Hijacking Airplanes With an Android Phone Slashdotby Soulskill on transportation at January 1, 1970, 1:00 am (cached at April 10, 2013, 11:32 pm)

An anonymous reader writes "Until today, hacking and hijacking planes by pressing a few buttons on an Android mobile app has been the stuff of over-the-top blockbuster movies. However, the talk that security researcher and commercial airplane pilot Hugo Teso delivered today at the Hack in the Box conference in Amsterdam has brought it into the realm of reality and has given us one more thing to worry about and fear (presentation slides PDF). One of the two technologies he abused is the Automatic Dependent Surveillance-Broadcast (ADS-B), which sends information about each aircraft (identification, current position, altitude, and so on) through an on-board transmitter to air traffic controllers, and allows aircrafts equipped with the technology to receive flight, traffic and weather information about other aircrafts currently in the air in their vicinity. The other one is the Aircraft Communications Addressing and Reporting System (ACARS), which is used to exchange messages between aircrafts and air traffic controllers via radio or satellite, as well as to automatically deliver information about each flight phase to the latter. Both of these technologies are massively insecure and are susceptible to a number of passive and active attacks. Teso misused the ADS-B to select targets, and the ACARS to gather information about the onboard computer as well as to exploit its vulnerabilities by delivering spoofed malicious messages that affect the'behavior' of the plane."

Read more of this story at Slashdot.



Serbia mourns 13 killed in shooting rampage AL JAZEERA ENGLISH (AJE)(cached at April 10, 2013, 11:30 pm)

Serbia holds national day of mourning as police search for possible motives in Balkan nation's worst peacetime massacre.
Thousands rally for US immigration reform AL JAZEERA ENGLISH (AJE)(cached at April 10, 2013, 11:30 pm)

Activists gather in Washington DC as bipartisan group of senators report progress towards deal on policy overhaul.
Massive Google scam sent by email to Colombian domains, (Wed, Apr 10th) (InternetSto SANS ISC SecNewsFeed(cached at April 10, 2013, 11:30 pm)

Massive Google scam sent by email to Colombian domains, (Wed, Apr 10th) SANS Internet Storm Center, InfoCON: green(cached at April 10, 2013, 11:30 pm)

This morning many users in my city woke up with supposedly good news from a resume they sent to google looking for open positions:

Google SCAM

Of course this scam does not have anything new and innovative to cause a massive impact, but here is the catch: in this part of the world, people love P2P networks and love to download unlicensed content like Windows Operating Systems, music and paid programs so they don't have to pay a cent for it. Since standard security controls like antivirus and Host IPS shows those programs like malicious and then block most of its functionality, there are a huge number of people that disregard such measures to access freely those unlicensed contents.

The file referenced in the e-mail is zip compressed, MD5 4e85b6c9e9815984087f6722498a6dfc. Once uncompressed, you get document.exe, MD5 3e41ab7c70701452d046b93f764564ec. This file is widely recognized by VirusTotal with a 40/46 detection radio. It is a mass mailer with backdoor capabilities. The mass mailer malware description can be found at http://home.mcafee.com/virusinfo/virusprofile.aspx?key=153521#none and the backdoor description can be found at http://home.mcafee.com/virusinfo/virusprofile.aspx?key=100938.

This little thing caused lots of help desk calls this morning to my company because people complained about very slow internet links without performing any download operations. If you were affected by this malware, please keep in mind the following recommendations:

Manuel Humberto Santander Peláez
SANS Internet Storm Center - Handler
Twitter: @manuelsantander
Web:http://manuel.santander.name
e-mail: msantand at isc dot sans dot org

(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Slutbluffat för ”Rockefeller” SvD Utrikes(cached at April 10, 2013, 11:02 pm)

En man som i åratal utgett sig för att vara medlem av den förmögna Rockefeller-familjen har åtalats för mordet på sin kaliforniska hyresvärdinnas son 1985.
Göteborg klagar på BBC om hemlösa SvD Inrikes(cached at April 10, 2013, 11:02 pm)

Göteborgs kommun vill att BBC ska rätta en uppgift om hemlöshet i staden.
Assistent åtalad för grovt bedrägeri SvD Inrikes(cached at April 10, 2013, 11:02 pm)

En personlig assistent i Östergötland har åtalats för bland annat grovt bedrägeri.
US judge raises bar in Bradley Manning case AL JAZEERA ENGLISH (AJE)(cached at April 10, 2013, 11:00 pm)

Government asked to prove army private knowingly helped al-Qaeda by leaking secrets to convict him of aiding the enemy.
Vuln: libytnef TNEF File Buffer Overflow Vulnerability (SecurityFocus Vulnerabilitie SANS ISC SecNewsFeed(cached at April 10, 2013, 11:00 pm)

Odlade cannabis i källaren SvD Inrikes(cached at April 10, 2013, 10:32 pm)

En 32-årig Uppsalabo dömdes till fängelse i tre och ett halvt år för att ha sålt stora mängder cannabis via nätet.
Iran Plans To Launch an 'Islamic Google Earth' Slashdotby Soulskill on earth at January 1, 1970, 1:00 am (cached at April 10, 2013, 10:32 pm)

Shipwack sends this quote from the Guardian: "The Iranian authorities have long accused Google Earth of being a tool for western spy agencies, but now they have taken their attacks on the 3D mapping service one step further — by planning the launch of an 'Islamic' competitor. ... The minister, however, gave little information on what he meant by an Islamic 3D map. 'We are developing this service with the Islamic views we have in Iran and we will put a kind of information on our website that would take people of the world towards reality Our values in Iran are the values of God and this would be the difference between Basir and the Google Earth, which belongs to the ominous triangle of the U.S., England and the Zionists [a reference to Israel].' Experts, however, have serious doubts about the project. An IT consultant who has worked on Iran's national internet project in the past said the announcement was merely an excuse to obtain funds and secure working contracts for the future. 'They have claimed to run their service in four months and said their data centre capacity will reach Google's size in three years,' he said. 'Three-year project, no business model and only relying on government funding, a piece of cake indeed To have a data centre with such capacity and security level they need power stations, cooler systems, bandwidth, etc, which will require billions of dollars of investment that doesn't fit with Iran's sanctions-hit economy.'"

Read more of this story at Slashdot.



House committee advancing pro-business cyber bill (Yahoo Security) SANS ISC SecNewsFeed(cached at April 10, 2013, 10:30 pm)

"Management Information Base for Virtual Machines Controlled by a Hyperviso SANS ISC SecNewsFeed(cached at April 10, 2013, 10:30 pm)

LulzSec: UK-based hackers plead guilty (Heise Security News) SANS ISC SecNewsFeed(cached at April 10, 2013, 10:30 pm)