<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: underworld]]></title>
    <link>http://securityratty.com/tag/underworld</link>
    <description></description>
    <pubDate>Thu, 14 Feb 2008 08:44:29 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[How America may be funding the Mafia in Japan.]]></title>
      <link>http://securityratty.com/article/f15a445cd9e45e1a5df0f67cd09029af</link>
      <guid>http://securityratty.com/article/f15a445cd9e45e1a5df0f67cd09029af</guid>
      <description><![CDATA[Those of us who may have thought of Japan as a country of respectful, law-abiding peaceful citizens, would do well to think again


In a Washington Post article titled: &quot;The Mob is Big in Japan&quot;, the...]]></description>
      <content:encoded><![CDATA[Those of us who may have thought of Japan as a country of respectful, law-abiding peaceful citizens, would do well to think again.<br /> <br /><br />In a Washington Post article titled: <a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/05/09/AR2008050902544.html">"The Mob is Big in Japan", </a>the writer, Jake Adelstein paints a far different picture.  Mr. Adelstein has spent the past 15 years covering the Mafia (Yakuza) as a crime reporter for Japan's largest newspaper, the Yomiuri Shimbun.  He has been so relentless in his reporting, that his life and that of his family are now in danger.    <br /><br />Apparently, Mobs are legal entities there and they have "fan magazines" and comic books.  The Japanese National Police Agency (NPA)estimates that the yakuza has nearly 80,000 members.  Police say that in Tokyo alone, there are more than 800 yakuza "front companies" in industries such as: investment and auditing firms, construction companies and pastry shops.  Disturbingly, it is reported that the mobsters have even opened their own bank in California.<br /><br />In more recent times, the yakuza have moved into finance.  Japan's Securities and Exchange Surveillance Commission know of more than 50 listed companies with ties to the underworld.  U.S. investors have invested billions of dollars in the Japanese stock market.  How much of that is going towards funding the Japanese Mob?  To add further insult to injury, the yakuza makes much of their ill-gotten profits from child pornography.  Want to hear something revolting?  Owning child porn in Japan is LEGAL.<br /><br />Investigation firms such as ours constantly advise clients to do their due diligence.  How would you like to enter into a business agreement with a Japanese company and later find out that they were a front company for drug runners and child porn peddlers?  Remember, you can't always rely on a government to tell you who the bad guys are and they don't always wear black hats.  <br /><br />Know what you are getting into and if it is a deal worth pursuing, hire somebody to conduct a thorough investigation or send over a member of your staff to check them out fully and avoid having your reputation damaged down the road.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Sun, 11 May 2008 21:15:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/japan">japan</category>
      <category domain="http://securityratty.com/tag/child porn peddlers">child porn peddlers</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <category domain="http://securityratty.com/tag/yakuza">yakuza</category>
      <category domain="http://securityratty.com/tag/child porn">child porn</category>
      <category domain="http://securityratty.com/tag/front companies">front companies</category>
      <category domain="http://securityratty.com/tag/adelstein">adelstein</category>
      <category domain="http://securityratty.com/tag/investigation">investigation</category>
      <category domain="http://securityratty.com/tag/investigation firms">investigation firms</category>
      <source url="http://www.thebulletproofblog.com/2008/05/how-america-may-be-funding-mafia-in.html">How America may be funding the Mafia in Japan.</source>
    </item>
    <item>
      <title><![CDATA[Hackers Holy Grail - Redefined by Microsoft]]></title>
      <link>http://securityratty.com/article/97046c89e45b2d143db873bee80ac614</link>
      <guid>http://securityratty.com/article/97046c89e45b2d143db873bee80ac614</guid>
      <description><![CDATA[Countdown to Black-Hat COFEE Device Begins
The Seattle Times is reporting today that Microsoft has developed the ultimate hacker tool for Windows. Of course, MS doesnt consider it a hacker tool, they...]]></description>
      <content:encoded><![CDATA[<p>Countdown to Black-Hat COFEE Device Begins !</p>
<p>The <a href="http://seattletimes.nwsource.com/html/microsoft/2004379751_msftlaw29.html" target="_blank">Seattle Times is reporting</a> today that Microsoft has developed the ultimate hacker tool for Windows. Of course, MS doesn&#8217;t consider it a hacker tool, they describe it as a <em>computer forensics tool</em>. Here is a quote from the <a href="http://seattletimes.nwsource.com/html/microsoft/2004379751_msftlaw29.html" target="_blank">article</a>:</p>
<blockquote><p>The COFEE, which stands for Computer Online Forensic Evidence Extractor, is a USB &#8220;thumb drive&#8221; that was quietly distributed to a handful of law-enforcement agencies last June. Microsoft General Counsel Brad Smith described its use to the 350 law-enforcement experts attending a company conference Monday.</p>
<p>The device contains 150 commands that can dramatically cut the time it takes to gather digital evidence, which is becoming more important in real-world crime, as well as cybercrime. It can decrypt passwords and analyze a computer&#8217;s Internet activity, as well as data stored in the computer.</p>
<p>It also eliminates the need to seize a computer itself, which typically involves disconnecting from a network, turning off the power and potentially losing data. Instead, the investigator can scan for evidence on site.</p></blockquote>
<p>Of course, on the one hand MS has developed a forensic tool for use by authorized law enforcement agents. They have also produced a compelling proof of concept that their operating system&#8217;s security can be soundly defeated anytime an attacker has physical access. And they have also created a treasure trove of exploits to be reverse engineered.</p>
<p>It is well documented that cybercrime is not only big business, but that it is highly organized. The fact that, in the cybercrime underworld, there are markets for stolen data, toolkits (such as the <a href="http://en.wikipedia.org/wiki/Rock_Phish" target="_blank">Rock Phish Kit</a>), and services (such as renting time on Botnets) is a strong demonstration of how organized (and profitable) cybercrime is. Microsoft has now defined a new Holy Grail for those organizations to pursue. The CSI/FBI computer crime report consistently demonstrates how significant the <a href="http://www.cert.org/insider_threat/" target="_blank">Insider Threat</a> is, and clones of the COFEE will make those individuals that much more dangerous.</p>
<p><strong>Also, the reverse engineering of one of these devices would certainly be of great value to the black hat community, and do potentially long term harm to desktop security.</strong> The fact that there are 150 exploit functions on the device written by Microsoft&#8217;s own, with their privileged knowledge, makes this device worth its weight in gold (or perhaps plutonium).</p>
<p>Given the number of governments that have been accused of either participating with or shielding cyber criminals, it is only a matter of time before these devices are reverse engineered and duplicated. Of course, it may not be necessary for  the black hat community to  acquire one to reverse engineer it. Many countries <strong>require </strong>public documentation of how evidence is collected and preserved. So it may only be a matter of time before Microsoft finds itself providing direct testimony, as other forensic product companies have done, on the exact workings of COFEE.</p>
<p>- Erik</p>
<p><a href="http://artofinfosec.com">Art of Information Security</a> would <a href="http://artofinfosec.com/feedback/">love your feedback</a> !</p>
<p><a href="http://artofinfosec.com/56/hackers-holy-grail-redefined-by-microsoft/">Hacker&#8217;s Holy Grail - Redefined by Microsoft&#8230;</a></p>
<img src="http://feeds.feedburner.com/~r/artofinfosec/~4/280202965" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 29 Apr 2008 12:53:42 +0000</pubDate>
      <category domain="http://securityratty.com/tag/holy grail">holy grail</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/hackers holy grail">hackers holy grail</category>
      <category domain="http://securityratty.com/tag/black hat community">black hat community</category>
      <category domain="http://securityratty.com/tag/cybercrime underworld">cybercrime underworld</category>
      <category domain="http://securityratty.com/tag/cybercrime">cybercrime</category>
      <category domain="http://securityratty.com/tag/computer">computer</category>
      <category domain="http://securityratty.com/tag/gather digital evidence">gather digital evidence</category>
      <category domain="http://securityratty.com/tag/reverse engineer">reverse engineer</category>
      <source url="http://feeds.feedburner.com/~r/artofinfosec/~3/280202965/">Hackers Holy Grail - Redefined by Microsoft</source>
    </item>
    <item>
      <title><![CDATA[The Cybercrime Arms Race]]></title>
      <link>http://securityratty.com/article/ec6ba32b6856b213a9441213fb5860fd</link>
      <guid>http://securityratty.com/article/ec6ba32b6856b213a9441213fb5860fd</guid>
      <description><![CDATA[Source: Kaspersky Labs) Sophisticated groups are leading underworld efforts into cybercrime, creating viruses, spyware, Trojans, worms and other malware. These groups now even provide complementary...]]></description>
      <content:encoded><![CDATA[<b>(Source: Kaspersky Labs)</b>  Sophisticated groups are leading underworld efforts into cybercrime, creating viruses, spyware, Trojans, worms and other malware. These groups now even provide complementary criminal services to their clients helping them to outsmart Internet security providers and users. With little or no investment, there's plenty of payback for cybercrime perpetrators at every level of this ecosystem.  Download this whitepaper to learn more.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=1XdOg4"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=1XdOg4" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/237638994" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 19 Feb 2008 11:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cybercrime">cybercrime</category>
      <category domain="http://securityratty.com/tag/cybercrime perpetrators">cybercrime perpetrators</category>
      <category domain="http://securityratty.com/tag/underworld efforts">underworld efforts</category>
      <category domain="http://securityratty.com/tag/kaspersky labs">kaspersky labs</category>
      <category domain="http://securityratty.com/tag/plenty">plenty</category>
      <category domain="http://securityratty.com/tag/source">source</category>
      <category domain="http://securityratty.com/tag/spyware">spyware</category>
      <category domain="http://securityratty.com/tag/users">users</category>
      <category domain="http://securityratty.com/tag/whitepaper">whitepaper</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/237638994/whitepapers.do">The Cybercrime Arms Race</source>
    </item>
    <item>
      <title><![CDATA[Botnet Evolution]]></title>
      <link>http://securityratty.com/article/98109b21c1bf8c59519d23b9751f2a39</link>
      <guid>http://securityratty.com/article/98109b21c1bf8c59519d23b9751f2a39</guid>
      <description><![CDATA[Some Botnet army commanders are not deterred by efforts to block traditional command-and-control pathways or take no for answer. This has resulted in two new bot distribution approaches from our...]]></description>
      <content:encoded><![CDATA[Some Botnet army commanders are not deterred by efforts to block traditional command-and-control pathways or take no for answer.  This has resulted in two new bot distribution approaches from our friends in the cyber-underworld.]]></content:encoded>
      <pubDate>Thu, 14 Feb 2008 08:44:29 +0000</pubDate>
      <category domain="http://securityratty.com/tag/bot distribution approaches">bot distribution approaches</category>
      <category domain="http://securityratty.com/tag/botnet army commanders">botnet army commanders</category>
      <category domain="http://securityratty.com/tag/block traditional">block traditional</category>
      <category domain="http://securityratty.com/tag/pathways">pathways</category>
      <category domain="http://securityratty.com/tag/efforts">efforts</category>
      <category domain="http://securityratty.com/tag/friends">friends</category>
      <category domain="http://securityratty.com/tag/answer">answer</category>
      <source url="http://networking.ittoolbox.com/r/rss.asp?url=http://blogs.ittoolbox.com/security/adventures/archives/botnet-evolution-22487">Botnet Evolution</source>
    </item>
  </channel>
</rss>
