Researcher: Tools Will Help Personalize ID Theft by 2010

April 20th, 2007

A well-known security expert demonstrates a framework at the CanSecWest conference that makes it easier for criminals to steal identifying data.

Hackers with scrounged-up data ask the same question as dogs who've caught the school bus: What do we do with it now?

Roelof Temmingh has the answer, at least for rogue hackers, in the form of a framework that makes identity theft a much easier proposition. The framework, which is in the early stages of development, is called Evolution. Temmingh, a security expert who's authored well-known security testing applications such as Wikto and CrowBar , demonstrated Evolution during his opening presentation here at the CanSecWest security conference on April 18.

Evolution works by feeding on disparate identifying data such as name, e-mail address, company, word or phrase, and Web site - or the hacker's version of that, which would translate to IP address, virtual hosts, Netblocks/AS routes, affiliations (with social sites such as LinkedIn, MySpace, Facebook, and so on), forward and reverse DNS-MX/NS records, Whois records/rWhois and referring registrars, Google, and microformats including, for example, vCards.

The framework's genius lies in transforming one type of information to another. Evolution can transform a domain into an e-mail address or telephone number, or both (through the Whois domain name lookup service), to related DNS names, to IPs, to a Web site, to e-mail addresses (again, via Whois), to telephone numbers, to geographic locations, to alternative e-mail addresses, to related telephone numbers, to co-hosted sites with the same IP, and so on.

The idea of using transforms to unearth hidden data builds on the logic that if A points to B points to C, and X points to Y points to C, then A points to X, Temmingh said. Transforms call on Java entities including affiliationEntity.java, DNSNameEntity.java, DocumentEntity.java, DomainEntity.java, EmailAddressEntity.java, and so on.

Evolution now contains 26 transforms and "is growing steadily," Temmingh said. An example of a transform that can move one type of information to another: PersonToEmailPhoneSiteGoogleBlog.java.

So what does that mean? The transforms are part of the answer to, "Who can do anything with a fill-in-the-blank?" Who can do anything with an e-mail address or a Social Security number, for example. Given a SSN and an entity with which to transform it, an identity thief or other criminal could do much, Temmingh said.

For example, with domain and e-mail data, a criminal can spoof e-mail to make it look as if it were coming from an internal source within a company. Making it look like an "accidental" cc, the crook could e-mail employees - or, less subtly, a business such as Bloomberg's - stating that the CEO has resigned, that the company is insolvent, that the recipient should hasten to sell his or her shares, and so on. Or a criminal could register a site in the name of the holding company's director and mirror a porn site to get it populated. Or spoof e-mail from a techie at a sister company to employees at a target company, mentioning a lamentable "discovery." Or spoof an SMS from a mobile phone to a high-profile investor about corruption in the company.

Next, sit back and watch share price drop. Buy low and sell high: the classic pump-and-dump scheme.

"It's kid's stuff, and it's easy to spot," Temmingh said. "Timing, however, is everything." If a criminal can do it at the right time, say, during a merger between two companies, the crime is likely to be successful, he said. "The only thing you need is to create doubt in the minds of other people."

To enable crimes such as these, a tool such as Evolution would come in handy. It returns hotlinked results in list form or in a spider diagram that shows each transform operation done on a given datum and where that transform leads. The question is, what does Temmingh intend to do with this potentially nefarious framework?

In fact, Evolution can do much on behalf of conventional security, he said. It can be used for standard footprinting (DNS, IPs and domains, for example), for identifying phishing sites or for finding partner alliances with weaker security postures.

On the other hand, it can also be used to identify targets for social engineering and client-side attacks, for finding war-dialing ranges, to find alternative e-mail addresses for content attacks, or to understand business drivers of specific organizations along with their sensitivities. For example, a socially engineered attack benefits greatly by having convincing backup data on hand, including knowing what the target's phone number or alternative e-mail addresses are.

This all demonstrates what Temmingh said is the scary side of Web 2.0. "Web 2.0 contains great technology, but little is known about the security implications when that technology is actually used," he said.

"Real criminals don't write buffer overflows," he said. "They follow the route of least resistance."

Mainstream criminals tend to lag behind technological advance, he said. For example, phishing attacks were known about as far back as 1995. The question is, what will be on criminals' minds in 2010? Temmingh believes that the Internet's darker elements will be using tools "something close to" what he's demonstrated in Evolution: a framework that can execute personalized identity theft with scraps of information.

"[Criminals] will be able to have tools to merge this information together to manipulate outcome of certain events," Temmingh said.

If the examples given aren't scary enough, here are more that he described: Who at the NSA uses Gmail? Which NASA employees are using MySpace? Which people in Kabul are using Skype? In which countries do marines have bases? What are the names and e-mail addresses of single, young women in my neighborhood who are straight - or not?

Better yet, post a fake help wanted ad, Temmingh suggested: "Looking for a nuclear scientist/engineer with experience in uranium enrichment and military background. Earn top dollar. 401k plan, dental coverage, 25 days leave. Flex time."

After applicants send in their life stories on their resumes, go ahead and create an identity for them. Create an e-mail address with their name, post responses on blogs, join affiliation sites.

Thus criminals can concoct entire legions of half- (or more) fake but credible (online) people with whom they can do mischief, Temmingh said - another illustration of how, while the security implications of Web 2.0 have largely been overlooked, criminals will likely pick up on them in the near future.

Copyright 2007 by Ziff Davis Media, Distributed by United Press International


print this article email this article download pdf blog this article bookmark this article     Digg this Stumble it share on Facebook share on Reddit add to delicious save to Yahoo! bookmarks
4.9/5 after 8 votes


April 20th, 2007 all stories
Technology / Other

Comments: 0
Rank: 4.9/5 after 8 votes

  • Stumble this up

  • Digg this

  • Share it:
  • share on Facebook
  • share on MySpace
  • share on Slashdot
  • rss-newsfeed
  • share on Google
  • share on Reddit
  • add to delicious
  • save to Yahoo! bookmarks
  • share on Windows Live
  • Add to Mixx!
Rating: 4.9/5 after 8 votes


Tags


  • Physicists Demonstrate Quantum Memory with Matter Qubits
    Physicists Demonstrate Quantum Memory with Matter Qubits
    Physics / General Physics
    created Jul 03, 2009 | popularity 4.4 / 5 (17) | comments 1
  • 'Holey' Nanosheets for Wastewater Dye Removal
    Nanotechnology / Nanomaterials
    created Jul 01, 2009 | popularity 5 / 5 (5) | comments 1
  • Jellyfish Robot Swims Like its Biological Counterpart
    Jellyfish Robot Swims Like its Biological Counterpart
    Electronics / Robotics
    created Jun 26, 2009 | popularity 4.4 / 5 (8) | comments 1
  • Could Maxwell's Demon Exist in Nanoscale Systems?
    Could Maxwell's Demon Exist in Nanoscale Systems?
    Physics / General Physics
    created Jun 24, 2009 | popularity 4.4 / 5 (18) | comments 29
  • Living Safely with Robots, Beyond Asimov's Laws
    Living Safely with Robots, Beyond Asimov's Laws
    Electronics / Robotics
    created Jun 22, 2009 | popularity 4.6 / 5 (52) | comments 40
  • Other News

    Japan demands 119 million dlrs in tax from Amazon: report

    Technology / Business

    created 16 hours ago | popularity 3.6 / 5 (5) | comments 1

    Japanese authorities told a sales affiliate of US retail giant Amazon.com to pay about 119 million dollars in tax for unreported income over a three-year period, a newspaper said Sunday.


    Iconic skyscrapers find new luster by going green (AP)

    Iconic skyscrapers find new luster by going green

    Technology / Energy

    created 17 hours ago | popularity 1 / 5 (1) | comments 0

    (AP) -- When owners of the Empire State Building decided to blanket its towering facade this year with thousands of insulating windows, they were only partly interested in saving energy. They also needed ...


    Geeks double as scourges and sages at media summit

    Technology / Business

    created 12 hours ago | popularity not rated yet | comments 0

    (AP) -- The media moguls attending an annual powwow staged by investment bank Allen & Co. used to be able to rest comfortably in the Idaho mountains as they mulled their next moves.


    Downturn dating: Hearts flutter as markets stutter (AP)

    Downturn dating: Hearts flutter as markets stutter

    Technology / Internet

    created 17 hours ago | popularity not rated yet | comments 0

    (AP) -- Credit the recession for "staycations" and bringing us more game-night parties at home. But also give it a shout for spurring more first dates.


    UK spy chief's family details posted on Facebook

    Technology / Internet

    created 17 hours ago | popularity not rated yet | comments 0

    (AP) -- He's the spy who came in from the beach.