<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Jonathan T Rajewski &#187; Cyber Terrorism</title>
	<atom:link href="http://jtrajewski.com/blog/category/cyber-terrorism/feed/" rel="self" type="application/rss+xml" />
	<link>http://jtrajewski.com/blog</link>
	<description>A look into the world of digital forensics, white collar crime and related topics</description>
	<lastBuildDate>Wed, 05 Aug 2009 13:50:56 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Weaponizing Web 2.0</title>
		<link>http://jtrajewski.com/blog/2009/07/30/weaponizing-web-2-0/</link>
		<comments>http://jtrajewski.com/blog/2009/07/30/weaponizing-web-2-0/#comments</comments>
		<pubDate>Thu, 30 Jul 2009 14:32:15 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Cyber Terrorism]]></category>
		<category><![CDATA[Web 2.0]]></category>
		<category><![CDATA[hacking]]></category>

		<guid isPermaLink="false">http://jtrajewski.com/blog/?p=64</guid>
		<description><![CDATA[In this link Brian Krebs blog, he describes how researchers Nathan Hamiel and Shawn Moyer presented a method to (link to paper &#8211; Moyer-Hamiel-DC17-Dynamic-CSRF) automate cross-site request forgery (CSRF) attacks.
Taken from the article &#8220;To take the Alice and Bob on the forum example a step further, consider what happens when Alice views a forum posting [...]]]></description>
			<content:encoded><![CDATA[<p>In this <a href="http://voices.washingtonpost.com/securityfix/2009/07/weaponizing_web_20.html#more">link</a> Brian Krebs blog, he describes how researchers Nathan Hamiel and Shawn Moyer presented a method to (<a href='http://jtrajewski.com/blog/wp-content/uploads/2009/07/Moyer-Hamiel-DC17-Dynamic-CSRF.pdf'>link to paper &#8211; Moyer-Hamiel-DC17-Dynamic-CSRF</a>) automate cross-site request forgery (CSRF) attacks.</p>
<p>Taken from the article <em>&#8220;To take the Alice and Bob on the forum example a step further, consider what happens when Alice views a forum posting by Bob that includes a link to an off-site image hosted at a site controlled by Bob. That image, when loaded by Alice&#8217;s browser, will automatically send Bob&#8217;s site a referrer URL that includes the full token that is unique to Alice&#8217;s browser session with that forum. Armed with the referring URL&#8217;s token, Bob can then respond to the image request from Alice&#8217;s browser with a request to silently take action on that forum in Alice&#8217;s name.&#8221;</em></p>
<p>This interesting attack has been around since <a href="  http://www.tux.org/~peterw/csrf.txt">2001</a>. The two researchers brought the CSRF concept a bit farther by systematically packaging payloads based on the referring site.. so essentially, they can have attacks ready for particular websites. <em>&#8220;We&#8217;ve come up with a way to take those tokens and repackage them on a payload-per-domain basis, with different types of payloads based on the referring site,&#8221; Hamiel said. &#8220;So, if it&#8217;s linked off of Twitter, the tool might respond one way, or if it&#8217;s linked off of something like LinkedIn, it might respond another way.&#8221;</em> </p>
<p>This also gives attackers the ability to scale up attacks in a modular fashion so updates can be made to payloads on fly when referring websites make changes.</p>
<p>Just something to keep your eye on.. </p>
]]></content:encoded>
			<wfw:commentRss>http://jtrajewski.com/blog/2009/07/30/weaponizing-web-2-0/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hackers attack Large Hadron Collider</title>
		<link>http://jtrajewski.com/blog/2008/09/12/hackers-attack-large-hadron-collider/</link>
		<comments>http://jtrajewski.com/blog/2008/09/12/hackers-attack-large-hadron-collider/#comments</comments>
		<pubDate>Sat, 13 Sep 2008 01:20:32 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Cyber Terrorism]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[large hadron collider]]></category>
		<category><![CDATA[lhc]]></category>
		<category><![CDATA[network intrusion]]></category>

		<guid isPermaLink="false">http://jtrajewski.com/blog/?p=30</guid>
		<description><![CDATA[The Large Hadron Collider is a controversial international research/science project. A (group of) hacker(s) decided to hack into the system&#8230; The following is a quote from the article..
Scientists working at Cern, the organisation that runs the vast smasher, were worried about what the hackers could do because they were &#8220;one step away&#8221; from the computer control system [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.lhc.ac.uk/" target="_blank">Large Hadron Collider</a> is a <a href="http://www.businessweek.com/globalbiz/content/sep2008/gb20080910_005256.htm?chan=globalbiz_europe+index+page_top+stories" target="_blank">controversial </a>international research/science project. A (group of) hacker(s) decided to hack into the system&#8230; The following is a quote from the <a href="http://www.telegraph.co.uk/earth/main.jhtml?xml=/earth/2008/09/12/scicern212.xml" target="_blank">article</a>..</p>
<blockquote><p>Scientists working at Cern, the organisation that runs the vast smasher, were worried about what <strong>the hackers</strong> could do because they <strong>were &#8220;one step away&#8221; from the computer control system</strong> of one of the huge detectors of the machine, a vast magnet that weighs 12,500 tons, measuring around 21 metres in length and 15 metres wide/high.</p>
<p>If they had hacked into a second computer network, they could have turned off parts of the vast detector and, said the insider, &#8220;it is hard enough to make these things work if no one is messing with it.&#8221;</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://jtrajewski.com/blog/2008/09/12/hackers-attack-large-hadron-collider/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Discount retail website Geeks.com hacked</title>
		<link>http://jtrajewski.com/blog/2008/01/10/discount-retail-website-geekscom-hacked/</link>
		<comments>http://jtrajewski.com/blog/2008/01/10/discount-retail-website-geekscom-hacked/#comments</comments>
		<pubDate>Thu, 10 Jan 2008 17:30:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Cyber Terrorism]]></category>
		<category><![CDATA[geeks.com]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[hacker safe]]></category>

		<guid isPermaLink="false">http://jtrajewski.com/blog/2008/01/10/discount-retail-website-geekscom-hacked/</guid>
		<description><![CDATA[Geeks.com hacked
Check out the bottom of the page -&#8221;Hacker Safe - Tested Daily&#8221;
]]></description>
			<content:encoded><![CDATA[<p><a target="_blank" href="http://www.scmagazineus.com/Geekscom-hacked-customer-credit-card-numbers-possibly-accessed/article/100508/">Geeks.com hacked</a></p>
<p>Check out the <a target="_blank" href="http://geeks.com/">bottom of the page </a>-&#8221;Hacker Safe - Tested Daily&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://jtrajewski.com/blog/2008/01/10/discount-retail-website-geekscom-hacked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Chinese Cyber Ninja?</title>
		<link>http://jtrajewski.com/blog/2007/12/17/chinese-cyber-ninja/</link>
		<comments>http://jtrajewski.com/blog/2007/12/17/chinese-cyber-ninja/#comments</comments>
		<pubDate>Mon, 17 Dec 2007 18:19:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Cyber Terrorism]]></category>
		<category><![CDATA[beijing]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[ncph]]></category>
		<category><![CDATA[Network Crack Program Hacker]]></category>

		<guid isPermaLink="false">http://jtrajewski.com/blog/2007/12/17/chinese-cyber-ninja/</guid>
		<description><![CDATA[Very interesting article
 &#8221;China has long regarded cyberwarfare as a critical component of asymmetrical warfare in any future conflict with the U.S. From China&#8217;s perspective, it makes sense to use any means possible to counter America&#8217;s huge technological advantage. &#8220;
]]></description>
			<content:encoded><![CDATA[<p>Very interesting <a target="_blank" href="http://www.time.com/time/magazine/article/0,9171,1692063,00.html">article</a></p>
<p> &#8221;China has long regarded cyberwarfare as a critical component of asymmetrical warfare in any future conflict with the U.S. From China&#8217;s perspective, it makes sense to use any means possible to counter America&#8217;s huge technological advantage. &#8220;</p>
]]></content:encoded>
			<wfw:commentRss>http://jtrajewski.com/blog/2007/12/17/chinese-cyber-ninja/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Report: Cybercrime Stormed the Net in 2007</title>
		<link>http://jtrajewski.com/blog/2007/12/09/report-cybercrime-stormed-the-net-in-2007/</link>
		<comments>http://jtrajewski.com/blog/2007/12/09/report-cybercrime-stormed-the-net-in-2007/#comments</comments>
		<pubDate>Mon, 10 Dec 2007 00:55:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Cyber Terrorism]]></category>
		<category><![CDATA[2007]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[on the rise]]></category>

		<guid isPermaLink="false">http://jtrajewski.com/blog/2007/12/09/report-cybercrime-stormed-the-net-in-2007/</guid>
		<description><![CDATA[Ryan Singel reported that:
Anti-virus vendor F-Secure added 250,000 new signatures to its malware database this year &#8212; as many as the company added in its first 20 years combined.
]]></description>
			<content:encoded><![CDATA[<p>Ryan Singel <a target="_blank" href="http://www.wired.com/politics/security/news/2007/12/2007_security">reported </a>that:</p>
<p><em>Anti-virus vendor F-Secure added 250,000 new signatures to its malware database this year &#8212; as many as the company added in its first 20 years combined.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://jtrajewski.com/blog/2007/12/09/report-cybercrime-stormed-the-net-in-2007/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FBI: Millions of computers roped into criminal &#8216;robot networks&#8217;</title>
		<link>http://jtrajewski.com/blog/2007/11/29/fbi-millions-of-computers-roped-into-criminal-robot-networks/</link>
		<comments>http://jtrajewski.com/blog/2007/11/29/fbi-millions-of-computers-roped-into-criminal-robot-networks/#comments</comments>
		<pubDate>Fri, 30 Nov 2007 00:58:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Cyber Terrorism]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[cyber terrorisim]]></category>
		<category><![CDATA[fbi]]></category>

		<guid isPermaLink="false">http://jtrajewski.com/blog/2007/11/29/fbi-millions-of-computers-roped-into-criminal-robot-networks/</guid>
		<description><![CDATA[The FBI reported that botnets are responsible for over 20 million is losses and theft. Since the FBI&#8217;s creation of the &#8220;Bot Roast&#8221; task-force, 13 search warrants have been served across the world and eight individuals in the USA have been found guilty or indicted related to crimes involving botnets. 
&#8220;Today, botnets are the weapon of choice [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-family: Georgia">The <a target="_blank" href="http://www.fbi.gov/pressrel/pressrel07/botroast112907.htm"><font color="#800080">FBI reported</font></a> <a target="_blank" href="http://www.cnn.com/2007/TECH/11/29/fbi.botnets/index.html">that</a> <a target="_blank" href="http://en.wikipedia.org/wiki/Botnet"><font color="#800080">botnets</font></a> are responsible for over 20 million is losses and theft. Since the FBI&#8217;s creation of the &#8220;Bot Roast&#8221; task-force, 13 search warrants have been served across the world and eight individuals in the <st1:country-region w:st="on"><st1:place w:st="on">USA</st1:place></st1:country-region> have been found guilty or indicted related to crimes involving botnets. </span></p>
<p><span style="font-family: Georgia"><o:p></o:p></span><span style="font-family: Georgia">&#8220;Today, botnets are the weapon of choice of cyber criminals. They seek to conceal their criminal activities by using third party computers as vehicles for their crimes. In Bot Roast II, we see the diverse and complex nature of crimes that are being committed through the use of botnets,&#8221; said FBI Director Robert S. Mueller. &#8220;Despite this enormous challenge, we will continue to be aggressive in finding those responsible for attempting to exploit unknowing Internet users.&#8221;</span><span style="font-family: Georgia"><o:p></o:p></span><span style="font-family: Georgia">If you understand what botnets are, well, even if you don&#8217;t, this direct quote should be an eye opener -</span><span style="font-family: Georgia"><o:p></o:p></span><span style="font-family: Georgia">&#8220;Botnets are considered the Swiss Army knives of cyber crime. You name it, they can do it,&#8221; Mueller said during a speech at <st1:place w:st="on"><st1:placename w:st="on">Penn</st1:placename> <st1:placetype w:st="on">State</st1:placetype> <st1:placetype w:st="on">University</st1:placetype></st1:place>. &#8220;A botnet could shut down a power grid, flood an emergency call center with millions of spam messages or disable a military command post.&#8221;</span><span style="font-family: Georgia"><o:p></o:p></span><span style="font-family: Georgia">+8 for the good guys<o:p></o:p></span></p>
]]></content:encoded>
			<wfw:commentRss>http://jtrajewski.com/blog/2007/11/29/fbi-millions-of-computers-roped-into-criminal-robot-networks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hot microphone an Iphone -or- any smartphone for that matter</title>
		<link>http://jtrajewski.com/blog/2007/11/20/hot-microphone-an-iphone-or-any-smartphone-for-that-matter/</link>
		<comments>http://jtrajewski.com/blog/2007/11/20/hot-microphone-an-iphone-or-any-smartphone-for-that-matter/#comments</comments>
		<pubDate>Wed, 21 Nov 2007 02:28:31 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Cyber Terrorism]]></category>
		<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[mobile phone]]></category>
		<category><![CDATA[cell phone]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[hot mic a cell phone]]></category>
		<category><![CDATA[hot microphone]]></category>
		<category><![CDATA[iphone]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[smartphone]]></category>

		<guid isPermaLink="false">http://jtrajewski.com/blog/2007/11/20/hot-microphone-an-iphone-or-any-smartphone-for-that-matter/</guid>
		<description><![CDATA[This article detailed how to use metasploit to exploit an Iphone.  After sucessfully exploiting the Iphone, the hacker will have root access and can do virtually anything to the phone. In the article, the author uploads a &#8220;hot microphone&#8221; software application which is designed to record sounds unannounced to the Iphones owner and saves separate files which [...]]]></description>
			<content:encoded><![CDATA[<p style="line-height: 15.6pt"><span style="font-family: Georgia">This <a target="_blank" href="http://blog.fastcompany.com/archives/2007/11/19/technology_hacking_the_iphone_for_espionage.html"><font color="#800080">article </font></a>detailed how to use <a target="_blank" href="http://www.metasploit.com/"><font color="#800080">metasploit </font></a>to exploit an Iphone.  After sucessfully exploiting the Iphone, the hacker will have root access and can do virtually anything to the phone. In the article, the author uploads a &#8220;hot microphone&#8221; software application which is designed to record sounds unannounced to the Iphones owner and saves separate files which the attacker can retrieve at a later date. If your one of those that works in a black faraday building or on occasion wears a tin foil hat, you might want to “check” your mobile device at the door when you’re talking about sensitive information. </span></p>
<p><span style="font-family: Georgia">If you haven’t seen mobile device &#8220;hacking&#8221; then this should be an eye opener for you. I hope everyone is up to speed on personal device security.<span>  </span>Sshould you feel the need to &#8220;refresh your memory&#8221;, <a target="_blank" href="http://www.amazon.com/Blackjacking-Security-Threats-BlackBerry-Enterprise/dp/0470127546/ref=pd_bbs_sr_1?ie=UTF8&amp;s=books&amp;qid=1195584850&amp;sr=8-1"><font color="#800080">this book</font></a> is a good start. Happy reading.<o:p></o:p></span></p>
]]></content:encoded>
			<wfw:commentRss>http://jtrajewski.com/blog/2007/11/20/hot-microphone-an-iphone-or-any-smartphone-for-that-matter/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sunday&#8217;s Forecast Calls For Network Outages</title>
		<link>http://jtrajewski.com/blog/2007/11/09/forecast-network-outages/</link>
		<comments>http://jtrajewski.com/blog/2007/11/09/forecast-network-outages/#comments</comments>
		<pubDate>Fri, 09 Nov 2007 15:32:05 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Cyber Terrorism]]></category>
		<category><![CDATA[11/11/2007]]></category>
		<category><![CDATA[Jihad]]></category>
		<category><![CDATA[network attack]]></category>

		<guid isPermaLink="false">http://jtrajewski.com/blog/2007/11/09/forecast-network-outages/</guid>
		<description><![CDATA[An article on Wired describes the suspected threat of a Jihad cyber attack on 11/11/2007.
Was the backbone network outage  on 11/8/2008  because of a &#8220;data migration&#8221; or was it a &#8220;test run&#8221;?
]]></description>
			<content:encoded><![CDATA[<p>An article on <a target="_blank" href="http://blog.wired.com/27bstroke6/2007/10/terrorists-with.html">Wired</a> describes the suspected threat of a Jihad cyber attack on 11/11/2007.</p>
<p>Was the <a href="http://www.eweek.com/article2/0,1895,2214230,00.asp">backbone network outage </a> on 11/8/2008  because of a &#8220;data migration&#8221; or was it a &#8220;test run&#8221;?</p>
]]></content:encoded>
			<wfw:commentRss>http://jtrajewski.com/blog/2007/11/09/forecast-network-outages/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
