Skip to main content

Posts

Ika-tako virus (aka the octopus virus) - (week 10)

In May of 2010, a Japanese file sharing website found a virus that has been named the Ika-tako virus. This virus has reportedly infected over 50,000 computers. It was able to infect so many computers because it was disguised as a music file. Users would search for a song they wanted, but instead of getting the song it was secretly the Ika-tako virus.  (Fish, 2010) Once downloaded by the user, it goes through picture files on the computer’s hard drive and replaces them with a picture of a squid or octopus. This is where it got the name Ika-tako, which is Japanese for octopus-squid. The original pictures were sent to the hacker’s personal server. (Fish, 2010) The hacker, Masato Nakatsuji, was caught a month later and was convicted for this attack. In 2008, he was caught and convicted for a similar attack where he used a copyrighted picture from the show Clannad. When asked why he performed the most recent attack he stated, “I wanted to see how much my computer programming s...
Recent posts

Target breach (week 9)

In 2013, Target had their systems targeted (no pun intended) by a group of hackers. They gained access to Target’s network via a third party company. A heating and air company known as Fazio Mechanical Services had access to Target’s network so they could monitor the systems of their stores in Pittsburgh. Target found that it was more cost effective to hire other companies to perform maintenance in their stores instead of hiring a fulltime team. (Carrol & Rigden, 2014) Fazio Mechanical Services was targeted by a spear phishing attack. It is estimated that this breach occurred a few months before the Target hack was successful, which puts the initial attack at August or September of 2013. Once the hackers had access to Fazio’s network they stole their credentials for Target’s network. They then installed malware on several Target POS systems on November 15 th , 2013. These POS systems acted as a ‘test system’ from the 15 th to the 28 th of November. On the 30 th of November ...

3 billion Yahoo accounts hacked - (week 8)

In August of 2013, Yahoo experienced the largest data breach in history. All 3 billion of their users had their accounts hacked. This included their other services such as Yahoo email, Tumblr, Fantasy, and Flickr. They stole email addresses and passwords, but no financial information was reported to be stolen.  (Larson, 2017) Originally, it was thought to be a much lower number of affected accounts but Verizon, the owner of Yahoo which is now a part of their digital media company called Oath, made the following statement in 2017; “The company recently obtained new intelligence and now believes, following an investigation with the assistance of outside forensic experts, that all Yahoo user accounts were affected by the August 2013 theft.”  (Larson, 2017) Cyber forensic specialists say that it is very odd for outside services to find more victims than what was originally thought. Usually, a business will over estimate to factor in the amount lost and the cost for clean-...

Hacking ATMs (week 7)

In 2014, two ninth-grade boys, Matthew Hewlett and Caleb Turon, discovered an online operators manual for an ATM. During their lunch hour, they decided to try using this information at an ATM at a Bank of Montreal ATM. The entered the ATM in to ‘operator mode’ which displayed sensitive information such as customer charges, cash available, and the transaction history. The ATM was password protected, but the boys were able to find the correct code based on information in the manual. At this point, the boys realized that this situation looked incriminating and they reported their findings to the bank.  (Lyne, 2014) When they reported the breach, the bank employees did not believe them. The boys then performed a live demonstration. When interviewed about the event, the boys said “I started printing off documentation like how much money is in the machine, how many withdrawals have happened today, how much it’s made off surcharges. Then I found a way to change the surcharge amount, ...

The Melissa Virus (week 6)

In 1999, David L. Smith released the macro virus known as W97M/Melissa.A@mm, aka the Melissa virus. This virus infected thousands of computers that utilized Microsoft Outlook. The virus was spread through email with a word attachment. The email had a format that looked like the text below.   (We Live Security, 2016) The document used a name of an exotic dancer, which Smith says was a bit of social engineering to get people to open the attachment. Once the user had downloaded the attachment and opened it, the virus went to work. It disabled the program’s macro security, slowed the processes of Outlook significantly, infected documents on the machine, and then sent itself to up to 50 addresses in the users email address list. Using these addresses, it would send itself to new victims under the guise of the previous victim. This got more people to open the attachment since it was from someone they trusted.   (We Live Security, 2016) The damage caused by the virus...

Hacking your health (week 5)

In early August, researchers demonstrated at the Black Hat USA convention that pacemakers are still very vulnerable. The researchers asked people with medical implants to leave the are for safety reasons and then began their demonstration. Billy Rios and Jonathan Butts showed how malware can be installed remotely on implants such as pacemakers and insulin pumps. They blamed the lack of encryption and the software delivery methods as the main breaches in security. They also demonstrated that they could breach CareLink 2090 programmer, a program used by doctors to control implanted pacemakers. They showed 2 hacks, one that delivered a large shock and another that stopped the pacemaker from shocking, both could be used for deadly reasons. These attacks are due to firmware not being digitally signed and updates that are sent out are not encrypted in any way. When they asked Medtronic, the creator of the devices and program, about the lack of security they stated that the threat is 'low...

Stuxnet (week 4)

In 2010, the Natanz uranium  enrichment plant in Iran was experiencing rapid failure of centrifuges used to enrich uranium gas. Five months after replacing and repairing the centrifuges, they noticed that computers were crashing and rebooting multiple times. After calling in a third party to investigate, they found many malicious files, which is now classified as the world's first digital weapon. The bug, known as Stuxnet, was the cause of the failures and crashes. Development of Stuxnet was started in 2005 by several coders in the US and Israel. The bug works similarly to program used in the Russian Pipeline Explosion incident. It was designed to cause physical failures with equipment, however, unlike the pipeline incident, Stuxnet stopped alarms from triggering while continuing to overload equipment and it was able to spread itself to other computers. While Stuxnet was discovered in 2010, it was released in 2009 and a 'test run' was launched in 2008. In 2009, Stuxnet ...