Translate

1/06/2014

2013: The Web in Review (or: What brought us together)



A six-minute tribute to some of the moments, people and stories that 'brought us together' this year, from tragic to triumphant, challenging or inspiring. Here's to 2013.

SB14-006: US-CERT - Vulnerability Summary for the Week
of December 30th, 2013



The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week. The NVD is sponsored by the Department of Homeland Security (DHS) National Cybersecurity and Communications Integration Center (NCCIC) / United States Computer Emergency Readiness Team (US-CERT). For modified or updated entries, please visit the NVD, which contains historical vulnerability information.

For Details SEE:

1/05/2014

Potentially Suspicious Blogsite: - viralblogspotblog.blogspot.com
Malicious Heap Spray Attempts

Potentially Suspicious Blogsite: Phish included Likely (Likely Malicious Heap Spray Attempt)

URL:

viralblogspotblog.blogspot.com
  • https://www.virustotal.com/de/url/3f174bab33559159c8177dc0c73bc6b17c8dde1ab4dae3aba5a0b193273551db/analysis/1388942353/

HTML (TITLE: Amazing Money Making Blog)

  • https://www.virustotal.com/de/file/1aa603f7c051f2d1344d631efac25b6e5f7a5b73a825dae63c1aa72c98bb682c/analysis/
Likely Malicious Heap Spray Attempt
  • https://urlquery.net/report.php?id=8705799
  • https://urlquery.net/report.php?id=8705803

 What is a heap spray attack ?

Heap spraying refers to the attempt to insert code into a predetermined location using the potential exploits of vulnerable browsers.

“Heap” comes from the term heap-based memory allocation (also known as Dynamic memory allocation), which is the allowance of memory storage to be used by a computer program when it runs. 

“Spraying the heap” is code that inserts a sequence of bytes into the memory of a target process by creating large blocks on the process’ heap and filling them in with specific values. 

This takes advantage of existing memory corruption errors in type-unsafe applications and allows the attacker to perform arbitrary code execution

Though heap spraying has been used since at least 2001, the method became popular in 2005 with the publication of several exploits involving the Internet Explorer web browser. Heap spraying proved popular due to how easy it was for novice hackers to write exploits or copy previous exploits for many vulnerabilities found in web browsers or browser plug-ins. 

When targeting browsers for heap spraying, JavaScript is mostly used. Microsoft Office has also been found to be vulnerable to heap spraying, so security experts recommend scanning all email going through a server for malware hidden in a Microsoft Office document attachment. Solutions such as Nozzle, a runtime monitoring infrastructure that detects attacker’s attempts to spray the heap, have been developed in order to counter this technique. 

Antivirus software also can protect against heap spraying attacks, so keeping your antivirus browser software up to date is essential.




by PC Tools (Symantec)

Facebook User of the Day: Rebekka (GronforWhite) from Apple Valley, Minnesota, a suburb of the Twin Cities


Say Hello to Rebekka and her kids and Support her LIKEs @:
https://www.facebook.com/rebekka.gronforwhite

Rebekka Likes:

...and more :)

Category MALICIOUS DOMAIN:
internetdo.com (with Snapchat Breach Report)
plus olafnyu.advidwebsite.com
Malicious Redirection & HTML as PUA (Potentially Unwanted Application)

Diese Zusammenfassung ist nicht verfügbar. Klicke hier, um den Post aufzurufen.

ROGER THAT, SIR - Looking Back at Fallujah's Warzone (Operation Phantom Fury):
Do YOU remember this horrific Footage ?
Or, did you ever came to see THE Horrific Footage ? (VIDEO)

Shoot the Messenger: How one journalist's footage from Fallujah in the Iraq War caused a firestorm over acceptable rules of combat.

The horrific shooting of an unarmed wounded Iraqi in a mosque shocked the world. But what really happened that day was never publicised. This exclusive report reveals the true story.



"I knew I had filmed something that has been captured on camera very few times in war," states NBC reporter Kevin Sites. His footage of a marine shooting a wounded combatant was so shocking that most American audiences didn't even get to see it. NBC released only a single black and white still. 

But even worse than the shooting, Sites alleges that four other wounded men were also killed in cold blood that day at the mosque. "These men were definitely shot again, freshly shot, after having been wounded the day before."


In Fallujah

The killing of the other insurgents went on and was largely ignored by the (U.S.) media at the time. 

With the war such a hot political issue in America, the press is reluctant to criticise the actions of its own soldiers. In the original NBC report, Sites went to great lengths to justify the marine's actions. 

But while the soldier involved was cleared of any wrong doing, Sites himself came under attack for releasing the footage. "I received thousands of hate mails and death threats saying I was a traitor." 

The real issue of acceptable rules of combat seems to have been lost in the rush to discredit Sites.

Marijuana or Obama - Who will win the Race ( Or Cohen just making Money with the Theme ? )


On this Podcast, Reihan Salam talks with Rebecca Richman Cohen, lecturer at Harvard Law School and an Emmy-nominated documentary filmmaker. Cohen's latest film, Code of the West, follows the political process of marijuana-policy reform in Montana, as well as the federal crackdown on medical-marijuana growers throughout the country (but only the country, as the online streaming video is only available within the United Statz :D ).



1/04/2014

Facebook User of the Day: Carla Alonso or Clara Alonsoo (Gigolo or Model)
Will we ever know...?

Is He She or is She him: A Model or Gigolo ?
This is Clara (Model)
Check Clara @ Wikipedia: http://en.wikipedia.org/wiki/Clara_Alonso

Say Hello to Carla aka Clara and Support her LIKEs @:
http://www.facebook.com/Carla.Alonsoo

They Like:

CALIFORNIA Online Child Predators 2012: CSU Assistant Sentenced to 450 Months in Prison for Aggravated Sexual Abuse of a 5-month-old infant

After Kenneth Martin Kyle, a former CSU assistant professor, plead guilty in 2009, he was sentenced March 8th, 2012, to 37-and-a-half years in prison. He also has been ordered to pay 50.000 USD in restitution for traveling across state lines to sexually abuse a infant, U.S. Attorney for the Northern District of California Melinda Haag announced.

US Attorney Melinda Haag
In pleading guilty, Kyle admitted, that in August 2009, he traveled from San Francisco to St. Louis for the purpose of engaging in sexual acts with an infant victim. Immediately following his guilty plea, which was pursuant to a plea agreement, Kyle was sentenced by U.S. District Judge Jeffrey S. White.

“It is my hope that the sentence Mr. Kyle received, sends a strong message about the abhorrent conduct in this case” (as well as in nationwide similar cases), U.S. Attorney Haag said.

Protecting (our) children from sexual predators like Kyle, is an absolute important priority (TASK) to do so. My office will continue to work diligently with partners in law enforcement to track down and prosecute sexual predators to the fullest extent of the law.” Haag also stated.

Pedophile Kyle sentenced to 450 Months
At the time of his arrest (in March 2010), Kyle was an Assistant Professor of Justice Studies (My goodness (Headshake)) at the California State University in East Bay.

He came to the attention of the FBI when undercover agents discovered that he was sharing child pornography over a peer-to-peer file-sharing network.

The FBI passed this information along to San Francisco police officers who obtained a search warrant for Kyle’s San Francisco apartment.

During the search of Kyle’s apartment, they found computers and other devices containing child pornography and similar material. Because Kyle was out of the country at the time (..and therefor the search warrant was officialy "handed out"), San Francisco police officers shared their information with U.S. Immigration and Customs Enforcement (ICE)-Homeland Security Investigations (HSI), as well to other LEA (FBI etc.).

“Nothing is more gratifying than seeing someone like this, going to prison for a very, very, very long time, where he will no longer have the opportunity to harm children or other potential victims, in such a horrible fashion. said Clark Settles, “HSI will use every tool at its disposal to track down those who would and will harm our children, and see that they are brought to justice, at best as it can reach.”

During his plea hearing, Kyle admitted to molesting a 5-month-old infant in St. Louis over several months. The infant victim’s mother, Tessa Vanvlerah, currently faced at the time federal child pornography charges in California and Missouri and has pleaded guilty to state child molestation charges in Missouri. She was sentenced to consecutive life sentences for incest, statutory sodomy and statutory rape of her infant daughter.

The woman who fostered and then adopted the girl said initially, the girl would scream when anyone bathed her or changed her diaper. She still has night terrors and asks at each bedtime to make sure nobody else comes into the home. However, she said the girl is improving day by day and "is no longer Tessa's plaything and she is no longer Tessa's child."

Vanvlerah was arrested in 2010 following the arrest of 49-year-old Kenneth Kyle, a California State University East Bay professor, on child pornography charges. Along with hundreds of child porn images on Kyle's computers, investigators found information that led them to the St. Louis area, where Kyle had visited Vanvlerah four times in five months, since meeting online. During those visits, prosecutors say the pair had sex with the girl and each other at various hotels. (SEX with THE Girl?? An Infant ??? How Sick THE FORMULATION !!)

Dr. KRAUSHAAR
Forensic psychologist Dr. Brooke Kraushaar testified at Vanvlerah's sentencing hearing that Vanvlerah's dependent-personality disorder caused her to participate in Kyle's sexual fantasies, even though she knew sex acts involving the baby were wrong.

Kraushaar, who was hired by defense lawyers Brent Labovitz and Kevin Whiteley, described Vanvlerah as "a passive offender." Brooke said Vanvlerah was so afraid of being rejected by others that she also allowed Kyle to choke, burn and urinate on her.

But assistant prosecutor Kathi Alizadeh disputed the diagnosis, pointing out that Vanvlerah exercised free will in electronic communications with another man. Vanvlerah carved her nickname for the man, "Lord Nikon" into her skin at his request, the prosecutor said, but drew the line at one of his suggestions involving bestiality.

Alizadeh said police learned that Vanvlerah and another man, from Avon, Missouri, exchanged child porn and discussed plans for him to come to St. Louis to have sex with the infant, but it was never acted upon.

In 2008, when Vanvlerah was 18, a woman obtained a court order of protection against her, accusing her of seducing and having sex with the woman's 16-year-old autistic son. Alizadeh said it resulted in Vanvlerah's pregnancy.

Worthless Mother Tessa Vanvlerah 1
Kyle, 47, of San Francisco, was indicted by a federal grand jury on April 1st, 2010. He was charged with aggravated sexual abuse of a child, production of child pornography, distribution of child pornography, transportation of child pornography, as well as possession of child pornography. Under the plea agreement, Kyle pleaded guilty to count one of the indictment.

Worthless Mother Tessa Vanvlerah 2
Owen Martikan is the Assistant U.S. Attorney who is prosecuting the case with the assistance of Rosario Calderon.

The prosecution is the result of an investigation by ICE-HSI.

This investigation also involved the U.S. Attorney’s Office for the Eastern District of Missouri.

Lets hope that these harmful creatures will be rotten out at some point in time, and wont be a burden for the average taxpayer...

1/03/2014

Facebook User of the Day: Victor Florez of Colombia

Victor Florez (Left or Right)
Say Hello to Victor and Support his LIKEs @:


Victor Likes:

Alert TA14-002A: US-CERT - Malware Targeting Point of Sale Systems
(January 02, 2014)



The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week. The NVD is sponsored by the Department of Homeland Security (DHS) National Cybersecurity and Communications Integration Center (NCCIC) / United States Computer Emergency Readiness Team (US-CERT). For modified or updated entries, please visit the NVD, which contains historical vulnerability information.

Systems Affected


  • Point of Sale Systems


Overview


Point of Sale Systems

When consumers purchase goods or services from a retailer, the transaction is processed through what are commonly referred to as Point of Sale (POS) systems. POS systems consist of the hardware (e.g. the equipment used to swipe a credit or debit card and the computer or mobile device attached to it) as well as the software that tells the hardware what to do with the information it captures.

When consumers use a credit or debit card at a POS system, the information stored on the magnetic stripe of the card is collected and processed by the attached computer or device. The data stored on the magnetic stripe is referred to as Track 1 and Track 2 data. Track 1 data is information associated with the actual account; it includes items such as the cardholder’s name as well as the account number. Track 2 data contains information such as the credit card number and expiration date.


Description


POS Targeting

For quite some time, cyber criminals have been targeting consumer data entered in POS systems. In some circumstances, criminals attach a physical device to the POS system to collect card data, which is referred to as skimming. In other cases, cyber criminals deliver malware which acquires card data as it passes through a POS system, eventually exfiltrating the desired data back to the criminal. Once the cybercriminal receives the data, it is often trafficked to other suspects who use the data to create fraudulent credit and debit cards.

As POS systems are connected to computers or devices, they are also often enabled to access the internet and email services. Therefore malicious links or attachments in emails as well as malicious websites can be accessed and malware may subsequently be downloaded by an end user of a POS system. The return on investment is much higher for a criminal to infect one POS system that will yield card data from multiple consumers.


Impact

There are several types of POS malware in use, many of which use a memory scraping technique to locate specific card data. Dexter, for example, parses memory dumps of specific POS software related processes looking for Track 1 and Track 2 data. Stardust, a variant of Dexter not only extracts the same track data from system memory, it also extracts the same type of information from internal network traffic. Researchers surmise that Dexter and some of its variants could be delivered to the POS systems via phishing emails or the malicious actors could be taking advantage of default credentials to access the systems remotely, both of which are common infection vectors. Network and host based vulnerabilities, such as weak credentials accessible over Remote Desktop, open wireless networks that include a POS machine and physical access (unauthorized or misuse) are all also candidates for infection.

Solution


POS System Owner Best Practices


Owners and operators of POS systems should follow best practices to increase the security of POS systems and prevent unauthorized access.

  • Use Strong Passwords: During the installation of POS systems, installers often use the default passwords for simplicity on initial setup. Unfortunately, the default passwords can be easily obtained online by cybercriminals. It is highly recommended that business owners change passwords to their POS systems on a regular basis, using unique account names and complex passwords.
  • Update POS Software Applications: Ensure that POS software applications are using the latest updated software applications and software application patches. POS systems, in the same way as computers, are vulnerable to malware attacks when required updates are not downloaded and installed on a timely basis.
  • Install a Firewall: Firewalls should be utilized to protect POS systems from outside attacks. A firewall can prevent unauthorized access to, or from, a private network by screening out traffic from hackers, viruses, worms, or other types of malware specifically designed to compromise a POS system.
  • Use Antivirus: Antivirus programs work to recognize software that fits its current definition of being malicious and attempts to restrict that malware’s access to the systems. It is important to continually update the antivirus programs for them to be effective on a POS network.
  • Restrict Access to Internet: Restrict access to POS system computers or terminals to prevent users from accidentally exposing the POS system to security threats existing on the internet. POS systems should only be utilized online to conduct POS related activities and not for general internet use.
  • Disallow Remote Access: Remote access allows a user to log into a system as an authorized user without being physically present. Cyber Criminals can exploit remote access configurations on POS systems to gain access to these networks. To prevent unauthorized access, it is important to disallow remote access to the POS network at all times.

Consumer Remediation
Fraudulent charges to a credit card can often be remediated quickly by the issuing financial institution with little to no impact on the consumer. However, unauthorized withdrawals from a debit card (which is tied to a checking account) could have a cascading impact to include bounced checks and late-payment fees.
Consumers should routinely change debit card PINs. Contact or visit your financial institutions website to learn more about available fraud liability protection programs for your debit and credit card accounts. Some institutions offer debit card protections similar to or the same as credit card protections.
If consumers have a reason to believe their credit or debit card information has been compromised, several cautionary steps to protect funds and prevent identity theft include changing online passwords and PINs used at ATMs and POS systems; requesting a replacement card; monitoring account activity closely; and placing a security freeze on all three national credit reports (Equifax, Experian and TransUnion). A freeze will block access to your credit file by lenders you do not already do business with. Under federal law, consumers are also entitled to one free copy of their credit report every twelve months through AnnualCreditReport.com.
Consumers may also contact the Federal Trade Commission (FTC) at (877) 438-4338 or via their website at www.consumer.gov/idtheft or law enforcement to report incidents of identity theft.
ALERT-SOURCE: 

MARYLAND Online Child Predators 2014: Daniel Burton "Snoop" got sentenced to 262 months in prison for Prostituting a 13-Year-Old Girl through the Internet on Craigslist

Judge Chasanow
On January 2nd (Yesterday), 2014, Daniel Burton (a/k/a "Snoop"), 30, of Capitol Heights, Maryland was sentenced by Chief U.S. District Judge Deborah K. Chasanow, to 262 months in prison followed by a lifetime supervised release. Judge Chasanow ordered that upon his release from prison, Burton must register as a sex offender in the place where he resides, where he is an employee, and where he might be a student, under the Sex Offender Registration and Notification Act (SORNA). The sentence was announced by United States Attorney for the District of Maryland Rod J. Rosenstein.

Rosenstein stated: “This is an egregious case because the 'prostitute' was a 13-year old child, the lengthy sentence should send a powerful message that sex trafficking of children will not be tolerated in Maryland.” (Or elsewhere, no ?)

United States Attorney Rosenstein
According to his plea agreement in March 2008, Burton asked a 13-year-old girl walking near her home for her phone number, which she provided. Burton began calling the girl and eventually recruited her to work as a prostitute. Burton drove her to hotels, photographed her in lingerie, and advertised her on Craigslist for sexual services (Who knows, maybe he the Craigslist Ripper ?). The girl had sex with many clients that responded to the ads and Burton kept all the money she earned. Burton provided the girl with alcohol, marijuana and ecstasy.

Craigslist Logo
On April 1st, 2008, police responded to a complaint at a hotel, where Burton was found with the girl in a room. Burton claimed the girl was a relative and police arranged for the girl to return home. Burton subsequently picked the girl up at her home and continued prostituting her.

On April 8th, 2008, law enforcement saw a Craigslist ad for the girl’s sexual services and arranged a “date”. Law enforcement arrived at the scene and arrested Burton who was sitting outside the hotel.

The case was investigated by the FBI-led Maryland Child Exploitation Task Force (MCETF), created in 2010 to combat child prostitution, with members from 10 state and federal law enforcement agencies. The Task Force coordinates with the National Center for Missing and Exploited Children and the Maryland State Police Child Recovery Unit to identify missing children being advertised online for prostitution.

MCETF partners with the Maryland Human Trafficking Task Force, formed in 2007 to discover and rescue victims of human trafficking while identifying and prosecuting offenders. Members include federal, state and local law enforcement, as well as victim service providers and local community members.

For more information about the Maryland Human Trafficking Task Force, visit: http://www.justice.gov/usao/md/priorities_human.html

Todays Useless Website: A Blue Box. Absolutely Worthless Site



This is for me, at least as long as i am profiling useless Websites and/or Domains real boring...However. Therefor absolutely USELESS:

See yourself: http://www.a-blue-box.com