<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/">
<channel>
<title>Techdirt. Stories filed under &quot;trojan&quot;</title>
<description>Easily digestible tech news...</description>
<link>http://www.techdirt.com/</link>
<language>en-us</language>
<image><title>Techdirt. Stories filed under &quot;trojan&quot;</title><url>http://www.techdirt.com/images/td-88x31.gif</url><link>http://www.techdirt.com/</link></image>
<item>
<pubDate>Wed, 27 Jun 2012 00:31:00 PDT</pubDate>
<title>Trojan Author Includes Integrated Chat, Challenges Security Researchers Digging Through His Code</title>
<dc:creator>Mike Masnick</dc:creator>
<link>http://www.techdirt.com/articles/20120622/01175719425/trojan-author-includes-integrated-chat-challenges-security-researchers-digging-through-his-code.shtml</link>
<guid>http://www.techdirt.com/articles/20120622/01175719425/trojan-author-includes-integrated-chat-challenges-security-researchers-digging-through-his-code.shtml</guid>
<description><![CDATA[ Here's a fascinating story, found via <a href="http://boingboing.net/2012/06/21/malware-author-taunts-security.html?utm_source=feedburner&#038;utm_medium=feed&#038;utm_campaign=Feed%3A+boingboing%2FiBag+%28Boing+Boing%29" target="_blank">Boing Boing</a>, of some malware (a password stealing trojan targeting <i>Diablo III</i> players) that included some sort of integrated chat function, which the researchers at AVG only noticed <a href="http://blogs.avg.com/news-threats/chatted-hacker-virus/" target="_blank">when the hacker reached out to them while they were searching through his code</a>.  Imagine their surprise when up popped a dialog box asking them what they were doing:
<center><i>
Hacker: What are you doing? Why are you researching my Trojan?
<br /><br />
Hacker: What do you want from it?
</i>
<br /><br />
<a href="http://imgur.com/KEkZY"><img src="http://i.imgur.com/KEkZY.jpg" width=400 /></a>
</center>
<br />
The AVG folks continued to chat with the guy for a little while, which is how they realized just how powerful the trojan was and how much it could do.  The guy controlling it demonstrated this to them by remotely shutting down their machine after talking to them for a little while.<br /><br /><a href="http://www.techdirt.com/articles/20120622/01175719425/trojan-author-includes-integrated-chat-challenges-security-researchers-digging-through-his-code.shtml">Permalink</a> | <a href="http://www.techdirt.com/articles/20120622/01175719425/trojan-author-includes-integrated-chat-challenges-security-researchers-digging-through-his-code.shtml#comments">Comments</a> | <a href="http://www.techdirt.com/articles/20120622/01175719425/trojan-author-includes-integrated-chat-challenges-security-researchers-digging-through-his-code.shtml?op=sharethis">Email This Story</a><br />
 ]]></description>
<slash:department>paying-attention</slash:department>
<wfw:commentRss>http://www.techdirt.com/comment_rss.php?sid=20120622/01175719425</wfw:commentRss>
</item>
<item>
<pubDate>Mon, 10 Oct 2011 16:13:43 PDT</pubDate>
<title>Hackers Claim That German Officials Have A Backdoor Trojan For Spying On Skype... Which Is A Huge Security Risk</title>
<dc:creator>Mike Masnick</dc:creator>
<link>http://www.techdirt.com/articles/20111010/14002616290/hackers-claim-that-german-officials-have-backdoor-trojan-spying-skype-which-is-huge-security-risk.shtml</link>
<guid>http://www.techdirt.com/articles/20111010/14002616290/hackers-claim-that-german-officials-have-backdoor-trojan-spying-skype-which-is-huge-security-risk.shtml</guid>
<description><![CDATA[ For many years various governments have complained about the fact that Skype communications are encrypted, and have <a href="http://www.techdirt.com/articles/20100702/17551510065.shtml">demanded backdoors</a>.  In the US, the FBI has been <a href="http://www.techdirt.com/articles/20110216/23535513143/its-back-fbi-announcing-desire-to-wiretap-internet.shtml">pushing hard</a> for such backdoors.  There have been some reports of applications that allow for wiretapping Skype, despite its supposed encryption, but not much in the way of details.  Now the famed Chaos Computer Club (CCC) is <a href="http://www.ccc.de/en/updates/2011/staatstrojaner" target="_blank">claiming to have reverse engineered</a> the "lawful interception" trojan being used by German law enforcement.
<br /><br />
They got the program after a lawyer whose client was under investigation <a href="http://news.cnet.com/8301-27080_3-20118194-245/hackers-say-german-officials-used-backdoor-trojan/" target="_blank">gave the CCC his client's hard drive</a>, where the group found the code.   As frequently happens with these kinds of things, the CCC found that the trojan actually introduces myriad security problems as well:
<blockquote><i>
The analysis concludes, that the trojan's developers never even tried to put in technical safeguards to make sure the malware can exclusively be used for wiretapping internet telephony, as set forth by the constitution court. On the contrary, the design included functionality to clandestinely add more components over the network right from the start, making it a bridge-head to further infiltrate the computer.
<br /><br />
"This refutes the claim that an effective separation of just wiretapping internet telephony and a full-blown trojan is possible in practice &ndash; or even desired," commented a CCC speaker. "Our analysis revealed once again that law enforcement agencies will overstep their authority if not watched carefully. In this case functions clearly intended for breaking the law were implemented in this malware: they were meant for uploading and executing arbitrary code on the targeted system."
<br /><br />
The government malware can, unchecked by a judge, load extensions by remote control, to use the trojan for other functions, including but not limited to eavesdropping. This complete control over the infected PC &ndash; owing to the poor craftsmanship that went into this trojan &ndash;  is open not just to the agency that put it there, but to everyone. It could even be used to upload falsified "evidence" against the PC's owner, or to delete files, which puts the whole rationale for this method of investigation into question.
<br /><br />
[....]
<br /><br />
The analysis also revealed serious security holes that the trojan is tearing into infected systems. The screenshots and audio files it sends out are encrypted in an incompetent way, the commands from the control software to the trojan are even completely unencrypted. Neither the commands to the trojan nor its replies are authenticated or have their integrity protected. Not only can unauthorized third parties assume control of the infected system, but even attackers of mediocre skill level can connect to the authorities, claim to be a specific instance of the trojan, and upload fake data. It is even conceivable that the law enforcement agencies's IT infrastructure could be attacked through this channel. The CCC has not yet performed a penetration test on the server side of the trojan infrastructure.
<br /><br />
"We were surprised and shocked by the lack of even elementary security in the code. Any attacker could assume control of a computer infiltrated by the German law enforcement authorities", commented a speaker of the CCC. "The security level this trojan leaves the infected systems in is comparable to it setting all passwords to '1234'".
</i></blockquote>
Even without the fact that more capabilities can be added, the existing software is pretty powerful.  It apparently can remotely control the computers that it's on, take screenshots of what's happening on the computer, including emails and personal messages.  And yet, time and time again law enforcement asks us to "trust" them when they want the power to secretly install this kind of crap on people's computers?<br /><br /><a href="http://www.techdirt.com/articles/20111010/14002616290/hackers-claim-that-german-officials-have-backdoor-trojan-spying-skype-which-is-huge-security-risk.shtml">Permalink</a> | <a href="http://www.techdirt.com/articles/20111010/14002616290/hackers-claim-that-german-officials-have-backdoor-trojan-spying-skype-which-is-huge-security-risk.shtml#comments">Comments</a> | <a href="http://www.techdirt.com/articles/20111010/14002616290/hackers-claim-that-german-officials-have-backdoor-trojan-spying-skype-which-is-huge-security-risk.shtml?op=sharethis">Email This Story</a><br />
 ]]></description>
<slash:department>breaking-the-internet</slash:department>
<wfw:commentRss>http://www.techdirt.com/comment_rss.php?sid=20111010/14002616290</wfw:commentRss>
</item>
</channel>
</rss>