EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

04.21.09

FBI, CIPAV, and the Windows Back Doors Revisited

Posted in Microsoft, Security, Windows at 6:30 am by Dr. Roy Schestowitz

Looking through the tube

Summary: How (and why) the American secret services rely on Windows

THE back doors in Microsoft Windows are a serious issue that we've already covered, so there is no point doing it again. Adding to what we already know, there is now this report from Wired Magazine and another from IDG:

CIPAV spyware helped nab unemployed engineer angry over outsourcing

There is also a discussion at Slashdot and one reader of ours wrote: “A good question to ask is, what is it about Windows that allows CIPAV to be so easily activated? Does it even require visiting a contaminated Web site (see the Slashdot article)? What is it in Windows that allows such features?” Here is some relevant information which this reader sent to us:

CIPAV, which stands for “Computer and Internet Protocol Address Verifier,” is secret surveillance software that the FBI used last month to help identify whoever was e-mailing bomb threats almost daily to a Washington high school.

[...]

The only clue in the affidavit is that the CIPAV would operate as a pen register for up to 60 days after the software had been “activated” by the recipient. In other words, the FBI swore that the monitor would “time out” after 60 days. But not that it would delete itself or not be able to spread in some worm or bot fashion.

This post neither defense nor criticism of malicious and dangerous behaviour that the FBI is rightly intercepting. It is merely recognition of the operation of Microsoft Windows.

It is not news that the FBI uses Windows viruses (there were several articles about it last year) and the DHS, which recently recruited Microsoft after pressure from the BSA, is now recruiting hackers.
________
[1] FBI remotely installs spyware to trace bomb threat

While there’s been plenty of speculation about how the FBI might deliver spyware electronically, this case appears to be the first to reveal how the technique is used in practice. The FBI did confirm in 2001 that it was working on a virus called Magic Lantern but hasn’t said much about it since.    

[2] FBI ducks questions about its remotely installed spyware

There are plenty of unanswered questions about the FBI spyware that, as we reported earlier this week, can be delivered over the Internet and implanted in a suspect’s computer remotely.

[3] FBI to Notify Microsoft Windows Users Who Were Victims of Botnets

The Department of Justice and FBI have announced the results of an ongoing cyber crime initiative to disrupt and dismantle “botherders” and elevate the public’s cyber security awareness of botnets.

[4] FBI: Operation Bot Roast finds over 1 million botnet victims

The Department of Justice and FBI Wednesday said ongoing investigations have identified more than 1 million botnet crime victims.

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

4 Comments

  1. The Mad Hatter said,

    April 21, 2009 at 11:03 am

    Gravatar

    Based on what I’ve read, you are regarded as a probable threat if you run an OS or Web Browser that CIPAV cannot infect. The reasoning seems to be that if you have made the choice to run Linux/OSX or use Firefox/Opera on Windows instead of Internet Exploder, you must have something to hide.

    No, I don’t have details or a link, I remember reading this a while back somewhere, and now can’t remember where.

  2. Roy Schestowitz said,

    April 21, 2009 at 11:14 am

    Gravatar

    There’s this recent incident.

  3. Yggdrasil said,

    April 21, 2009 at 7:30 pm

    Gravatar

    You are misleading people, again. You should have cited this from the Computer World article:

    “Some user action was CLEARLY REQUIRED to infect the PC with the CIPAV. In the warrant application, the FBI used the term activate several times and alluded to a spyware plant failure if the target did not trigger the CIPAV through the targeted MySpace account. MySpace accounts can’t receive traditional e-mail, so one hacker standard — attach the CIPAV to a message and hope the recipient is stupid enough to launch it — wasn’t available”

    Exactly. If you want to infect a Linux users, it’s as simple as sending them some program and getting them to run it. You also mention Slashdot, but of course, you only mention comments that would be critical of Microsoft. How about these comments instead? Both of which received high rankings.

    “What makes you think they don’t have a variant for Linux? User stupidity (i.e: bad/no security) isn’t unique to Windows. Off the top of my head, if they are relying on the web as an infection vector combined with user stupidity, why not write it into a Firefox extension?

    Yeah, it wouldn’t get your typical /. geek, but most criminals aren’t known for their foresight or intelligence. “Oh, the private website with the bank account information needs me to install this software! Ok, what could possibly go wrong?”

    In response to that:

    “This is an excellent statement. Stupidity knows no bounds. Its also dangerous to assume that the FBI doesn’t know what it is doing. When I worked in law enforcement, the FBI computer crimes agents I knew were well versed in operating systems other than Windows. The two I worked with most often had a solid knowledge of Linux and Cisco IOS.”

  4. Brian Assaf said,

    April 23, 2009 at 7:53 pm

    Gravatar

    “If you want to infect a Linux users, it’s as simple as sending them some program and getting them to run it.”

    Um. That easy huh? By default files aren’t executable, so it would require changing the permission. It would also need to be run as root to infect the whole system. How about dependencies? How about architecture differences. Just x86 or 64-bits? MIPS? Arm?
    So on and so forth. Linux isn’t a monoculture (no pun intended here guys/gals!) like the Windows ecosystem is.

    Even a pre-packaged deb (which can be installed ala double click in Ubuntu) would ask for a password, and again, wouldn’t be viable for every Linux distribution out there, architecture not withstanding.

    Having to run something out of the blue is odd if you use a package management system. Cryptographically signed, easily installed/uninstalled and updated (and source available for those interested.)

    Although maybe I’m alone in the 24,000+ packages available in Ubuntu being enough for regular computer use.

    My point here is I’ve unlearned a habit, there is no need to grab software willy nilly off the net. Instead check the repos, and check the source of software. Do you trust it, etc and why should I install this. Plus does it behave like a rootkit, if so then it can be scanned for, if this really does become some sort of popular vector…

    So, yes, you could use social engineering to get someone to install something, but the process should set off a red flag in the user.
    There isn’t some autorun or double click deal here. For those users that understand binaries are a blackbox, where no one can inspect, change, etc. anything, install at your own risk.

What Else is New


  1. Alice v CLS Bank (SCOTUS, 2014) Has Had a Profound Effect on 2017 as Nearly No Software Patents Upheld at a High Level

    As 2017 nears its end (less than two weeks left), a look back reveals a terrible year for proponents of software patents and a milestone for opponents of software patents



  2. PTAB Helps Defend and Encourage Work by Actual Technology Companies in the US, the Patent Trolls' Lobby is Upset

    The Patent Trial and Appeal Board (PTAB), which continues to invalidate software patents by the thousands, comes under attack from the expected sites, namely those that are fronting for patent trolls and parasites



  3. Patent Misconceptions Promoted in Media Dominated by the Patent Microcosm, Not Actual Innovators

    Examples from the media where popular myths have been promoted over the past few days, taking advantage of passivity and silence among those who actually create and invent



  4. Links 17/12/2017: KStars 2.8.9, GNOME 3.27.3, Parrot Security 3.10

    Links for the day



  5. Raw: Benoît Battistelli Has Long Been Obsessed With 'Alternative Facts' (Lying) Regarding Everything

    The chronic lying by Battistelli’s EPO goes way back and reveals a total lack of integrity, shedding doubt on just about any statement issued by the Office



  6. Raw: At the EPO “Social Democracy” is Actually a Euphemism for Authoritarian Regime

    An old document about the EPO‘s transition to so-called ‘social’ ‘democracy’ and what that means in practical terms



  7. Battistelli's 'UPC Buddy' Michel Barnier Helped Squash EU Intervention in Dysfunctional (Subverted by Battistelli) Administrative Council

    A look back at how Michel Barnier helped cover Battistelli's back, insisting that the Commission cannot do anything to rectify matters at the EPO (Elżbieta Bieńkowska, another UPC proponent, said something similar later)



  8. Raw: “Experienced Examiners Can Examine Anything.” (Even Not in Their Field!)

    An internal document shows how the EPO handles imbalance in filings, in essence shifting examiners to fields they are not familiar with



  9. Andrei Iancu in Charge of the United States Patent Office (USPTO) Would be a Patent Microcosm Coup

    The progression of Andrei Iancu's nomination/appointment is a reason for concern; it is, for a fact, a reason for optimism among patent extremists



  10. The Latest IAM Puff Pieces That Launder the 'Reputation' of Patent Trolls

    The creeping threat of patent extortion (litigation from companies that are empty shells with nothing but patents) does not worry IAM; instead, this is the vision IAM wants to actualise, having been paid by stakeholders in such a nefarious outcome



  11. The EPO Has Found 'Creative' New Ways to Bribe the Media and Promote Software Patents

    From Computer-Implemented Inventions (CII) and "Industry 4.0" the EPO is moving to creative new misnomers for carriers of software patents, SEP (patents-encumbered 'standards'), so-called 'FRAND' etc.



  12. EPO Busy Distracting From Miscarriage/Abuse of Justice at the EPO (Both Office and Organisation)

    The European Patent Organisation continues to be a vassal of the Office (Christoph Ernst is defending Battistelli) and justice is not being honoured; it's being discarded in the darkness (in secret meetings)



  13. Bristows LLP/IP Kat Carrying on With Dead UPC Jingoism

    The same old tune from Bristows not only gets played in Bristows' 'alternate reality' blog but also in other blogs where Bristows staff is 'contributing' (to confusion and misconceptions)



  14. Links 16/12/2017: Mesa 17.2.7, Wine 3.0 RC2, Kdenlive 17.12.0, Mir 0.29

    Links for the day



  15. Patrick Corcoran is Innocent, Yet Battistelli Will/May Have the Power to Sack Him Next Month (in DG1)

    The EPO's Administrative Council does not want to even mention Patrick Corcoran, as merely bringing that up might lead to the suggestion that Benoît Battistelli should be fired (yes, they can fire him), but to set the record straight, at the EPO truth-tellers are punished and those whom they expose are shielded by the Administrative Council



  16. Patent Trolls Are Going Bust in the United States (Along With the 'Protection' Racket Conglomerates)

    RPX continues its gradual collapse and patent trolls fail to find leverage now that software patents are kaput and patent opportunists struggle to access Texan courts



  17. IBM's Manny Schecter is Wrong Again and He is Attempting to Justify Patent Trolling

    In yet another dodgy effort to undermine the US Supreme Court and bring back software patents, IBM's "chief patent counsel" (his current job title) expresses views that are bunk or "alternative facts"



  18. EPO Administrative Council Disallows Discussion About Violations of the Law by Benoît Battistelli

    The EPO crisis is not ending for the Administrative Council does not want to tackle any of the obvious problems; Patrick Corcoran is a taboo subject and Ernst is coming across as another protector of Benoît Battistelli, based on today's meeting (the second meeting he chairs)



  19. Links 13/12/2017: GIMP 2.9.8, Fedora 25 End Of Life, AltOS 1.8.3

    Links for the day



  20. Judge Corcoran Got His User ID/Desk Back (as ILO Asked), But Cannot Perform Actual Work

    The latest update regarding Patrick Corcoran, whose 3-year ordeal is far from over in spite of ILO's unambiguous rulings in his favour



  21. The End of Software Patents and PTAB's Role in Enforcing That End

    Software patents are fast becoming a dying breed and the appeal board (PTAB) of the USPTO accelerates this trend, irrespective of patent immunity attempts



  22. No, China Isn't Most Innovative, It's Just Granting a Lot of Low-Quality Patents

    Patent extremists are trying to make China look like a role model or a success story because China grants far too many patents, spurring an explosion in litigation



  23. Battistelli-Campinos Transition Will Be a Smooth One as the Administrative Council Remains the Same and the Boards Still Besieged

    A rather pessimistic (albeit likely realistic) expectation from tomorrow's meeting of the Administrative Council, which continues to show that no lessons were learned and no strategy will be altered to avoid doom (low-quality patents and stocks running out)



  24. Links 12/12/2017: New BlackArch ISO and Stable Kernels

    Links for the day



  25. German Media Helps Cover Up -- Not Cover -- the Latest EPO Scandal

    EPO-Handelsblatt attention diversion tricks may be effective as German media barely shows interest in one of the EPO's biggest scandals to date



  26. PTAB Haters Fail to Guard Bogus Patents, But They Still Try

    Three Affiliated Tribes probably won't enjoy sovereign immunity from PTAB, Dennis Crouch won't manage to slow down PTAB, and patent litigation will stagnate as bad patents perish before they even land in a lawsuit



  27. Team UPC's Tilmann Defends Rogue Vote at 1 AM in the Morning With Just 5% of Politicians (Those With Vested Interests) Attending

    Just when German democracy is being stolen by a legislative coup (in the dead of night when 95% of politicians are absent/asleep) there's someone 'courageous' enough to rear his ugly head and attempt to justify that coup



  28. The Mask Falls: Lobbyist David Kappos Now Composes Pieces for the Patent Trolls' Lobby (IAM)

    David Kappos, a former USPTO Director who is now lobbying for large corporations that derive revenue from patent extortion, is writing for IAM even if his views are significantly biased by his aggressive paymasters (just like IAM's)



  29. The EPO Protest Tomorrow Isn't Just About Judge Corcoran But About the EPO as a Whole

    PO staff is about to protest against the employer, pointing out that "Battistelli is still showing a total and utter lack of respect not only for his staff and their rights but also for the Administrative Council and for the Tribunal"



  30. Claim: Judge Corcoran to Be Put Under Benoît Battistelli's Control in DG1

    Benoît Battistelli, who openly disregards and refuses to obey judges (while intervening in trials and delivering 'royal decrees' whenever it suits him), may soon gain direct control over the judge he hates most


CoPilotCo

RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

CoPilotCo

Recent Posts