Powered by WebAds

Wednesday, February 22, 2017

Who's trying to infiltrate my computer?

Well, isn't this interesting?

My anti-virus software has now blocked - at least five times this morning - someone with an IP address in Sweden attempting to infiltrate my computer.

Anyone know if there is a way to report this?

Labels: ,

Wednesday, June 10, 2015

Report: Israel spied on Iran nuclear talks

You didn't really expect us to trust the Obama administration to keep us informed, did you? The Wall Street Journal is reporting that the Kaspersky Lab - one of the leading cybersecurity firms in the world - has discovered that Israel was spying on the P 5+1 nuclear talks.
When a leading cybersecurity firm discovered it had been hacked last year by a virus widely believed to be used by Israeli spies, it wanted to know who else was on the hit list. It checked millions of computers world-wide and three luxury European hotels popped up. The other hotels the firm tested—thousands in all—were clean.
Researchers at the firm, Kaspersky Lab ZAO, weren’t sure what to make of the results. Then they realized what the three hotels had in common. Each was targeted before hosting high-stakes negotiations between Iran and world powers over curtailing Tehran’s nuclear program.
The spyware, the firm has now concluded, was an improved version of Duqu, a virus first identified by cybersecurity experts in 2011, according to a Kaspersky report reviewed by The Wall Street Journal and outside security experts. Current and former U.S. officials and many cybersecurity experts believe Duqu was designed to carry out Israel’s most sensitive intelligence-collection operations.
Senior U.S. officials learned Israel was spying on the nuclear talks in 2014, a finding first reported by The Wall Street Journal in March. Officials at the time offered few details about Israel’s tactics.
...
Kaspersky, in keeping with its policy, doesn’t identify Israel by name as the country responsible for the hacks. But researchers at the company indicate that they suspect an Israeli connection in subtle ways. For example, the company’s report is titled “The Duqu Bet.” Bet is the second letter of the Hebrew alphabet.
Researchers at the company acknowledge that many questions remain unanswered about how the virus was used and what information may have been stolen. Among the possibilities, the researchers say, the intruders might have been able to eavesdrop on conversations and steal electronic files by commandeering the hotel systems that connect to computers, phones, elevators and alarms, allowing them to turn them on and off at will to collect information.
Israeli officials have denied spying on the U.S. or Israel’s other allies, although they acknowledge conducting close surveillance on Iranians generally. Israeli officials declined to comment specifically on the allegations relating to the Duqu virus and the hotel intrusions.
The Federal Bureau of Investigation is reviewing the Kaspersky analysis and hasn’t independently confirmed the firm’s conclusions, according to people familiar with the discussions. U.S. officials, though, said they weren’t surprised to learn about the reported intrusions at the hotels used for the nuclear talks.
A senior congressional aide briefed on the matter said Kaspersky’s findings were credible. “We take this seriously,” the aide said.
...
U.S. intelligence agencies view Duqu infections as Israeli spy operations, former U.S. officials said. While the new virus bore no overt links to Israel, it was so complex and borrowed so heavily from Duqu that it “could not have been created by anyone without access to the original Duqu source code,” Kaspersky writes in its report.
To check his conclusions, Mr. Raiu a few weeks ago emailed his findings to a friend, Boldizsár Bencsáth, a researcher at Budapest University of Technology and Economics’ Laboratory of Cryptography and System Security. Mr. Bencsáth in 2011 helped discover the original Duqu virus.
“They look extremely similar,” Mr. Bencsáth said in an interview Tuesday. He estimated a team of 10 people would take more than two years to build such a clean copycat, unless they were the original author.
...
Kaspersky declined to identify the three hotels.
Hotels that served as venues for the talks include: the Beau-Rivage Palace in Lausanne, Switzerland, the Intercontinental in Geneva, the Palais Coburg in Vienna, the Hotel President Wilson in Geneva, the Hotel Bayerischer Hof in Munich and Royal Plaza Montreux in Montreaux, Switzerland.
A Beau-Rivage spokeswoman said the hotel was unaware of being hacked. A manager on duty at the Intercontinental said he also was unaware of such an incident. The management team at the Royal Plaza said, “Our internal policy doesn’t allow us to deliver any information.”
The others didn’t respond to requests for comment.
In addition to the three hotels reported to have been hacked, the virus was found in computers at a site used to commemorate the 70th anniversary of the liberation of the Nazi death camp at Auschwitz. Some world leaders had attended events there.
A former U.S. intelligence official said it was common for Israel and other countries to target such international gatherings. “The only thing that’s unusual now is you hear about it,” the official said.
Mr. Raiu said Kaspersky doesn’t know what was stolen from the three hotels or from the other venues. He said the virus was packed with more than 100 discrete “modules” that would have enabled the attackers to commandeer infected computers.
One module was designed to compress video feeds, possibly from hotel surveillance cameras. Other modules targeted communications, from phones to Wi-Fi networks. The attackers would know who was connected to the infected systems, allowing them to eavesdrop on conversations and steal electronic files. The virus could also enable them to operate two-way microphones in hotel elevators, computers and alarm systems.
In addition, the hackers appeared to penetrate front-desk computers. That could have allowed them to figure out the room numbers of specific delegation members.
The virus also automatically deposited smaller reconnaissance files on the computers it passed through, ensuring the attackers can monitor them and exploit the contents of those computers at a later date.
All is fair in love and war. This is definitely war. I'm proud of our troops and I hope they did this and that our government got a lot out of it. Oh wait... we already know we got a lot out of it, don't we?

Labels: , , , , , , ,

Tuesday, December 18, 2012

BWAHAHAHAHA! New virus wiping out Iranian hard drives

The Washington Free Beacon's Adam Kredo is reporting that a new computer virus is wiping out computer hard drives in Iran (Hat Tip: Sunlight).
A mysterious new computer virus has infected Iranian computers and is completely wiping users’ hard drives, according to Iranian officials.
The “efficient” virus is said to “wipe files on different drives in various predefined times” and cannot be detected by anti-virus software, Iran’s official Information Technology Organization revealed in a statement over the weekend.
The malware does not appear to be as sophisticated as previous viruses that have targeted computers governing Iran’s nuclear program, according to the statement.
However, the website Ars Technica reported that the virus bears similarities to previous programs used to spy on Iran:
Dubbed Batchwiper, the malware systematically wipes any drive partitions starting with the letters D through I, along with any files stored on the Windows desktop of the user who is logged in when it’s executed, according to security researchers who independently confirmed the findings. The reports come seven months after an investigation into another wiper program targeting the region led to the discovery of Flame, the highly sophisticated espionage malware reportedly designed by the US and Israel to spy on Iran. Wiper, as the earlier wiping program is known, shared a file-naming convention almost identical to those used by the state-sponsored Stuxnet and Duqu operations, an indication it may have been related, security researchers said.
And the virus stays on the computer after it has been rebooted. BWAHAHAHAHAHA!

Labels: ,

Wednesday, July 25, 2012

The motivational video for Iran's nuclear agency

You will recall that I reported on Tuesday that another computer worm has infiltrated into Iran's nuclear agency, causing all the computers to play AC/DC's Thunderstruck.

Here's a video they should have played with the music. Yes, there's a music warning for those of you who don't listen to music today (including me), but it's worth watching the video anyway.

Let's go to the videotape.

Labels: , ,

Tuesday, July 03, 2012

Make sure your computer is not using rogue DNS servers…before july 9

According to Mrs. Carl's boss, who is very up on these things (because she has to be), this one is for real.

If your computer is not using a rogue DNS service, you will be done with this less than a minute after you click the link. If you are using a rogue DNS service, it will take you much longer, but it beats the alternative of not being able to surf the internet after July 9.

Labels: , ,

Friday, June 22, 2012

Flame doesn't just collect data: It deletes files

Next thing you know they'll discover that it washes dishes too....

A Symantec expert says that the allegedly US-Israeli developed Flame computer virus doesn't just collect data. It also destroys files.
Iran had previously blamed Flame for causing data loss on computers in the country's main oil export terminal and Oil Ministry. But prior to Symantec's discovery, cyber experts had only unearthed evidence that proved Flame could spy on conversations on the computers it infects and steal data.

Symantec researcher Vikram Thakur said on Thursday that the company has now identified a component of Flame that allows operators to delete files from computers, which means it can cause critical programs to fail or completely disable operating systems.

"These guys have the capability to delete everything on the computer," Thakur said. "This is not something that is theoretical. It is absolutely there."

...

If Symantec's conclusions are validated, that means Flame could be used as a weapon to attack computers that run critical infrastructure systems, including dams, chemical plants and manufacturing facilities, security specialists said.

Boldizsár Bencsath, an expert on cyber warfare with Hungary's Laboratory of Cryptography and System Security, said there was at least a 70 percent chance that Flame was used to attack Iran in April.

"Of course it can be used for sabotage," said Bencsath, who began investigating Flame several weeks before it was first reported to the public. "It may have been used to attack critical infrastructure and it may be used in the future."

Sean McGurk, a former Department of Homeland Security official who helped direct the US effort to protect critical infrastructure from cyber attacks, said that Flame was not the first piece of malicious software designed to sabotage systems by deleting data.

What makes it unique, he said, is that the data-wiping module works alongside a suite of other programs including the espionage tools that have previously been identified.

"It could render computing devices useless," said McGurk, who is now chief executive of a consulting firm known as NExt Generation Micro LLC.

That presents a threat, he said, because computers are used in all sorts of industrial control systems, affecting everything from critical processes at manufacturing plants to the pressure inside water networks. "Cyber elements can have catastrophic impacts," he said.
This is really cool so long as it's only used to attack bad guys like Iran. And definitely not my computers.

Labels: ,

Monday, June 11, 2012

Flame has a built-in suicide feature

The Flame computer virus, which was recently discovered in computers in Iran and elsewhere, has a self-destruct feature, which has apparently been activated by its creators in order to destroy the virus and make forensic analysis more difficult (Hat Tip: MFS - The Other News).
Flame has a built-in feature called SUICIDE that can be used to uninstall the malware from infected computers. However, late last week, Flame's creators decided to distribute a different self-removal module to infected computers that connected to servers still under their control, Symantec's security response team said in a blog post.

The module is called browse32.ocx and its most recent version was created on May 9, 2012. "It is unknown why the malware authors decided not to use the SUICIDE functionality, and instead make Flamer perform explicit actions based on a new module," the Symantec researchers said.

However, even though it is similar in functionality to the SUICIDE feature -- both being able to delete a large number of files associated with the malware -- the new module goes a step further.

"It locates every [Flame] file on disk, removes it, and subsequently overwrites the disk with random characters to prevent anyone from obtaining information about the infection," the Symantec researchers said. "This component contains a routine to generate random characters to use in the overwriting operation. It tries to leave no traces of the infection behind."

Deleting a file in Windows does not remove its actual data from the physical hard disk. It only flags the hard disk sectors occupied by that file as available for the operating system to rewrite.

However, since there is no way to predict when the operating system will actually overwrite those sectors, the deleted file, or portions of it, can be recovered with special data recovery tools -- at least for a limited period of time.

According to Aleks Gostev, chief security expert with Kaspersky Lab's global research & analysis team, the overwriting of file data with meaningless characters happens before the Flame files get deleted by browse32.ocx, not after as Symantec suggested. However, the goal is the same -- eliminating all traces of the malware and making forensic analysis harder, he said via email.
Those Jews are so smart.... Heh.

Labels: ,

Wednesday, June 06, 2012

Google warning users of 'state-sponsored attacks' on GMail and personal data

Google has started warning users that their accounts might be compromised by 'state-sponsored attacks' on their GMail accounts, and on their personal data (Hat Tip: NY Nana).
Grosse said the new step includes a specific warning — with a pink message bar and blue letters — to be issued in cases where users might be targeted.

“You might ask how we know this activity is state-sponsored,” he said. “We can’t go into the details without giving away information that would be helpful to these bad actors, but our detailed analysis — as well as victim reports — strongly suggest the involvement of states or groups that are state-sponsored.”

The warnings do not necessarily mean that the account has been hijacked, but indicates that it may be a target, of phishing or malware.

The move comes amid growing concerns about malware from the so-called Flame virus which has been spreading in the Middle East, and indications of cyber warfare involving the United States and other countries.

Google said users who receive the warning should create “a unique password that has a good mix of capital and lowercase letters, as well punctuation marks and numbers” and take other measures including two-step verification as additional security.

“Attackers often send links to fake sign-in pages to try to steal your password, so be careful about where you sign in to Google,” he said.

“We believe it is our duty to be proactive in notifying users about attacks or potential attacks so that they can take action to protect their information,” Grosse said. “And we will continue to update these notifications based on the latest information.”
I don't know about the rest of you but on a practical level, I'm finding it harder and harder to remember my own passwords and what password goes with what account.

And Google seems more paranoid than most. Last week, I tried logging into a GMail account from my cell phone - the same cell phone to which they send a verification number about once a month - and the screen froze. As a result, I got an email saying that my account might have been compromised (even though I never succeeded in signing in from the phone) and insisting that I must change my password to something I had never used as a password before.

Maybe if they weren't trying to collect all that information about us for their own purposes, they wouldn't have to worry so much about our accounts being compromised. Just sayin'....

Labels: ,

Monday, June 04, 2012

Krauthammer: Outrageous Obama leaking cyberwar details to boost reelection bid

Charles Krauthammer thinks the same I said last week: That the Obama administration is purposely leaking details of the United States' cyber war in order to boost the President's chances for reelection in November.

Let's go to the videotape.

Labels: , , , , ,

Thursday, May 31, 2012

The Flame and the Angry Birds

We need to get into the mood for this, so let's go to the videotape.



YNet comments on the use of the LUA programming language for the computer virus Flame. Lua is a language that is a favorite of game programmers, including those who programmed the Angry Birds.
The "Flame" computer virus, which wreaked havoc on several major Iranian computer systems, is related to none other than the "Angry Birds" game, Fox News reported Thursday.

According to the report, "Flame" – dubbed "the most sophisticated cyber-weapon ever" – was written in LUA computer language, which the incredibly popular game was written in.

Fox quoted cyber experts as saying Flame's complexity indicates that it contains some 250,000 lines of code or more, yet it was constructed using LUA, which is favored by game programmers due to its ease of use.

"The people who developed the malware found an ingenious way to use a code not part and parcel of a hacker's normal arsenal, and that made it harder to detect," Cedric Leighton, a former Air Force Intelligence officer told the American news network.
Here's the Fox News report.

Let's go to the videotape.

Labels: , ,

Tuesday, May 29, 2012

Soccer Dad's Middle East Media Sampler

Here's Soccer Dad's Middle East Media Sampler for Tuesday, May 29.
1) Iran vs. the world

The Washington Post reports U.S. officials among the targets of Iran-linked assassination plots:
The threat, many details of which were never made public, appeared to recede after Azerbaijani authorities rounded up nearly two dozen people in waves of arrests early this year. Precisely who ordered the hits, and why, was never conclusively determined. But U.S. and Middle Eastern officials now see the attempts as part of a broader campaign by Iran-linked operatives to kill foreign diplomats in at least seven countries over a span of 13 months. The targets have included two Saudi officials, a half-dozen Israelis and — in the Azerbaijan case — several Americans, the officials say.
In recent weeks, investigators working in four countries have amassed new evidence tying the disparate assassination attempts to one another and linking all of them to either Iran-backed Hezbollah militants or operatives based inside Iran, according to U.S. and Middle Eastern security officials. An official report last month summarizing the evidence cited phone records, forensic tests, coordinated travel arrangements and even cellphone SIM cards purchased in Iran and used by several of the would-be assailants, said two officials who have seen the six-page document.
Strikingly, the officials noted, the attempts halted abruptly in early spring, at a time when Iran began to shift its tone after weeks of bellicose anti-Western rhetoric and threats to shut down vital shipping lanes. In March, Iranian officials formally accepted a proposal to resume negotiations with six world powers on proposals to curb its nuclear program.
That last paragraph is bewildering. The arrests mentioned occurred in the middle of March. Couldn't that have accounted for the attacks halting "abruptly," rather than, as the "officials" suggest, that Iran was softening its stance?
How does the United States react to this apparent "clenched fist?"
The Obama administration has declined to directly link the Azerbaijan plot to the Iranian government, avoiding what could be an explosive accusation at a time when the two governments are engaged in negotiations on limiting Iran’s nuclear program. U.S. officials say they are less convinced that top Iranian and Hezbollah leaders worked together to coordinate the attempted hits, noting that both groups have a long history of committing such acts on their own, and for their own purposes.
“The idea that Iran and Hezbollah might have worked together on these attempts is possible,” said a senior U.S. official who has studied the evidence, “but this conclusion is not definitive.”
2) ????? vs. Iran

A new computer threat against Iran has been discovered. The Washington Post reports, Newly identified computer virus, used for spying, is 20 times size of Stuxnet:
Flame contains 20 megabytes of code. Though malware’s size is not per se a measure of sophistication, Schouwenberg said, in this case “its size shows that it’s taken a lot of time and work to create.”
So far Kaspersky, which has clients around the world, has identified Flame infections primarily in Iran, Israel and other Middle Eastern countries but none in Europe or North America. The infections have hit computers belonging to individuals, educational institutions and state- related organizations, Kaspersky said.
The virus’s creators seemed interested in general intelligence — e-mails, documents, even instant messages, Kaspersky said. But the lab has no evidence so far to document any data stolen.
Kaspersky is a Russian anti-virus firm. I guess (but can't be certain) that they're in the employ of Iran.

Wired has more (via Instapundit):
Symantec, which has also begun analyzing Flame (which it calls “Flamer”), says the majority of its customers who have been hit by the malware reside in the Palestinian West Bank, Hungary, Iran, and Lebanon. They have received additional reports from customer machines in Austria, Russia, Hong Kong, and the United Arab Emirates.
Researchers say the compilation date of modules in Flame appear to have been manipulated by the attackers, perhaps in an attempt to thwart researchers from determining when they were created.
“Whoever created it was careful to mess up the compilation dates in every single module,” Gostev said. “The modules appear to have been compiled in 1994 and 1995, but they’re using code that was only released in 2010.”
3) Jenin and nation building

The Washington Post reports on the Drama in West Bank city of Jenin shows cracks in Palestinian nation-building project:
The Jenin events have alarmed the Palestinian leadership in Ramallah, where officials are divided on the strategy of building state institutions as a step toward nationhood, and even defenders of the idea say its credibility has a limited shelf life.
“The calm and stability that you achieve in the occupied territories cannot be maintained for a long period of time without any sort of political progress toward a final agreement,” said Qais Abdul-Karim, a Palestinian lawmaker who said he never supported the state-building project. Today, he said, “there is a lot of unrest in the security services.”
What's frustrating about this way of portraying the security issue is that it ignores other factors.

One is that it is Abbas who has refused to negotiate. The lack of political progress is the fault of the Palestinians.

Two, even as Abbas insists that he is interested in peace with Israel, he seems a lot closer to Hamas. The New York Times reports, Hamas Takes Step Toward Palestinian Unity Government:
Mr. Haniya began talks with officials from the Central Elections Commission, a group appointed by President Mahmoud Abbas of the Palestinian Authority to begin registering voters in preparation for an election.
Hamas — among its many disputes with Mr. Abbas’s Fatah party and the Palestinian Authority — had banned the elections commission from operating in Gaza. That move had delayed a deal that Qatar brokered in February between Hamas and Fatah that envisioned the appointment of a transitional government that would rule both the West Bank and Gaza in preparation for elections.
Hanna Nasser, the head of the elections commission, told reporters after the meeting that Mr. Haniya had “blessed” its role in Gaza. “Now, the C.E.C. works in complete confidence,” he said.
This will likely amount to nothing as neither Hams nor Fatah seems willing to subordinate its will to the other. But Hamas should be beyond the pale if Fatah is interested in peace. Time after time, though, Abbas seeks agreements with Hamas without insisting that it change its official position regarding Israel.

Finally, the complaint that the security cooperation has a "shelf life" would be more convincing if the official Palestinian media wasn't regularly calling for the destruction of Israel.
Contrary to the Palestinian Authority's claim that it recognizes Israel's right to exist, PA TV and official cultural events continue to reinforce the message of non-recognition of Israel by depicting all of Israel as "Palestine."
This month marked the 27th broadcast by official PA TV of a song that presents all of Israel's land as Palestinian land. The song was originally performed at a Fatah event last year in the presence of PA Chairman Mahmoud Abbas and many other senior PA officials. The Palestinian singer declares that "my land" and "our coast" span from Rosh Hanikra in Israel's north to Rafah in the Gaza Strip in the south, and from Haifa on Israel's western coast to Beit Shean on Israel's eastern border.
Nation building isn't the only obligation of the Palestinian Authority. Rejecting terror and promoting coexistence are parallel obligations that the PA still seems reticent to fulfill.

4) Not Jordan

Last week I wrote about Sen. Mark Kirk's efforts to have Palestinian refugees accounted for. I wrote that Jordan was against the effort.

An alert reader pointed out that I didn't read carefully enough:
An intensive background set of discussions took place between Leahy, the State Department, Kirk's office, and the Jordanian Embassy, two congressional aides told The Cable. Initially the Jordanians were inclined to oppose the amendment and agreed with Leahy, but after being given the final text, decided not to weigh in on what is essentially an internal U.S. government reporting requirement.
"The government of Jordan has informed congressional staff they do not oppose the Kirk amendment," one senior GOP Senate aide said. "That is definitely the correct decision for a foreign government, as this is simply a request for info on behalf of the U.S. taxpayer to the U.S. state department."

Labels: , , , , , , , , ,

An Israeli Flame?

In an earlier post, I reported that a new computer virus has invaded Iran, among other countries. There have been two developments on Tuesday morning. First, Iran has admitted that the virus, known as Flame, has caused it to lose considerable data. And second, Deputy Prime Minister Moshe (Boogie) Yaalon has hinted that Israel might be behind the new virus.
In comments that could be construed as suggesting that Israel is behind the "Flame" virus, the latest piece of malicious software to attack Iranian computers, Vice Premier Moshe Ya'alon on Tuesday said that "whoever sees the Iranian threat as a serious threat would be likely to take different steps, including these, in order to hurt them."

Speaking in an interview with Army Radio, Ya'alon further hinted that Jerusalem was behind the cyber attack, saying "Israel is blessed to be a nation possessing superior technology. These achievements of ours open up all kinds of possibilities for us."
Hmmm.

Meanwhile, the Iranians are whining about what they lost. This is from the first link.
Iran's MAHER Center said Tuesday that the Flame virus "has caused substantial damage" and that "massive amounts of data have been lost."

The center, which is part of Iran's Communication's Ministry said that the virus' level of complexity, accuracy and high-functionality – noted mostly by the information corrupted – indicated that there is a "relation" to the Stuxnet virus.

Iranian experts said that Flame was able to overcome 43 different anti-virus programs.

While no one knows who is behind "the most sophisticated virus of all times," the bottom line, computer experts say, is that only a state could have developed such a complex virus.
Would you rather that we blow up the facilities instead? Heh.

Labels: , ,

New massive spy malware found in Iran

A new piece of massive spy malware called 'Flame' has been found in Iran (Hat Tip: Memeorandum).
The malware, discovered by Russia-based anti-virus firm Kaspersky Lab, is an espionage toolkit that has been infecting targeted systems in Iran, Lebanon, Syria, Sudan, the Israeli Occupied Territories and other countries in the Middle East and North Africa for at least two years.

Dubbed “Flame” by Kaspersky, the malicious code dwarfs Stuxnet in size – the groundbreaking infrastructure-sabotaging malware that is believed to have wreaked havoc on Iran’s nuclear program in 2009 and 2010. Although Flame has both a different purpose and composition than Stuxnet, and appears to have been written by different programmers, its complexity, the geographic scope of its infections and its behavior indicate strongly that a nation-state is behind Flame, rather than common cyber-criminals — marking it as yet another tool in the growing arsenal of cyberweaponry.

The researchers say that Flame may be part of a parallel project created by contractors who were hired by the same nation-state team that was behind Stuxnet and its sister malware, DuQu.

“Stuxnet and Duqu belonged to a single chain of attacks, which raised cyberwar-related concerns worldwide,” said Eugene Kaspersky, CEO and co-founder of Kaspersky Lab, in a statement. “The Flame malware looks to be another phase in this war, and it’s important to understand that such cyber weapons can easily be used against any country.”

Early analysis of Flame by the Lab indicates that it’s designed primarily to spy on the users of infected computers and steal data from them, including documents, recorded conversations and keystrokes. It also opens a backdoor to infected systems to allow the attackers to tweak the toolkit and add new functionality.

The malware, which is 20 megabytes when all of its modules are installed, contains multiple libraries, SQLite3 databases, various levels of encryption — some strong, some weak — and 20 plug-ins that can be swapped in and out to provide various functionality for the attackers. It even contains some code that is written in the LUA programming language — an uncommon choice for malware.

Kaspersky Lab is calling it “one of the most complex threats ever discovered.”
Read the whole thing. This one does everything but wash the dishes for you, and from the fact that the second most common place for finding infections (after Iran) is the 'Israeli-occupied territories' and that it's also hit Lebanon and Syria, I would guess that people are going to think that the evil Jooos are behind it.

Here's a report based on Iranian sources (Hat Tip: MFS - The Other News).
Iran's National Computer Emergency Response Team has detected an attack of a new computer virus close to Stuxnet and Duqu malwares.

CERT announced on Sunday that following the continuous research on the targeted attacks of Stuxnet and Duqu since 2010, it detected a new attack, codenamed "Flamer" and launched by a new malware.

...

According to CERT, the research results show that the recent incidents of mass data loss in Iran could be the outcome of the new virus' attack.
More here.

Granted Iran, but what's more intriguing to me is the possibility that Israel could have planted malware in 'Palestinian Authority' computers. The 'Palestinians' have had some problems themselves lately, and are accusing Mohamed Dahlan and Mohamed Rashid of messing with their computers. What if it's the Jooos instead?

Heh.

For the next several hours, posting may be sporadic.

Labels: , , , , , ,

Wednesday, April 25, 2012

Soccer Dad's Middle East Media Sampler

Here's Soccer Dad's Middle East Media Sampler for Wednesday, April 25.
1) The road to Arab democracy?

In The Islamist Road to Democracy Reuel Marc Gerecht argues:
We can easily find truly disturbing commentary and actions by members of the Egyptian Brotherhood, or by the Tunisian Rachid Ghannouchi, the intellectual guru behind the ruling Nahda Party. But we can just as easily find words and deeds that ought to make us consider the possibility that these men are neither Ernest Röhm and his fascist Brownshirts nor even religious versions of secular autocrats. Rather, they are cultural hybrids trying to figure out how to combine the best of the West (material progress and the absence of brutality in daily life) without betraying their faith and pride.v We know that in Iran, under theocracy, once die-hard members of the revolutionary elite have become proponents of evermore liberal democracy. Fundamentalists became fundamentalist critics. The Islamic Republic's controlled elections created a powerful appetite for real ones.
In Arab lands, militant Muslims who once espoused violent revolution now back representative government. They do so, in part, because they know how powerful the appeal of democracy is among the faithful. They also do so, as Iraq's Shiite clerics have made clear, because they are certain that free Muslims voting can't do worse than the Westernized dictators before them. Democracy is thus a means to keep Muslims more religious whereas theocracy actually secularizes society.
Gerecht even explains Turkey's - which would seem to be a counterexample to his thesis - growing radicalism as a response to previous liberal governments that persecuted its minorities.

Barry Rubin, though, in The Iraq model: as good at it gets writes:
Of the greatest importance is the fact that Islamist elements have been defeated (in the Sunni case) or held at bay (in the Shia case). Things can certainly get worse but some stability seems to have been achieved at this time.
Another key factor is that Iraq is acting more “normally” as a state by minding its own business. It is not subverting neighbors or trying to take over the Middle East. Iraq also has decent relations with the West. This is a country that is trying to deal with its own problems. And if there is factionalism and corruption, at least it appears to be clear that no force can monopolize power and establish a repressive dictatorship.
Call it chaotic pluralism as an alternative to Islamist dictatorship. And, yes, that appears to be the best that can be expected in those countries not still dominated by traditionalist monarchies. It is certainly preferable to the “Turkish model.” Yet I don’t expect many people in the West to appreciate that point.

Neither Gerecht nor Rubin is discussing a near term political horizon, but just what is the preferable first step on the long road to democracy.

2) Black gold blues

The Iranian oil industry suffered a cyberattack. In Facing Cyberattack, Iranian Officials Disconnect Some Oil Terminals From Internet, Thomas Erdbrink of the New York Times reports:
Iranian officials said the virus attack, which began in earnest on Sunday afternoon, had not affected oil production or exports, because the industry is still primarily mechanical and does not rely on the Internet. Officials said they were disconnecting the oil terminals and possibly some other installations in an effort to combat the virus.
“Fortunately our international oil selling division has not been affected,” said a high-level manager at the Oil Ministry who asked not to be mentioned for security reasons. “There is no panic, but this shows we have shortcomings in our security systems.”
There were some reports that the virus had forced widespread Internet shutdowns. “The ministry has disconnected all oil facilities, operations and even oil rigs from the Internet to prevent this virus from spreading,” said another Oil Ministry official who asked to remain anonymous, because he was not authorized to speak publicly about the attack. “Everybody at the ministry is working overtime to prevent this.” His assertion about the extent of the shutdowns could not be independently verified.
3) Settlements > Hamas?

In Israel Retroactively Legalizes 3 West Bank Settlements, new New York Times Jerusalem bureau chief Jodi Rudoren reports:
But while antisettlement advocates saw it as a significant shift in policy that could undermine the prospects for a two-state solution — and the United States and other foreign governments immediately raised concerns about the move — a spokesman for Prime Minister Benjamin Netanyahu argued that it was simply a matter of resolving technical problems such as improper permits and mistakenly building on the wrong hill.
“One can be critical of the Israeli settlement policy, that’s everybody’s right, but you can’t tell me that the Israeli government has built new settlements, and you can’t tell me this is legalizing unauthorized outposts,” said the Netanyahu spokesman, Mark Regev. “These decisions are procedural or technical. They don’t change anything whatsoever on the ground.”
To support her reporting, Rudoren gets two statements from two anti-settlement Israeli organizations, one the Palestinian Authority (“Netanyahu has pushed things to a dead end yet again.” ) and a disapproving statement from the State Department.

Contrast that with Unity Deal Brings Risks for Abbas and Israel, by Ethan Bronner from two months ago.
President Mahmoud Abbas of the Palestinian Authority embraced reconciliation with the Islamist movement Hamas on Monday, agreeing to head a unity government to prepare for elections in the West Bank and Gaza.
His move was welcomed cautiously by a broad range of Palestinians who are fed up with the brutal split at the heart of their national movement. It promised to upend Israeli-Palestinian relations, with Prime Minister Benjamin Netanyahu warning Mr. Abbas that he could have peace with Israel or unity with Hamas, but not both.
Bronner only cites the government of Israel as opposing the deal. The State Department dismissed the unity deal as an "internal matter."

Now these unity deals don't ever seem to work out. However, the differing treatment of these two stories illustrates a disturbing dynamic. "Settlements" are automatically designated an obstacle to peace. Any Palestinian objections to existing or potential settlements are taken at face value - by the media, even by the American government - though it isn't at all clear that the Oslo Accords forbid them.

However, a Fatah-Hamas deal demonstrates a blatant rejection of the premise of the peace process - that the PLO would reject terror. No NGO's who have reporters' attention object to this. The State Department yawns.

In the end the Palestinian Authority's objections and actions are what drives the peace process, not the documents they signed with Israel. As long as Palestinian obstructionism continues to be tolerated and rewarded, there will be no peace.

Labels: , , , , , , , , ,

Tuesday, April 24, 2012

Iran attacked by Viper

Iran has been attacked by a viper. But this viper is a computer virus, and it has attacked Iran's oil industry and the management of its oil exports.
Iran has confirmed that a cyber attack hit its Oil Ministry data systems. It claims there was no damage, but the National Iranian Oil Company website was inaccessible as of Monday.

Oil ministry spokesman Alireza Nikzad told the government-run Fars News Agency, "This cyber attack has not damaged the main data of the oil ministry and the National Iranian Oil Company since the general servers are separate from the main servers; even their cables are not linked to each other and are not linked to Internet service.

"We have a backup from all our main or secondary data, and there is no problem in this regard.”

He said the virus was identified as “Viper” and was aimed at deleting data off the servers. The attack was focused on the Kharg Island oil export terminal, where 2.2 million barrels of crude oil are transferred every day.
By Tuesday morning, however, Iran was singing a different tune.
According to Iranian media, over 50 of Tehran's top technical experts have been ordered to report to the ministry and assist in the "cyber battle."

The cyber attack, which has been ongoing throughout April, peaked on Sunday, when it took down several key computer systems in the Oil Ministry and corrupted the data stored on them in its entirety.

A virus was first detected inside the control systems of Kharg Island, which handles the vast majority of Iran's crude oil exports.

An Oil Ministry official said that it was still unclear whether the origin of the attack was external or internal.

Some Iranian media outlets ventured that the ministry may choose to shut down all non-vital systems for the near future to protect the Islamic Republic's crude exports while the problem was being resolved.
Now, who would want to attack Iran's oil exports? Hmmm.

Labels: ,

Google