net127: a scrapbook of words and images

January 27, 2004

The Giant Wooden Horse Did It!

Mark Rasch, Security Focus, writes:

According to Greek mythology, the seer Laocoon, a priest of Apollo, warned the residents of Troy against accepting into their city the giant wooden horse designed by Odysseus and created by the architect Epeius. His famous warning, "Trojans, trust not the horse. Whatever it be, I fear the Greeks, even when bringing gifts," applies equally today to importing unknown files as it did to the Trojans 4,000 years ago.

We think we know all about the dangers of Trojan horses, but there is a new and more dangerous legal wrinkle to consider. In the past few months, a couple of people in England were acquitted based upon the so-called "Trojan defense" -- what we criminal lawyers used to call the "SODDI" defense: Some Other Dude Did It.

The Trojan defense presents two equally frightening problems: the possibilities of acquitting the guilty, or convicting the innocent.

In the first case, given the nature of electronic evidence, virtually all computer crime prosecutions rely on "circumstantial" evidence. To prove that John Doe, for example hacked into ABC company, you collect IP history logs and other corroborating data, maybe engage in an IRC chat with John Doe, get a warrant or subpoena for his ISP information, show a pattern of activity consistent with the hacking, and then (if you are a law enforcement agent) get a warrant to kick in Mr. Doe's door and seize his computer. If the forensic examination of the computer shows hacking files, access to hacking sites, relevant e-mail, and even versions of the malicious code, it's a slam-dunk case for conviction. Right

Trouble in the UK

But what if, in addition to all of this "evidence," you also find the existence of a Trojan horse server -- say, a version of Optix Pro or another remote access program. Does the mere existence of such a program provide a Get Out of Jail Free card Probably not. However, given the ephemeral nature of electronic evidence, and the fact that it can always be altered, how confident would you be that Doe was in fact guilty beyond a reasonable doubt

The higher the hacker's profile, the more attractive a target he or she may make for other hackers. And after all, if you were a hacker, would you want to store your contraband files on your own machine, or, like the cuckoo, would you keep your eggs in another bird's nest Such "file parking" strategies have been used by hackers for years.

In October, 2002 Julian Green was arrested in Devon, England after police searched his home PC and found examples of child pornography. ISP had logs identified Green as the person responsible for the downloads, and the existence of the child porn on his PC seemed to be all the corroboration the constable would have needed to obtain a conviction.

However, a defense forensic expert also found evidence that there were Trojans planted on Green's computer that were designed to piggyback his browser, and log into porn sites. The Trojans probably were downloaded as e-mail attachments -- made all the more likely by the fact that Green had a teenage son. Unable to definitively prove that Green knowingly and intentionally downloaded the files, the prosecution dismissed the charges.

Similarly, Aaron Caffrey, a 19-year-old hacker, was charged in Southwark Crown Court with carrying out a denial of service attack on the computers of the port of Houston, Texas on September 20, 2001 -- less than two weeks after the 9/11 attacks. The port's webserver was frozen, and ISP logs traced the source of the attack to Caffrey's computer.

Unlike Green's case, a forensic audit of Caffrey's computer showed no trace of a Trojan. At his trial, Caffrey simply argued that a Trojan could have been responsible, and that the government could not prove its case beyond a reasonable doubt. The jury agreed, and acquitted Caffrey in October, 2003.

Trojan Extortions

In late December, 2003 companies around the world began to report a new kind of cyber-attack that had been apparently going on for about a year. Cyber extortionists (reportedly from Eastern Europe) threatened to "plant" child pornography on their computers and then call the cops if they didn't agree to pay a small fee. Unless the recipient pays a nominal amount ($30), the hacker claims he will either wipe the hard drive or plant kiddie porn. The possibility of Trojans and the relative ease with which they could be used to promulgate just such an attack made the threats credible.

The two British cases illustrate the problems with the Trojan defense: not only does it make it difficult to definitively prove guilt with electronic evidence, but it is relatively easy to manufacture and plant electronic evidence consistent with guilt. In fact, with a few skills and tools, not only could you plant such evidence, but you could do so in such a way as to be virtually undetected, and so that it would be virtually impossible to determine that your target was not guilty.

The very Trojan planted to launch the attack or download the incriminating files may be designed to self destruct and wipe itself from the hard drive. It would be almost impossible to overcome the circumstantial evidence pointing to your guilt. With sentencing guidelines becoming ever more draconian for computer related offenses, it is only a matter of time before not only cyber extortion but cyber set-ups become reality, if they aren't already.

Of course, good information security practices help in this regard. Preventing the Trojans from entering in the first place, scanning for malware, monitoring for unusual activity and spam filtering all can help. Audit logging and reviewing can also help. Similarly, strong authentication and access control might prevent such activity. Yet another reason to do what the security professionals have been arguing for years.

As for Laocoon, the first to issue an advisory on the Trojan horse danger, his warning to the Trojans violated the wishes of Poseiden, so the gods sent serpents to kill him and his sons. This proved another axiom in law: no good deed goes unpunished.

Posted by glenn at January 27, 2004 09:28 AM | TrackBack
Comments

Playing online blackjack
is better than playing it in the casino. Of course thats my opinion.

Posted by: blackjack online at February 25, 2004 04:39 PM

Try skelaxin it's the best prescription drug there is. Make sure it's cheap skelaxin though because no one wants to over pay. Rubin the painter

Posted by: cheap skelaxin at March 3, 2004 10:10 AM

Playing casinos online can be risky. Make sure that they are legit casinos.

Posted by: casinos at March 3, 2004 11:28 AM

Reports of online gambling
are rampant. So be careful not to get caught up in gambling
online.

Posted by: online gambling at March 3, 2004 12:47 PM

You know sleeping pills
can be addictive right Did you know Ambien
gets you high

Posted by: sleeping pills at March 3, 2004 02:21 PM

If you like generic firoicet you will
love this drug. Its called butalbital
and its sweeping the pill popper inner sanctum like wild fire.

Posted by: butalbital at March 3, 2004 03:39 PM

Got a fat ass Try adipex I lost 120
lbs on it!

Posted by: adipex at March 3, 2004 04:55 PM

If you can't afford phentermine
you have to re evaluate your career. If you need Phentermine you need to re-evaluate
your diet.

Posted by: order phentermine at March 3, 2004 06:16 PM

I love tramadol even though
I have no idea what it is. And this sentence is just filler for the drug.

Posted by: cheap tramadol at March 3, 2004 07:34 PM

Taking diet pills can be dangerous.
Be cautious when popping these little guys.

Posted by: diet pills at March 3, 2004 08:50 PM

The fountain of youth is known as HGH
it's a hormone secreted by your glands. It is also known as human
growth hormone.

Posted by: human growth hormone at March 4, 2004 04:33 AM

Again stating that I have tramadol but
have no idea what it is.

Posted by: tramadol at March 4, 2004 05:50 AM

Playing online blackjack
is better than playing it in the casino. Of course thats my opinion.

Posted by: blackjack online at March 4, 2004 07:08 AM

Get your free credit report
online and know where you stand. A bank wont lend you anything if your destitute.

Posted by: credit report online at March 4, 2004 08:26 AM

Meeting people through the online personals is a great way to hook up! Just watch out for wierdo Al and his tin foil hat.

Posted by: personals at March 4, 2004 09:43 AM

Once you buy soma from us you will never
be the same. Because some drugs are good.

Posted by: soma at March 4, 2004 11:03 AM

Loosing weight with phentermine has never been easier! Just pop one pill of the drug a day and you will loose weight.

Posted by: phentermine at March 4, 2004 12:25 PM

Hooking up on the internet involves dating online for sure. be certian to check it out if your in the market.

Posted by: online dating at March 10, 2004 11:20 AM

Consolidation of debt is the best way to get ahead. remember to do debt consolidation at least once a year.

Posted by: debt consolidation at March 10, 2004 12:38 PM

Viagra is designed to improve your sex life by adding plesure to your partners experiance. You can buy viagra at this link you should buy viagra online when ever posible.

Posted by: viagra at March 23, 2004 05:09 PM

Hooking up on the internet involves dating online for sure. be certian to check it out if your in the market.

Posted by: online dating at March 23, 2004 06:26 PM

Consolidation of debt is the best way to get ahead. remember to do debt consolidation at least once a year.

Posted by: debt consolidation at March 23, 2004 07:44 PM

Order direct tv from this URL. One Saturday afternoon with DTV will change your life forever.

Posted by: direct tv at March 23, 2004 09:02 PM

Buying propecia online is easy. keeping your hair is going to help you get laid.

Posted by: propecia at March 23, 2004 10:19 PM

Cialis is in a class of medications known as PDE-5 inhibitors, which are used to treat cases of male impotence. Remember Cialis is approved in authorized markets for the treatment of mild to severe Erectile Dysfunction at both 10 and 20 mg Cialis doses. Cialis should be taken prior to anticipated sexual activity and without regard to food. Just like Viagra, sexual stimulation is needed for Cialis to work.

Posted by: cialis at March 24, 2004 08:37 AM

Fact is, when taken correctly, Viagra works for most men. Studies show that it works for up to 4 out of 5 men (versus 1 out of 4 on sugar pill). you can Buy Viagra to improve erections in most cases no matter how long you have had ED, what caused it, how often they have it, or how old they are. And Viagra has been proven to work in clinical studies of thousands of men.

Posted by: at March 24, 2004 09:55 AM

It's only for russians: ÍÅ ÈÍÒÅÐÅÑÍÎ!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

Posted by: Do you like anything from it: gay picture gay video gay movie gay site gay fucking gay cum gay anal at April 9, 2004 08:50 AM
Post a comment