Showing posts with label FBI. Show all posts
Showing posts with label FBI. Show all posts

Wednesday, August 14, 2013

Russian crypto expert arrested at Defcon



The Federal Bureau of Investigation brought a Russian encryption expert into custody Monday at his hotel in Las Vegas for allegedly releasing software that cracks a assortment of formulas used to secure e-books.

The apprehension was first accounted by Planet eBook.

Sunday, July 8, 2012

Hundreds of thousands may lose web access July 9 due to virus



fbi, internet, malware, spyware, dns, dnschanger, viruses, warnings, isc, dcwg, hundre
July 9 is the day thousands of PCs (and Macs) infected with DNSChanger will lose their ability to surf the web. Although the virus was introduced in 2007, according to the DCWG's data, as many as 500,000 computers may still be infected. This is a friendly reminder to make certain your computers are malware-free and that their DNS settings are nominal.

In 2011, the FBI busted the unscrupulous band of individuals responsible for DNSChanger, shutting down their Eastern European servers -- a move which actually knocked millions of infected users off the web. Although those servers run by the criminals were used to feed infected users profitable ads, phishing attempts and malware, they also provided victims with a working DNS service -- servers which allow human-friendly hostnames to point to Internet locations that computers understand (IP address numbers). 

Victims were left with computers configured to use DNS servers which no longer existed. As a result, nearly 4 million people were left without Internet access.

As a courtesy, FBI technorati organized an effort to temporarily provide DNS service for DNSChanger victims. After a period of time though, the FBI handed off this responsibility to the Internet Systems Consortium, a non-profit organization who has managed to keep the DNS flowing to infected users. However, this act of kindness will end on Monday.


How do I find out if I'm infected with DNSChanger?
Google and Facebook have been warning infected users. You can also manually check using this tool.

What should I do if I'm infected?

Visit DCWG for instructions and a list of utilities capable of removing DNSChanger from your computer. If none of these tools seem to work, your router's settings may have been changed by the virus (it does do that, believe it or not). You'll need to enter your router's web configuration (instructions vary) and change its DNS settings.

Virus scanners have been able to detect and prevent DNSChanger infections for some time now. Protect yourself!

Friday, November 25, 2011

FBI says hackers not responsible for Illinois water pump failure


fbi, department of homeland security, water pump, feds, scada, supervisory control and data acquisition system, illinois
The Federal Bureau of Investigation and the Department of Homeland Security are nowsaying that a water pump failure at a Springfield, Illinois water utility plant was not destroyed by hackers. This contradicts an earlier report on November 10 from the Illinois fusion center that claimed someone had hacked into the Supervisory  Control and Data Acquisition System (SCADA) and repeatedly turned a water pump on and off, resulting in the burnout of said pump.

To gain access, the attacker(s) obtained multiple usernames and passwords from SCADA that were used to access the water facility. The detailed report, which shows the IP addresses were traced to Russia, suggested that the hacker(s) could have had access to the system for a few months prior to the attack.

But now, the FBI and DHS say they have found no evidence of a cyber intrusion into the SCADA system at the Curran-Gardner Public Water District. In fact, they further elaborate and say there was no evidence to support the claim in the initial report. The raw and unconfirmed data was leaked to the media and should have never been made public.

Joe Weiss, a control system expert and the person that first reported the data from the fusion report, believes something doesn’t quite add up.

“This smells to high holy heaven, because when you look at the Illinois report, nowhere was the word preliminary ever used,” Weiss said. “It was just laying out facts. How do the facts all of a sudden all fall apart? There’s a lot of black and white stuff in that report. Either there is or there isn’t a Russian IP address in there. It’s hard to miss that. This stuff about the vendor being hacked… How can two government agencies be so at odds at what’s going on here? Did the fusion center screw up, or is the fusion center being thrown under the bus?”
As of writing, the investigation is ongoing and additional relevant information will be released at it becomes available. No other explanation has been provided thus far.