Security [CENTRAL] Forum - SCforum.info
24. May 2012., 08:37:44 *
Welcome, Guest. Please login or register.

Login with username, password and session length

SCforum.info - Security [CENTRAL] Forum

↑ Grab this Headline Animator

Custom Search
News: For ultra cheap bullet proof vests, hard armor ballistic plates or for advice on body armor in general visit SafeGuardClothing.com
 
  Home Help Chess Links Login Register   *

SCforum.info


furniture store



Members
Total Members: 11258
Latest: donna717
Stats
Total Posts: 15637
Total Topics: 4337
Online Today: 2172
Online Ever: 51419
(01. January 2010., 10:27:49)

SCF UnSpam

Top Ten Antivirus Software

Friend of WOT


SCF Feedburner

SCF Facebook

SCF Twitter

Welcome to SCforum.info - Security [CENTRAL] Forum, a home of the SCF Community devoted to provide Computer related News, Alerts, Downloads and FREE Help in such a way that even the novice computer user can understand.

Getting started using our community is extremely easy, check the two steps below:

Step 1: Create an account by clicking here and wait for approval from Administrator. It's completely free with no hidden strings attached.

Step 2: If you have a computer problem and need some help, or just want to take part in opened discussions, simply browse Forum. Once you *Register an account, you can quickly post your questions and comments.

(*Registered Members get: free support, also, they can communicate privately with other members via PM, removal of this message, see fewer ads and much more...)






Pages: 1
  Print  
Author Topic: German government created Bundestrojaner aka Federal Trojan, R2D2, 0zapftis  (Read 1504 times)
0 Members and 1 Guest are viewing this topic.
Samker
SCF Administrator
*****

KARMA: 86
Gender: Male
Location: Europe
Posts: 5078


Whatever doesn't kill us makes us stronger.

Google Talk
WWW
« on: 10. October 2011., 19:07:30 »



German hackers have captured and analysed a cyber-sleuth Trojan which they claim may have been used by police to tap Skype calls and IM chats of criminal or terrorist suspects.

German wiretap laws do in fact permit the use of a "Bundestrojaner" ("Federal Trojan"), which has been used by police to record VoIP conversations for a few years.

But the so-called R2D2 (AKA 0zapftis) Trojan – which has not been confirmed as a creation of the German government – has far more capabilities than this, including the ability to download updates from the internet, log keystrokes, eavesdrop on IM chats and take screenshots. The backdoor function exceeds what's permissible under German law.

Sophos has said:

"We have no way of knowing if the Trojan was written by the German state – and so far, the German authorities aren't confirming any involvement.

The comments in the Trojan's binary code could just as easily be planted by someone mischievously wanting the Trojan to be misidentified as the infamous Bundestrojaner."



The R2D2 Trojan was captured by the Chaos Computer Club (CCC) and made public over the weekend, sparking a huge row in privacy-sensitive Germany.

A CCC spokes-hacker said:


"This refutes the claim that an effective separation of just wiretapping internet telephony and a full-blown Trojan is possible in practice – or even desired. Our analysis revealed once again that law enforcement agencies will overstep their authority if not watched carefully."


Hackers from the group reverse-engineered samples of the malware code before analysing the functions built into the software. It concludes that any machine infected by the Trojan might be easily seized by third-party hackers.

The screenshots and audio files it sends out are encrypted in an incompetent way, the commands from the control software to the Trojan are completely unencrypted. Neither the commands to the Trojan nor its replies are authenticated or have their integrity protected. Not only can unauthorised third parties assume control of the infected system, but even attackers of mediocre skill level can connect to the authorities, claim to be a specific instance of the Trojan, and upload fake data.

A English-language statement by CCC on its find can be found here: http://www.ccc.de/en/updates/2011/staatstrojaner
The German chancellor's press secretary denied that the R2D2 trojan has been used by the BKA, the German Federal criminal police. This denial has failed to stem speculation.

One popular theory is the Trojan might have been created by Digitask for the Bavarian government. Such speculation in interesting, though not based on any evidence outside of papers released by WikiLeaks suggesting Digitask had at least offered to create this sort of software: http://wikileaks.org/wiki/Skype_and_SSL_Interception_letters_-_Bavaria_-_Digitask

Security firms say it is impossible to know who created the code from the evidence available.

Net security firm F-Secure writes:


"We have no reason to suspect CCC's findings, but we can't confirm that this Trojan was written by the German government... As far as we see, the only party that could confirm that would be the German government itself."



Anti-virus firms including F-Secure and Sophos have already added detection against the malware, along with commentary on the row (here: http://www.f-secure.com/weblog/archives/00002249.html and here: http://nakedsecurity.sophos.com/2011/10/09/government-backdoor-trojan-chaos , respectively). Other security outfits can be expected to follow suit; they are obliged to add detection for any blob of malware they come across regardless of who created it. Turning a blind eye to state-sponsored malware, especially in the post-Stuxnet era, would be commercial suicide.

Bootnote

The R2D2 name comes from a string of ASCII, "C3PO-r2d2-POE", found in the mystery Trojan. Likewise, the 0zapftis name also appears, a phrase meaning "the barrel is open" that's used by the Munich mayor in opening Oktoberfest every year.

Security firms agree with CCC that the Trojan is lame. F-Secure's Mikko Hypponen tweeted amusingly:

"It's not well written: http://twitter.com/mikko/status/122794637420277760
Which, I guess, makes it *more* likely it's developed by a Government..."



-----


Download complete release from CCC (german)
: http://www.ccc.de/system/uploads/76/original/staatstrojaner-report23.pdf



Logged

Security [CENTRAL] Forum - SCforum.info
« on: 10. October 2011., 19:07:30 »



 Logged
Samker
SCF Administrator
*****

KARMA: 86
Gender: Male
Location: Europe
Posts: 5078


Whatever doesn't kill us makes us stronger.

Google Talk
WWW
« Reply #1 on: 11. October 2011., 17:52:47 »

Here's some additional details about the "Bundestrojaner": http://www.f-secure.com/weblog/archives/00002250.html



Logged

vishwanath99
SCF Member
**

KARMA: 7
Posts: 56


« Reply #2 on: 12. October 2011., 07:51:49 »

McAfee 8.7i patch 5  detected this Trojan as Artemis!87195B5F6272.
Control software for the Trojans Command and Control server(in Columbus, Ohio, USA) of this Trojan still running..
 According to ccc.de  It uses TCP/IP 443 port but not as HTTPS How it possible can any one explain

I wl try to install it on vmware.. thank u for the information
Logged
Samker
SCF Administrator
*****

KARMA: 86
Gender: Male
Location: Europe
Posts: 5078


Whatever doesn't kill us makes us stronger.

Google Talk
WWW
« Reply #3 on: 16. October 2011., 06:12:48 »


"German officials admit using spyware on citizens, as Big Brother scandal grows": http://redtape.msnbc.msn.com/_news/2011/10/11/8274668-german-officials-admit-using-spyware-on-citizens-as-big-brother-scandal-grows



What to say...?? Undecided

Logged

Pages: 1
  Print  
 
Jump to:  

Enter your email address to receive daily email with 'SCforum.info - Security CENTRAL Forum' newest content:

Terms of Use | Privacy Policy | Advertising
Powered by MySQL Powered by PHP Powered by SMF | SMF © 2011, Simple Machines
TinyPortal © Bloc
Valid XHTML 1.0! Valid CSS!


Google visited last this page 21. May 2012., 13:24:06