CRYPT NEWSLETTER 50
August 1998

Editor: George Smith, Ph.D.
INTERNET: 70743.1711@compuserve.com
          crypt@sun.soci.niu.edu
http://www.soci.niu.edu/~crypt

Mail to:
Crypt Newsletter
1635 Wagner St.
Pasadena, CA 91106
ph: 626-568-1748

Crypt Newsletter articles may not be copied or reproduced in or
on other media, on CD-ROM collections of data, or offered - in part
or in toto - as part of any database, data survey, information or
research service without prior consent of the editor. Rates based
on word count are reasonable. Queries by e-mail are welcome.


                                       
  Contents: Crypt Newsletter #50       
                                       

 THIS ISSUE

NEWS
Hire the Bulgarians . . . please
The Anti-Christ Doom Squad (has a nice ring to it)
Jack van Impe sees the return of Jesus in "electronic Pearl Harbor"
One of the Nutty Professors (tm) gets a grant
Hoisted by own petard: Anti-virus publicity and the CIH virus
High level sightings of the chupacabras of info-war
The right way, the wrong way and the Department of Defense way:
The U.S. military struggles with its info-warriors.
LETTERS SECTION: Screech gun (tm) invented; Beware the Unnameable


HIRE THE BULGARIANS PLEASE . . . OR ELSE

International financier George Soros has ponied up an alleged
$3 million for Bulgarian programmers based in Sofia to provide
software fixes for the Millenium bug problem.

However, the best part of this story is the rationale and
history behind it.

When it was part of the Soviet empire Bulgaria's
leadership embarked on a plan to educate a large number of
its people in computer programming -- the aim of which was,
if you believe the popular mythology -- to create a large
pool of expertise capable of reverse-engineering Western
software with the aim of ripping off the intellectual property
of the hated capitalist hordes.

Another legend that grew from the same soil was that of "the
Bulgarian virus factory."

Embittered by their inability to find productive work,
Bulgarian programmers and computer science students were said
to have bent themselves to the writing of computer viruses as
revenge upon the West. In the process, they wound up with a
reputation as the Typhoid Mary's of computer programming.

While anecdotal reports from the anti-virus industry documented
that a small handful of Bulgarians did produce a number of computer
viruses, one virus exchange BBS and one virus-writer, The Dark
Avenger, who was successful enough to pass into worldwide virus lore,
in 1998 the story is silly and quaint.  Most every country with
computers can lay claim to a couple of well-publicized
virus-writers.

In any case, Grosdan Karadzhov, the head of a firm known as
Bulgarian Telecommunications Company, has made the phlogiston-filled
claim that his Bulgarian programmers have discovered a cure for the
Millenium bug while working on anti-virus software.  And with the
assistance of Soros, it is time to sell it to the West.

The unusual logic behind this appears to be that since
Bulgaria has had trouble with computer viruses, its programmers
must be good at curing the Millenium bug -- which is not a
computer virus at all. Plus, they constitute a pool of workers
who will work for wages which would drive everyone else into
penury.

So Crypt Newsletter says please hire the Bulgarians so they
aren't motivated to start writing viruses again and everyone has
to suffer through more stories about the "Bulgarian virus
factory," OK?


THE ANTI-CHRIST DOOM SQUAD HACKS AUSTRALIAN CREDULITY

Julian Assange, moderator of the Legal Aspects of Computer
Crime list and researcher on Suelette Dreyfus' "Underground"
came across a gem that reveals Australian ex-Cold Warriors
are much like the Pentagon's: Not above the presentation of
techno-ghost stories and myths as reality to justify
operations.

Assange writes:

"While browsing through the Australian Parliament House library,
I came across [the following] report."

Thinking about the Unthinkable: Australian Vulnerabilities
to High-Tech Risks by Dr. Adam Cobb, Foreign Affairs, Defence and
Trade Group (FAD&T) -- 29 June 1998.

[Those with a nose for real insider humor will note the ripping
off of the Rand Corporation and Hudson Institute's original Dr.
Strangelove: Herman Kahn.]

But back to our transmission:

"[It] appears to be your typical info-worrier paranoia-inducing
budget purloiner. What struck me, however, was the disingenuous
`cover grab' used on page one:"

Hackers Attack NZ & Aust for Joining Gulf Taskforce

AZP London: A hacker group calling themselves the 'Anti-Christ
Doom Squad' was involved in attacks against New Zealand and
Australia just days after Wellington and Canberra announced troop
deployments to the latest Gulf Crisis.

In a secret UK Government Communications Headquarters (GCHQ)
report leaked today, the Auckland blackouts that crippled the city
for weeks earlier in the year, were traced to electronic attacks
on New Zealand's electricity distribution network, launched by
computers in Amsterdam over the Internet. A senior government
source in the Australian equivalent to GCHQ, the Defence Signals
Directorate (DSD), confirmed that the widespread blackouts across
the Australian state of Queensland were also traced to the same
source.

The 'Anti-Christ' hackers traversed computer systems worldwide
using 'spoofed' user-names and stolen passwords to try to conceal
their identity. Once inside the New Zealand power companies'
supercomputer, the hackers accessed a control system commonly used
in energy distributions systems to launch their attack . . .

The 'Anti Christ Doom Squad' then concentrated on manipulating one
key choke-point on the outskirts of Auckland. It was the location
where all five main powerlines converged before entering the
city. The 'Doom Squad' altered the temperature within the
gas-encased power lines thereby crippling them within minutes. The
whole operation was launched and conducted from a drug cafe in
Amsterdam using a lap-top and a modem.

Simultaneous widespread blackouts across the Australian state of
Queensland disrupted businesses, schools and emergency
services . . .

"Which is, of course, complete fiction," Assange says. "Telling the
reader that the splash page -- and a big splash, at that -- is an
outright lie, doesn't sit easily with Dr. Cobb. In fact in following
100 or so pages that comprise the body of the FAD&T report, the only
reference we see to it is [the following]:"

--In early 1998, both Queensland and Auckland, New Zealand, were
afflicted with severe blackouts as key choke-points (or nodes) in
the electricity distribution networks collapsed (2). As the
Auckland crisis proved, contemporary cities quickly grind to a
halt when electricity, telecommunications and financial networks
are out of action.--

Assange continued, ". . . if anything, [this reinforces] the
fiction the report started with.  Observant readers will be asking
about that little '(2)' in `.. networks collapsed (2).' Is it a
footnote? No. However, some 100 pages later we find this
endnote:"</P>

--2. The exact cause of each failure has not been made public
as of 04/06/1998. However, as the fictitious news story was
attempting to suggest, aggressive attacks are now just as
plausible as technical failure.--

Assange makes the point that Cobb's fictitious scenario about
Amsterdam hackers is delivered within the context of the Australian
government report as if it were true -- and assembled so that
only the most industrious reader, one willing to slog through a
hundred pages or so of government prose, will find its miniscule
caveat.

Other tidbits within the Australian report: the pro forma
info-warrior sci-fi twaddle concerning electromagnetic pulse
weapons as tools of hackers and the bacteria that eat computer
hardware.


GET THEE BEHIND ME, ELECTRONIC PEARL HARBOR!

What do the Pentagon's John Hamre and televangelist, the
reverend Jack van Impe, have in common? They both believe
"electronic Pearl Harbor" means the end of things is nigh.

Blend Qatipi, an alert insomniac Crypt News reader, 
reports of observing Jack van Impe at 1 a.m. on TV in late 
July when the reverend warned of the name of the Beast.

"[Jack van Impe Ministries] said that 'electronic Pearl
Harbor' is one sign, among others, that Jesus will come
back.  It is even written in the Bible, according to them!"
the alert Crypt News correspondent added.

Crypt Newsletter was unable to confirm that reference to
"electronic Pearl Harbor" is contained within the pages of
The Good Book.

Jack van Impe and colleagues also discussed the implications
of the Millenium Bug.

" . . . Y2K was created by Satan," confided our source. But,
"[it was also said] that those who will resolve it will be sent
by Satan, too," which, while apparently contradictory, is
proof of something Crypt Newsletter has suspected for a long 
time: The Gartner Group is an instrument of Beelzebub.


PEARLS BEFORE SWINE

While skimming the Web, Crypt Newsletter noticed that an old
star of the magazine, Andra Katz of Wichita State University, had
received a windfall grant from the Department of Justice.

An on-line faculty news publication at Wichita State from August of
1997 states:

"Andra Katz, assistant professor of administration of justice, Hugo
Wall School of Urban and Public Affairs, has been awarded $871,256 by
the Department of Justice for the project "Use of Internet and
Distance Education Technologies to Train Rural Community Police
Officers in Kansas and Nebraska."

Alert readers may remember Katz as part of the team that unwittingly
wrote about April Fool's jokes for an article on Internet computer
crime in the FBI's Law & Enforcement Bulletin for December of
1996.

In that article, Katz and colleague David L. Carter of Michigan
State University confused April Fool's jokes published in Datamation
magazine with the real thing.

The FBI article was a condensed version of a longer scholarly
paper presented by Katz and Carter at a meeting of the Academy of
Criminal Justice Sciences in Las Vegas, Nevada, sometime during 1996.
Entitled "Trends and Experiences in Computer-Related Crime: Findings
>From A National Study," the paper told of a government dragnet in which
federal agents arrested a dangerously successful gang of hackers.

"The hackers reportedly broke into a NASA computer responsible for
controlling the Hubble telescope and are also known to have re-routed
telephone calls from the White House to Marcel Marceau University, a
miming institute," wrote Katz and Carter as part of their findings.
Unfortunately, this anecdote, too, was a rather obvious April Fool's
joke the authors had unintentionally taken seriously.

[The original stories about this affair are archived under
"The Nutty Professors" on the Crypt News Website.]


HOISTED BY OWN PETARD

In late February of this year the Manchester Guardian published an
interesting article on the advent of the computer virus silly
season: a period encompassing two Friday the 13ths, Michelangelo
and March 6 and April Fool's day.

Unlike most product in the mainstream media, this article wasn't
a press release for the anti-virus industry.  In fact, it was almost
hostile.

"There's a growing body of evidence which shows that far from
escalating out of control, the virus problem is containable . . ."
wrote the Guardian reporter. Further, "The National Computing
Centre's most recent survey of virus attacks shows that in 1996
only 5 per cent of virus attacks had a serious impact. 'Unlike
thefts, the seriousness of virus incidents seems to have
diminished,' it says."

The article dealt with the rise in prevalence of hoaxes, quoting
from Virus Myths guru Rob Rosenberger: "The publicity that the
anti-virus industry created in the last few years has come back
to haunt them."

"A few fearmongers knew that the publicity would sell anti-virus
software, so they were willing to lower themselves to [it]," he
added.

And, unfortunately, haunt them it has.

Recently, Crypt Newsletter heard from Rod Fewster, an Australian
anti-virus expert who, in the past, has strongly criticized his
industry colleagues for selling fear too often.

"I thought you might be interested in my latest bitch about how
the media beats up shitty going-nowhere viruses at the request of
their 'big name' anti-virus advertisers while ignoring serious
virus warnings from the rest of us," wrote Fewster in electronic
mail.

"I've been in loud opposition to 'Crying Virus Wolf' for years
. . . even to the point of being threatened with lawsuits for
publicly denouncing some 'Killer Virus' warnings and anti-virus
advertising as snake oil . . . but 'end of the world' stories
are invariably [reports] of trivial viruses, while
serious threats are usually ignored until after the damage
has been done."

However, said Fewster, a new virus called CIH was worth a
warning because of its destructive payloads.

"On the 26th of any month, [a] CIH variant will overwrite the
[system areas] of an infected hard disk," wrote Fewster. "This
can be very troublesome in a Windows95 environment, but such
damage can usually be repaired and the PC returned to 100
percent original condition with the right tools and a current
backup."

"However, the worst is yet to come," Fewster added.

"Although [I] have not yet been able to confirm this first hand,
it appears certain that CIH can overwrite 'flash' BIOS on some
PC motherboards when this part of its payload triggers . . .
'flash' BIOS damage would not be trivial to repair . . .
Without an intact BIOS a computer is useless and cannot
be started and unless the chip containing the BIOS is
in a socket [most 'flash' BIOS chips are not removable] a
PC trashed [in this manner] would have to be returned to the
factory for repair."

Fewster said he distributed reasonable warnings after the
virus's first activation date on June 26 and was ignored.

"But the media didn't want to print 'A new highly destructive
virus trashed a number of PCs . . . on June 26. They wanted to
scream 'KILLER VIRUS DESTROYS THOUSANDS OF COMPUTERS WORLDWIDE!
WHY WEREN'T WE WARNED?' on 27 July. Doom and gloom sells magazines
and newspapers," he opined.

Fewster's points were extremely well taken but consider the
following, too:

The flash BIOS payload, alarming as it sounds, isn't quite new;
neither is the hard disk corruption.  An Australian virus-writing
group tried to implement writing to the flash BIOS a couple of
years ago. However, like many virus-writer plans, it didn't work
because of mistakes in coding.

The anti-virus industry insists that this time around,
in CIH, the payload works.  And that makes it extremely
destructive. However, and this is a big "however" -- which they
don't add -- many have not _actually_ seen it work.  One company's
researcher admitted the only thing the virus did on activation day
was hang his machine.  And the reports Crypt News has read
about CIH actually corrupting the computer in this manner have
all been apocryphal or attributed to unnamed, unverifiable sources
-- hearsay. Translated: Code _intended_ to do such a nasty thing
exists in the CIH virus but there's not substantive proof that it
works precisely as billed.

The CIH virus, said Fewster, was put into the wild by uploading
infected copies to Gamerz sites -- legitimate and underground --
disguised as various software cracks and cheats and to pirated
software sites as a phony serial number crack for the Windows98 beta.

In June, after people had downloaded CIH contaminated software, the
biggest gaming site posted a warning about the infected downloads
along with an URL pointing to an anti-virus software program
that detected and removed it.

That being the case, the average user wasn't at risk from CIH unless
he was fetishistically hanging around on the Internet downloading
software to enable the pirating of Windows 98 or computer games.

The places that had infections seemed to have been universities
where a student was using school computers and network time
to satisfy his taste for pirated software or trivial
computer games he couldn't afford in the store.

"I had it on a university in the Netherlands," commented Fewster,
adding it had spread very quickly in this environment.

However, activation dates for the virus have passed. The world's
PC's did _not_ have their Flash BIOS's overwritten.  If they did,
Crypt News missed it. As did all those reading the latest
issue.

Most of the anti-virus vendors know this.  However, the
recent publicity over the virus has been purely a result of an
increasingly acrimonious industry squabble over publicity -- who
gets it, who doesn't -- hung on the tale of CIH.

Those articles that appeared in the computer media on CIH
appeared because they were prodded by vendors, not -- and this is
an important point -- because the journalists writing them
received reports or actually saw computers failing 
catastrophically.


MORE HIGH LEVEL SIGHTINGS OF INFO-WAR CHUPACABRAS

radio frequency weapon: syn. -- electromagnetic pulse gun, microwave
gun. Like the Mexican chupacabras, the radio frequency gun is always
suspected but never seen. It is said to be responsible for much
nettlesome corporate computer failure nationwide, according to
information warriors and law enforcement agents.

Usage: Dodson was relieved the computer security guru had been able
to convince management that the corrupted data on the network was the
work of a _radio frequency weapon_ attack on the corporation, not the
boobytrapped pornographic bit of software he had obtained from
alt.sex.watersports.

                 -- from the Joseph K Guide to Tech Terminology

Michael Vatis, the FBI head of the new National Infrastructure
Protection Center (NIPC) is _supposed_ to instruct his agency on
the gathering of threat information on menaces to cyberspace and
the nation's networked computers. Then NIPC is _supposed_ to issue
analyses and warnings of these threats to both the government and
private sector.

But what happens if the head of the organization cannot distinguish
a techno-ghost story from reality?

At a Congressional hearing in front of the House Joint Economic
Committee in February of this year, Vatis, presented written
testimony on an assortment of hacker menaces.

However, the most mystifying and mind-numbing claim made by the FBI
man was in reference to electromagnetic pulse guns as hacker tools --
indicating he seems to believe this ongoing myth.

"Advanced electronic hardware also can be used in cyber attacks,
including such items as high-energy radio frequency (RF) weapons,
electromagnetic pulse weapons . . . These weapons can be used to
destroy property and data . . ." wrote Vatis. 


THE RIGHT WAY, THE WRONG WAY AND THE DoD WAY: The
military struggles with its own info-warriors.

Strapped, or so it claims, for savvy information warriors, the
Pentagon is considering employing reserves as a pool of cyberdefense
warriors. The plan calls for approximately 300 reservists with Ph.D's.
to be employed as virtual info-warriors working from the redoubts
of their homes on PCs.

Upon learning of it, an alert Crypt Newsletter reader quipped: "I'm
still trying to get my mind around the reaction of other reservists when
they learn that their new Brainiac, Ph.D.-certified, info-warrior
colleagues get to work at home!"

And if they're real Brainiacs, they'll sell themselves to the
private sector computer security industry which, in turn, will sell
their services back to the Department of Defense for much more
than what they were earning as military men. [And we won't even
mention the little problem of _where_ DoD expects to produce 
300 Ph.D. reservists who specialize in comsec from overnite.] 

Ironically, many ex-soldiers with comsec experience are already 
doing this, landing in paradoxical situations in which they find 
themselves directing commanding officers, the same officers who had 
ignored them or brushed aside recommendations and suggestions when 
they were subordinates.

In this world, it should come as no surprise to find
instances where the military literally eats its young.

Take the example of the Air Force's 609th Information Warfare
Squadron at Shaw AFB, SC.

The 609th, a group that pioneered base perimeter computer
security for the Air Force, finds itself set to be closed down
in approximately a year. Outwardly a victim of budget cuts,
sources say it was a victim of publicity wars and professional rivalries
within the USAF.

Just prior to the 609th's creation in 1995, then Air Force 
Chief of Staff Ronald Fogelman realized the Air Force Information 
Warfare Center was beholden to the Air Intelligence Agency in 
San Antonio, Texas. The Air Intelligence Agency did whatever it 
wanted because it didn't have to report to anyone.

"Air Combat Command knew this and decided it had to do
its own thing," said one of the info-warriors interviewed for
this article. "General Fogelman wanted to see a fresh approach to
information superiority. The Air Force Computer Emergency Response
Team wasn't doing good enough with its hacker intrusion software."

Fogelman ordered the Air Combat Command, not the Air Intelligence
Command, to come up with something useful. Their idea was to come
up with a deployable formation, throw tons of money at it and
cultivate cyber-crews in its new information warfare squadron.

With no preconceptions and rules, members of the newly formed
609th fanned out into the worlds of military and corporate computer
security, looking for anything that could serve as base
perimeter defenses.

Enter a group of computer scientists who comprised former staff
members of the Air Force's Information Warfare Center and who
had led the investigation of the Brit hacker break-ins at
Rome Labs/Air Force Material Command in 1994.

"These guys had opted out of the Air Force because leadership
at AFIWC wasn't listening," said one information warrior close
to the action in San Antonio, Texas. "There was a need for a network
sniffer and Asim, AFIWC's choice, didn't cut it. The Air Force's
computer scientists, however, had developed one that did, called
NetRanger . . . so they jumped and formed WheelGroup."

To members of the 609th, however, NetRanger seemed ideal.
WheelGroup provided a neat solution: a box and software ready to
go. The squadron installed NetRanger at Shaw AFB. "AFIWC was pissed
at WheelGroup and the 609th. There was lots of bad blood."

However, the 609th knew nothing about politicking and public
relations. "AFIWC did," said one source who sympathizes with the
plight of the 609th. "They [AFIWC] always have people lobbying for
their causes at the Pentagon."


[WheelGroup was recently purchased by Cisco Systems.  The NetRanger
product and its successors will undoubtedly be used by many
military installations.]


LETTERS

On emp and assorted ray guns
============================

So, Crypt, you think all that stuff is bullshit! Well just you
wait until I get you in the sights of my Screech Gun (tm)! What
we've done here at the Institute for Serious Studies (tm) is
record the worst chalk-on-blackboard screeches by the most
careless possible professors, then extract the WORST part of
that waveform (tested on cats, dogs, unsuspecting neighbors),
prolong it, and emit it at 120DB SPL! This reduces
all in range to helpless, quivering, jelly!

The main problem is that it also reduces the shooter to that
same squirming blob. The weapon is best deployed by the
congenitally deaf.

So look out!

D. Von Doom, Ph.D.
Federal Institute for Serious Studies


Beware the Unnameable
=====================

Crypt:

You have no idea what a relief it is to read your newsletter
after reading article after article about an _unnamed_ source at an
_unnamed_ government agency predicting that hackers are about to
destroy the Internet -- and, of course, Internet "commerce." It's
either that or an _unnamed_ source at an _unnamed_ company that
has lost millions of dollars -- actually, they usually STAND to lose
millions -- because of vile hackers.

I get extremely bummed because I feel powerless against the
constant media onslaught. I'm immune to media idiocy but
most people aren't. I do my best to educate people that the sky
isn't falling and that hackers haven't wrested control of the
world's nuclear arsenals but I can only talk to so many.

The Mighty Mike Master

-------------------------------------------------------------
George Smith, Ph.D., edits the Crypt Newsletter from Pasadena,
CA.

copyright 1998 Crypt Newsletter. All rights reserved.

Crypt Newsletter's PGP 
public key.

-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: 2.6.1

mQBtAy9uMW0AAAEDAMU9Dj5kvpNLBfD04jwBd7r07/c+uH/MtH8yKGEvR/y5wJUz
I0BYZ+v1lFi6qIBuMJDzDzgOtvxKRV+wFW3AjqsHHX6m64VX/S9a0QqsTyLN71WE
e5a4cFjN1fh1QnW9uQAFEbQoR2VvcmdlIFNtaXRoIDw3MDc0My4xNzExQGNvbXB1
c2VydmUuY29tPg==
=IyYG
-----END PGP PUBLIC KEY BLOCK-----
 
