NK suspect for US and South Korea Cyber Attack
The powerful attack that overwhelmed computers at U.S. and South Korean government agencies for days was even broader than realized, also targeting the White House, the Pentagon and the New York Stock Exchange. An early analysis of the malicious software used in the attack found its targets also included the National Security Agency, Homeland Security Department, State Department, the Nasdaq stock market andThe Washington Post. Many of the organizations appeared to successfully blunt the sustained attacks. The Associated Press obtained the target list from security experts analyzing the attack. It was not immediately clear who might be responsible or what their motives were. The attack was remarkably successful. The widespread attack knocked out the Web sites of the Treasury Department, the Secret Service and other U.S. government agencies, according to officials inside and outside the government. Sites in South Korea were also affected, and South Korean intelligence officials believe the attack was carried out by North Korean or pro-Pyongyang forces. The U.S. government Web sites, which also included those of the Federal Trade Commission and the Transportation Department, were all down at varying points over the holiday weekend and into this week. South Korean Internet sites began experiencing problems Tuesday. U.S. officials refused to publicly discuss details of the cyber attack. But South Korea's National Intelligence Service, the nation's main spy agency, told a group of South Korean lawmakers Wednesday that it believes that North Korea or North Korean sympathizers in the South "were behind" the attacks, according to an aide to one of the lawmakers briefed on the information. The aide spoke on condition of anonymity, citing the sensitivity of the information. The National Intelligence Service — South Korea's main spy agency — said it couldn't immediately confirm the report, but it said it was cooperating with American authorities. Amy Kudwa, spokeswoman for the Homeland Security Department, said the agency's U.S. Computer Emergency Readiness Team issued a notice to federal departments and other partner organizations about the problems and "advised them of steps to take to help mitigate against such attacks." Others familiar with the U.S. outage, which is called a denial of service attack, said the fact that the government Web sites were still being affected three days after it began signaled an unusually lengthy and sophisticated attack. Two government officials acknowledged that the Treasury and Secret Service sites were brought down, and said the agencies were working with their Internet service provider to resolve the problem. The officials spoke on condition of anonymity because they were not authorized to speak on the matter. Ben Rushlo, director of Internet technologies at Keynote Systems, said problems with the Transportation Department site began Saturday and continued until Monday, while the FTC site was down Sunday and Monday. Keynote Systems is a mobile and Web site monitoring company based in San Mateo, Calif. The company publishes data detailing outages on Web sites, including 40 government sites it watches. According to Rushlo, the Transportation Web site was "100 percent down" for two days, so that no Internet users could get through to it. The FTC site, meanwhile, started to come back online late Sunday, but even on Tuesday Internet users still were unable to get to the site 70 percent of the time. Web sites of major South Korean government agencies, including the presidential Blue House and the Defense Ministry, and some banking sites were paralyzed Tuesday. An initial investigation found that many personal computers were infected with a virus ordering them to visit major official Web sites in South Korea and the U.S. at the same time, Korea Information Security Agency official Shin Hwa-su said.
Some of the affected government Web sites were still reporting problems days after it started during the July 4 holiday.
Researcher cracks Mac in 10 seconds at PWN2OWN, wins $5k
Charlie Miller defends his title; IE8 also falls on Day One of hacking contest
March 18, 2009 (Computerworld) Charlie Miller, a security researcher who hacked a Macintosh in two minutes last year at CanSecWest's PWN2OWN contest, improved his time today by breaking into another Macintosh in under 10 seconds.
Miller, an analyst at Independent Security Evaluators in Baltimore, walked off with a $5,000 cash prize and the MacBook he hacked.
"I can't talk about the details of the vulnerability, but it was a Mac, fully patched, with Safari, fully patched," said Miller on Wednesday, not long after he had won the prize. "It probably took five or 10 seconds." He confirmed that he had researched and written the exploit before he arrived at the challenge.
The PWN2OWN rules stated that the researcher could provide a URL that hosted his exploit, replicating the common hacker tactic of enticing users to malicious sites where they are infected with malware. "I gave them the link, they clicked on it, and that was it," said Miller. "I did a few things to show that I had full control of the Mac."
Two weeks ago, Miller predicted that Safari running on the Macintosh would be the first to fall.
PWN2OWN's sponsor, 3Com Corp.'s TippingPoint unit, paid Miller $5,000 for the rights to the vulnerability he exploited and the exploit code he used. As it has at past challenges, it reported the vulnerability to on-site Apple representatives. "Apple has it, and they're working on it," added Miller.
According to Terri Forslof, manager of security response at TippingPoint, another researcher later broke into a Sony laptop that was running Windows 7 by exploiting a vulnerability in Internet Explorer 8. "Safari and IE both went down," she said in an e-mail.
TippingPoint's Twitter feed added a bit more detail to Forslof's quick message: "nils just won the sony viao with a brilliant IE8 bug!"
Forslof was not immediately available to answer questions about the IE8 exploit.
TippingPoint will continue the PWN2OWN contest through Friday, and will pay $5,000 for each additional bug successfully exploited in Safari, Internet Explorer 8, Firefox or Google's Chrome. During the contest, IE8, Firefox and Chrome will be available on the Sony, while Safari and Firefox will be running on the MacBook. The researcher who exploited IE8 will, like Miller, be awarded not only the cash, but also the laptop.
"It was great," said Miller when asked how it felt to successfully defend his title. "But I was really nervous for some reason this time. Maybe it was because there were more people around. Lucky [the exploit] was idiot-proof, because if I had had to think about it, I don't know if I'd had anything."
This year's PWN2OWN also features a mobile operating system contest that will award a $10,000 cash prize for every vulnerability successfully exploited in five smartphone operating systems: Windows Mobile, Google's Android, Symbian, and the operating systems used by the iPhone and BlackBerry.
Miller said he won't enter the mobile contest. "I can't break them," said Miller, who was one of the first researchers to demonstrate an attack on the iPhone in 2007, and last year was the first to reveal a flaw in Android. "I don't have anything for the iPhone, and I don't know enough about Google."
CanSecWest, which opened Monday, runs through Friday in Vancouver, British Columbia.