December 22, 2024

Tokyo Cyber Security Competition Draws 90 Hackers

Posted on February 8, 2015 by in Security

Tokyo – A cyber security competition began Saturday in Tokyo, with organizers aiming to show off the skills of young Japanese hackers by testing them against international rivals.

The final rounds of the Security Contest 2014, or SECCON, brought together 90 participants in 24 teams from seven nations and regions: China, Japan, Poland, Russia, South Korea, Taiwan, and the United States.

The winners of the Tokyo competition will advance to the prestigious Def Con CTF (Capture the Flag) competition, slated for later this year, organisers said. SECCON was designed to allow young Japanese technology engineers to show off their skills on the world stage, while also encouraging more to get into the field of cyber security.

Teams compete for points by hacking six virtual servers to discover particular keywords, and can also intervene to stop their rivals’ cyberattacks.

“There is a need for a forum where fledgling, young… hackers can grow and gain understanding of their families, schools and the outside world,” said Yoshinori Takesako, the head of the SECCON organising committee.

“This is important in order to keep them away from being pulled into the underground world,” he said in a statement to AFP.

The Japan-based event has drawn a total of 4,186 participants from 58 countries through various qualifying rounds.

Takesako said the organizers, supported by government agencies, tech firms, and scholars, also want to change the media image that Japan lags other nations in the cyber security field.

Subscribe to the SecurityWeek Email Briefing

view counter

© AFP 2013


SecurityWeek RSS Feed

North Korea Calls Obama ‘Monkey’, Blames US for Blackout

Posted on December 27, 2014 by in Security

North Korea on Saturday called US President Barack Obama a “monkey” for inciting cinemas to screen a comedy featuring a fictional plot to kill its leader, and blamed Washington for an Internet blackout this week.

The isolated dictatorship’s powerful National Defence Commission (NDC) threatened “inescapable deadly blows” over the film and accused the US of “disturbing the Internet operation” of North Korean media outlets.

The Internet outage triggered speculation that US authorities may have launched a cyber-attack in retaliation for the hacking of Sony Pictures — the studio behind madcap North Korea comedy “The Interview”.

Washington has said the attack on Sony was carried out by Pyongyang.

The NDC accused Obama of taking the lead in encouraging cinemas to screen “The Interview” on Christmas Day. Sony had initially cancelled its release after major US cinema chains said they would not show it, following threats by hackers aimed at cinemagoers.

“Obama always goes reckless in words and deeds like a monkey in a tropical forest,” a spokesman for the NDC’s policy department said in a statement published by the North’s official KCNA news agency.

“If the US persists in American-style arrogant, high-handed and gangster-like arbitrary practices despite (North Korea’s) repeated warnings, the US should bear in mind that its failed political affairs will face inescapable deadly blows,” the NDC spokesman said.

He accused Washington of linking the hacking of Sony to North Korea “without clear evidence” and repeated Pyongyang’s condemnation of the film, describing it as “a movie for agitating terrorism produced with high-ranking politicians of the US administration involved”.

Unlikely symbol of free speech

The film took in $ 1 million in its limited-release opening day, showing in around 300 mostly small, independent theatres. It was also released online for rental or purchase.

The film, which has been panned by critics, has become an unlikely symbol of free speech thanks to the hacker threats that nearly scuppered its release.

The low-brow comedy revolving around the fictional assassination of North Korean leader Kim Jong-Un played to packed cinemas across the US.

A file sharing website reported the film had been illegally downloaded more than 750,000 times.

Online services for Sony’s PlayStation and Microsoft’s Xbox gaming consoles, which had decided to release the film online, went down Thursday, apparently attacked by hackers.

Microsoft’s online network for its Xbox gaming console was restored to nearly full service Friday but the PlayStation network remained down.

The NDC spokesman called again for a joint investigation into the Sony hack, which has already been rejected by the US, while accusing Washington of “beating air after being hit hard by others”.

“In actuality, the US, a big country, started disturbing the Internet operation of major media of the DPRK (North Korea), not knowing shame like children playing a tag,” he said.

From Monday night, websites of the North’s major state media went dead for hours.

The cause of the outages in North Korea’s already limited Internet access has not been confirmed. The US has refused to say whether it was involved in the shutdown.

The North has about one million computers — mainly available at educational and state institutions — but most lack any connection to the world wide web.

All online content and email are strictly censored or monitored with access to the Internet strictly limited to a handful of top party cadres, propaganda officials and expatriates.

KCNA previously compared Obama to a black “monkey” in a zoo in May, prompting Washington to condemn the comments as “ugly and disrespectful”.

The North Korean mouthpiece also earlier this year called South Korean President Park Geun-Hye a “prostitute” in thrall to her “pimp” Obama.

Subscribe to the SecurityWeek Email Briefing

view counter

© AFP 2013


SecurityWeek RSS Feed

MBR Wiper Attacks Hit Korean Power Plant: Trend Micro

Posted on December 24, 2014 by in Security

Researchers at Trend Micro revealed details of an attack against a major Korean utility company hit by malware designed to wipe the master boot records (MBR) of compromised computers.

According to Trend Micro, the malware is believed to have infected the targeted systems through a vulnerability in the Hangul Word Processor (HWP), a commonly-used application in South Korea. The attackers used a variety of social engineering lures as well.

“We detect the malware as TROJ_WHAIM.A, which is a fairly straightforward MBR wiper,” according to Trend Micro. “In addition to the MBR, it also overwrites files that are of specific types on the affected system. It installs itself as a service on affected machines to ensure that it will run whenever the system is restarted. Rather cleverly, it uses file names, service names, and descriptions of actual legitimate Windows services. This ensures that a cursory examination of a system’s services may not find anything malicious, helping this threat evade detection.”

“This particular MBR-wiping behavior, while uncommon, has been seen before,” the researchers noted. “We observed these routines in March 2013 when several attacks hit various South Korean government agencies resulting in major disruptions to their operations. The malware involved in this attack overwrote the MBR with a series of the words PRINCPES, HASTATI, or PR!NCPES. The recent attack on Sony Pictures also exhibited a similar MBR-wiping capability.”

Trend Micro also found similarities to the previous MBR wiper attacks as well. All three attacks overwrite the MBR with certain repeated strings; this attack uses the repeating “Who Am I?” string, while the Sony attack used a repeating 0xAAAAAAAA pattern.

The attack on Sony has caused a further rift between North Korea and the United States, as U.S. President Barack Obama promised last week that the United States would offer a proportional response to North Korea’s involvement in the attack.

North Korea has denied any involvement in the incident. The country began suffering Internet outages this week, though the cause of those outages remains unclear.

“While there are definite similarities in the behavior of all these attacks, this is not enough to conclude that the parties behind the attacks are also related,” according to Trend Micro. “All three attacks have been well documented, and it is possible that the parties behind each attack were “inspired” by the others without necessarily being tied. Without sufficient evidence, we cannot make claims either way.”

“These attacks highlight our findings about the destructive, MBR-wiping malware that appear to have become a part of the arsenal of several threat actors,” the researchers added. “This is a threat that system administrators will have to deal with, and not all targeted attack countermeasures will be effective. Techniques to mitigate the damage that these attacks cause should be considered as a part of defense-in-depth networks.”

Subscribe to the SecurityWeek Email Briefing

view counter

Brian Prince is a Contributing Writer for SecurityWeek.

Previous Columns by Brian Prince:


SecurityWeek RSS Feed