- +
Blog: Regulatory Compliance & the Real Risk of Undetected Malware 01/02/2008 12:35:37
With the emergence of regulatory laws borne out of experience from a variety of embarrassing security breaches, today's corporate leaders face a myriad of repercussions. These range from serious fines to jail time when found not in compliance with regulations such as Sarbanes-Oxley (SOX), Health Insurance Portability and Accountability Act (HIPAA), Gramm-Leach-Bliley (GLB), and Payment Card Industry (PCI), etc. - +
How to Be a Supremely Productive Person: A Chat With John Halamka 11/01/2008 10:59:10
John Halamka has two CIO titles, a family, passionate rock-climbing and wine-making interests and a major-league blog habit. We discuss his celebrity turn in a BlackBerry ad, his tips for e-mail triage, how he sleeps three hours a night and why he now understands Britney Spears.John Halamka has two CIO titles, a family, passionate rock-climbing and wine-making interests and a major-league blog habit. We discuss his celebrity turn in a BlackBerry ad, his tips for e-mail triage, how he sleeps three hours a night and why he now understands Britney Spears. - +
Your World. . . Hacked 02/10/2007 10:51:23
As your business becomes more collaborative and global, the risks to your company’s trade secrets rise proportionally. Fortunately, there are new strategies to protect the data that allows you to competeThe call to Bob Bailey, an IT executive with a major US government contractor, came on an otherwise ordinary day in October 2003. "Why are you attacking us?" demanded the caller, an IT leader with a Silicon Valley manufacturer. He wanted to know why Bailey's company had launched a denial-of-service attack against his network - +
Big Brother Is Watching You. . . and He's a Computer 25/06/2007 10:57:08
Schools are increasingly installing cameras to spy on students. The stated reasons include the prosecution of crimes likely to occur at a school such as vandalism and theft, but the cameras also can be used to enforce school rules such as tardiness, truancy and running in the hallsPrivacy activists have been lamenting increasing surveillance by cameras and warn of abuse by authorities who have access to them. But two additional trends portend a disturbing new direction - +
Ever-evolving Malware Is Getting Nastier 04/06/2007 12:34:20
For the past seven years, the most frequent way that people got infected with malware was by clicking malicious file attachments or rogue embedded Web linksMalware evolves in trends. Yesterday's boot virus is today's Web server exploit program. Malware follows popularity, and it morphs to get past ubiquitous defences. Understanding the growing trends in malware will help you plan better defences
Read up on the latest ideas and technologies from companies that sell hardware, software and services. An EMC Perspective on Data De-Duplication for Backup
ALM in Geographically Distributed Development Environments
The value of Project Portfolio Management
IDG Strategy Guide: Best Practice Quality Management
Agile in the Enterprise
Release Management
Realizing the Value of Unified Communications
A Guide to Next-Generation Backup, Recovery and Archive
Zones provide focussed content from Computerworld and leading technology partners.Newsletter Subscription
Authorities were able to clearly identify Essebar as the author of the worm; not only had he signed it with the words "by Diabl0" buried in the source code, but he'd written the worm using Microsoft's Visual Studio, which embeds information about the computer on which the code is written into the compiled program -- in this case, the directory path "C:\Documents and Settings\Farid." D'oh!
When Moroccan cops seized his computer, Essebar had formatted the hard drive. Forensic specialists helped recover the source code, which had not been completely wiped clean from the drive. In contrast, Turkish authorities had a more difficult time establishing evidence against Ekici because he'd physically removed and thrown out his hard drive days earlier.
Lessons learned: If you don't want to draw attention to yourself, avoid targeting major media organizations with your poorly designed malware attacks. Always throw out your hard drive that contains all the source code and evidence of your criminal malware creations before the cops arrive. Name your account on your malware creation computer something innocuous, like "user." Also, neither Turkish nor Moroccan prisons are places you want to be. Ever.
When the DDoS ain't stoppin' expect the cops to come knockin'
Perps: Ivan Maksakov, Alexander Petrov, and Denis Stepanov
Status: All three are guests of the Russian penal system, sentenced to eight years at hard labor and a 100,000 ruble fine
Dossier: Looking to make a little extra money while at college in 2003, Ivan Maksakov, then 22, devised an inventive, entrepreneurial scheme that probably sounded good at the time: He created a botnet to engage in DDoS (distributed denial-of-service) attacks and then blackmailed online gambling sites based in the UK, threatening to take the sites down during major sporting events.
However, Maksakov -- a student at the Balakov Institute of Engineering, Technology, and Management -- couldn't anticipate that the Russian government, looking to demonstrate its resolve in dealing with cybercriminals, would make an example of him.
The botnet, based in Houston, was directed to launch DDoS attacks against the UK-based bookmaking Web sites and online casinos only if Maksakov's demands weren't met. According to Russian news reports, Maksakov, along with co-conspirators Alexander Petrov and Denis Stepanov, attacked nine Web sites from the US autumn of 2003 until the US spring 2004. The sites were initially attacked for a short time, before a ransom demand was e-mailed.
In one example, the attacks crippled a site run by Canbet Sports Bookmakers during the Breeders' Cup horse races, costing the firm US$200,000 for each day it was offline. But even when the firm paid a US$40,000 ransom to a Western Union account in Riga, Latvia, the attacks continued.
Authorities allege that the attacks for which the trio were convicted cost the UK-based Web site operators upward of US$4 million, not including an additional US$80 million the companies paid out for additional bandwidth and security hardware designed to thwart DDoS attacks. Charges weren't filed for 54 similar attacks the group is alleged to have engaged in, affecting companies in 30 other countries.
Britain's intelligence services tracked the IP address used to send commands to the botnet to Maksakov's home computer. When the British government provided the information to the Russian Federation's Interior Ministry, the three were arrested. Authorities say at least 13 others who have not been arrested were involved in the scheme, including 10 people working as "money mules" in Riga, two other cyberattackers in Kazakhstan, and one more in Russia.
Computerworld Member Login
Beyond Virtualisation - The Roadmap to 2012
CIO Breakfast Briefing
8:30am - 10:30am
Brisbane | 22 July | Sofitel Brisbane
Sydney | 23 July | Four Seasons Hotel
Canberra | 24 July | The Hyatt
Attend and discover:
- What happens after virtualisation
- The benefits automation drives
- When automated infrastructures will emerge
- What the roadmap to 2012 looks like
- How to deliver an automated architecture
- How to maximise your investment in virtualisation
- +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future. - +
Data Management Edition #9: Data centre makeover 24/04/2008 07:43:06
This week CW Live looks at the death of the old style data centre which is undergoing its first makeover in more than 30 years.
WatchGuard Unveils Vision of Extensible Network Security 2008-07-09 16:53:00+10
Bridgewater Systems Wins Inaugural Internet Telephony 2008 Wimax Distinction Award 2008-07-09 15:42:00+10
WD’s New My Book® Mirror Edition™ External Hard Drive Provides The Safest Place For Valuable Personal Content 2008-07-09 15:00:00+10
Zepto release the Mythos, the 2nd installment in the Centrino 2 refresh 2008-07-09 12:05:00+10
Symantec Data Protection Solutions Preferred by Users and Industry Experts 2008-07-09 11:56:00+10
Supercharging Aurora Energy’s Core Business Applications
HP TestDirector & WinRunner offer business process savings, operational efficiencies and productivity gains. Discover how by reading on.







