Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Monday, May 30, 2022

NRA I Don't Need an AR-15 to Hunt a Duck But I Need a Raise

What do the NRA and the NRA stand for?


By Dominic Alvieri


May 29th, 2022



The National Rifle Association


The National Rifle Association held their annual convention in Houston Texas this week days after the mass shooting in Uvalde, Texas. Texas senator Ted Cruz made a speech last night blaming everything but the truth on the increase in the amount of mass shootings in our country. Cruz blamed violent video games which have been proven not to be the root cause and thoroughly written about.

I hate politics.

The NRA board of directors just re-elected longtime head Wayne LaPierre even amid scandals which says a lot about the group at the moment.





I am a firm believer in the right to keep and bear arms but a person does not need an AR-15 to hunt a duck or a deer. 

***Nearly every single mass shooting in the United States from Columbine to Uvalde has been carried out with an AR-15***

It is time for command and control. WE have the right to keep and bear arms and to be protected. Guns don't kill without being in control of the wrong person.

Not only were the speakers unshaken but they were heartless.




What does the NRA lobby? How much do they spend? Who contributes?

Good questions. Many sites have data readily available and in this case used from /opensecrets.org



2021 data was not available




For arguments sake lets say this dataset is a correct representation. A majority of spending is in the classic general "outside spending' category. What does that entail? This outside spending funds an entity called the Victory Fund which is a special purpose vehicle tied closely to the National Rifle Association.

Who donates to the NRA? Readily available information with the usual suspects like the gun makers themselves that I will not go over here but was an informative journey and a deeper dive is required. 

What does the group lobby? This is a small sample with viewpoints and political comments aside.




In 13 years the NRA has not budged on gun control.

S-3 was recently hired by the NRA





Americans will never give up their right to bear arms but we have past the point for gun control. In most states you can buy a gun at the age of 18 but have to wait until you are 21 to drink. 

Let that thought marinate for a moment.

There are many groups that are intent on keeping loose gun regulation and control. How many more innocent people have to die before we recognize the need for some control. 

 

The National Restaurant Association


This NRA represents the second largest private sector employer in the United States. 




In 13 years the National Restaurant Association has lobbied against raising the minimum wage in every instance. Contributors include the usual large corporate chain restaurants from Darden and new economy firms like DoorDash who contribute and lobby to keep wages down.

But how low?

The servers who serve you food and beverages have not had a raise in 13 years. In the state of Pennsylvania a server makes $2.83 per hour. In 35 years the pay rate for a server in Pennsylvania has only gone from $2.01 to $2.83 an hour. That is not a typo.

How can this be?


The largest growth industry pre-pandemic was the food and beverage sector which needed and still needs low wages to not only get back to previous levels but to continue to grow. Growth at the expense of a young and uneducated revolving door work force except for those for whom it is their profession.

Server wages are based off of a percentage of the Federal minimum wage subsidized by the employer to that Federal minimum, currently $7.25 an hour if tips are not made above that minimum hourly level.











Coca-Cola, McDonald's, DoorDash all donating to lobby and lobbyists to keep the minimum wage down. It is in their best interest to keep wage costs down and margins up. Business 101.

What about the people. We the people?






I will spare you the complete list but it is fair to say there a a lot of people who have a keen interest in keeping the Federal minimum wage down.


Both the NRA and the other NRA, the National Restaurant Association receive substantial amounts of money from groups intent on keeping the status quo, but for how much longer?




In 13 years the National Rifle Association has done nothing to control AR-15s which have been used in every mass school shooting.

In 13 years the National Restaurant Association has lobbied against raising the minimum wage every time.

Who do these groups work for? That was a rhetorical question.

Stay safe.


Friday, March 11, 2022

The DarkWeb is Pretty Bright on Telegram and Twitter

Dark net services displayed on social media.


By Dominic Alvieri

@AlvieriD

3-9-2022



More and more services and communications that were once reserved for the deepest depths of the DarkWeb are crawling up the stack, if you will to social media platforms. Ransomware group posts are now mainstream on Telegram and Twitter with calls for action, mis or disinformation and fake data leaks.

The hacking free for all


The Russian invasion of Ukraine on February 24th brought about armies of hacktivists, some real while the majority are unskilled and caught up in the wave. Legitimate groups like LAPSUS have taken to social media to announce high profile breaches from Samsung and Nvidia while other groups pretend to have hacked the world.

IT Army of Ukraine

The IT group turned army calls on users to for action providing details of direct targets the group requires taken down. More and more the IT Army of Ukraine posts targets in English and Ukrainian.





Network Battalion 65' posted a fake leak that was so embarrassing for the group but yet they post again. Not shown.


Network Battalion 65'



Like many groups constantly changing members. Brief synopsis is that the group revamping after a fallout and fake Kaspersky leak attempt. Keep an eye out.

Outrageous breach claims have been the norm. Unverified claims ranging from The National Bank of Russia to the FBI itself have been hacked. Hack the Planet until there is nothing left. Peak infosec I believe it was called. Thanks Carl.

Epic leak fail award goes to Network Battalion 65'


Right now this is a black eye that needs to be addressed. Kaspersky itself is facing intense pressure from security staff but this data breach was confirmed fake.


Kaspersky fake data leak.


Kaspersky has issued an official response courtesy of @ajvicens



Kaspersky official response to March 9th NB65 breach claim.

GhostSec

GhostSec like many malicious groups has several channels. IntelGS is Intel GhostSec a darker splintered part of the group that has also joined in the cyber war.


GhostSec


GhostSec channels appear to be currently fragmented and not coordinated.




Lapsus$


After two successful high profile leaks of Samsung and Nvidia last week LAPSUS is toying around with an anonymous poll when allegedly they have already breached Vodafone.

Mercado Libre just disclosed a breach on their latest 8k release this week with the Securities and Exchange commission. Mercado did not release a timeline or provide more vector details at this moment. 

Impresa the Portuguese media giant was hacked by Lapsus$ over the new years holiday and has had several website and platform issues ever since. The main Impresa website /impresa.pt has been down and is currently down as of March 11th, 2022.


Impresa of Portugal hacked by Lapsus.



Lapsus$ is seen toying with companies they have already hacked and allegedly hacked. Vodafone is unconfirmed at the moment.



LAPSUS Vodafone breach claim.


Groups regularly post claims and recruit people of all types. Anonymous groups large and small have taken over social media with misinformation and disinformation campaigns creating profiles, hashtags and using automated software and bots to promote their goals.

Videos and photoshopped imagers are the norm. 


IY Army of Ukraine post.


Against the West / Blue Hornet


The group appears to be restructuring and has been quiet this week as of last check. Like all groups use caution so that you don't get stung.


Against the West.

Trolls

Don't waste your time.

Stormus group tops that list. Others come to mind.

Verify any information or disinformation before you respond in any way, if at all.



Gazprom alleged data leak on Telegram




Lapsus$ live post as I blog taking credit for Ubisoft hack and advertising The Verge article about it on one of their channels.


Ubisoft hacked by Lapsus$


Lapsus$ appears to have several flaws, youth, inexperience in several key areas, smashing and grabbing what they can, the group is buying inside access from either an employee or vendor and then getting to work. Access is usually gained through a VPN or AnyDesk remote control application, recon, targeting and then deploying payloads. Social engineering methods and other low grade tactics.

Check your employees and vendors.

Currently advertising for services now.

Updated: 7 members of Lapsus$ have been arrested aged 16-21. Other members are still at large and doubtful ring leader or mastermind is teenager arrested in Oxford, England as media claims. I do not believe that to be true. There are more members at large. To be continued...


Lapsus$ advertising for hackers.

Conti

Still alive and kicking albeit smaller and segmented. Looking to reform in Russia.

Samsung Leak

Lapsus$ again.



LockBit has just allegedly leaked several companies from Singapore, verification pending. LockBit has been very active in the past 30 days. Lapsus has a mock vote due this weekend to leak another high profile company and I'm sure they will be plenty of fake anonymous group claims. 

There are other groups but this was intended to be a brief account.  
Stay safe.




Dominic Alvieri

Twitter @AlvieriD

Monday, October 18, 2021

Hovering Over a Link is Not as Safe as You Think

Decoding HTML is not illegal but this line of code should be


By Dominic Alvieri

October 18th, 2021



Cybersecurity Awareness Month


Twitter was abuzz this week when inspecting HTML elements came to the headlines with the Governor of Missouri threatening to prosecute a reporter for simply viewing readily accessible web site code and attempting to help rectify the problem. The Governor is unaware of the basic structure of a website. Everyone can F12.

What is HTML? HyperText Markup Language (HTML) and Extensible HyperText Markup Language (XHTML) are the foundational coding languages and technologies of designing web pages. 

But do you know HTML? What is XHTML?  Is it CSS or XSS? You need one for style.
Luckily I happen to know both.

Dropper files, phishing kits, payloads...

We are at HTML5 and HTML file paths are used to find the geolocation of a user. 



Info security.



The latest from Info Security by Dan Raywood is the Top Ten Ways to Detect Phishing above. 

Hovering over a link was not on the list.




Cybersecurity Awareness Month


There are several ways to weaponize a link and a hover and script to a link. A hover over instance of malware is not new. Zusy banking trojan comes to mind but it was easily detectable because you needed to open a Microsoft PowerPoint first. You did not need to enable macros or JavaScript for the dropper file to download the malicious trojan. 

No click was needed either, just hovering over the link. 



So what does this all mean today?

There are several different variants and tricks that can be coded and multiple languages and programs to fool the unsuspecting visitor after arrival to a web site and page. Basic HTML coding will be required for all web pages as a basic framework. Finding the location beforehand is essential for all. Cyber security practitioners should be aware of the changing threat landscape. Phishing accounts for the vast majority of initial network entry for malware, 89%, and malware deployment, 95%,  according to Sans, Info Security and others. 



Start with the basic terminology


Markup Language


By definition a set of symbols or tags that allow you to render text on a web browser or in print.


SGML


Standard Generalized Markup Language defines the syntax of a markup language.

HTML


HyperText Markup Language files enable navigation from one page to another web page via links invented by Tim Berners-Lee in 1989. HTML is defined syntactically by SGML. The main difference between HTML and XHTML is basically syntax-based rules. HTML was created basically for text while XHTML is more dynamic and defined.

XHTML


Extensible HyperText Markup Language is a combination of XML and HTML and has been a World Wide Web Consortium (W3C) recommendation since 2000. XHTML is based on XML which is restrictive and stricter than more lenient HTML. It is used for more consistent display across browsers to accommodate for mobile browsers.

XML


Extensible Markup Language is a subset of SGML and used to define the syntax of a markup language. You can create and define elements. Elements are a set of instructions.

CSS


Cascading Style Sheets are a set of rules to define the appearance of a web pages color, style, etc. There are three types of Cascading Style sheets: embedded, inclined and linked.

Elements


Elements are a set of instructions.

TAGS


TAGS are indicators and are used to identify the type of content in this section. There are many types of TAGS such as <h1>,  <span> etc. Opening and closing TAGS are required. <title></title>.  For empty elements the slash would follow the tag to be syntactically correct,  <tag/>.


Attribute


An attribute is a part of an element that modifies the characteristics of that element.

JavaScript, PhP, Python...more to know.


An email, a mobile site or a traditional web page can all be manipulated differently. These are the simple basic terms of one of the many ways used to manipulate a malicious link.


Mouse over script in an HTML element 



Apple mouse over script example.

October 13th, 2021 CNBC article about the new iPhone Watch series 7 has a blue underlined hyperlink with the text "Apple" in the first sentence of the paragraph, also know as an HTML element. Where does it take you? Implicit trust is implied with a reputable site such as CNBC so trust shouldn't be a major concern in most cases. A programmer from CNBC most likely.

The web page was coded this way.

Technically the link can lead anywhere if you do not inspect the element. Attacking the host site and other entries are topics for another day. Lets focus on the simple things first. I was expecting the link to go to the Apple website but instead it was coded and directed to CNBC's Apple stock quote below.


Apple stock price 10/13/21

What coding is required to enable or disable functions of an element? JavaScript? Python?


The Apple example above is technically an HTML element. There are several ways to accomplish obfuscation of origin but with simple HTML you can code as you wish. You can change styles, fonts, links, text and input the address you want to show on the mouseover, or your hovering script. You can even disable the hover over script. How about blocking the security feature in an email that shows the address when hovering? Sound easy? Let us drill down deeper.


Disable hover text over an HTML element


visibility: hidden;



Here is a tool tip. I just disabled the hover over text on this HTML element by hiding the visibility. By removing the hover text script now when you hover over the text there is no hover over the text showing again hiding the actual link or any text. 

Creating believable, clickable copy text is the next step in making you click. 






The line to locate is <a href



It isn't the line, it's how you use it. 


Much like real world real estate, virtual real estate is all about location, location, location. There is another way to code the location but lets stick with the basic that is known rather than educate the nefariously minded phisherman should one come across this.

href basics indicate actual location in quotes > followed by text to show.


<a href="Actual address of this link">What I am showing you goes here</a>



Link address is dictated by the location attribute in the href element shown highlighted in line 13 of code below. Line number will vary depending on site and complexity. Very easy to code and see.

It is as simple to code as entering text and seeing it is as easy as inspecting an element. Be aware of redirects, MiTM, MiTMO and other tactics, but the basic address of where you are going is shown.

The actual location goes first and is in quotations, ""> with text component to follow before closing the tag, </a> in <a href example above. It is all in the code.



HTML code of sample site.


For the early stages I have not coded any CSS or JavaScript yet so we are just creating the basic frame. This one line of HTML code determines the location in the href element and additional text can obfuscate or add to the ploy. 

Be aware of actual location and ip address, among other things.


Hover over text in an email


Playing with location in an email


The following email was obfuscated without any header spoofing which is another topic. 

Adding to the deception most email platforms will let you input your desired location and text. Below you can see the safelinks protection status in Outlook. I created the text to look like a secure, safe link.


Email spoofed and changed.


The hover over email


Other security features for the email hover over include showing the destination address at the lower left of the screen. Working on a bounty to disable an email hover over but it requires more work and I have had inconsistent results so far. Full details will be released at a later date after completion and repair or patch.

The security location bar at the bottom left of the screen does not disable so far, but what if you created your own camouflage pop up to block or surround the actual location message may be an option and an alert.

How easy is it to get safelinks protection status?


The idea is to protect the user and not give away too many secrets to cyber criminals but it is no big secret that garnering safelinks status is quite easy. The header and other coding will be adjusted and not discussed here. This isn't a how-to-hack guide. 

Insert link as you wish.





Hover over text in a smartphone?


Yes. On Apple iPhone and most modern smartphones just lightly tap and hold and security pop up appears. Please note the safelinks status. This is actually safe and from NIST, the National Institute of Standards and Technology.



NIST cybersecurity week.


This Facebook link below actually leads to my Twitter profile. 





I deleted my Facebook account last year


As always be aware of where you click or even hover.

 Always look for the actual location and do not take blue text for what it is worth. 

Stay safe. More blue text.


Dominic Alvieri
 

Saturday, July 17, 2021

Baby Twitter Coin is Not From Twitter

 Baby Coin Mania Fuels Surge in Crypto Fraud


Unofficial Baby Twitter Coin


Warning New Baby Twitter Coin is not from Twitter. 

New BEP20 tokens are popping up daily flooding the market with fake coins being created out of thin air in many cases. Many coins are copying other coins and projects. Buyer beware.

I caught this fake Baby Twitter Coin operator last week attempting to offer the non official Twitter named baby coin.


Baby Twitter Coin website



After a few days offline the fake Baby Twitter Coin website is back up. The Twitter profiles are inactive but open. 

Opening a new website and Twitter account the unofficial Twitter baby coin operators were quick to attempt to tweet an offering pictured below.



I informed Twitter and responded to the tweet and quickly got blocked. What a surprise. A block is meaningless to a cybersecurity professional because there are always ways to get information legally. 

Original operators Twitter profile, changed several times.


Operators Twitter profile


Blocked after informing Twitter and questioning the coin operators.


Blocked after questioning.

These operators look to be out of Germany with initial registrations and are on the run changing details trying to sell this fake offer.

There is a great follow feature on Twitter the operators don't know about. Even if you are blocked the profile still shows up with all of your changes.

Example shown below of the alleged Baby Twitter Coin operator.


Alleged Baby Twitter Coin operator.


Always do your research and know who is backing your coin or project. This Baby Twitter Coin is not from Twitter. Always go to official Twitter sites for information on Twitter projects.

This unofficial Twitter baby coin even pitched a charity component. Selling a fake coin and giving some to charity doesn't legitimize the fake offer. 

Fake coin charity.

Elon Musk has fueled the baby coin mania and there is no end in sight. The Securities and Exchange Commission is due to give an official stance on crypto by the end of July. As always be careful what you buy and click on. This is not an official Twitter sponsored coin. 

Fake Twitter tokens are being offered on other non official Twitter knock offs like Twitter-Finance[.]com which is also not from Twitter.



The Cyber Show
Dominic Alvieri
Not on Facebook
Twitter @AlvieriD

The Kremlin, Politics and Ransomware

Qilin Ransomware caught with politically motivated fake document (and old data) in post. by Dominic Alvieri March 8th, 2025 @AlvieriD Was it...