Showing posts with label Attack. Show all posts
Showing posts with label Attack. Show all posts

Friday, September 6, 2013

Online Attack Leads to Peek Into Spam Den

If he were known at all to Western security analysts who track the origins of spam, and in particular the ubiquitous subset of spam e-mails that promote male sexual enhancement products, it was only by the handle he used in Russian chat rooms, Engel.

His pleasant existence, living in obscurity, changed this summer when a court in Moscow linked Mr. Artimovich and three others with one of the world’s most prolific spambots, or illegal networks of virus-infected computers that send spam.

The ruling provided a peek into the shrouded world of the Viagra-spam industry, a multimillion-dollar illegal enterprise with tentacles stretching from Russia to India. Around the world every day, millions of people open their e-mail in-boxes to find invitations to buy Viagra or some other drug, potion or device to enhance sexual performance.

Who sends these notes and how they make money had remained a mystery to most recipients. The court put names and faces to a shadowy global network of infected computers known outside Russia as Festi and inside the country as Topol-Mailer, named after an intercontinental ballistic missile, the Topol-M. It was powerful enough to generate, at times, up to a third of all spam e-mail messages circulating globally.

Prosecutors say Mr. Artimovich was one of two principal programmers who controlled the network of infected computers in a group that included a former signals intelligence officer in the Federal Security Service, or F.S.B., the successor agency to the K.G.B.

Once they control the virus-infected computers, they are able to use software embedded on home and business computers to send persistent e-mails. The owner of an infected computer usually never knows the PC has been compromised.

More often than not these days, those infected computers are in India, Brazil and other developing countries where users cannot afford virus protection. But the high-end programming of viruses often takes place in Russia.

While the business model has been well understood — it was the subject of an extensive study by the University of California, San Diego — the individuals behind one of the largest spam gangs using it have largely avoided official scrutiny, until recently.

The Tushino Court in Moscow convicted two people of designing and controlling the Festi botnet, and two others of paying for its services, but none of them specifically of distributing spam. Instead, the court convicted the group of using the Festi network in 2010 to turn thousands of browsers simultaneously to the Web page of the online payment system of Aeroflot, the Russian national airline, crashing it in what is known as a distributed denial of service attack.

The spambot problem has vexed Western law enforcement officials, who complain the Russians ignore losses to global businesses that pay about $6 billion annually for spam filters, and to companies like Pfizer for sales lost to counterfeit pills.

Computer security experts have long been intrigued by the possibility that the Russian government has turned to so-called black hat hackers for political tasks in exchange offering protection from prosecution. But any direct evidence has been lacking, though the Festi case adds to the circumstantial evidence.

Russian authorities deny creating or turning a blind eye to botnets used to attack the Web sites of dissidents, or banks and government institutions in neighboring countries like Estonia or Georgia.

Valery V. Yaschenko, a deputy director of the Kremlin-linked Institute for Problems of Information Security, said the Russian government “condemns the practice of using strangers’ computers for attacks, or for any reason.”

For years, spam has been a very good business for Russian criminal gangs. An estimated $60 million a year is pulled in through these networks. Despite the Russian prosecutors’ victory this summer, similar networks remain active as tools for fraud and hacker attacks. Computer security experts say that suggests either the wrong men were convicted or the controlling codes were passed to somebody else.

Stefan Savage, a professor in the systems and networking group at the University of California, San Diego, studied the Festi scheme, in part by making test purchases.

Saturday, March 30, 2013

Devices Like Cable Boxes Figured in Internet Attack

The organization most suspected, victims said, was Stophaus, an elusive group of disgruntled European Internet users, although Sven Olaf Kamphuis, its spokesman, denied he was responsible for the attacks. At the same time, he shifted blame to Russian Internet service providers, which he said were retaliating against Spamhaus, a European anti-spam group, for blacklisting them.

But the real enablers of the attack were the operators of more than 27 million computers around the globe who left their equipment wide open to a motivated attacker. Those enablers are not just companies, but regular people with home cable boxes.

“There is a big possibility that you are part of the problem without even knowing it,” said Paul Vixie, chairman of the Internet Software Consortium, a nonprofit company responsible for the software used by many of the servers that power the Internet.

The servers the attackers used — what the Internet community calls open recursive servers or, more commonly, open resolvers — are simply home Internet devices, corporate servers, or virtual machines in the cloud that have been sloppily configured to accept messages from any device around the globe.

Open resolvers have been set up in such a way that they are not unlike the naïve users of public Wi-Fi who forget to turn off their file-sharing settings, so that any hacker on the Internet can creep inside the computer. It’s similar to PC users who do not realize that by not updating their software, they let their computers get infected with malware and used as a zombie in a cyberattack.

The difference is that if you think of a computer as a digital weapon, then an open resolver is a machine gun. Attackers can use open resolvers to amplify the strength of a cyberattack by a factor of 100.

In this week’s attack on Spamhaus and the company hired to fight it, CloudFlare, attackers made use of more than 100,000 open resolvers to inflict an attack that reached 300 billion bits per second, the largest such attack ever reported. When they could not take down those targets, they aimed and fired open resolvers at the world’s major Internet exchanges, first London, then Amsterdam, Frankfurt and then Hong Kong.

“At some point, we thought, ‘They are going to hit everything at once, and that’s when this gets real,’ ” said Matthew Prince, the chief executive of CloudFlare. “That’s the nightmare scenario that hasn’t happened — yet.”

“We’ve now seen an attack that begins to illustrate the full extent of the problem,” Mr. Prince wrote in a blog post.

Closing an open resolver, unfortunately, is not as simple as flipping a switch or downloading some software. Finding out if your home cable box is an open resolver, for instance, requires you to call your cable company and tell them that you do not want to be running an open resolver — a tough request when most of the world’s population does not even know what an open resolver is.

Recent efforts have been made to increase awareness of the issue. Computer security experts have recently started “naming and shaming” the operators of open resolvers. The DNS Measurement Factory, one such group, published a survey of top offenders by network, and more recently the Open Resolver Project published a full list of the 27 million open servers online.

The campaign is making slow progress; thousands dropped off those lists in the last few months.

But Dr. Vixie calls the open resolvers just the low-hanging fruit. Even if they were all fixed tomorrow, there are other types of servers that could just as easily be used to amplify an attack, a fact that hackers are eager to point out.

Friday, October 5, 2012

DealBook: Ads Attack Wall Street Ties, No Matter How Flimsy

Jeff Swensen for The New York TimesKeith Rothfus, a Republican, said his opponent’s commercial was “deceitful.”

Wall Street has taken a beating this election season. Yet what is considered to be Wall Street may be surprising.


Take Keith J. Rothfus, a Republican candidate for Congress in Pennsylvania. A lawyer at a small firm, he specializes in drafting software-licensing agreements. While unglamorous, it helps pay the bills.


Among the clients he has represented is Bank of New York Mellon, which has a large presence in western Pennsylvania. Two commercials backed by Democratic groups are attacking Mr. Rothfus’s relationship with his banking client.


“Millionaire Wall Street lawyer Keith Rothfus will fit right in in Washington,” said the narrator of one of the ads. The spot shows a plunging stock market and a grim-looking Mr. Rothfus entering what looks to be a bank. Over ominous music, the narrator goes on: “As a wealthy attorney, Keith Rothfus represented a Wall Street bank that received a bailout from taxpayers.”


In an interview, Mr. Rothfus called the ad “deceitful, shameful and outrageous.” He said that while BNY Mellon took bailout funds, his work for the company — most of which predates Bank of New York’s 2006 takeover of Mellon Financial of Pittsburgh — had no connection to the financial crisis.

Jeff Swensen for The New York TimesKeith Rothfus, on phone, said his legal specialty was drafting software licensing agreements.

“I’m a Stanwix Street lawyer, not a Wall Street lawyer,” Mr. Rothfus said, referring to his firm’s downtown Pittsburgh address. “I visited Wall Street once, in 1980, as a tourist at the New York Stock Exchange. If I’m a Wall Street lawyer, then the 7,500 people that work for Mellon bank in western Pennsylvania are fast-money traders who charter private jets to the Hamptons on weekends.”


As campaigns enter their final month, a number of candidates are flooding the airwaves with advertisements demonizing Wall Street. From the presidential race to local Congressional contests, from Montana to New Mexico, candidates — both Democrats and Republicans — are relentlessly attacking their opponents by linking them to bankers and bailouts, no matter how tenuous the connection.


“Candidates are bashing each other over the heads for being in Wall Street’s back pocket,” said Elizabeth Wilner of Kantar Media’s Campaign Media Analysis Group. “Wall Street is this campaign season’s punching bag, and it’s bipartisan and it’s escalating.”


In the turmoil of the 2008 financial crisis, Heather A. Wilson, then a Republican congresswoman from New Mexico, voted in favor of the Troubled Asset Relief Program, or TARP, which provided rescue funds to banks. Four years later, Ms. Wilson — a former Air Force officer — is running for the United States Senate. An opponent’s ad assails what it characterizes as her deep ties to Wall Street.


“As a congresswoman from New Mexico, it wasn’t Heather Wilson’s job to represent Wall Street banks,” said the narrator in a spot paid for by a liberal super PAC. The ad shows a series of dark, shadowy Manhattan office towers — those of Bank of America, Morgan Stanley, Merrill Lynch, JPMorgan Chase and Citigroup. “But she voted time and again to give them special tax breaks, and then voted to bail them out.”


In Montana, the incumbent, Senator Jon Tester, a Democrat, is facing a fierce challenge from the state’s sole congressman, Denny Rehberg. Mr. Tester, who has received substantial money from executives in the financial industry, has boasted in television spots that he “opposed all of those Wall Street bailouts.” Mr. Rehberg also voted against the bank bailout. So instead of focusing on TARP, ads pummel Mr. Rehberg for his longtime support for privatizing Social Security — in other words, putting retirement funds in the hands of Wall Street money managers.


One of the ads features the floor of the New York Stock Exchange and an electronic ticker showing shares in a nose dive. The narration features voices of market commentators: “A wild ride on Wall Street … the biggest point drop … a precipitous fall … these guys have been gambling … gambling … bad bets … they didn’t know when to back away. A gamble. That’s Congressman Denny Rehberg’s plan for Social Security.”


Josh Mandel, the Republican Ohio state treasurer running for United State Senate as a Washington outsider, has an ad that goes after members of Congress on both sides of the aisle for supporting the bailout.


“Every Democrat and every Republican who took our tax dollars and used them to bail out Wall Street banks was dead wrong,” Mr. Mandel says in the spot, speaking in an angry tone to a group of factory workers. “It was fiscally irresponsible. It was morally wrong.”


The presidential candidates have also criticized one another for their Wall Street ties. Ads for President Obama have homed in on Mr. Romney’s leadership of Bain Capital, the private equity firm he started. By focusing on private equity — a specific pocket of the financial industry — Mr. Obama has largely avoided a broader critique of Wall Street, where he has raised millions of dollars. On Monday, the Obama campaign announced a new ad that links Bain to a company outsourced American jobs.


Republicans, meanwhile, depict Mr. Obama as a pawn of the financial services industry. One advertisement from the conservative organization American Future Fund titled “Obama’s Wall Street” highlights Mr. Obama’s vote in favor of TARP when he was a United States senator running for president and says that his cabinet is full of financiers. Another, called “Justice for Sale,” suggests that campaign contributions from the banking industry explain why the administration has not prosecuted more executives relating to their conduct during the financial crisis.


“Under Obama, Wall Street keeps winning, and Obama keeps taking their cash,” the narrator says. “Tell Obama to stop protecting his Wall Street donors.”


Mr. Rothfus, the Republican candidate in Pennsylvania, is locked in a tight race with his opponent, the Democratic incumbent Mark S. Critz. He has countered the attack ads with humorous “Keith Rothfus is a regular guy” 30-second spots. In one, he is shown gardening in his modest front yard, driving his kids around town and repairing his daughter’s bicycle.


In response, the American Federation of State, County and Municipal Employees has produced an ad that starts, “Regular guy? Hardly. Keith Rothfus is a millionaire attorney for a Wall Street bank.” Banner headlines of the BNY Mellon’s $3 billion bailout run across the screen.


Mr. Rothfus, who lives in Sewickley, Pa., with his wife and six children, has worked as a corporate lawyer since graduating from Notre Dame Law School in 1980. For the last 15 years he has practiced on and off at Yukevich, Marchetti, Liekar & Zangrilli, a 12-lawyer firm. He earned about $125,000 last year. His assignments for BNY Mellon constitute a tiny portion of his overall practice, which focuses on small- and medium-size businesses.


“I’ve never done anything close to securities work for Mellon, never came close to those C.D.O.’s,” said Mr. Rothfus, referring to collateralized debt obligations, the complex mortgage instruments that contributed to the near collapse of the financial system. “I’ve never even done an I.P.O.”


Spokesmen for organizations behind the attack ads against Mr. Rothfus — the Democratic House Majority PAC and Afscme — said that they stood behind the ads.


Despite Mr. Rothfus’s modest salary — top Wall Street lawyers earn substantial seven-figure salaries — the millionaire epithet is accurate. That comes courtesy of his wife, the daughter of a successful Pittsburgh businessman. Based on his most recent financial disclosure, Mr. Rothfus’s total assets, including those of his wife, range from $5.1 million to $13.9 million.


With clean-cut looks and wire-rimmed glasses, Mr. Rothfus does look the part of a button-down Wall Street lawyer. But he is quick to point out that he favors Brooks Brothers off-the-rack suits instead of the bespoke variety and prefers Land’s End neckwear to Hermès ties.


“There were certain individuals on Wall Street who were reckless and betrayed our trust,” he said. “But I wasn’t one of them.”