ie8 fix
madison

Threat Chaos

Richard Stiennon

Haephrati technique used to crack US research lab

By | December 10, 2007, 9:13am PST

Summary: The New York Times is reporting that they obtained a copy of a report from US-CERT that attacks eminating from Chinese IP addresses successfully targeted employees of Oak Ridge National Laboratory in Tennessee. In addition to research in energy, nanotechnology and “isotope production”, Oak Ridge provides federal, state and local government agencies and departments [...]

The New York Times is reporting that they obtained a copy of a report from US-CERT that attacks eminating from Chinese IP addresses successfully targeted employees of Oak Ridge National Laboratory in Tennessee. In addition to research in energy, nanotechnology and “isotope production”, Oak Ridge

provides federal, state and local government agencies and departments with technology and expertise to support national and homeland security needs. This technology and expertise is also shared with industry to enhance America’s economic competitiveness in world markets.

According to Wikipedia.

The attacks took the form of up to seven carefully crafted emails sent to internal addresses that induced employees to open attachments or click on links that installed Trojans that could steal information. Sound familiar? Remember the Israeli Trojan fiasco using Michael Haephrati’s crimeware?

I would expect by this time that all US research facilities would be protected from malicious downloads and should certainly not allow the transfer of information from a user’s machine to an untrusted site. I guess there is a large gap between my expectations and reality.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Disclosure

Richard

http://blogs.zdnet.com/threatchaos/?page_id=455

Biography

Richard

A former ZDNet blogger, Richard Stiennon is an industry consultant. Most recently he was Chief Marketing Officer for Fortinet, Inc., the largest privately held security vendor. prior to that he was Chief Research Analyst at IT-Harvest. And before creating IT-Harvest, he was VP of threat research for Webroot Software, Inc. the leading commercial anti-spyware solution.

Previously, Richard was VP Research at Gartner, Inc. where he covered security topics including firewalls, intrusion detection, intrusion prevention, security consulting and managed security services for the Security and Privacy group. He is a holder of Gartner's Thought Leadership award for 2003 and was named "One of the 50 most powerful people in Networking" by NetworkWorld magazine. His speaking engagements have included conferences and meetings throughout North and South America, Hawaii, Tokyo, Tel Aviv, Istanbul, Milan, Munich, Hannover, Madrid, London, and Cannes.

The discussion hasn’t started yet. Why don’t you begin it?

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix