Showing posts with label milworm. Show all posts
Showing posts with label milworm. Show all posts

Saturday, February 19, 2011

Anti-sec - group of hackers to keep security

Anti-sec is the group of underground hackers; and they are here with the cause. They say big no to promoting Hacking related open materials and making it a child’s play. This is probably the revulsion to combat evil trends in cyber arena and control over this deservedly elite occupation which has been encroached by larger commercial groups such as virus creators, antivirus producers, that the movement is more a rebellion against that. This group came in lime light after hacking “imageShack’ one of the most popular image hosting service in the cyber world. Anti-Sec Movement, staunchly dedicated to the eradication of “full disclosure” hacked this world’s largest image hosting site, played around with their own ideas and they replaced the images uploaded by users with that of their own, which is supposedly the image of the manifesto of ‘their movement’. The entire visual display was rounded off with the message “no images were harmed in the making of this.. Image.”

Anyways nobody could deny their abilities after the attack of milw0rm. Anti-secs want to keep security - in particular, exploits - private. In way they are right because inj3ct0rs were getting bad name because of open display of exploits. There are evidences that the exploits were used by antinationalist for elicit purpose. Milw0rm is their nemesis. There's a discernible political bent to their writings and ratings. While we see a general shift on the internet towards the idea that "information just wants to be free", the anti-sec people don't agree with this when it comes to matters of security. From a white-hat point of view, they're saying that full disclosure actually causes more damage than if only a select few, capable, and not necessarily malevolent, people were to know about any particular exploit. So far it’s not clear that there's a tad of immaturity and insecurity in these people or they really want to work in the interest of cyber security, and one should appreciate that. The common claim of the Movement is that “full disclosure is the disclosure of exploits publicly - anywhere.” the security industry for making profit due to “full-disclosure” with “scare tactics” that were intended to make the public purchase anti-virus software and firewalls. Well, with their daring “heist”, the members surely have managed to across loud and clear the gist of their intention.

In other terms you can say this movement is kind of fight or crusade against the traditional for-profit computer security industry. They think that publicizing security holes and those hole's exploits causes more pain than it helps. They also seem to be kind of anti-capitalist and are very talented security researchers. Antisec are the kind of amazing group of hackers who don't want profit from fear. Generally Hackers are known for creating deterrence, fear and penetrations. Here is this group to sabotage such intentions of Dark side of cyber world. There are so many myths and misconceptions about them but the fact is that they at least have credibility. These guys are sticking to their guns and keeping the hacking underground just that, underground. Anti-sec is a response to the fear-mongering era of 1998 - 2004 when every hanger-on wannabe computer guy became a security researcher and started publishing "advisories". Between dotcom bubble eras to 9/11, everybody was a security guy, and not only that, but the "security guy" was pointing the finger at the hacker community every time a script kiddie defaced some web page. Those most sec guys are snake-oil salesmen and absolutely deserve no sympathy. If they're gonna bad-mouth hackers and promise protection to everyone then let them protect themselves from the real Hackers; by and large, they're out-gunned and out-skilled.

There are many so called security ( tech or defense agencies) minting money over suing the tag of Hacker, they have made it business, every year thousand of hackers are (youngsters) manufactured in their so called industry but still nation lacks hundreds of security personals towards national security. This is irony and here is need of someone to stop these ‘manufacturers of hackers’, I think hackers like Anti sec are the proper takers on these morons. Anti-sec doesn't go after civilians, by the way. The another biggest threat today is there are hundreds of exploit writers around the globe, One group publishes exploits and carries out mayhem for fun so make such high profile hacks were attempted just because of open display of these exploits. It doesn't matter what they are or what they do and why they do the most important thing is they are here with the Cause, and that is nothing but the security at large.
The Anti Security Movement or popularly written as Anti-sec is a popular movement opposed to the computer security industry. It attempts to censor the publication of information relating to but not limited to: software vulnerabilities, exploits, exploitation techniques, hacking tools, attacking public outlets and distribution points of that information. Movement followers have cited websites such as Security Focus, Security team, Packet Storm Security, and milw0rm to be targets of their cause, as well as mailing lists like "full-disclosure", "vuln-dev", "vendor-sec" and bugtraq, as well as public forums and IRC channels. The start of most public attacks in the name of the anti-security movement started in around 1999 and 2000. The "anti-security movement" as it is understood today was coined by the following document which was initially an index on the anti.security.is website. The purpose of this movement is to encourage a new policy of anti-disclosure among the computer and network security communities. The goal is not to ultimately discourage the publication of all security-related news and developments, but rather, to stop the disclosure of all unknown or non-public exploits and vulnerabilities. In essence, this would put a stop to the publication of all private materials that could allow script kiddies from compromising systems via unknown methods.

A common misconception is that if groups or individuals keep exploits and security secrets to themselves, they will become the dominators of the "illegal scene", as countless insecure systems will be solely at their mercy. This is far from the truth. Forums for information trade, such as Bugtraq, Packetstorm, www.hack.co.za, and vuln-dev have done much more to harm the underground and net than they have done to help them. This was one of the first anti-security hacktivist groups. The group waged war on the security industry with their popular assault known asAnti-Sec. In a nutshell, this group doesn't like websites that promote security. If a website provides different methods for safety then Anti-Sec wants to blank their site. They want to take away the ability of organizations to sell their services.

No one knows about this group so far, they don’t have any sort of forum or website or any traces where the members can be located, and if someone clames about knowing them, then It can subject to doubt. The kinds of hacks they have performed and beguile they blown against bigwigs are not in a mood to spare them, maintaining anonymity is compulsion for them. Still it’s very much interesting and leaves the reason to think about their agenda and activities. Bravo guys..

Read in details ,soon to be published “Cat Techie”………………….

Sunday, January 2, 2011

What is Cyber-terrorism?

In the wake of the recent computer attacks, many have been quick to jump to conclusions that a new breed of terrorism is on the rise and our country must defend itself with all possible means. As a society we have a vast operational and legal experience and proved techniques to combat terrorism, but are we ready to fight terrorism in the new arena – cyber space? A strategic plan of a combat operation includes characterization of the enemy’s goals, operational techniques, resources, and agents. Prior to taking combative actions on the legislative and operational front, one has to precisely define the enemy. That is, it is imperative to expand the definition of terrorism to include cyber-terrorism. As a society that prides itself on impartiality of justice, we must provide clear and definitive legislative guidelines for dealing with new breed of terrorism. As things stand now, justice cannot be served as we have yet to provide a clear definition of the term. In this light, I propose to re-examine our understanding of cyber-terrorism. There is a lot of misinterpretation in the definition cyber-terrorism, the word consisting of familiar "cyber" and less familiar "terrorism". While "cyber" is anything related to our tool of trade, terrorism by nature is difficult to define. Even the U.S. government cannot agree on one single definition. The old maxim, "One man's terrorist is another man's freedom fighter" is still alive and well. The ambiguity in the definition brings indistinctness in action, as D. Denning pointed in her work Activism, Hactivism and Cyberterrorism, "an e-mail bomb may be considered hacktivism by some and cyber-terrorism by others" It follows that there is a degree of "understanding" of the meanings of cyber-terrorism, either from the popular media, other secondary sources, or personal experience; however, the specialists’ use different definitions of the meaning. Cyber-terrorism as well as other contemporary "terrorisms" (bioterrorism, chemical terrorism, etc.) appeared as a mixture of words terrorism and a meaning of an area of application. Barry Collin, a senior research fellow at the Institute for Security and Intelligence in California, who in 1997 was attributed for creation of the term "Cyberterrorism", defined cyber-terrorism as the convergence of cybernetics and terrorism. In the same year Mark Pollitt, special agent for the FBI, offers a working definition: "Cyberterrorism is the premeditated, politically motivated attack against information, computer systems, computer programs, and data which result in violence against noncombatant targets by sub national groups or clandestine agents." Since that time the word cyber-terrorism has entered into the lexicon of IT security specialists and terrorist experts and the word list of mass media "professionals". One of the experts, a police chief, offers his version of definition: "Cyber-terrorism – attacking sabotage-prone targets by computer – poses potentially disastrous consequences for our incredibly computer-dependent society." The media often use cyber-terrorism term quite deliberately: "Canadian boy admits cyberterrorism of his family: "Emeryville, Ontario (Reuter) - A 15-year-old Canadian boy has admitted he was responsible for months of notorious high-tech pranks that terrorized his own family, police said Monday" A renowned expert Dorothy Denning defined cyber-terrorism as "unlawful attacks and threats of attack against computers, networks, and the information stored therein when done to intimidate or coerce a government or its people in furtherance of political or social objectives". R. Stark from the SMS University defines cyber-terrorism as " any attack against an information function, regardless of the means" Under the above-mentioned definitions of cyber-terrorism one can only point to the fact that any telecommunications infrastructure attack, including site defacing and other computer pranks, constitute terrorism. It means that cyber-terrorism has already occurred and we "live " in the epoch of cyber terror. However, another expert, James Christy the law enforcement and counterintelligence coordinator for the DIAP (Defense-wide Information Assurance Program), which is steered by the office of the assistant secretary of defense for command, control, communications and intelligence, states that cyber-terrorism has never been waged against the United States. "Rather, recent hacking events – including a 1998 web page set up by a supporter of the Mexican Zapatistas rebel group, which led to attacks on the U.S. military from 1,500 locations in 50 different countries – constitute computer crime. William Church, a former U.S. Army Intelligence officer, who founded the Center for Infrastructural Warfare Studies (CIWARS) agrees that the United States has not seen a cyber terrorist threat from terrorists using information warfare techniques. "None of the groups that are conventionally defined as terrorist groups have used information weapons against the infrastructure" Richard Clarke, national co-ordinator for security, infrastructure protection and counterterrorism at the National Security Council offered to stop using "cyberterrorism" and use "information warfare " instead The above-mentioned observations drive a clear line between cyber-terrorism and cyber crime and allow us to define cyber-terrorism as: Use of information technology and means by terrorist groups and agents. In defining the cyber terrorist activity it is necessary to segment of action and motivation. There is no doubt that acts of hacking can have the same consequences as acts of terrorism but in the legal sense the intentional abuse of the information cyberspace must be a part of the terrorist campaign or an action. Examples of cyber terrorist activity may include use of information technology to organize and carry out attacks, support groups activities and perception-management campaigns. Experts agree that many terrorist groups such as Osama bin Ladenn organization and the Islamic militant group Hamas have adopted new information technology as a means to conduct operations without being detected by counter terrorist officials. Thus, use of information technology and means by terrorist groups and agents constitute cyber-terrorism. Other activities, so richly glamorized by the media, should be defined as cyber crime.

Reference:Computer Crime reserch center

CATTECHIE HERE AGAIN

A true story of CATTECHIE

CATTECHIE HERE AGAIN