The John Batchelor Show

Brief

Lessons Learned from the Hacking: "Black Hole Exploit Kit"

| 0 Comments
The black hole discovered in the galaxy NGC 3842 dwarfs our Solar System.  

blackhole_v2.jpg

The JBS site was hacked and malware was distributed on it sometime very early Friday morning, January 27.  My thanks to my web colleagues who have cleaned out the hack attackers and their malware (the site is acceptable again to the Google watchtowers) and taught me what took the site down from Friday 27 until Sunday 29 January.  I learn the that method of attack was a relatively new malware weapon system (dating from December 2011) called the  "Black Hole Exploit Kit. (BEP)"  The suspects may well be Russian hackers, who are always perfecting their code to avoid detection by the defense systems.  The entry method is the old-fashioned phising, that is inserting a false link in the posts that let the BEP enter the site.   I learn from the "Imperva Data Security Blog" that this new BEP is able to avoid detection up to 70% of the time:

What's New?
The new black hole exploit kit has been out and we've had a chance to deconstruct it.  Before we get super geeky, some general observations about the innovation in this kit:

  • Malware developers continue to use the latest tools to encrypt their malware to evade anti-virus (AV) software.  As usual, the encryption signature is new, avoiding AV--our analysis showed that 70 percent of AV software would miss this altogether.  This serves as a not-so-gentle reminder the fundamental problem with signature based AV--it changes every week with the use of a new encryption algorithm.  
  • Hackers are deploying resiliency.  In the past, we've seen hackers deploy a single exploit server.  In this case, there were four that could be redirected if any of the URLs was taken down.

What are BEPs?
An exploit kit, a browser exploit pack (BEP) is a toolkit that automates the exploitation of client side vulnerabilities. 

The toolkit is a bundle of PHP and HTML files with a list of exploit files (including JAVA, PDF, Browsers, Adobe Flash Player ...etc) designed to target the operating system, browser or other client side application.  Toolkits are usually heavily obfuscated using some known or unknown obfuscation and crypto algorithms tools to avoid detection by anti-virus vendors.  

Black hole is yet another web exploit kit developed by Russian hackers. Blackhole is a very powerful kit with a number of recent exploits including Java and Adobe PDF exploits. One blog published (with updates) a great overview of the most known exploit packs. 



Koobfaced Gang.  

koob-popup.jpg
I also learn that there are a host of suspects, though the Imperva blogger aims his remarks at the Russians.  My conversation with Misha Glenny teaches me (author: Darkmarket: Cyberthieves, Cybercops and You, Knopf 2012) that the phishing attacks are well-known to a variety of hackers, from Odessa to Petersburg to Berlin to San Francisco.  I have covered a number of these issues recently.  Most readily, I spoke to the NYT Riva Richmond a week ago, Friday 20 January, about the Petersburg-based Russian hackers called the "Koobfaced Gang," who are regarded as especially successful.  They used to employ Facebook to attack and steal by using phony vendors (no delivery) or selling their power to redirect traffic to fraudsters.  A member of the Koobfaced Gang posted the picture to to left  to Foursquare, which included the coordinates on an accompanying map.  Bold and trite, by Misha Glenny has taught me that the Russia hackers know they are safe in Russia as long as they do not mess with Russian based sites.  Facebook is said to have made it no longer worth their while, and they have gone elsewhere.  Perhaps it was the Koobfaced Gang just swinging by to leave a calling card.  What is odd about the attack is that it is a major weapon system, newly developed and most effective so far against lots of guardians.  My site is non-commercial: no cash, no credit cards, no passwords, nothing to steal or exploit or manipulate.  It is a bookish record of the show's ceaseless conversation with authors, professors, journalists, editorial writers and think-tankers.  What use a BEP?

So Many Villains, So Little Time.    

We did entertain the possibility of the China geniuses, since Gordon Chang sits with me as co-host each Wednesday, and he was mostly rewarded for his diligence in criticizing the China Communist Party's bullies and bosses by having the People's Daily declare him an "enemy of the state."  Then too Malcolm Hoenlein and I sit together each Thursday and speak roughly of the Tehran Twelvers and their stooges.  China and Iran both have their share of clever hackers.  



 
black exploit kit.jpg





Enhanced by Zemanta

True Virtual Dotcom Crime Reports

| 2 Comments
 



Screen shot 2012-01-24 at 12.50.37 PM.png
Wonderful to see my colleague Simon Constable featured in this web report (Simon on the WSJ newsroom floor noting the CofD3 stats) constructed by the infamous web buccaneer Kim Dotcom, the impressario of the pirate site MegaUload. It is a pleasure to see that Mr. Dotcom now only surfs the web, he can play the web to championship level. The detention will slow the results, and we can assume someone has now passed Megaracer. Still, a grand record, and all the sweeter because of the allegation that Mr. Dotcom cheated the system to run up his kill records -- just like Captain Kirk fixing the computer simulation at Star Fleet Academy to win the Kobayashi Maru scenario). (Mention also that Dotcom has a rep in the gamer world as a vindictive sore loser: surprise!)  I have tried to manage the Xbox controls. It requires eye-hand coordination beyond the reach of a middle-aged dad.  Am seeking Misha Glenny to follow up on the MegaUpload case, the new new world of virtual piracy.  Below find the report from Auckland, New Zealand on the indictment of Mr. Dotcom (aka Kim Schmitz) and colleagues, in addition to a glimpse of their automobile park and former rented mansion.


  
Enhanced by Zemanta

"The Senator" Gone

| 10 Comments

CFR Theme Park and the GOP

| 22 Comments
ObamaCFR.jpg

John Bolton, AEI, endorses Mitt Romney in a matter of fact presentation of why the US has stumbled badly with the Obama administration's unusual clumsiness. Speak to John Bolton routinely, and over the last years we have catalogued the arrogance and indifference of POTUS foreign policy, from the Mideast delusions of making peace with the gangsters of Hamas to the passivity in the face of Tehran and Pyongyang aggression. John Bolton is a leading candidate for StateSec in a Romney administration, and his endorsement has much weight in the posh CFR theme park (below). Also, the Bolton measure is a direction for the GOP that will provide a sharp contrast with the Obama administration the next ten months. The just revealed episode of the IRGC harassing the USS New Orleans at the Hormuz Strait (January 6) and the same game against a Coast Guard cutter east of Kuwait City (Jan 6) point to a building Gulf crisis. John Bolton doubts that POTUS Obama has the talent, boldness or desire to solve the rogue threats. Bolton mentions that the Bin Laden op was the result of ten years of search and destroy, and that Obama was at the end of a long chain of decisions. Tehran requires statecraft, not generic electioneering to a timid, downcast citizenry.




counfor.gif

Enhanced by Zemanta

DPRK Cult Opera Themes

| 5 Comments

 


New video from North Korea, DPRK, starring Kim Jong Un playing his father in the walk-and-talk-with-the-bosses scenes that serve as a regime opera. The many faces of military cadres is the best evidence available of who is in charge of the  Kim cult.  What is striking is how closely KJU imitates his father's casual haberdashery and regal gestures, as if he is trying out for the role of Big Kim.  Are they now experimenting with doubles and triples in the same rolly-polly format, so that they can send KJU on secret missions while his doubles hold court for cameras?  This is bizarre discovery.  The PRC and its PLA cadres are held in check by the play-acting of these unusually dim-witted actors on a stage of severe depravity (famine as a weapon is commonplace in DPRK).  KJU is a stooge to stooges.  The KJU cult development proceeds in a separate reality to ours, a parallel performance, and it is testing the audience (us) to learn if the cult is satisfactory.  This may be the best version we will ever get of what the planet would look like if the junta opera cults ever achieved their goals of conquest.  For now, it is as if there are cult theme parks, in Tehran, in Pyongyang, in Damascus, in Harare and so forth, where the melodramas struggle in their central casting roles.

Screen shot 2012-01-10 at 12.09.06 PM.png

Screen shot 2012-01-10 at 12.08.24 PM.png
  
Enhanced by Zemanta

Who owned the Titanic?

| 4 Comments
 


the-funeral-of-john-jacob-astor-iv-who-died-in-the-sinking-of-the-titanic-new-york-may-4-1912.jpg
The White Star Line was built by the self-made Liverpool sharpie Thomas Ismay from the remains of a failed line that sent immigrants out to Australia in the mid 19th Century. Ismay made the move from sail to steam and launched larger and larger ships until he was well capitalized enough to build twin behemoths, Titanic and Olympic. By then, Thomas Ismay had lost control of the original company to the sharholders of International Mercantile Maritime (IMM) which was controlled by the significant presence of J.P. Morgan. Thomas Ismay's son Bruce Ismay (below) was the president of the Line, and, at 49, world prominent after 80 crossings of the Atlantic in his duties, Bruce Ismay was onboard the Titanic along with the stunningly weatlhy John Jacob Astor IV (then 47, a $100 Billionaire by today's collar) for the maiden voyage. I learn from Frances Wilson's new book, "How to Survive the Titanic: the Sinking of J Bruce Ismay," that Ismay chose to put himself into one of the last lifeboats lowered from B Deck.   The New York papers were immediately convinced that Ismay was a coward and rat, and the Congressional inquiry in the Ritz that followed within days put Ismay on the stand as if he was the criminal of the event.  The English press lords were sympathetic to Ismay and protected him when he arrived back in London for a British inquiry of what was in effect an American company's conduct.  Ismay spent the remainder of his life in seclusion, indifferent or deaf to the accusations that he left his post as owner of the ship.  The auction in New York is unlikely to offer any artifact that connects to the Ismay scandal.  It will show lots of evidence of the 400 first-class passengers on board.  However the White Star Line was built on the fact that it made money on the third-class passengers, and that Ismay's great genius was to build giant floating bins to take advantage of the immigrant push to America after the Civil War.  Note that Astor's body was recovered (funeral left), with a surprising amount of personal paraphernalia (below) that illustrates how the richest of men lived and died one century ago: Astor is said to have placed his 19 year-old bride (after a scandalous divorce to his children's mother) in a lifeboat, and then to have boosted two children into place beside her.  The anecdotes of Astor's conduct as the ship sank made him an immediate hero to the press.

CLOTHING - Blue serge suit; blue handkerchief with "A.V."; belt with gold buckle; brown boots with red rubber soles; brown flannel shirt; "J.J.A." on back of collar.
EFFECTS - Gold watch; cuff links, gold with diamond; diamond ring with three stones; £225 in English notes; $2440 in notes; £5 in gold; 7s. in silver; 5 ten franc pieces; gold pencil; pocketbook.
  
ismay.jpg

Enhanced by Zemanta

Apple Harvest of the Late 20th

| 20 Comments



Apple's success derives from the simple fact that the Facebook generation has grown up alongside the single-minded product line. The video above connects to the first 25 years of Apple, 1976-2000, when it was a cluttered, self-centered cult, imitating grown-up office environments without direction or success.  After 1984, it did manage to put its sealed, peculiarly boxy, toylike Macintoshes into numerous primary and secondary schools.  I watched as my children were trained in a so-called computer lab with rows of Macs, simple, icon-based, hard to break, easy to learn.  No laptop to speak of in the Apple line until the late 90s. What was happening?  Conditioning.  These years, Apple promotes itself as a software company. The IPhone dominates the streets and subways of NY in the hands of the young and no longer young. I favor the notion that what Steve Jobs and Apple achieved was to listen to the practical needs of the Millenniums, who are restless, connected, socially skilled, and relentless consumers of cultural intelligence. Apple did not get out front. Apple developed a product line from what was extant, and then it connected the products to each other.  Apple responded to the least among the consumers, the children who couldn't choose their own products but who lived with what their parents and school boards considered child appropriate, the 1-20 year-olds of 1999, who are the dominant players of the next business cycle.  Apple didn't sell the young; it harvested them.

apple-campus-overhead-sketch.png
Enhanced by Zemanta

Worst-Elect Scenario

| 5 Comments



 


Surprisingly fresh-faced and prideful Jim Messina, the Obama re-elect manager in Chicago, leads the faithful through the Electoral College scenarios for the November 2012 election.   In 2008, POTUS achieved 365 Electoral College votes.  The thinking in Chicago is that they can give up a lot of territory and win the bare minimum 270 plus a handful.  The West scenario, winning CO, NM, NV and IA, is surprising to me, as it gives up OH, NC and VA.  The Florida scenario gives up everything including OH.  The New South scenario wins VA and NC while giving up OH and the West.  Oddest of all is the Midwest scenario, where they win with just OH and IA.  The planning is routinely defeatist, defensive, cautious -- more resembling a worst-elect briefing.   Also, note that PA and NH are in the Obama re-elect camp in each scenario except the so-called "expansion path," which puts PA and NH in the Red and presumes VA and AZ along with IA, NM, CO, and NV.  Strange brew, like some idle game on an iPhone hanging around O'Hare.  What I focus on is how they take PA and NH for granted.  The Electoral College is so tight, the loss of NH wrecks that re-elect game.  Odd that Messina doesn't focus on NH?  At 4 EC votes, it would seem available to POTUS, with heavy Boston TV exposure and a sympathetic, college-educated urban electorate; but no special mention.  With Mitt Romney the primary candidate that the Obama team most expects in the general, with his home in toney, splendid Wolfeboro, NH (below, the oldest summer resort on Lake Winnipesaukee), the autumn campaigning will be in a headwind for POTUS.  Why no Wolfeboro worrying in Chicago?

Wolfeboro_Bay.jpg

  
Enhanced by Zemanta

Climate Family

| 0 Comments
 

Speaking Bob Zimmerman re the year past in climate science, where we exchange our thoughts that we know surprisingly little about the climate change dynamic. Our main sequence G-type star is likely critical to the climate; however, we do not know how, or how much, the sunspots and the solar wind affect out climate cycles. There is a theory that the supervolcano Toba in what is now Sumatra Island, Indonesia (below: remains of the crater, now a vast lake), and the following nuclear winter lasted perhaps a thousand years of ecological defeat, reducing Homo Sapiens worldwide population to under 100,000, perhaps as low as 3,000 Homo Sapiens and 3,000 Neanderthals. This is a deep irony, that we are just 70,000 years from the near end, and only 60,000 years from the theory that the Homo Sapiens remnant, boosted in intellectual property by language, emerged from out of Africa. We are fragile, fleeting, accidental, unprotected from the violent whims of planetary physics. Watching the new Rise of the Planet of the Apes later on iTunes, and how much fun it is to consider that our political culture springs from the family unit and is only as nimble as the family unit. What I enjoy about the Silverback ape scenes above from Uganda is the family of the gigantic, self-confident family man; the much smaller, secure, watchful females, and the curious, secure infants. Our instincts to survive and prosper derive from this drama, and the vagaries of climate are not an unanswerable threat. The nuclear winter would have damaged the numbers, but not the concept of the unit, just as our climate change, perhaps a warming, perhaps drought, will not change the fundamental unit.

TobaExpeditionRoute3D.jpg

Enhanced by Zemanta

Advantage Wukan, News Desk of Tomorrow

| 1 Comment



The Central Committee in Beijing climbs down from its confrontation with the modest village of Wukan by making what are called "concessions" to the villagers to release hostages and investigate the suspect murder of a village leader.  The big picture (my favorite pet metaphor of the Second World War) is that the Central Committee is weakening perceptibly as the Chinese people advance their understanding of transparency, fair play, the rule of law and the advantage of elected official held accountable at the ballot box for grotesque stupidity and other routine careerist potholes.  Tibet, the Uyghurs, the Christians, Taiwan, the Mongolians, all these subsets of Imperial China are predicates for the Wukan rising, as the Wukan advantage so far will encourage the defiance of the conquered regions to reject the Central Committee and the sectarian bullying of the Party and the Han majority.  All positive steps.  There is the 20% chance that the Central Committee is lying cynically, and the Wukan dissenters will be punished gradually.  The village, county and province Party bosses who concocted the land grab and fishing rights larceny may be punished, or may buy off their masters and move on to other crony games.   For now, Wukan is an inspiration for all the villagers who see the facts on the ground that the Maoists in Beijing and their toadies in the provinces have no legitimacy nor do they derive genuine authority from their so-called peasant roots.  Most enjoy the snapshot below of what is described as the Wukan News Desk.  Those teenagers are the future of free and democratic China.  Speaking Gordon Chang, Naomi Revnick, Bruce Bechtol, Isaac Stone Fish, Joseph Sternberg, John Lee of Sydney University, re the Central Committee fail with regard the economy, Wukan, DPRK and the Kim cult, Taiwan elections on January 12, 2012, and Tibet. 

wukan news desk.jpg

Enhanced by Zemanta