Saturday, April 18, 2009

Hack Poll Machines = P100M  

MANILA, Philippines—Senator Alan Peter Cayetano has filed a resolution setting aside P100 million as an incentive to anyone who can convincingly demonstrate the weakness of the automated poll system.

Cayetano, at a press conference Friday, said that if any IT expert can establish that the system to be used in the 2010 polls is not secure from fraud and tampering, "Comelec should cancel the contract, save the P11 billion and sue for damages the contractor in the event of such successful hacking."

He said he would rather revert to the manual counting of votes if the computerized system would lead to wholesale cheating.

Cayetano said the resolution, which he would file on Monday, was in response to a statement by a Comelec official challenging cyber security experts to test the system for weaknesses.

"The most effective way to test if indeed a system is credible, reliable and tamper-proof or fraud-proof is to offer a sizable prize to whoever can hack and convincingly show the weaknesses of the system," Cayetano said in his draft resolution.

"To make the said incentive system work, there is a need to authorize the Commission on Elections to set aside the amount not exceeding P100 million to be utilized as a prize money for the said successful hacker," he said.

If the system is successfully hacked, the Comelec will then be authorized to cancel the contract and sue the winning bidder.

Despite repeated assurances poll automation will significantly curb cheating, Cayetano said there are fears it might actually induce a "bigger and more sophisticated method of election cheating if the system is vulnerable to manipulation."

Source: Inquirer.net

Thursday, April 2, 2009

PRC Website Defaced  



Yesterday, the official website of the Professional Regulation Commission (PRC) was defaced by a group of hackers known as "linuXploit_crew" on the afternoon of April 1, April Fools Day.

I managed to have a screenshot of the defaced site (see above) at around 9:30PM, showing a blank page (no images) with words "Hacked by linuXploit_crew =) by DeRf-, Hualdo and _serial_killer_". I checked its subpages and I found out that its still intact thus only the main page was compromised.

As of noon of April 2, the site is still unaccessible. But as I have visited the site (its 3:05PM on my PC's clock), the site has been back to normal.

This surely mean that some .gov.ph sites are vulnerable to hacking.

Tuesday, March 31, 2009

New Security Tool to detect Conficker Worm  

The US Department of Homeland Security released a tool on Monday to detect whether a computer is infected by the Conficker worm.

Full Story

Saturday, March 28, 2009

Conficker's April 1st routine still a mystery  

Conficker's routine on the April 1st with its newest variant dubbed as "Conficker.C" is still a mystery to security researchers.

PCs infected with Conficker.c, the third version of the worm that first appeared late last year, will use a new communication scheme on April 1 to establish a link to the command-and-control servers operated by the hackers who seeded the malware. The date is hard-coded into the worm, which in turn polls any of a number of major Web sites, including Yahoo, for the date, said Stewart.


"So far, we haven't seen any evidence [on those machines] of what it will do April 1," added Stewart, although that's to be expected. "It's not April 1 yet, so they're not going to put something online, where it might be found. In fact, it's almost a little risky for us to try to look for those sites, since it might give away that we have some bots in their network."

Source: http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9130228

However, on F-Scure's notes on their blog, nothing is likely to happen on the said date. Hopefully.

Thursday, February 26, 2009

An Update on Gmail Outage  

Gmail is already up after an outage occurred last Tuesday at approximately 0930 GMT leaving millions of people worldwide disrupted on their access for about two and a half hours.


Google engineers are still investigating the root cause of the problem.