It's been one of those days. I started writing this post hours ago and never finished it....
As I am sure many of you have already heard, the FBI has managed to hack the cell phones of the San Bernadino terrorists 'all by itself' and has dropped the lawsuit it had filed against Apple, the manufacturer of the iPhone. But they didn't exactly do it all by themselves. They were helped by an Israeli startup called Cellebrite.
The Israeli mobile forensics firm Cellebrite helped the FBI hack into the iPhone of San Bernardino shooter Syed Rizwan Farook, NBC reports, citing industry sources.
The
firm has been rumored to be behind the FBI’s newfound ability to access
the device, thanks to a previous and unconfirmed report from an Israeli
newspaper.
Neither Cellebrite nor the Department of Justice has confirmed the reports.
The
FBI has routinely contracted Cellebrite over the last five years. The
company, which publicly boasts of its ability to hack into Apple
devices, has received over $2 million in purchase orders from the agency
since 2012.
The Justice Department on Monday withdrew
its case against Apple, telling a federal court it was able to unlock
the device without the tech giant's help.
You didn't really expect us to trust the Obama administration to keep us informed, did you? The Wall Street Journal is reporting that the Kaspersky Lab - one of the leading cybersecurity firms in the world - has discovered that Israel was spying on the P 5+1 nuclear talks.
When a leading cybersecurity firm discovered it
had been hacked last year by a virus widely believed to be used by Israeli
spies, it wanted to know who else was on the hit list. It checked millions of
computers world-wide and three luxury European hotels popped up. The other
hotels the firm tested—thousands in all—were clean.
Researchers at the firm, Kaspersky Lab ZAO,
weren’t sure what to make of the results. Then they realized what the three
hotels had in common. Each was targeted before hosting high-stakes negotiations
between Iran and world powers over curtailing Tehran’s nuclear
program.
The spyware, the firm has now concluded, was an
improved version of Duqu, a virus first identified by cybersecurity experts in
2011, according to a Kaspersky report reviewed by The Wall Street Journal and
outside security experts. Current and former U.S. officials and many
cybersecurity experts believe Duqu was designed to carry out Israel’s most
sensitive intelligence-collection operations.
Kaspersky, in keeping with its policy, doesn’t
identify Israel by name as the country responsible for the hacks. But
researchers at the company indicate that they suspect an Israeli connection in
subtle ways. For example, the company’s report is titled “The Duqu Bet.” Bet is
the second letter of the Hebrew alphabet.
Researchers at the company acknowledge that many
questions remain unanswered about how the virus was used and what information
may have been stolen. Among the possibilities, the researchers say, the
intruders might have been able to eavesdrop on conversations and steal
electronic files by commandeering the hotel systems that connect to computers,
phones, elevators and alarms, allowing them to turn them on and off at will to
collect information.
Israeli officials have denied spying on the U.S.
or Israel’s other allies, although they acknowledge conducting close
surveillance on Iranians generally. Israeli officials declined to comment
specifically on the allegations relating to the Duqu virus and the hotel
intrusions.
The Federal Bureau of Investigation is reviewing
the Kaspersky analysis and hasn’t independently confirmed the firm’s
conclusions, according to people familiar with the discussions. U.S. officials,
though, said they weren’t surprised to learn about the reported intrusions at
the hotels used for the nuclear talks.
A senior congressional aide briefed on the
matter said Kaspersky’s findings were credible. “We take this seriously,” the
aide said.
...
U.S. intelligence agencies view Duqu infections
as Israeli spy operations, former U.S. officials said. While the new virus bore
no overt links to Israel, it was so complex and borrowed so heavily from Duqu
that it “could not have been created by anyone without access to the original
Duqu source code,” Kaspersky writes in its report.
To check his conclusions, Mr. Raiu a few weeks
ago emailed his findings to a friend, Boldizsár Bencsáth, a researcher at
Budapest University of Technology and Economics’ Laboratory of Cryptography and
System Security. Mr. Bencsáth in 2011 helped discover the original Duqu
virus.
“They look extremely similar,” Mr. Bencsáth said
in an interview Tuesday. He estimated a team of 10 people would take more than
two years to build such a clean copycat, unless they were the original
author.
...
Kaspersky declined to identify the three
hotels.
Hotels that served as venues for the talks
include: the Beau-Rivage Palace in Lausanne, Switzerland, the Intercontinental
in Geneva, the Palais Coburg in Vienna, the Hotel President Wilson in Geneva,
the Hotel Bayerischer Hof in Munich and Royal Plaza Montreux in Montreaux,
Switzerland.
A Beau-Rivage spokeswoman said the hotel was
unaware of being hacked. A manager on duty at the Intercontinental said he also
was unaware of such an incident. The management team at the Royal Plaza said,
“Our internal policy doesn’t allow us to deliver any information.” The others didn’t respond to requests for
comment.
In addition to the three hotels reported to have
been hacked, the virus was found in computers at a site used to commemorate the
70th anniversary of the liberation of the Nazi death camp at Auschwitz. Some
world leaders had attended events there.
A former U.S. intelligence official said it was
common for Israel and other countries to target such international gatherings.
“The only thing that’s unusual now is you hear about it,” the official
said.
Mr. Raiu said Kaspersky doesn’t know what was
stolen from the three hotels or from the other venues. He said the virus was
packed with more than 100 discrete “modules” that would have enabled the
attackers to commandeer infected computers.
One module was designed to compress video feeds,
possibly from hotel surveillance cameras. Other modules targeted communications,
from phones to Wi-Fi networks. The attackers would know who was connected to the
infected systems, allowing them to eavesdrop on conversations and steal
electronic files. The virus could also enable them to operate two-way
microphones in hotel elevators, computers and alarm systems.
In addition, the hackers appeared to penetrate
front-desk computers. That could have allowed them to figure out the room
numbers of specific delegation members.
The virus also automatically deposited smaller
reconnaissance files on the computers it passed through, ensuring the attackers
can monitor them and exploit the contents of those computers at a later
date.
All is fair in love and war. This is definitely war. I'm proud of our troops and I hope they did this and that our government got a lot out of it. Oh wait... we already know we got a lot out of it, don't we?
Report: Iran conducted massive cyber attack on Israel during Operation Protective Edge
The Hebrew news portal Walla is reporting that during Operation Protective Edge, Iran attempted to launch a massive cyber attack on Israel. According to the report, many of the attack's targets were civilian media. The report does not name any specific websites that were attacked, but I have to wonder whether this was one of them.
Anonymous hackers exposed, one goes by 'niggakillah'
Israeli hackers have exposed the photos and identities of several Anonymous hackers who tried to take down Israeli websites earlier in the week.
The hacker behind the counterattack, an Israeli known as
"Buddhax", said that he did it to make anti-Israel hackers "think twice"
before attacking Israeli sites, and to expose them as amateurs.
Israeli hackers had already responded to attempts last week to infiltrate Israeli and Jewish sites by taking down or defacing anti-Zionist and Muslim sites.
But Buddhax has gone a step further.
After infiltrating the target computers via a Trojan horse, he
managed to lure the hapless hackers to their computers and take pictures
of them using their own webcams - which he promptly posted online
together with a list of personal information and a direct message to his
targets: "Next time don't take part in OpIsrael. Long live Israel."
"I’m not a great hacker, but I’m at least good enough to expose
you," he wrote, and signed off with a message for anti-Israel hackers:
"Israel will stay ISRAEL so forget about "Palestine". Long Live Israel."
...
The exposed anti-Israel hackers hailed from a variety of countries
in Europe, the Middle East and Asia, most prominently from Indonesia
and Malaysia.
The full list and details of the hackers is here. The one with the user name Niggakillah (yes, really) is a guy from Finland. He's not the guy in the picture.
I hate to give traffic to Electronic Intifada by linking them, but this has to be shared.
The big 'success' of Anonymous' #OpIsrael was that they supposedly hacked the Mossad's website - a claim that the Mossad denied. It seems that Anonymous posted personal data of 35,000 Mossad 'spies' and that many of them were Israeli Arabs who had nothing to do with the Mossad and whose lives were endangered. It was all a hoax.
M. arrived at work last Friday morning in a city in the north of
present-day Israel. As she walked in, one of her colleagues approached
her with a look of concern and asked her to step outside. “Your name is
on a list of Mossad agents,” M. recalls the colleague saying.
“ ‘Then congratulate me,’ I said, thinking this was all a strange joke,” M. recalls responding.
But then M. found that many other people at her workplace were
talking about a list, a file obtained by hackers and circulated on
social media purporting to contain the names of agents of Israel’s
notorious spy and assassination agency Mossad.
The vast majority of names on the list are Hebrew names of Israelis.
“I looked at the list, it had my name on it, my ID number and other
details. By the end of the day everyone knew about it and was talking
about it.”
M., however, is a Palestinian, a citizen of Israel, with an Arabic
name – although like all the other names on the list her name was
written in the Hebrew alphabet. She was stunned.
The false accusation or suspicion of being an Israeli agent can be absolutely devastating for any Palestinian.
The Electronic Intifada was able to independently verify the identity
of M. Because of the serious implications for her and her family, M.
agreed to speak to The Electronic Intifada on condition that we not use
her real name or initials or identify the city where she lives.
“After work I went home and started to google this list and I was horrified by what I found,” M. said. “It was everywhere.”
M. doesn’t know how she got on the list but looking at it she thinks
that the information could come from the database of a store’s loyalty
card program or an online commerce site that was hacked into. “I saw the
names of many companies as well as individuals on the list, including
shoe stores and baby clothing stores.”
M. is not the only one affected in the Palestinian community. “My
dad’s cousin is on the list as well, among many other people I know,”
she said.
The Electronic Intifada asked M. if she would help put us in touch
with other Palestinians who had found their names on the list. She said,
“When I tried to talk to them and see if they are willing to do
anything about it, or at least talk to you, they were too scared to
react.”
M. began to contact Arabic-language news sites that had posted the
list, telling them that the list was a fraud and that it was putting
many Palestinians like herself under suspicion. “I didn’t sleep for
three nights,” M. said.
Several websites have now published retractions, apologies and explanations.
Jordanian security forces arrested several youths who are
suspected of attacking Israeli internet sites as part of the large
scale cyber attack on Israel declared by the group called Anonymous.
This has really upset the hacker community, who is now threatening to attack Jordan.
They’ve also declared that once they are done attacking Jewish websites, they will go attack Jews in their homes.
“Today we invade their internet sites and their
electronic fortresses, and tomorrow we will attack them in their homes,
which were established upon our land and which robbed us of our rights,”
the group wrote.
By attack I think it’s pretty safe to assume they mean kill.
Several dozen sites belonging to Israeli NGOs have been damaged, the
web vandals claimed, including that of Larger than Life, and NGO for
children with cancer.
"The website of Larger than Life has been under attack from
pro-Palestinian hackers for a week," Larger than Life wrote on its
Facebook page Thursday, "and every day they take down our site and plant
different content – flags, a skull, symbols and all sorts of
hate-related things."
"It is too bad that this is happening,
of all places, to a website for an organization whose purpose is one of
love, and assistance to every cancer stricken child under treatment in
Israel, without differentiating on the basis of religion, race or
nationality."
These bullies should pick on someone their own size.
Anonymous' attack on Israeli web sites impressed Haaretz, but it doesn't seem to have impressed anyone else.
Israeli websites were disrupted on a wide-scale by noon on Sunday,
the day that hackers affiliated with the Anonymous group vowed to
protest Israeli policies in Gaza and the West Bank by wiping Israel "off
the map of the Internet," but the damage appeared minimal.
Some
small websites were shut down in the attack, and the few major sites
that were hit were affected only briefly. Meanwhile, Israel's Internet
service providers have said they expect locals to experience difficulty
accessing Israeli websites Sunday.
The
hackers behind the so-called "Operation Israel" on Sunday released a
list of email addresses and credit card numbers they said had been
lifted from the online catalog of Israel Military, a privately owned
business that sells military surplus. Israel Military said the
information made public did not come from its site.
The
Israel Police website was one target of the cyber attack, which began a
day before the threatened large-scale virtual invasion, but the site
had difficulties loading for only a short time before going back to
normal.
Hackers
reported Saturday night that they had shut down several government
sites, including those of the Prime Minister's Office, the Israel
Securities Authority, the Immigrant Absorption Ministry and the Central
Bureau of Statistics, but the government denies the claim. Those sites –
as well as defense-related ones reported down, such as the Defense
Ministry, the Mossad and Israel Military Industries – were operating
normally Sunday, so if they were hacked, any damage appears to have been
fleeting.
A
source at the Defense Ministry on Sunday confirmed that its site had
been hacked for several minutes in the early morning hours, but its
service has since been restored. Additional attempts to hack the site
have failed.
In addition, some of the sites the hackers said they brought down are accessed through outdated links.
A
message from a Twitter account linked to Anonymous said Israel Defense
Forces troops were arresting suspected hackers, a report the IDF
spokesman also denied.
Yitzhak Ben Yisrael, of the government's National Cyber Bureau, said hackers had mostly failed to shut down key sites.
"So far it is as was
expected, there is hardly any real damage," Ben Yisrael said. "Anonymous
doesn't have the skills to damage the country's vital infrastructure.
And if that was its intention, then it wouldn't have announced the
attack ahead of time. It wants to create noise in the media about issues
that are close to its heart," he said.
Posters using the name of the hacking group Anonymous had warned they
would launch a massive attack on Israeli sites in a strike they called
OpIsrael starting April 7.
Israel's
Bureau of Statistics was down on Sunday morning but it was unclear if
it was hacked. Media said the sites of the Defense and Education
Ministry as well as banks had come under attack the night before but
they were mostly repelled.
And Elder of Ziyon reports that one claim that I published last night was not accomplished by hacking but by some clever domain name purchasing.
On the Israeli side, people are reporting that the main domain of
OpIsrael, the group spearheading the hacking effort, was hacked itself
by a Zionist hacker. This does not seem to be correct; it looks like
some Zionist simply bought the OpIsrael.com domain a couple of days ago and set up the page to appear "hacked" when it was never the webpage of the anti-Israel hackers. This is their page.
MK Danny Danon's (Likud) website was hacked on Thursday afternoon, shortly after he announced that he had more than 5,000 signatures on a petition he posted calling on the Israeli government to stop supplying electricity and water to Gaza.
"Hamas owes NIS 103 million to the State of Israel for electricity,
and instead of paying back the debt, they shoot missiles on Ashkelon,"
he said. "It cannot be that Hamas can shoot at the power plant that
provides them with electricity."
Minutes after the Likud MK's announcement, his website was hacked.
Visitors to Danon's site saw the headline "Team Kuwait Hackers,"
along with a photo of missiles and another of Ahmed Said Khalil Jabari,
the senior Hamas figure killed in an IAF strike on Wednesday night. In
addition, a song in Arabic played automatically when the site was
opened.
"If extremist hackers broke into my website because of the petition, we must be doing something right," Danon stated.
Not really. If we were doing something right, the government led by Danon's party would not need to be petitioned to take this action. They would do it on their own.
Make sure your computer is not using rogue DNS servers…before july 9
According to Mrs. Carl's boss, who is very up on these things (because she has to be), this one is for real.
If your computer is not using a rogue DNS service, you will be done with this less than a minute after you click the link. If you are using a rogue DNS service, it will take you much longer, but it beats the alternative of not being able to surf the internet after July 9.
The Saudi hacker who brought down several Israeli government websites a few months ago is said to have died of an asthma attack brought on by sandstorms (Hat Tip: Shy Guy).
The hacker, who called himself “Cyber Terrorist,” was known for hacking well-protected sites including Microsoft. He targeted Jewish and Israeli sites in particular, as well as a site belonging to Danish cartoonists who drew cartoons of Mohammed.
A fellow Saudi hacker calling himself “hell cyber” told the media that “Cyber Terrorist” had put “defending Islam and the Prophet” as his top priority.
“One company had shown interest in working with him for a large sum of money, but he rejected the offer because it came from a Jewish company,” he related.
The Anonymous hackers group isn't just after Syria. They're after Israel too. The group, whose goal is to "seek anarchy through disrupting government and law enforcement networks," posted a video on YouTube on Thursday night, in which it threatened Israel, which it accused of 'crimes against humanity.'
I am an Orthodox Jew - some would even call me 'ultra-Orthodox.' Born in Boston, I was a corporate and securities attorney in New York City for seven years before making aliya to Israel in 1991 (I don't look it but I really am that old :-). I have been happily married to the same woman for thirty-five years, and we have eight children (bli ayin hara) ranging in age from 13 to 33 years and nine grandchildren. Four of our children are married! Before I started blogging I was a heavy contributor on a number of email lists and ran an email list called the Matzav from 2000-2004. You can contact me at: IsraelMatzav at gmail dot com