire people to do it for you.

In a recent article KrebsonSecurity describes an Online Service Offers Bank Robbers for Hire.
 An online service boldly advertised in the cyber underground lets miscreants hire accomplices in several major U.S. cities to help empty bank accounts, steal tax refunds and intercept fraudulent purchases of high-dollar merchandise.
Now this is nothing new in the world of cyber crime, but it is a bit new for physical crime.

Last year it was reported that there was a service offering to break Captchas, those often unreadable, always annoying distorted letters that you're required to type in at many a Web site to prove that you're really a human.

Also there is a service for False Answer Supervision.

Or there was the case of out sourcing to hack phone systems for Al Qaeda - $2 million stolen for the cost of $4,000.

It seems that the criminals are working harder to find ways to make money from committing crimes, they share tools and data in forums that cater to cybercrooks or hackers.

It is time that we start to work harder to share information to beat these guys before they unionize.

Sunday, November 11, 2012

Thursday, November 1, 2012

Holiday Hacks are upon us again

Today I found a very nice article on the CSO Security News site called The 12 Cons of Christmas by Joan Goodchild (CSO (US)).

In this article she points out that this is the time of the year when the fraudsters and phishers are out in force.  Or as Joan put it:
While the risk of being hacked, conned or having sensitive information stolen is possible all through the year, most security experts agree that the holiday season brings a spike in fraudulent activity, both online and off.

Hot Holiday items are lures

With the increased use of Facebook and Twitter they can get more information about what you want and can use that to better target you. To make it worse, the scammers have learned not to be so obvious, and "the signs that made scams so obvious before are no longer always present as more sophisticated techniques employed by criminals on Twitter and Facebook make it harder than ever to know what's legit."

Take a look at the article for some good hints on how to detect these scams and protect yourself.  
Full article: http://www.cso.com.au/article/440664/12_cons_christmas/


Wednesday, October 3, 2012

Activity at Astricon’12


During Astricon’12  I will be part of the Greenfield Technology team at the show, along with speaking I will be at the Kamailio booth during Astricon’12.

Astricon’12 is taking place in Atlanta, GA, USA, during October 23-25, 2012

Speaking 

Nir and I will be presenting at the event. I will be presenting on Wednesday, October 24, 2012, in the 11:40-12:15 time slot.

Presentation title:

Found in the wild: Telecom Fraud and Security Problems 

Abstract

Last year's Security Panels at AstriCon brought examples from the audience (like: found and hacked in under 10 min. and $400k in fraud in 2 days). This year there are many new fraud attacks and audit horror stories and recommendations for you.
This session will review the security breaches of the past year as well as highlights of the most common problems found in security audits. The audience is encouraged to provide their own examples and jointly define solutions.


Also, Nir Simionovich will be presenting on Thursday, October 25, 2012, in the 10:00-10:35am time slot.

Presentation title: 

Asterisk Lock Down - Beyond Fail2Ban

Abstract

Fail2Ban is a wonderful tool, but it is only one of many tools out there to assist in the protection of your Asterisk server. Some of these tools are so simple, that by utilizing very simple techniques, a complete lock down can be enforced. The session will share some methods that were deployed over the course of the years 2010 and 2011 and several locations and had proved to reduce the risk of hacking and fraud tremendously. 

Kamailio Booth

Along with speaking we will be at the Kamailio booth in the open source area. The Kamailio booth number is 20, if you are attending the show; stop by to learn about use cases of Kamailio and what is new in the project.

Friday, August 3, 2012

Infographic: Fraudulent Calls Up 29 Percent in 2012

Threat Post, the Kaspersky Labs Security News Service has a nice article about the status of fraudulent calls in 2012 titled Report: Fraudulent Calls Up 29 Percent in 2012 that starts:
On average, there were almost five fraudulent phone calls every minute earlier this year according to a report released today from security firm Pindrop Security. The Atlanta-based company found phone fraud was up 29 percent January to June this year from the last half of 2011 after it analyzed 1.3 million different instances as part of its 2012 State of Phone Fraud Report.
The accompanying graphic shows how things are already looking in 2012 speaks loudly as to why companies need to be proactive in their approach to telecom fraud.


Thursday, June 28, 2012

Cloning makes its return

I am not sure if this has become a problem in other areas yet, but apparently there is a new twist in cloning the SIM card in a mobile phone.

Ok a little history first, when mobile phones first came out they did not have SIM cards. Identifying information was "hard coded" to the phone letting the network know that it was you on your phone using the network. Then someone worked out that they could scan and clone that information (similar to what is now starting to be common for RFIDs). You see that by broadcasting your "unique" identifier to the network the fraudster can trick the system into thinking they are you. For RFID this means that they can clone your credit card and start charging against your account.

In the late '90s I know that fraudsters rented a room on the lowest floor of a building that was over FDR Drive in NYC. This put them close enough to ping and scan the mobile devices in the cars that passed below them. They then input the information into other phones and were able to arrange dial out, long distance, premium number and saweepstakes fraud against those mobile user's accounts.

Now in theory this has stopped happening in mobile devices as the information is supposed to be harder to get.

Today I came across an article in the Arab Times Phone Clone Latest Scam To Prey On Mobile Users. A man called a reporter on her mobile phone and told her
Congratulations, you have just won KD 100,000 from ------ (name of the telecommunication company). I’m from the (name of the telecommunication company) International Government Department. You can claim your prize from ------ (name of local bank) by calling this number  00447624192661 for instructions on how to claim the KD 100,000 prize from (name of the local bank),” went a man to one of the reporters of the Arab Times early this week. He was calling her on her mobile phone from the number 22280636.
Now to be fair, at this point she knew it was a scam - but being a journalist she wanted to get the full story and called the number and got the same man.
 He was the same man who called up the reporter earlier but this time he introduced himself as Michael Husky of the (name of the telecommunication company) International Govern-ment Department of Kuwait. He then gave an eight-digit number to the reporter and asked her to check if the eight-digit number that he gave matched the first eight-digit number at the back of her mobile phone SIM card. “Switch it off and check it. Please check if it’s the same and please call again to confirm and I will give you the final instructions on how to claim your KD 100,000 prize from _____ (name of local bank)” said the man.  The reporter removed the SIM card from her phone and much to her surprise, the eight-digit number that the man gave her earlier was the exact number at the back of her SIM card.
The reporter removed the SIM card from her phone and much to her surprise, the eight-digit number that the man gave her earlier was the exact number at the back of her SIM card. However, when she switched on her mobile phone, it went offline and she had to go to one of the branches of this telecommunication company to check on what had gone wrong with her phone line. Her phone started working again after a customer service representative helped her out. The reporter then told the customer service representative about the earlier incident about the KD 100,000 cash prize. The customer service representative laughed aloud and told the reporter that it was not the first time that she heard such story as a number of other subscribers had also called up and claimed that they had won a cash prize from the telecommunication company.
The article goes on to say that she called again, got new instructions and was told to expect a text (SMS) message with a new PIN and to sign in using it.

When she checked with the legitimate phone company she was told that if she had gone ahead with it they would have cloned her phone.

There is a well written and detailed explanation about this could be done by the fraudsters and what each part of the scam actually was doing.

But this shows that when you get unexpected "You have won" calls or messages you should be wary as they are almost always too good to be true and can end up costing you a lot.