Showing posts with label Hacker. Show all posts
Showing posts with label Hacker. Show all posts

Monday, September 17, 2007

Computer threat - Network Security

Every TCP package have 'flag bit’ defining content and intention of each package.

Example:

    A package with flag bit contain "SYN or SYNCHRONIZE" will undertake to conduct initiation connection from sender to recipient. A package with flag bit contain "ACK" will undertake to inform receiver about sender information.
    While a TCP package with beet flag contain "FIN" or "FINISH" undertaking to stop connection from sender to recipient.

To build a TCP connection, need data transfer package between two host, transfer of this data recognized by the name of "TCP Three-Way Handshake" as below picture.



Computer Network Threat


Threat is very harmful to the entire system and also by application at internal and external network.

The threat as follows:


Remote Login - this matter happened when someone capable to connect to a computer and have ability to control to several things related to resource found on the host or computer.


Application Backdoors - some program have special ability to access with long distance (remote access). Some bug program, exactly contain a backdoor or hidden access providing level control the computer and program.


SMTP session hijacking - SMTP is most commonly method used to deliver E-mail. By getting E-mail mailing-list, someone can deliver undesirable E-mail to thousands of or more users. This matter is called unsolicited junk mail or spam.


Spamming conducted with joining SMTP server which not suspect, then deliver thousands of E-mail called redirecting process, so that complicate to detect who is the real sender of the Mail Spam.


Operating system bugs – In application, some operation system have conducive security gap to be exploited illegally.


E-mail bombs - is an Individual attack, someone send hundreds or thousands of E-mail to one address so the victim E-mail cannot accept E-mail anymore.


Macro - To make simple or facilitate procedure an application, many application program permit us to make command which can be run by the program (script). By exploiting ability of script or macro, attacker can cause damage of data at computer.


Virus – Most known to make trouble at computer. The growth of virus from method, way of, making, effectiveness, damage storey, and also speed of spreading is different each other.


Redirect bombs – Hacker or Cracker can use ICMP to change direction of information and attack to other router.


Source routing - At many case, a data package which work through one or some network determined by router pass to route information by the router, but sometime hacker used the package as the real sender.

Another type of computer attack are from (next posted about this) :

    Denial of Service (DoS)
    Spoofing
    Broadcast Amplification
    TCP SYN

The method to run the threat above, can be conducted variously including using virus.

Saturday, August 11, 2007

UK hacker loses extradition fight

A British man has lost his High Court fight against extradition to the US for allegedly carrying out the "biggest military computer hack of all time".



Glasgow-born Gary McKinnon, of north London, is accused of gaining access to 97 US military and Nasa computers.



Home Secretary John Reid granted the US request to extradite him for trial.



At the High Court in London, his lawyers argued the 41-year-old had been subjected to "improper threats" and the move would breach his human rights.



His lawyers had argued that, if extradited, he would face an unknown length of time in pre-trial detention, with no likelihood of bail.



He would also face a long prison sentence - "in the region of 45 years" - and may not be allowed to serve part of the sentence at home in the UK, his lawyers had said.



But, on Tuesday, Lord Justice Maurice Kay and Mr Justice Goldring dismissed his legal challenge, saying they could not find any grounds for appeal.



Ben Cooper, for Mr McKinnon, said his client would now seek to make an appeal against his extradition at the House of Lords.



Alleged threats by US authorities, including one from New Jersey prosecutors that "he would fry", would be among issues raised, Mr Cooper said.



"We will certainly be applying for this court to certify a point of law of public importance and to grant leave," he said.



Mr McKinnon had been suffering from ill health during recent court hearings, he added.



Mr McKinnon has never denied that he accessed the computer networks of a wide number of US military institutions between February 2001 and March 2002.



Mr McKinnon, arrested in November 2002, has always maintained that he was motivated by curiosity and that he only managed to get into the networks because of lax security.



Technology News by BBC NEWS