Translate

1/07/2014

Who is Who ? The Next Election Hack ! Matthew Weaver, the arrogant and unteachable wannabe "Hacker", Sentenced to one Year Federal Prison for Rigging Campus Elections

Matthew Weaver, 22, resident of Huntington Beach, California, and a former candidate for student council president at California State University San Marcos, hoped to guarantee himself victory by rigging the 2012 Associated Students, Inc. election through cyber fraud, but, he ended up winning a year in prison instead. (ROFL)

Weaver was using a Keylogger to steal passwords and identities of nearly 750 fellow students. Then he cast votes for himself (as well of some supporters of him on the ballot) using those stolen names. He was caught during the final hour of the election in March 2012 when network administrators noticed unusual voting activity associated with one single CPU on the campus. A California State Police officer sent to investigate the suspicions, found Weaver working on that particular machine. He had casted more than 600 votes for himself using the stolen identities.


Matthew Weaver
“Some people wanted to paint this as a college prank gone bad, but he took the identities of almost 750 people, and that’s a serious thing,” said Special Agent Charles Chabalko, who worked the investigation out of the FBI San Diego Field Division after being contacted by California State Police authorities. “He had access to these students’ e-mails, financial information, and their social networks. He had access to everything.”
Weaver installed keyloggers (inexpensive devices easily purchased on the Internet) on 19 different campus computers. Those who used the machines were unaware that Weaver later retrieved every keystroke they made, enabling him to obtain their usernames and passwords and then gain access to all their information.


California State University San Marcos
When cyber investigator Chabalko and his partner, Special Agent Nick Arico, analyzed Weaver’s laptop after his arrest, they found a spreadsheet that included the names of all the people whose identities he had stolen. “He kept a detailed indept accounting,” Chabalko said. And that’s not all investigators found.

Weaver had made online searches that included topics such as “jail time for keylogger” and “how to rig an election.”

“He knew what he did was wrong,” Chabalko said. “And even after he was caught, he didn’t want to stand in to what he did. He tried to cover up his actions and blame his crime on other fellow students.”



The evidence against Weaver was simply overwhelming, however, he finally pled guilty in March 2013. At his sentencing, the federal judge who sent Weaver to prison noted that Weaver trying to frame others for his crime is “the phenomenal misjudgment I just can’t get around. That’s what bothers me more than the original rigging of the election.”

The investigators agreed, noting that while it was wrong for Weaver to try and steal the election, “what we were really concerned about was the privacy of those students whose identities he stole” Chabalko said. Prosecutors from the U.S. Attorney’s Office felt the same way, writing in their sentencing memorandum, “Weaver determinedly and repeatedly spied on his classmates, stole their passwords, read their secrets, and usurped their votes—and he did it with his eyes wide open.” (like a child that does not want to acknowledge his wrongdoing ! If someone like that would come to power, then: GOD (PLEASE) BLESS AMERICA !)

Source: FBI, dailymail.co.uk, 10news.com

Facebook User of the Day: Roberto Pargliola from Italy
(Possible "Italian Style Flyfisher")

Say Hello to Roberto and Support her LIKEs @:
https://www.facebook.com/roberto.pargliola

Roberto Likes: Unknown. Maybe:

Flyfishing

Category MALICIOUS DOMAIN & IP: www.7secretsearch.com - Referrer-Bot - Spam-Bot - (IP: 192.157.253.9 - United States)

Potentially Malicious Spam (PHISHING, REFERRER) Domain:


 SECRET SPAM 

 

How To Control Visits From Referring Bots Such as Vampirestat, 7secretsearch and Adsensewatchdog ?


Have you ever been annoyed by these sites which increases your visits in your blog and no visits appear in Google Analytics? Or the infamous Whos.amung.us toolbar ? The anonymous robot visits from Vampirestat or Adsensewatchdog and www.7secretsearch.com. Neither Adsensewatchdog nor any other of these Bots have anything whatsoever to do with Google or Google AdSense and are simply spam sites that use automated traffic to blogs to attract clicks to their own sites from blog owners such as you.

Stay away. Traffic from these sites won't affect your standing with the real Adsense, so just ignore them.

Follow the next steps to get these bots under contol and to reduce their traffic:
  • Never click on the referred Domain links in your Blog or Webmaster Satistics, or visit their site.
  • Instead make a post (like this one) on your blog, with a negative review. On the long run their reputation will fall down to negative. Reputation is all that makes them lose.
  • Go to Virus Total (you can stay there anonymous), scan the URL of that Malware Domain, and give em a red flag. If you register you can also post your meaning giving a review. On my blog, if you look through deeply enough, there are enough referring Lookup-Domains for getting information (good or bad) upon a suspicious link or Domain.
  • Additionally, you also can submit a SPAM report to Google (Webmastertools) here.
Vampirestat whois info can be found here:


DOMAIN:
www.7secretsearch.com
  • https://www.virustotal.com/de/url/739a8261db4d68ae323ed83cfbc607b660a24b795f8303556f69a16ff8401d3d/analysis/1389109170/
  • https://www.mywot.com/en/scorecard/7secretsearch.com

www.7secretsearch.com also LINKS TO THESE MALICIOUS DOMAINS (either directly or indirectly):
widgets.amung.us
  • https://www.virustotal.com/de/url/7d7680eeb36197872a2ece324606e7743b74fd3a8e9630c6c368a3e1e21750b3/analysis/1389106363/
  • https://www.mywot.com/en/scorecard/widgets.amung.us
ad.yieldmanager.com
  • https://www.virustotal.com/de/url/e0a975001a88f4f74a9d2b665d51f2926c2419314d71064df9154651e39cf4a3/analysis/1389106564/
  • https://www.mywot.com/en/scorecard/ad.yieldmanager.com
content.yieldmanager.edgesuite.net
  • https://www.virustotal.com/de/url/e6800829b1dc059b832b190918b88a3bf2a9e3abec2ec851fd97f1ef0cae3d5f/analysis/1389106685/
  • https://www.mywot.com/en/scorecard/content.yieldmanager.edgesuite.net
i.imgur.com
  • https://www.virustotal.com/de/url/342cf1310c26da63f694aa634371ad46b4eca8e3a872cf6fa57580da670b3f18/analysis/1389110141/ 
  • http://www.urlvoid.com/scan/i.imgur.com/
  • https://www.mywot.com/en/scorecard/i.imgur.com
ads1.qadabra.com
  • https://www.virustotal.com/de/url/12a7166afab22285b29fbb66a049ff087a12cc15de8946c14c8f854a32753030/analysis/1389110286/
  • https://www.mywot.com/en/scorecard/ads1.qadabra.com
******************************************
IP:
www.7secretsearch.com = 192.157.253.9
  • https://www.virustotal.com/de/url/53855973d65537bd71949729a1f4d4d0e8cb9abb1a4cf483e3cbabaa00b3b0ed/analysis/1389106168/
  • https://www.virustotal.com/de/ip-address/192.157.253.9/information/
Fwd/Rev DNS Match: No
  • http://www.senderbase.org/lookup/?search_string=192.157.253.9
RELATED POSTS: 

Category MALICIOUS DOMAIN & IP: www.vampirestat.com - Referrer-Bot - Spam-Bot - (IP: 192.157.253.9 - United States)

Potentially Malicious Spam (PHISHING, REFERRER) Domain:


 

How To Control Visits From Referring Bots Such as Vampirestat and Adsensewatchdog ?


Have you ever been annoyed by these sites which increases your visits in your blog and no visits appear in Google Analytics? Or the infamous Whos.amung.us toobbar ? The anonymous robot visits from Vampirestat or Adsensewatchdog. Neither Adsensewatchdog nor any other of these Bots have anything whatsoever to do with Google or Google AdSense and are simply spam sites that use automated traffic to blogs to attract clicks to their own sites from blog owners such as you.

Stay away. Traffic from these sites won't affect your standing with the real Adsense, so just ignore them.

Follow the next steps to get these bots under contol and to reduce their traffic:
  • Never click on the referred Domain links in your Blog or Webmaster Satistics, or visit their site.
  • Instead make a post (like this one) on your blog, with a negative review. On the long run their reputation will fall down to hell. Reputation is all that makes them lose.
  • Go to Virus Total (you can stay there anonymous), scan the URL of that Malware Domain, and give em a red flag. If you register you can also post your meaning giving a review. On my blog, if you look through deeply enough, there are enough referring Lookup-Domains for getting information (good or bad) upon a suspicious link or Domain.
  • Additionally, you also can submit a SPAM report to Google (Webmastertools) here.
Vampirestat whois info can be found here:


DOMAIN:
www.vampirestat.com
  • https://www.virustotal.com/de/url/351a5e04578dbede25165617ca14aa393ee229efdc533bae6a1f0960af976edf/analysis/1389105156/
  • https://www.mywot.com/en/scorecard/vampirestat.com
  • http://www.urlvoid.com/scan/vampirestat.com/
www.vampirestat.com also LINKS TO THESE MALICIOUS DOMAINS (either directly or indirectly):
widgets.amung.us
  • https://www.virustotal.com/de/url/7d7680eeb36197872a2ece324606e7743b74fd3a8e9630c6c368a3e1e21750b3/analysis/1389106363/
  • https://www.mywot.com/en/scorecard/widgets.amung.us
ad.yieldmanager.com
  • https://www.virustotal.com/de/url/e0a975001a88f4f74a9d2b665d51f2926c2419314d71064df9154651e39cf4a3/analysis/1389106564/
  • https://www.mywot.com/en/scorecard/ad.yieldmanager.com
content.yieldmanager.edgesuite.net
  • https://www.virustotal.com/de/url/e6800829b1dc059b832b190918b88a3bf2a9e3abec2ec851fd97f1ef0cae3d5f/analysis/1389106685/
  • https://www.mywot.com/en/scorecard/content.yieldmanager.edgesuite.net
******************************************
IP:
www.vampirestat.com = 192.157.253.9
  • https://www.virustotal.com/de/url/53855973d65537bd71949729a1f4d4d0e8cb9abb1a4cf483e3cbabaa00b3b0ed/analysis/1389106168/
  • https://www.virustotal.com/de/ip-address/192.157.253.9/information/
Fwd/Rev DNS Match: No
  • http://www.senderbase.org/lookup/?search_string=192.157.253.9
RELATED POST: 

Category MALICIOUS DOMAIN & IP: www.adsensewatchdog.com - Referrer-Bot - Spam-Bot - (IP: 62.116.143.21 - GERMANY)

Potentially Malicious Spam (PHISHING, REFERRER) Domain:


 

How To Control Visits From Referring Bots Such as Vampirestat and Adsensewatchdog ?

Have you ever been annoyed by these sites which increases your visits in your blog and no visits appear in Google Analytics? Or the infamous Whos.amung.us toolbar ? The anonymous robot visits from Vampirestat or Adsensewatchdog. Neither Adsensewatchdog nor any other of these Bots have anything whatsoever to do with Google or Google AdSense and are simply spam sites that use automated traffic to blogs to attract clicks to their own sites from blog owners such as you.

Stay away. Traffic from these sites won't affect your standing with the real Adsense, so just ignore them.

Follow the next steps to get these bots under contol and to reduce their traffic:
  • Never click on the referred Domain links in your Blog or Webmaster Satistics, or visit their site.
  • Instead make a post (like this one) on your blog, with a negative review. On the long run their reputation will fall down to negative. Reputation is all that makes them lose.
  • Go to Virus Total (you can stay there anonymous), scan the URL of that Malware Domain, and give em a red flag. If you register you can also post your meaning giving a review. On my blog, if you look through deeply enough, there are enough referring Lookup-Domains for getting information (good or bad) upon a suspicious link or Domain.
  • Additionally, you also can submit a SPAM report to Google (Webmastertools) here.
Adsense Watchdog whois info can be found here:


DOMAIN:
www.adsensewatchdog.com
  • https://www.virustotal.com/de/url/921112e01ece904b7e24283c7ec7ef528e7a3dc1ac245b8f587e6433436ce107/analysis/1389090321/
  • http://zulu.zscaler.com/submission/show/fe117411f30d42cb7739f297064075f2-1389090365
  • https://www.mywot.com/en/scorecard/adsensewatchdog.com
  • http://www.urlvoid.com/scan/adsensewatchdog.com/
adsensewatchdog also LINKS TO MALICIOUS DOMAIN:
g.ateway.net/scripts/js3caf.js
  • https://www.virustotal.com/de/url/0b99952398ba93d977c9cc1e2643ceafe173bfabe3457b2ab3e625458dbc983e/analysis/1389090678/
*************************************
IP:
www.adsensewatchdog.com = 62.116.143.21
  • https://www.virustotal.com/de/url/39f28e85728fbfeaa15bee84c353657140821d8e8b77585f1e57bbd8628ebf60/analysis/1389091150/
  • http://www.urlvoid.com/ip/62.116.143.21
Web Reputation: Poor
  • http://www.senderbase.org/lookup/?search_string=62.116.143.21
  • https://www.virustotal.com/de/ip-address/62.116.143.21/information/
 
RELATED POST: 

Todays Useless Website: Bury Me With My Money !

Even though its a obvious useless Site, it seems to have much followers on FB !



CLICK: BURY ME WITH MY MONEY

Facebook User of the (Yester)-Day: Doc. Andrew Nguyen from Orange, California

NguyEN
Say Hello to NguyEN and Support his LIKEs (or Not-Likes: Presidents) @:
https://www.facebook.com/andrew.nguyen.988711

NguyEN does Not Like:
https://www.facebook.com/pages/Dead-Presidents
NguyEN Likes:
https://www.facebook.com/pages/Slave-Skateboards
https://www.facebook.com/pages/Kanye-West
https://www.facebook.com/BreakingBad

1/06/2014

2013: The Web in Review (or: What brought us together)



A six-minute tribute to some of the moments, people and stories that 'brought us together' this year, from tragic to triumphant, challenging or inspiring. Here's to 2013.

SB14-006: US-CERT - Vulnerability Summary for the Week
of December 30th, 2013



The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week. The NVD is sponsored by the Department of Homeland Security (DHS) National Cybersecurity and Communications Integration Center (NCCIC) / United States Computer Emergency Readiness Team (US-CERT). For modified or updated entries, please visit the NVD, which contains historical vulnerability information.

For Details SEE:

1/05/2014

Potentially Suspicious Blogsite: - viralblogspotblog.blogspot.com
Malicious Heap Spray Attempts

Potentially Suspicious Blogsite: Phish included Likely (Likely Malicious Heap Spray Attempt)

URL:

viralblogspotblog.blogspot.com
  • https://www.virustotal.com/de/url/3f174bab33559159c8177dc0c73bc6b17c8dde1ab4dae3aba5a0b193273551db/analysis/1388942353/

HTML (TITLE: Amazing Money Making Blog)

  • https://www.virustotal.com/de/file/1aa603f7c051f2d1344d631efac25b6e5f7a5b73a825dae63c1aa72c98bb682c/analysis/
Likely Malicious Heap Spray Attempt
  • https://urlquery.net/report.php?id=8705799
  • https://urlquery.net/report.php?id=8705803

 What is a heap spray attack ?

Heap spraying refers to the attempt to insert code into a predetermined location using the potential exploits of vulnerable browsers.

“Heap” comes from the term heap-based memory allocation (also known as Dynamic memory allocation), which is the allowance of memory storage to be used by a computer program when it runs. 

“Spraying the heap” is code that inserts a sequence of bytes into the memory of a target process by creating large blocks on the process’ heap and filling them in with specific values. 

This takes advantage of existing memory corruption errors in type-unsafe applications and allows the attacker to perform arbitrary code execution

Though heap spraying has been used since at least 2001, the method became popular in 2005 with the publication of several exploits involving the Internet Explorer web browser. Heap spraying proved popular due to how easy it was for novice hackers to write exploits or copy previous exploits for many vulnerabilities found in web browsers or browser plug-ins. 

When targeting browsers for heap spraying, JavaScript is mostly used. Microsoft Office has also been found to be vulnerable to heap spraying, so security experts recommend scanning all email going through a server for malware hidden in a Microsoft Office document attachment. Solutions such as Nozzle, a runtime monitoring infrastructure that detects attacker’s attempts to spray the heap, have been developed in order to counter this technique. 

Antivirus software also can protect against heap spraying attacks, so keeping your antivirus browser software up to date is essential.




by PC Tools (Symantec)

Facebook User of the Day: Rebekka (GronforWhite) from Apple Valley, Minnesota, a suburb of the Twin Cities


Say Hello to Rebekka and her kids and Support her LIKEs @:
https://www.facebook.com/rebekka.gronforwhite

Rebekka Likes:

...and more :)

Category MALICIOUS DOMAIN:
internetdo.com (with Snapchat Breach Report)
plus olafnyu.advidwebsite.com
Malicious Redirection & HTML as PUA (Potentially Unwanted Application)

Diese Zusammenfassung ist nicht verfügbar. Klicke hier, um den Post aufzurufen.

ROGER THAT, SIR - Looking Back at Fallujah's Warzone (Operation Phantom Fury):
Do YOU remember this horrific Footage ?
Or, did you ever came to see THE Horrific Footage ? (VIDEO)

Shoot the Messenger: How one journalist's footage from Fallujah in the Iraq War caused a firestorm over acceptable rules of combat.

The horrific shooting of an unarmed wounded Iraqi in a mosque shocked the world. But what really happened that day was never publicised. This exclusive report reveals the true story.



"I knew I had filmed something that has been captured on camera very few times in war," states NBC reporter Kevin Sites. His footage of a marine shooting a wounded combatant was so shocking that most American audiences didn't even get to see it. NBC released only a single black and white still. 

But even worse than the shooting, Sites alleges that four other wounded men were also killed in cold blood that day at the mosque. "These men were definitely shot again, freshly shot, after having been wounded the day before."


In Fallujah

The killing of the other insurgents went on and was largely ignored by the (U.S.) media at the time. 

With the war such a hot political issue in America, the press is reluctant to criticise the actions of its own soldiers. In the original NBC report, Sites went to great lengths to justify the marine's actions. 

But while the soldier involved was cleared of any wrong doing, Sites himself came under attack for releasing the footage. "I received thousands of hate mails and death threats saying I was a traitor." 

The real issue of acceptable rules of combat seems to have been lost in the rush to discredit Sites.

Marijuana or Obama - Who will win the Race ( Or Cohen just making Money with the Theme ? )


On this Podcast, Reihan Salam talks with Rebecca Richman Cohen, lecturer at Harvard Law School and an Emmy-nominated documentary filmmaker. Cohen's latest film, Code of the West, follows the political process of marijuana-policy reform in Montana, as well as the federal crackdown on medical-marijuana growers throughout the country (but only the country, as the online streaming video is only available within the United Statz :D ).