<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>GrayHat Forensics &#187; Digital Forensics and Security</title>
	<atom:link href="http://grayhatforensics.secbible.org/index.php/category/digital-forensics-and-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://grayhatforensics.secbible.org</link>
	<description>The Adventures of a GrayHat in Digital Forensics</description>
	<lastBuildDate>Sun, 07 Mar 2010 07:09:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Dead or alive? This is the answer.</title>
		<link>http://grayhatforensics.secbible.org/index.php/2010/03/07/dead-or-alive-this-is-the-answer/</link>
		<comments>http://grayhatforensics.secbible.org/index.php/2010/03/07/dead-or-alive-this-is-the-answer/#comments</comments>
		<pubDate>Sun, 07 Mar 2010 07:09:12 +0000</pubDate>
		<dc:creator>DarkSYN</dc:creator>
				<category><![CDATA[Digital Forensics and Security]]></category>
		<category><![CDATA[Forensics News]]></category>

		<guid isPermaLink="false">http://grayhatforensics.secbible.org/?p=36</guid>
		<description><![CDATA[All those who thought the GrayHat Forensics blog (or myself) died, rejoice! No, the blog isn&#8217;t dead, it was just resting for a period of time (admittedly a long one) while I was trying to put some semblance of an order to a rapidly-galloping-uncontrollably-away PhD. So, after about a year of working frantically at various [...]]]></description>
			<content:encoded><![CDATA[<p>All those who thought the GrayHat Forensics blog (or myself) died, rejoice!</p>
<p>No, the blog isn&#8217;t dead, it was just resting for a period of time (admittedly a long one) while I was trying to put some semblance of an order to a rapidly-galloping-uncontrollably-away PhD.</p>
<p>So, after about a year of working frantically at various issues, solving (or attempting to solve) problems that should not have existed had I yelled when I needed to yell, changing supervisors and departments in exactly the middle of my PhD, gathering data that needed gathering (My most sincere thanks to Zapotek of segfault.gr for his assistance in this!), teaching a lovely and amazingly smart and perceptive bunch of 3rd &amp; 2nd year BSc Digital Forensics students, getting taught the Forensic Way by some amazing Forensic Science lecturers, and making drastic changes to my PhD&#8217;s structure, content, design and implementation details, I&#8217;m finally where I should be!</p>
<p>So, with a PhD software prototype FINALLY written and evaluated, proceeding to the actual implementation of my PhD&#8217;s full software (more on that later, both here and in publications to be written), I now am starting to once again have the time and the disposition to concentrate on my pet projects, such as keeping this blog moving forward.</p>
<p>Stories and comments on stories exist and are in the process of being thought through and further investigated, so keep checking back, cause they&#8217;ll start cropping up over the next few days (worst case scenario: 1-2 weeks) once more!</p>
<p>Until then, stay safe out there and keep digitally forensicating!!</p>
<p>DarkSYN</p>
]]></content:encoded>
			<wfw:commentRss>http://grayhatforensics.secbible.org/index.php/2010/03/07/dead-or-alive-this-is-the-answer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>GST strikes again, this time in both English &amp; Greek!</title>
		<link>http://grayhatforensics.secbible.org/index.php/2008/11/30/gst-strikes-again-this-time-in-both-english-greek/</link>
		<comments>http://grayhatforensics.secbible.org/index.php/2008/11/30/gst-strikes-again-this-time-in-both-english-greek/#comments</comments>
		<pubDate>Sun, 30 Nov 2008 04:08:03 +0000</pubDate>
		<dc:creator>DarkSYN</dc:creator>
				<category><![CDATA[Digital Forensics and Security]]></category>
		<category><![CDATA[aegeanportal.org]]></category>
		<category><![CDATA[CERE]]></category>
		<category><![CDATA[CERN]]></category>
		<category><![CDATA[defacement]]></category>
		<category><![CDATA[Fish]]></category>
		<category><![CDATA[GST]]></category>
		<category><![CDATA[PHP++]]></category>
		<category><![CDATA[web-attacks]]></category>

		<guid isPermaLink="false">http://grayhatforensics.secbible.org/?p=32</guid>
		<description><![CDATA[Just prior to hitting the pillows, a traceback arrived for my inspection from the PHP++ blog. Fish (the author of the said blog) reports that the GST stroke again, this time defacing a &#8220;I don&#8217;t know where the hell they found that&#8221;-type website, as reported in the following blog post and left a message in [...]]]></description>
			<content:encoded><![CDATA[<p>Just prior to hitting the pillows, a traceback arrived for my inspection from the <a title="PHP++ Blog" href="http://www.rhapsody.intheblackbox.com/blog/" target="_blank">PHP++</a> blog.</p>
<p>Fish (the author of the said blog) reports that the GST stroke again, this time defacing a &#8220;I don&#8217;t know where the hell they found that&#8221;-type website, as reported in the following <a title="GST - Just another brick on the greek wall of shame" href="http://www.rhapsody.intheblackbox.com/blog/?p=29" target="_blank">blog post</a> and left a message in both the Greek and the English languages (with a rather helpful JavaScript button to point you to your preferred language).</p>
<p>The Greek language version of the text is surprisingly well-written, compared to the CERN one (different author, perhaps?). The English language version is written in the typical Just-out-of-highschool-Greeks-writing-in-the-English-language style.</p>
<p>In it, summarily stated, they rant and rave about the following: The &#8220;hack&#8221; of Greekhackers.gr by some lame Turkish group (and the lameness of the whole Greece vs Turkey thing (which I too think is too lame for the 21st century)), their previous defacement of one of the CERN&#8217;s LHC webservers and the media coverage (foreign and Greek) on the whole issue, followed by some standard &#8220;greets and shouts to&#8221; some site and the security scene.</p>
<p>I won&#8217;t translate, this time, as you have both versions at your disposal through the screenshots of the <a title="GST Deface Starting Page" href="http://grayhatforensics.secbible.org/uploads/GST-HackStart.png" target="_blank">starting page</a>, the <a title="GST Deface Greek Language" href="http://grayhatforensics.secbible.org/uploads/GST-HackEl.png">Greek language page</a> and the <a title="GST Deface English Language" href="http://grayhatforensics.secbible.org/uploads/GST-HackEng.png" target="_blank">English language page</a>.</p>
<p>My only comment is the following: Looking at the source code of the page, which I&#8217;m linking <a title="Source Code of the defaced page" href="http://grayhatforensics.secbible.org/uploads/info.txt" target="_blank">here</a>, I can see that the GST logo was linked from the following address &#8220;http://www.cere.gr/upload/logoGST.png&#8221; ( where it appears as &lt;img src=&#8221;http://www.cere.gr/upload/logoGST.png&#8221;&gt;) which belongs to the Center for Russia and Eurasia (http://www.cere.gr/).</p>
<p>This possibly indicates that the attackers used CERE&#8217;s webserver as a possible staging area for at least part of their attack. Which would possibly mean that we&#8217;re dealing with two compromises. The one at http://www.aegeanportal.org and the one at http://www.cere.gr. I cannot, of course, in any way/shape/form confirm this is truly the case, as I do not have access to either of the said servers, but it seems a viable hypothesis to make. So, it might be prudent for the administrators of both web-sites to at the very least have a look at their webserver/hosting space logfiles for possible traces of the attackers. It might also be prudent to check the webserver logfiles for IP addresses accessing the info.html file in the first 5-10 minutes since the file was placed there (check filename timestamps for the exact dates/times/etc, and compensate for read/write/access times depending on the OS the servers are running).</p>
<p>I should note, here, that in my personal opinion, website defacement is nothing more than an act of vandalism (in the same way sprayed messages on busses etc are vandalism).</p>
<p>I should also note that, again in my personal opinion, the whole CERN LHC defacement was blown WAY out of proportion by the international media/press. This, and ONLY this, is why I stayed up half the night translating! And, to make matters worse, the Greek press/media further disgraced themselves by mistranslating the already mistranslated articles instead of reading the page which was, after all, written in the Greek language.</p>
]]></content:encoded>
			<wfw:commentRss>http://grayhatforensics.secbible.org/index.php/2008/11/30/gst-strikes-again-this-time-in-both-english-greek/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>&#8220;Get safe online&#8221; how?</title>
		<link>http://grayhatforensics.secbible.org/index.php/2008/11/18/get-safe-online-how/</link>
		<comments>http://grayhatforensics.secbible.org/index.php/2008/11/18/get-safe-online-how/#comments</comments>
		<pubDate>Tue, 18 Nov 2008 01:10:07 +0000</pubDate>
		<dc:creator>DarkSYN</dc:creator>
				<category><![CDATA[Digital Forensics and Security]]></category>
		<category><![CDATA[CMA]]></category>
		<category><![CDATA[DDoS]]></category>
		<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[DoS]]></category>
		<category><![CDATA[getsafeonline]]></category>
		<category><![CDATA[network security]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://grayhatforensics.secbible.org/?p=26</guid>
		<description><![CDATA[Just a couple of thoughts, as I&#8217;m resting after a long long time working on my ongoing PhD and the new CSI module I&#8217;m taking&#8230; The &#8220;Get Safe Online&#8221; (http://www.getsafeonline.com) week-long campaign by the British government began this week&#8230; The page (and campaign) itself supposedly deals with some rather interesting questions by providing rather simplified [...]]]></description>
			<content:encoded><![CDATA[<p>Just a couple of thoughts, as I&#8217;m resting after a long long time working on my ongoing PhD and the new CSI module I&#8217;m taking&#8230;</p>
<p>The &#8220;Get Safe Online&#8221; (http://www.getsafeonline.com) week-long campaign by the British government began this week&#8230;</p>
<p>The page (and campaign) itself supposedly deals with some rather interesting questions by providing rather simplified (but ones which I think even the PC-World-certified public in this country can somewhat understand) answers&#8230;</p>
<p>Don&#8217;t get me wrong, here&#8230;I really really think its a good idea and a lovely way to raise the UK public&#8217;s non-existent security consciousness, devoting a whole week (I mean, come on, JUST a week??!!) (and not advertising it) to security.</p>
<p>Or, rather, it would be a good idea if the Computer Misuse Act had not been recently ammended to be a security-research-killer (good The Register coverage: http://www.theregister.co.uk/2008/11/14/dos_criminalised/).</p>
<p>So, other than criminalising DoS/DDoS attacks, which is pointless (since they can&#8217;t actually find the attackers, DUH! And if, in some miraculous way they do, they don&#8217;t have the firepower to take them on!!) in a knee-jerk-reaction sort of way, they&#8217;ve managed to also criminalise genuine and legitimate network security research and network security development.</p>
<p>From The Register&#8217;s article on the Computer Misuse Act ammendments: &#8220;The Computer Misuse Act has also been changed to make it an offence to make, adapt, supply or offer to supply any article which is &#8220;likely to be used to commit, or to assist in the commission of, [a hacking or unauthorised modification or DoS] offence&#8221;. It is also an offence to supply an article &#8220;believing that it is likely&#8221; to be used to commit such an offence.</p>
<p>The meaning of &#8220;article&#8221; includes any program or data. The provisions would cover the supply of DoS or virus toolkits. Anyone convicted of breaking this section of the Act could be jailed for up to two years.&#8221; (from http://www.theregister.co.uk/2008/11/14/dos_criminalised/)</p>
<p>But the Police and Justice Act 2006 (with the mods enabled) reads:</p>
<p>&#8221;</p>
<p><span id="pt5-pb2-l1g37" class="LegDS LegP1No">37</span> <span class="LegDS LegP1GroupTitle">Making, supplying or obtaining articles for use in computer misuse offences</span></p>
<p id="pt5-pb2-l1g37-l1p1" class="LegRHS LegP1Text">After section 3 of the 1990 Act there is inserted—</p>
<h5 class="LegClearFix LegP1ContainerFirst"><span id="Legislation-IDAMWMLB" class="LegDS LegP1NoC1Amend"><span id="Legislation-IDASWMLB" class="LegAmendQuote">“</span>3A</span> <span class="LegDS LegP1GroupTitleFirstC1Amend">Making, supplying or obtaining articles for use in offence under section 1 or 3</span></h5>
<p id="Legislation-IDAYWMLB" class="LegClearFix LegP2Container"><span class="LegDS LegLHS LegP2NoC1Amend">(1)</span> <span class="LegDS LegRHS LegP2TextC1Amend">A person is guilty of an offence if he makes, adapts, supplies or offers to supply any article intending it to be used to commit, or to assist in the commission of, an offence under section 1 or 3.</span></p>
<p id="Legislation-IDACXMLB" class="LegClearFix LegP2Container"><span class="LegDS LegLHS LegP2NoC1Amend">(2)</span> <span class="LegDS LegRHS LegP2TextC1Amend">A person is guilty of an offence if he supplies or offers to supply any article believing that it is likely to be used to commit, or to assist in the commission of, an offence under section 1 or 3.</span></p>
<p id="Legislation-IDAMXMLB" class="LegClearFix LegP2Container"><span class="LegDS LegLHS LegP2NoC1Amend">(3)</span> <span class="LegDS LegRHS LegP2TextC1Amend">A person is guilty of an offence if he obtains any article with a view to its being supplied for use to commit, or to assist in the commission of, an offence under section 1 or 3.</span></p>
<p id="Legislation-IDAWXMLB" class="LegClearFix LegP2Container"><span class="LegDS LegLHS LegP2NoC1Amend">(4)</span> <span class="LegDS LegRHS LegP2TextC1Amend">In this section “article” includes any program or data held in electronic form.</span></p>
<p id="Legislation-IDADYMLB" class="LegClearFix LegP2Container"><span class="LegDS LegLHS LegP2NoC1Amend">(5)</span> <span class="LegDS LegRHS LegP2TextC1Amend">A person guilty of an offence under this section shall be liable—</span></p>
<p id="Legislation-IDALYMLB" class="LegClearFix LegP3Container"><span class="LegDS LegLHS LegP3NoC1Amend">(a)</span> <span class="LegDS LegRHS LegP3TextC1Amend">on summary conviction in England and Wales, to imprisonment for a term not exceeding 12 months or to a fine not exceeding the statutory maximum or to both;</span></p>
<p id="Legislation-IDAVYMLB" class="LegClearFix LegP3Container"><span class="LegDS LegLHS LegP3NoC1Amend">(b)</span> <span class="LegDS LegRHS LegP3TextC1Amend">on summary conviction in Scotland, to imprisonment for a term not exceeding six months or to a fine not exceeding the statutory maximum or to both;</span></p>
<p id="Legislation-IDA5YMLB" class="LegClearFix LegP3Container"><span class="LegDS LegLHS LegP3NoC1Amend">(c)</span> <span class="LegDS LegRHS LegP3TextC1Amend">on conviction on indictment, to imprisonment for a term not exceeding two years or to a fine or to both.<span class="LegAmendQuote">”</span></span></p>
<p>&#8221; (http://www.opsi.gov.uk/Acts/acts2006/ukpga_20060048_en_7#pt5-pb2-l1g35)</p>
<p>So (and please correct me if I&#8217;m getting/reading this wrong!!), its not JUST about DoS/DDoS/Virii tools/toolkits (ummm&#8230;.eg. the ping utility???!!).</p>
<p>And, of course, this can be easily, if converted into lawyerspeak (legalese) by the CPS (Crown Prosecution Service), be applied to pretty much everything under the sun, if my Legal Issues and Evidence Recovery and my CSI training taught me anything&#8230;</p>
<p>So, how would they actually trial it by fire (test the case in a court of law)? Easiest and by far the most productive way would be to nab some sort of newbie (of any age) who accidentally opened an e-mail attachment containing a virus or downloaded a bad bad <span style="text-decoration: line-through;">security</span> <span style="text-decoration: line-through;">tool</span> virus/DDoS toolkit to check their home network, villify them, find a technically illiterate jury (dead easy, in this country) take them through the painful experience of a trial, throw them with an Anti-Social Behavior Order (all the rage in the UK, nowadays) or some other &#8220;caution&#8221; for being a first offender (they wouldn&#8217;t actually dare to put them in prison, would they?), slap a fine on them, destroy their lives, and ZAPPO instant prior casework is established!!!</p>
<p>What this will do to legitimate security research conducted by people without the backing of big security software houses? Most likely either drive them underground (VERY deep underground) or drive them off this country&#8230; What this would do to academic research? Gods only know!</p>
<p>And, just as a reminder, these lone and unbacked legitimate security researchers are the ones who actually invent the algorithms, write the code, and test and debug the code that ultimately finds its way to the big security firms&#8217; labs and thus products&#8230; Without them, how will the public &#8220;Get safe online&#8221;? Buy a copy of a big-name brand internet security suit, install it on their Windows XP/Vista hole-ridden computers (after cleaning them up from the 999*10^100 different types of virii they contain) and be made to feel safe in their little snake-oil secure environment.</p>
<p>If my PhD wasn&#8217;t on the line, I&#8217;d sit back and have a good laugh about it. Since it is, and since I&#8217;d have to (as a DF Scientist/Investigator?) shift through legitimate security researchers&#8217; stuff to find the bad bad <span style="text-decoration: line-through;">security tool</span> virus or DoS/DDoS toolkit sometime in the future&#8230;. I will just sit back, pray to my deity it all starts happening AFTER I get my PhD, and watch the steady and unavoidable death of Network Security Research in this country I&#8217;ve up till now chosen to live and work in&#8230;.</p>
<p>As always, flames &gt; /dev/null !</p>
]]></content:encoded>
			<wfw:commentRss>http://grayhatforensics.secbible.org/index.php/2008/11/18/get-safe-online-how/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Uberdatabase dreams and the harsh reality</title>
		<link>http://grayhatforensics.secbible.org/index.php/2008/10/10/uberdatabase-dreams-and-the-harsh-reality/</link>
		<comments>http://grayhatforensics.secbible.org/index.php/2008/10/10/uberdatabase-dreams-and-the-harsh-reality/#comments</comments>
		<pubDate>Fri, 10 Oct 2008 09:22:46 +0000</pubDate>
		<dc:creator>DarkSYN</dc:creator>
				<category><![CDATA[Digital Forensics and Security]]></category>
		<category><![CDATA[base-rate fallacy]]></category>
		<category><![CDATA[Bayesian]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[Intrusion Detection]]></category>
		<category><![CDATA[Statistical]]></category>
		<category><![CDATA[Type I errors]]></category>
		<category><![CDATA[Type II errors]]></category>
		<category><![CDATA[uberdatabase]]></category>
		<category><![CDATA[UK]]></category>

		<guid isPermaLink="false">http://grayhatforensics.secbible.org/?p=21</guid>
		<description><![CDATA[After a couple of insane weeks filled with a Progression Report to be delivered, loads of lecturing work and a nice bout of flu that has me sitting somewhat sleepless on the keyboard this lovely Friday morning, GrayHat Forensics is back. Today&#8217;s topic? Uberdatabases: State/Country-wide government databases storing phonecall-related information (and conversations), texts, e-mail, IM [...]]]></description>
			<content:encoded><![CDATA[<p>After a couple of insane weeks filled with a Progression Report to be delivered, loads of lecturing work and a nice bout of flu that has me sitting somewhat sleepless on the keyboard this lovely Friday morning, GrayHat Forensics is back.</p>
<p>Today&#8217;s topic? Uberdatabases: State/Country-wide government databases storing phonecall-related information (and conversations), texts, e-mail, IM messages, web browsing histories etc to protect their citizens from the threat of the T-word and all those other lesser evils which governments believe they can cure out of society through monitoring and witch-hunting.</p>
<p>Recently, a study by the National Research Council in the US (http://news.cnet.com/8301-13578_3-10059987-38.html?part=rss&amp;subj=news&amp;tag=2547-1_3-0-20 and http://www.theregister.co.uk/2008/10/08/us_gov_data_mining_report/) essentially stated what a large number of people in the NetSec community have been saying for a number of years: Pattern-matching/data mining to spot T-word people will not really work.</p>
<p>This comes at the same time that the UK government is making yet another big push for the full-scale interception of pretty much everything in the way of communication and storing it in an uberdatabase, as reported in TheRegister (http://www.theregister.co.uk/2008/10/07/detica_interception_modernisation/), after deciding it will not do it (http://www.theregister.co.uk/2008/09/25/interception_modernisation_bill/) after all.</p>
<p>The problem? The rate of false-positives and false-negatives, otherwise known (in statistics) as Type I and Type II errors. This wikipedia article (http://en.wikipedia.org/wiki/Type_I_and_type_II_errors) explains the whole concept rather nicely, and has a most informative research literature backing it.</p>
<p>Essentially: Type I errors refer to the improper rejection of the null hypothesis, and Type II errors refer to the improper acceptance of the null hypothesis (http://en.wikipedia.org/wiki/Null_hypothesis).</p>
<p>So, then, trying not to turn this into either a statistics lecture or a conference paper while at the same time trying to pass on the gist of the whole process, in order to create a model that will fit the data in a reasonable fashion and will then be able to infer relationships and forecast future trends based on past experience (data), we need to understand the subject, formulate a sound and reasonable null hypothesis, and then sit down, study the data and the subject area and remove all non-explanatory variables (the variables which do not help us explain what we see), which will leave us with a simplified model which SHOULD (but might not, in which case its &#8220;back to the drawing board&#8221;) fit the data to some degree.</p>
<p>Problem in this instance is: What on earth is the null hypothesis? And what can we consider to be the explanatory variables in the model that we cannot as yet have because we don&#8217;t know the null hypothesis OR the subject area?</p>
<p>Oh, I&#8217;ll grant you, there&#8217;s any number of &#8220;experts&#8221; in the subject area we are considering, and a search in Amazon will give us a distressingly large number of &#8220;books&#8221; on the subject area&#8230;All of which are a rather complete and utter waste of time and money for those of us who have been educated and trained to sit down and work with data.</p>
<p>In his paper on the base-rate fallacy and the difficulty of intrusion detection (http://portal.acm.org/citation.cfm?id=357849), Axelsson S. compares anomaly and signature detection Intrusion Detection Systems against a Bayesian base-rate fallacy model which models the rate of occurence of false positives/negatives. While his conclusions deal with Intrusion Detection Systems, his Bayesian base-race fallacy model is a more-than-acceptable standard through which we can determine the effectiveness of an Intrusion Detection System, and the standards this paper sets can and should be adaptable to the current problem with regards to data mining and pattern analysis, and it can and should form the basis of a standard against which all these different &#8220;solutions&#8221; that aim to find the perfect model of what consists a t-word activity should be like.</p>
<p>But to do that we need to properly and SCIENTIFICALLY (and I MEAN mathematically and statistically) define the subject area!!! And the problem here, of course, is that we really really cannot do that, because the subject area is by far too abstract to be defined.</p>
<p>Result: These uberdatabases will do pretty much nothing to detect occurences related to the subject area. Ahhh, but they (these uberdatabases) CAN &amp; WILL find other uses, extending the surveillance capabilities to include any number of extraneous things and thus do other interesting things.</p>
<p>Any network administrator of moderate intellect knows that putting all of your eggs in one basket just creates a single point of failure. So, not only will these UK and US Uberdatabases will do pretty much nothing to infer and forecast T-word occurences, but they would be so badly succeptible to abuse, and so invitingly a target for the real bad-guys to get at.</p>
<p>Note: All those with a maths and stats background, please forgive my oversimplified explanations of Type I &amp; II problems and the statistical analysis process, but I found no better way of reducing the complexity of the subject area to allow the public to understand the whole concept without turning this into a conference paper.</p>
]]></content:encoded>
			<wfw:commentRss>http://grayhatforensics.secbible.org/index.php/2008/10/10/uberdatabase-dreams-and-the-harsh-reality/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Greek &#8220;hackers&#8221; deface CERN&#8217;s LHC-related website</title>
		<link>http://grayhatforensics.secbible.org/index.php/2008/09/13/greek-hackers-deface-cerns-lhc-related-website/</link>
		<comments>http://grayhatforensics.secbible.org/index.php/2008/09/13/greek-hackers-deface-cerns-lhc-related-website/#comments</comments>
		<pubDate>Sat, 13 Sep 2008 01:24:00 +0000</pubDate>
		<dc:creator>DarkSYN</dc:creator>
				<category><![CDATA[Digital Forensics and Security]]></category>
		<category><![CDATA[CERN]]></category>
		<category><![CDATA[defacement]]></category>
		<category><![CDATA[GST]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[LHC]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://grayhatforensics.secbible.org/?p=10</guid>
		<description><![CDATA[It may surprise the audience how someone who&#8217;s forehead-deep in writing their research report under a tight deadline can find the time to keep an ear out on the whispers of the underground community, but interesting things do come out of there. Note: I may be a Digital Forensic researcher, but I am ALSO a [...]]]></description>
			<content:encoded><![CDATA[<p>It may surprise the audience how someone who&#8217;s forehead-deep in writing their research report under a tight deadline can find the time to keep an ear out on the whispers of the underground community, but interesting things do come out of there.</p>
<p>Note: I may be a Digital Forensic researcher, but I am ALSO a Network Security researcher. As such, its my job and responsibility to know these things.</p>
<p>Such is the case of this interesting bit of news which came to surface only today, but which I&#8217;ve been told about a few hours after it happened&#8230;</p>
<p>Apparently, then, a Greek hacking group calling themselves Greek Security Team defaced the lxplus.cern.ch web server (mode of entry unknown at present time) and replaced the main page with a statement in the Greek language.</p>
<p>Although the IT Pro website and the Daily Telegraph posted articles on this, which can be found in http://www.itpro.co.uk/606150/cerns-lhc-network-hit-by-greek-hackers and http://www.telegraph.co.uk/earth/main.jhtml?xml=/earth/2008/09/12/scicern312.xml , they contain quite a few inaccuracies with regards to the content of the speech and the purpose of the hack.</p>
<div class="wp-caption alignnone" style="width: 468px"><a href="http://grayhatforensics.secbible.org/uploads/s3jed2dn4erowhksu2ql.png"><img title="GSTs CERN LHC hack" src="http://grayhatforensics.secbible.org/uploads/s3jed2dn4erowhksu2ql.png" alt="GSTs CERN LHC hack" width="458" height="614" /></a><p class="wp-caption-text">GST&#39;s CERN LHC hack</p></div>
<p>So, given that I despise misinformation, lets see what they ACTUALLY said in there!!</p>
<p>Line-by-line translation:</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>10/09/08</p>
<p>At this time an experiment attempt is being performed in CERN.</p>
<p>The reason we chose this page is to remind you of some things.</p>
<p>It [the deface] did not happen due to a conflict between us and CERN&#8217;s system administration team but because of the expected increase in number of visitors in the page in the next few days.</p>
<p>Some data from the base:</p>
<p>[...a c/p of the process listing follows...]</p>
<p>and some e-mails:</p>
<p>[...a c/p of e-mails follows...]</p>
<p>The ** have simply been placed so that we don&#8217;t expose people who has done nothing to anger us.</p>
<p>As we stated in the preamble, we do not want to destroy either the [operating] system or the website&#8230; Our purpose is to show, through action, our reaction to a lot of &#8220;active&#8221; members of the GHS [Greek Hacking Scene] which has become arrogant (litteral translation of the phrase &#8220;Καβαλήσει το καλάμι&#8221;, riding the stick) without offering anything&#8230;</p>
<p>Stupid cliques get created simply to insult and cause trouble (translated from &#8220;τραμπούκος&#8221;, insulting troublemaker, &#8220;τραμπουκίζω&#8221;, cause insult &amp; trouble) through either words or IRC channel banning people who are not considered, by them or their flunkies, worthy of their knowlege and their image.</p>
<p>Some others, the 1337 (leet, elite) of the &#8220;scene&#8221;, only chat over cups of coffee and don&#8217;t do anything practical, as they are good at gossiping&#8230;but of &#8220;security&#8221;&#8230;what is that? we are 2600&#8230;don&#8217;t mess with us.</p>
<p>IRRELEVANT AND QUAINT!</p>
<p>Stop salivating and licking and start keyboarding! But, of course, criticising is easy especially when you have many 20year-olds around whispering &#8220;2600&#8243;-&#8221;2600&#8243;. Get yourselves in insomnia.gr and start gossiping (litteral translation of &#8220;θάβετε με μεγάλο φτυάρι&#8221;, burrying people through gossiping with a big shovel)&#8230;But it will also bear the seal of GST.</p>
<p>We are everywhere&#8230;because unlike you we don&#8217;t spend our nights writing songs or &#8220;rapping&#8221; away in public squares&#8230;nor do we laugh at what we cannot touch&#8230;</p>
<p>We don&#8217;t publicly expose you (translated from &#8220;ξεβρακώνουμε&#8221;, pulling your underpants down, Greek expression) because we don&#8217;t want to see you all running like mad and naked trying to find a hiding place and because we are not like you. You should, however, expect the response when you were laughing at things you had never considered doing&#8230;but we have spent enough time dealing with a bunch of schoolkids who learned about hacking through Hollywood movies and their dumb American culture of the neo-geek who reads hacking magazines while trying to crack his girlfriend&#8217;s e-mail account to see if she&#8217;s being unfaithful and has Linux on dual-boot to pose (translated from &#8220;ψαρώνει&#8221;, Greek expression) to his mates who also read neo-hacking mania-inspired magazines.</p>
<p>The entire Greek Internet is riddled with holes&#8230;some of the biggest government sites don&#8217;t even know the term &#8220;security&#8221;&#8230;since they assign the design of their sites to irrelevant companies.</p>
<p>SECURITY IS NOT CONDUCTED BY PAY-OFFS.</p>
<p>We are everywhere&#8230;</p>
<p>We salute the real hobbyists and the fanciers of the art of computers. Some old ones who stopped because they were bored and tired not with this art but with the stuck-up attitude (translated from &#8220;κόμπλεξ&#8221;) of all those &#8220;specialists&#8221; in the field!! And the young ones who don&#8217;t say many words but work with their heads down because what they care about is knowledge, and only knowledge!!</p>
<p>Dear CERN admins we patched the biggest BUG in your webpage so it doesn&#8217;t turn into a Dork and gets defaced every day with the silliness of every wannabe hacker.</p>
<p>Don&#8217;t try to find us&#8230;We will find you&#8230;pretty soon!!!</p>
<p>Tnx Mr Server [lxplus.cern.ch]</p>
<p>_Greek Security Team_ &#8211; [.GST]</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>IMPORTANT NOTE 1: This was simply a Greek-to-English language translation of the statement. DO NOT shoot the messenger (me)!!!!</p>
<p>IMPORTANT NOTE 2: I neither condone nor share GST&#8217;s sentiments. Nor am I in the job of publishing defaced websites (eg like zone-h). I am only writing this because the ITPro and Daily Telegraph articles were, in my honest opinion, mistaken about what this whole defacement represented.</p>
<p>So, then&#8230;. This was not about the GST warning CERN, there was no altruism involved&#8230;.</p>
<p>What I can safely say (without it getting a PG rating) is that they just wanted to impress the Greek underground scene with a &#8220;high profile&#8221; hack. For the love of whichever deity you wish to name, they wrote the whole thing in the Greek language!!! Their ONLY target audience was, therefore the Greek skiddies (script kiddies).</p>
<p>Furthermore, you will notice references to purely Greek websites and IRC servers and channels. Which leads us to the conclusion that there were simply venting spleen at their opponents, whoever those people are.</p>
<p>Clearly, then, Mr Highfield and Mr Wattanajantra, the GST group didn&#8217;t actually describe CERN&#8217;s technicians as high-school kids (I don&#8217;t remember seeing that word in the text, but I do remember GST saying they had nothing against the aforementioned technicians!). Nor did they refrain from pulling CERN&#8217;s technicians pants down. Nor was there any political, religious, fear-filled or whatever of this sort meaning in what they said. Nor did they target internal servers. It was a web server they defaced.</p>
<p>A couple of comments with regards to what those people (the GST) said, and I&#8217;m done for the night.</p>
<p>During the last few years, the Greek Hacking Underground has been plagued by what I would call &#8220;turf wars&#8221; between rival script kiddie groups/crews waged on GRNet IRC (http://www.irc.gr) channels and Greek Hacking and Security-related discussion forums. The reasons for those wars are, as always, who&#8217;s the cooler of the lot. Furthermore, these &#8220;turf wars&#8221; managed to anger the old-school generation, which ultimately resulted in bigger chaos, as all sides started fighting with each other. The old-schools told the skiddies they were lamers, the skiddies told the old-schools they were a whole lot of bad things. Some of this spilled into the outside world in the form of speech-oriented defacements.</p>
<p>It is, thus, unfortunate that CERN&#8217;s LHC webserver got hacked as a result of the aforementioned &#8220;turf wars&#8221;, but they too are responsible for the mess they found themselves in. I sincerely hope they learn from this incident and make sure to, in future, secure and patch even those servers which are at the outside tier of their network and thus visible to the public.</p>
<p>As I keep telling my students, Security and Forensics ones alike, servers on the outside of a DMZ may be less important but they too require TLC (Tender Loving Care)!!! <img src='http://grayhatforensics.secbible.org/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://grayhatforensics.secbible.org/index.php/2008/09/13/greek-hackers-deface-cerns-lhc-related-website/feed/</wfw:commentRss>
		<slash:comments>22</slash:comments>
		</item>
	</channel>
</rss>
