- +
Your World. . . Hacked 02 October, 2007 10:51:23
As your business becomes more collaborative and global, the risks to your company’s trade secrets rise proportionally. Fortunately, there are new strategies to protect the data that allows you to competeThe call to Bob Bailey, an IT executive with a major US government contractor, came on an otherwise ordinary day in October 2003. "Why are you attacking us?" demanded the caller, an IT leader with a Silicon Valley manufacturer. He wanted to know why Bailey's company had launched a denial-of-service attack against his network - +
How to Save the Internet 12 May, 2005 10:59:59
Imagine labels on software like those on cigarettes - Infosecurity General's Warning: The use of software and hardware that is not certified secure can harm your system and other people's systems, and you may be held liable for those damages.Computing on the Net is heading for a fall because security is a joke. So we summoned the best minds to see if we could put Humpty back together again. - +
Gen X Marks Its Spot 06 October, 2004 11:44:02
Call them slackers at your peril. Chances are good that somewhere in your company there's a generation X employee who wants your job . . . - +
The SCO Slugfest 13 September, 2004 14:19:47
Your guide to the past, present and future of the legal challenge that may change the face of the open source revolution - +
Franken Patch 09 December, 2003 12:18:01
The current manufacturing process for patches - from disclosure of a vulnerability to the creation and distribution of the updated code - makes patching untenable. At the same time, the only way to fix insecure post-release software (in other words, all software) is with patches.The more you patch, the more you need to patch, and the more kludgy and terrifyingly unpredictable your systems and applications become. Is there any way to escape this horror?
- +
Adobe launches hosted services, adds Flash to Acrobat 03 June, 2008 09:02:44
Adobe to launch Web site offering users free hosted services for document creation, sharing and storageAdobe this week is set to unveil the next version of its Adobe Acrobat software, which adds support for the company's Flash multimedia technology. The company also plans to launch a new Web site offering users free hosted services for document creation, sharing and storage. - +
Canadian Teen Arrested in Web Attack on CNN 20 April, 2000 12:01:01
Confirming suspicions that the attacks on CNN.com, Yahoo.com Inc. and a handful of other popular Web sites in February were the work of "script kiddies," officials have arrested a 15-year-old Canadian who allegedly bragged about perpetrating at least one of the attacks. - +
"Anna" virus writer turns himself in 15 February, 2001 14:00:00
A 20-year-old man has turned himself in to police in the Dutch province of Friesland, identifying himself as the author of the so-called Anna Kournikova virus, police spokesman Robert Rambonnet said Wednesday. - +
Canadian Mounties Nab 'MafiaBoy' 20 April, 2000 12:01:01
A 15-year-old hacker from Montreal, known as MafiaBoy, was charged in connection with February's denial-of-service attacks, which struck well-known Web sites such as CNN.com, Yahoo, eBay, Amazon.com, Excite and ETrade. - +
Network Associates hit by DoS attack 05 February, 2001 09:30:00
SAN FRANCISCO (02/01/2001) - U.S. antivirus software vendor Network Associates Inc. (NAI) was hit by a DoS (denial-of-service) attack late Wednesday, a company executive confirmed Thursday. [Note to editors: New information appears in bold.]Access to NAI's Web site was hampered for a period of about 90 minutes, although the site never went fully offline, according to Jim Magdych, security research manager at the Computer Vulnerability Emergency Response Team (COVERT) at PGP Security, an NAI business.
Read up on the latest ideas and technologies from companies that sell hardware, software and services. Extending Business Solutions across the Organisation
The Secrets of C-Suite Success
Growth Strategies in Uncertain Times: Building and Maintaining Lasting Client Relationships in Professional Services Organisations
The State of Internet Security
Application Modernization: Preserving Your Organization’s DNA
SOA Governance: Rule your SOA
EMC Solutions for Databases Microsoft SQL Server 2005 Nseries iSCSI
How to Protect Business from Malware at the Endpoint and the Perimeter
Newsletter Subscription
Not all hackers are bad guys. But understanding what motivates them can make you less vulnerable to an attack.
It might be an old computer industry term for programmers that dates back to the 60s, but the word "hacker" has become firmly fixed in the public mind to mean people who break into computer systems.
Not true, say the hackers CIO spoke to. They are members of the Sydney chapter of 2600 Australia, a loose-knit collection of people who share a common interest in computer security - and ways of getting around it. Most of the hackers in 2600 haunt the Net round the clock, sniffing out insecure systems and searching for their vulnerabilities. But the aim of the game is not to steal or vandalise, they say, but to demonstrate one's technical prowess. For them the thrill of hacking lies in the hunt, not the kill.
Besides, as the 2600 guys are only too happy to point out, why rip someone off when you can earn $100K a year hacking professionally? Make no mistake about it, today's hackers have the skills to pay the bills.
The current generation of keyboard jockeys is paid to invade systems. If the first wave of hackers were true outlaws, often cracking systems in defence of the people's right to know as well as for personal gain, today's hackers are taking the family business legit. And much like the Mob or any other Machiavellian institution, their power derives not from the destruction they cause, but from proving to others that they can be destroyed at any time.
CIO: The word hacker means a lot of things to a lot of people. What's your definition of the word?in0m: I personally believe that hacking is mainly advanced networking skills. If you can put together a network - which is how most of these guys learned their skills - the more advanced you'll be at securing your network. And that's all hacking is: securing a network by knowing how to break it. avantguard: Hacking is a mentality, in that you see behind the shroud thrown over everything and see a system for what it's worth.
Anonymous Hacker 1: Everyone's mentioned software and systems, but it goes beyond that. Anything you do where you can take something further than what it was designed to do is a form of hacking.in0m: Whatever you do, we don't want to be seen as is criminals. We're not the kind of guys who go out and deface Web pages.
CIO: What's the difference?
in0m: Most of these guys [2600] have access to large infrastructures and if they want to test something they can go into their own company and test it 100 per cent legally. I think the statistics are that something like 90 per cent of hacks come from internal sources. If you look at the St George bank hack from September, I think it's quite coincidental that they put 1400 people off the week before.
in0m: I had a situation a while ago where a site in Perth was hacked. It was a static page, which means there was nothing the guy could've gained apart from just messing it around - real junior stuff. That guy was nothing more than an online graffiti artist. He wrote himself all over the Internet as being this Robin Hood hacker out to make security safer. Let me tell you, that's the kind of guy you want off the Internet. He should have his modem broken in half.
CIO: Is that the kind of person you'd describe as a script-kiddie?in0m: Yes, guys who do "point and click" hacking. They don't invent anything or come up with anything new, they just use tools that have been left lying around. They attack people with old stuff - other people's intellectual property - and don't do anything unique. Personally, I prefer to contact the administrator of a site and say, "Hey, your site's weak. Would you like some help fixing it up?"
CIO: If you're not doing it for personal gain, the big question is: why do you do it?avantguard: It really does blur. It's a hobby but it also crosses over into our careers because it's what we like to do.
Anonymous Hacker 2: I earn over 100 grand a year doing it.
CIO: Do you target any specific systems?
All together: Insecure ones!
CIO: Notorious hacker Kevin Mitnick was released last year. Any thoughts on his case?
MneMoniX: The thing about Kevin Mitnick was he used a GSM mobile during most of his hardcore hacks, which was very atypical at the time in the US. They caught him because they traced his mobile phone.in0m: The first thing Kevin Mitnick will tell you is he never hacked anything that was hard. The reason he broke into sites was because 1) he used social engineering [verbally conning people into revealing their access secrets, such as impersonating a repairman], and 2) he exploited the top 10 security vulnerabilities. One of the things you should learn from speaking to people like us is that we're not these super-genius guys. Most of the time we're just using known holes - info about them is readily available and they're easy to patch. But people don't have the time to get to them or they're not paying attention to their security. Unfortunately, people are only paying attention to their security after the fact. After the Nazi party page has been stuck up on your Web site is not the time to start worrying about security.
CIO: Where does the name 2600 come from?
Dogcow: The name 2600 refers to a sound frequency. When making a long-distance call back in the 60s and 70s in the US, if you played the 2600 hertz tone on the line it would stop the billing, in which case you could continue to talk at zero cost. The 2600 tone was one of the things people used to explore the phone system in various ways. All the signalling was in band at the time and you could actually hear connections as they were made between exchanges. 2600 is also an organisation in the US that started in 1984. It centred around a magazine they used to put out and continued on from there. Over the years they started having meetings in cities around the US, and last year we decided to have a Sydney 2600 meeting. It was just people hooking up in a hotel for a few drinks and talking about stuff.
CIO: How big is the hacker community in Australia?
Dogcow: We have about 60 or 70 people who physically attend the meetings around the country, but counting our mailing lists there's probably between 400-500 people who in some way choose to associate with the group. 2600 can be found on the Web at www.2600.org.au.
Great Moments in Hacker History
1969-73
Using a whistle given away in a box of breakfast cereal, engineering student John Draper begins making long-distance calls for free by blowing a precise tone into the receiver that tells the phone system to open a line. Draper is hounded by authorities for phone tampering throughout the 70s.
Counterculture icons the Yippies launch YIPL/TAP (Youth International Party Line/Technical Assistance Program) magazine to help phone hackers (known as "phreaks") make free long-distance calls.
Two members of California's Homebrew Computer Club, Berkeley Blue and Oak Toebark begin making "blue boxes" - devices used to hack into the phone system. The two are in reality Steve Jobs and Steve Wozniak, who later go on to found Apple Computer.
Great Moments in Hacker History
1974-1984
ARPANET moves away from its research and military beginnings and becomes commercialised.
William Gibson coins term "cyberspace" in his novel Neuromancer.
In one of the first arrests of hackers, the FBI busts the 414 gang (named after the local Milwaukee area code) after members are accused of 60 computer break-ins.
The film War Games is released.
The first issue of 2600: The Hacker Quarterly is published.
Great Moments in Hacker History
1984-88
Two hacker groups form, the Legion of Doom in the United States and the Chaos Computer Club in Germany.
Veteran hacker Kevin Mitnick arrested for secretly monitoring the e-mail of corporate security officials. He is sentenced to one year in prison.
First National Bank of Chicago is the victim of a $US70-million computer heist Student Robert Morris releases a worm program that penetrates military and intelligence systems, crashing 6000 computers attached to the Internet.
Great Moments in Hacker History
1989-90
After AT&T long-distance service crashes, US government begins national crackdown on hackers, arresting Knight Lightning, Eric Bloodaxe and Masters of Deception trio Phiber Optik, Acid Phreak and Scorpion. Operation Sundevil, conducts raids in 12 major US cities.
Hacker Kevin Lee Poulsen (Dark Dante) is captured after a 17-month hunt, and is later indicted for stealing military documents.
Great Moments in Hacker History
1991-95
Russian Vladimir Levin creates a group that hacks into Citibank, getting away with more than $US10 million.
Kevin Mitnick incarcerated again, this time on charges of wire fraud and illegal possession of computer files stolen from Motorola and Sun Microsystems, among others.
Great Moments in Hacker History
1996-99
Hackers break into and deface US government Web sites, including the US Department of Justice, US Air Force, CIA, NASA and others.
The New York Times Web site defaced in protest over the imprisonment of Kevin Mitnick.
Two hackers in China sentenced to death for hacking into a bank and stealing money.
The Pentagon hacked by an Israeli teenager.
The hacker group L0pht speaks to the US Congress about security issues, warning it could shut down US access to the Internet in less than 30 minutes Unidentified hackers seized control of a British military communication satellite and demand money in return for control of the satellite.
Great Moments in Hacker History
2000
January
Russian hacker steals customer credit card numbers from online music retailer CD Universe and threatens to sell them if not paid $US100,000. When his demands are not met, details of 25,000 credit cards are promptly posted on a Web site.
Kevin Mitnick is released from prison. As a condition of his parole, he is prohibited from using computers.
February
The Web sites of Yahoo, eBay, CNN.com, Amazon.com, Buy.com, ZDNet, E*Trade, and Datek are targeted by an unknown hacker using denial of service. Months later, 16-year-old Montreal-area high-school student known as Mafiaboy is captured and agrees to plead guilty to the series of attacks.
Hackers penetrate the ASX Web site, causing an outage of four hours. The anonymous intruder, nicknamed "Prosthetic", breaks into the exchange's public information Web site for 30 minutes, leaving it littered with banner messages reading "Prosthetic owns the ASX".
May
The "I Love You" virus wreaks havoc on systems worldwide, causing an estimated $US8.7 billion in damage. A Filipino student is eventually arrested in connection with the bug, but is later released because prosecutors lack a law with which to charge him.
October
NY Yankees win US baseball's World Series. Next morning the team's Web site is defaced with a pornographic image and the words "Yankees suck!!!"
November
A hacker attacks the US Republican National Committee's Web site and plants a rambling tirade against Texas Governor George W Bush, forcing the site to be temporarily taken off-line on the day when voters are casting their ballots in the presidential election.
A 19-year-old Dutch hacker mocks software giant Microsoft by hacking into one of its Web servers twice within one week. Shortly afterward, Dimitri visits Microsoft's Dutch office and meets with the company officials to discuss the break-ins.
December
Security at the US Naval Research Laboratory is breached and an unidentified intruder downloads aerospace software that can be used to control satellites.
A hacker penetrates the computer network of a major hospital in Seattle, making off with files containing information about 5000 patients.
Malicious intruders plant the image of a nude woman on the Web site of Japan's top security organisation, the National Police Agency.
Creditcards.com is the victim of an extortion attempt by a cyber thief accused of hacking into its site and exposing more than 55,000 credit card numbers on the Internet.
Great Moments in Hacker History
2001
January
One day after a technical error shut down several of its Web sites, Microsoft announces that an outside attack is to blame for a second round of embarrassing outage. A denial of service attack hits the routers that direct traffic to several Microsoft Web sites when a hacker floods the company's equipment that directs traffic to its sites, blocking other users from reaching popular properties such as Expedia.com and Hotmail.com.
February
A group of malicious hackers go on a defacement spree, breaking into a string of corporate Web sites to replace text and graphics with digital graffiti. Among the victims of the hackers, who go by the name "Sm0ked Crew", were Web sites owned by The New York Times, Compaq Computer, Intel, AltaVista, Hewlett-Packard and Disney.
Brazilian police investigate an online attack on the country's largest Internet service provider, UOL, in which hackers succeeded in stealing credit-card numbers from over 10,000 users. According to Brazilian press reports, one of the suspects arrested is the son of a Brazilian congressman.
March
Hackers steal customer records from Amazon.com subsidiary Bibliofind.com, including credit card information. Some 98,000 customers are affected.
2008 CIO Summit
19th August, 2008 Four Seasons Hotel, Sydney Developed in partnership with CIO Magazine, IDC, INTEP and the CIO Executive Council.
The world of the CIO is extremely complex and diverse. Multiple priorities demand attention and decisions are needed instantly. Individual teams need to be driven towards common goals, and businesses strive to become more mobile, agile and responsive. For CIOs, the challenge never ends.
Every year the CIO Summit identifies what is top of mind for CIOs across Australia and New Zealand, and offers insight for CIO benchmarking and vendor strategic planning alike.
Recent IDC research shows that over 59% of CIO's believe that 'to achieve their business strategies, technology should be used more aggressively than today.'
Join us on August 19th to discover how this is possible with the latest technologies including Virtualisation, Web 2.0, IP Surveillance and Software as a Service (Saas).
Click here for more information.
Please email Denyse_Robertson@idg.com.au for further information.
- +
CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II 05 October, 2007 06:00:00
For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders. - +
CIO Live Podcast #78: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires 28 September, 2007 17:34:25
For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders. - +
CIO Live Podcast #77: Panasonic Speeds Up Trans-Pacific File Transfers, Part III 21 September, 2007 07:00:00
Part three in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance. - +
CIO Live Podcast #76: Panasonic Speeds Up Trans-Pacific File Transfers, Part II 14 September, 2007 07:00:00
Part two in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance. - +
CIO Live Podcast #75: Panasonic Speeds Up Trans-Pacific File Transfers, Part I 07 September, 2007 07:00:05
Part one in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
- +
Citibank debit card fraud highlights ATM vulnerabilities 08 July, 2008 08:17:53
'Back-end servers are kind of a joke,' and the trouble doesn't end thereMalicious ATM intrusions, such as the late-winter breach that resulted in the compromise of Citibank debit card data, are not at all surprising given the vulnerable state of many of the servers and other components involved in processing such transactions, according to some industry representatives. - +
How to not have your Web site hacked like Sony's 07 July, 2008 08:23:22
A SQL injection attack was used to plant malicious code on pages of two popular Sony Playstation games - SingStar Pop and God of War, reports security company Sophos. Hundreds of Web pages from other businesses have also been compromised.The US Sony Playstation Web site is the latest high-profile victim of a hacker attack on business sites that's spreading malware at breakneck pace, says a security vendor. - +
AG launches review into national e-security 07 July, 2008 11:07:49
Howard's security agenda dragged over coals.A review of Australia's top e-security projects lead by the Attorney-General's Department has been launched to scrutinise the Howard's government's $73 million E-Security National Agenda. - +
Selling zero-day exploits has a down side 07 July, 2008 10:16:36
There is an ongoing argument about the ethics of selling 0-day exploits on the open market: It helps if you don't sell exploits targeting the company you work for.Information Security can sometimes be a funny field to work in. Some days it seems as if anybody with their hands on unpublished exploit code can sell it for all they're worth, and others it seems that they are set to become the target of law enforcement and the companies the code affects. It does help if you don't work for one of the companies that is set to be affected by the exploits you are trying to sell and aren't trying to bootstrap a competing company in the process. - +
'I have a lost laptop horror story for you' 30 June, 2008 10:08:14
The devil of identity theft is in the details that follow...The devil of identity theft is in the details that follow: Russ Jones tells a tale of woe that isn't particularly dramatic -- or rare -- and yet it's exactly the kind of story that worries me enough to ignore my better judgment and buy identity-theft protection from my insurance provider.
WD’s New My Book® Mirror Edition™ External Hard Drive Provides The Safest Place For Valuable Personal Content 09 July, 2008 15:00:00
Zepto release the Mythos, the 2nd installment in the Centrino 2 refresh 09 July, 2008 12:05:00
Symantec Data Protection Solutions Preferred by Users and Industry Experts 09 July, 2008 11:56:00
Frost & Sullivan: Australia’s Mobile Advertising Spend to Grow 300 Per Cent in 2008 09 July, 2008 07:57:00
DIARY ALERT - Symantec data leakage prevention seminars 08 July, 2008 17:20:00
|
||
|
||
|
|
||
|
Using EMC Celerra IP Storage with Vmware Infrastructure 3 over iSCSI and NFS
Learn to tie virtualized computing to virtualized storage, to offer a dynamic set of capabilities within the data centre and create improved performance and system reliability. Discover how best to utilize EMC Celerra in a VMware ESX environment.









