Deuce Bigalow Male Gigolo – Full Movie

Deuce Bigalow: Male Gigolo is a 1999 comedy film starring Rob Schneider. Other cast members include Eddie Griffin, Amy Poehler, Oded Fehr, Arija Bareikis, and William Forsythe.

The story is about a hapless fishtank cleaner who goes into business as a male prostitute in an attempt to earn enough money to repair damage he caused while house-sitting.

TOP-SECRET – Defense Security Service Cybersecurity Operations Division Counterintelligence Presentation

https://publicintelligence.net/wp-content/uploads/2013/05/DSS-CyberCI.png

 

Defense Security Service Cybersecurity Operations Division

  • 33 pages
  • For Official Use Only
  • December 2012

Download

DSS Supports national security and the warfighter, secures the nation’s technological base, and oversees the protection of U.S. and foreign classified information in the hands of Industry

CI Mission

DSS CI identifies unlawful penetrators of cleared U.S. defense industry and articulates the threat for industry and government leaders

Scope

-10K+ firms; 13K+ facilities; 1.2m personnel
-1 CI professional / 261 facilities
-10.5% of facilities report

Capability

• (U) 11 personnel conducting analysis, liaison, field support, strategic development and program management
• (U) Wide range of skill sets – CI, CT, LE, Cyber, Security, Intel, IA, CNO and more
• (U) Direct access to cleared industry across 25 DSS field offices nationwide
• (U) Large roles at U.S. Cyber Command, National Security Agency, National Cyber Investigative Joint Task Force and the Department of Homeland Security

Challenges

• (U) Secure sharing of threat information with industry partners
• (U) Identifying and reporting suspicious network activity
• (U) Limited resources to execute for an quickly expanding mission area Significant Achievements and Notable Events
• (U) Since September, 2009 – Assessed over 3,000 cyber-related suspicious contact reports from Industry and the Intelligence Community; facilitating action on over 170 federal investigations/operations
• (U) Developed four benchmark product lines for Industry and the Intelligence Community to include the 3rd edition of the DSS Cyber Trends
• (U) Briefed at 24 venues and over 1,000 personnel in FY12 on the cyber threat
• (U) In FY12, delivered over 350 threat notifications to industry, detailing adversary activity occurring on their networks.

(U) FY12 Industry Cyber Reporting

• (U//FOUO) 1,678 suspicious contact reports (SCR) categorized as cyber incidents (+102% from FY11)
• (U//FOUO) 1,322 of these were assessed as having a counterintelligence (CI) nexus or were of some positive intelligence (PI) value (+186% increase from FY11)
• (U//FOUO) 263 were categorized as successful intrusions (+78% increase from FY11)
• (U//FOUO) 82 SCRs resulted in an official investigation or operation by an action agency (+37% increase from FY11)

Revealed – DHS and FBI Bulletins on OpUSA Tools and Tactics

The following bulletins were released May 6, 2013 by the National Cybersecurity and Communications Integration Center and FBI in anticipation of the OpUSA campaign.  A DHS bulletin on the campaign was released May 2, 2013 by computer security journalist Brian Krebs.

National Cybersecurity and Communications Integration Center OpUSA: Potential Tools May 6, 2013 4 pages Download
FBI Liaison Alert System #C-000007-DD May 6, 2013 1 page Download

Multiple groups, and individual hacker handles have claimed their intent to attack U.S. websites as part of OpUSA. As seen in many hacktivist operations (Ops), willing participants have posted free tools to assist other like minded individuals in their attack efforts. Often, more coordinated attacks will name a specific tool, target, day and time for the attack. That has not been the case for OpUSA thus far. Individual hacker groups seem to be conducting attacks independently, each claiming responsibility for individual defacements and data breaches that have supposedly recently taken place. Below you will find some of the tools being posted in conversations about OpUSA and links to US-CERT sites which provide background on the vulnerabilities exploited by these tools as well as mitigation advice for computer network defense actions.

Structured Query Language (SQL) injection

The following is a sampling of tools being offered to willing members interested in using SQL attacks during OpUSA.

  • Havij: Automates SQL Injection attacks. It allows the attacker to ‘fingerprint’ the database, retrieve Database Management System users and password hashes, dump tables and columns, retrieve specific data from the database, run SQL statements, and access the underlying file system and execute commands on the operating system.
  • SQL Poison: This exploit scanner tool incorporates automated Google Dorking methods to look for SQL vulnerabilities. Once the vulnerability is discovered, it performs an SQL injection attack.

The following US-CERT advisories offer further information:

Distributed Denial of Service (DDoS)

DDoS tools are often used by hacktivist so users may voluntary botnets. These are a list of the available DDoS tools via Open Source:

  • Low Orbit Ion Cannon (LOIC): Floods servers with TCP or UDP packets with the intention of disrupting service.
  • High Orbit Ion Cannon (HOIC): Can attack as many as 256 sites simultaneously and can target subdirectories of the main page using “booster packs” that enable traffic with multiple user-agent strings, referrers, and headers.
  • HTTP Unbearable Load King (HULK): Also referred to as HULK DDoSser. Generates unique requests for each and every request generated, which bypasses caching engines and impacting the server’s load directly.
  • Slowloris: Attempts to keep multiple open connections to the target web server and keep them open as long as possible.
  • DDos Notepad: Attackers can create a simple Batchfile DDoS echo script using Notepad.
  • ByteDOS: Windows desktop DOS application that is a standalone executable file and doesn’t require any special installation on the attacking machine. It is equipped with embedded IP resolver capabilities that allow the tool to resolve IPs from domain names. It also supports SYN Flood and ICMP flood.
  • Turbinas: Also referred to as VOLKS TURBINAS.EXE, which are associated with Cloaked Malware group designed to evade security detection systems.
  • Syn Flood DOS: Attack in which the actor sends a number of consecutive SYN requests to a target attempting to consume server resources.
  • Jays Booter: A customized shell booter, which can be instructed to attack a specific IP for a period of time in an attempt to boot the target off of the internet. There are three types of shells: POST, GET, and SLOWORIS.
  • HTTPFlooder: Program that attempts to flood the HTTP layer through GET and POST requests.
  • TORSHAMMER: A Slow POST DOS tool written in Python. It can be run through the TOR network, which will anonymize the attacker. It can impact unprotected web-servers running Apache and IIS.
  • R.U.D.Y: Also known as R-U-Dead-Yet. This is an HTTP POST DOS attack that allows the attacker to choose the forms and form fields that they want to use for the POST attack.
  • OWASP HTTP Tool: A Slow POST DOS tool that allows the attacker to generate a customized number of connections, connection rate, timeouts, and even the content length.
  • Anonymous DOSer: A customized DOS tool put together in visual basic. It is very simple to use and can be used for HTTP floods or UDP floods.
  • Windows_DNS_Attack_Tool: DNS Amplification tool. It uses open DNS resolvers and source address spoofing to create large denial of service attacks.
  • Goodbye: Similar to HTTPFlooder and R-U-Dead-Yet DDoS tools.

The following US-CERT advisories offer further information:

Password Crackers/Stealers

Several password crackers and stealers were spotted on related forums. Some of which are found below:

  • Backtrack 5: A Linux based penetration testing tool. The most recent edition was synced up with the new release of KaliLinux. This toolkit provides easy-to-use tools such as port scanners, metasploit, Nmap, Browser Exploitation Framework, Hydra, Aircrack-ng, and Ophcrack. Aircrack and Ophcrack are password crackers.
  • Hash Cracker: Refers to multiple free applications designed to crack MD2, MD5, SHA-1, SHA-256, SHA384, and SHA-512 using bruteforce techniques or using a rainbow table/dictionary attacks.
  • CpanelBruteReiluke: Bruteforce password cracking tool designed by a developer known as Reiluke. Reiluke also has made his blind SQL, email brute force, and exploit scanner tools available via open source.
  • Gmail_Hacker: Labeled as a free Gmail-specific password cracking tool which is advertised as taking less than 2 minutes to retrieve passwords.
  • Firefox Password Stealer: Provides details on how an attacker can turn their Firefox browser into a password stealer. This is not a tool, but rather direction for end users.
  • ICQ Steal0r: Program seems to be dedicated to stealing passwords of ICQ users. ICQ is an instant messaging application popularized by Mirabilis.

The following US-CERT advisories offer further information:

Proxy Servers/Anonymizers

In additional to options like the onion router (TOR), OpUSA members have advertised the following to assist actors in obfuscating their activity.

  • CYBERGHOST: A Virtual Private Network (VPN) simulator which sets up a proxy server allowing anonymous activity with 128-bit AES encryption. It also has the most server locations available in the US and a number of countries in Europe.
  • TunnelBear: This VPN simulator also circumvents Geoblocking, which is geographically blocking internet users from certain web services.
  • SumRando: This VPN simulator allows users to generate random IP addresses, which can obfuscate attribution.
  • Real Hide IP: Hides the IP address of anyone employing the application.
  • Hotspot Shield: Hides the IP address of anyone employing the application.

Other Tools Mentioned

Hacker groups have mentioned the following tools among several others that don’t fit the above categories.

  • Net Tools: This could refer to any number of items, but c|net offers a network toolbox that has network sniffing and scanning tools.
  • Pack Del Hacker: This is a simplified, online-based file-sharing service.
  • EmailScraperWizardv06b: This is noted as one of the more successful email scrapers on the internet. It can extract email addresses from websites.
  • IP Port Scanner: This could refer to multiple tools dedicated to scanning, mapping and discovering open ports.
  • IP Scanner: These types of tools can scan networks, detect devices, wireless devices, routers, and can find HTTP, HTTPS, and FTP folders.
  • DHCP_IP_Forcer: This allows an attacker to essentially scan a network and detect IP addresses and MAC addresses on a network. Some DHCP Force components allow the attacker to reconfigure modems.

Summary

While it is difficult to assess the specific tools that may be used against targeted organizations, this product is intended to provide organizations with an idea of the type of free tools that may be employed against them, so they may better prepare mitigation strategies during OpUSA or similar hacktivist operations. As always, NCCIC reminds users and administrators of the importance of best practices to strengthen the security posture of their organization’s systems. Critical Infrastructure Key Resource (CIKR) owners and operators should work toward a resilient network model that assumes such an attack will occur against their enterprise. The goal is to minimize damage, and provide pathways for restoration of critical business functions in the shortest amount of time possible.

The Files TV – The Hidden Costs of Hamburgers

Americans love hamburgers — we eat about three burgers a week. But what are the hidden environmental costs? See sources from the Center for Investigative Reporting.http://cironline.org/reports/hidden-c…

Directed and produced by Carrie Ching, Reported by Sarah Terry-Cobo and Carrie Ching, Illustrated and animated by Arthur Jones.

This animation is part of The Food for 9 Billion series, a yearlong look at the challenge of feeding the world at a time of social and environmental change.

http://cironline.org/projects/food-fo…

For more great stories, subscribe to The I Files:http://www.youtube.com/subscription_c…
Like The I Files on Facebook: http://fb.com/theifiles
Follow us on Twitter: http://twitter.com/ifiles
Reblog us on Tumblr: http://theifiles.tumblr.com
Repin us on Pinterest: http://pinterest.com/theifiles
+1 us on Google+: http://gplus.to/ifiles

SECRECY NEWS – SUBPOENA OF AP PHONE RECORDS SAID TO DAMAGE PRESS FREEDOM

The government seizure of Associated Press telephone records in the course
of a leak investigation undermined freedom of the press in the United
States, congressional critics said yesterday.

"It seems to me the damage done to a free press is substantial," said Rep.
Zoe Lofgren at a hearing of the House Judiciary Committee.

Pursuant to subpoena, the government captured call records for 20
telephone lines of Associated Press reporters and editors over a two month
period last year.  The records are logs of calls made and received, but do
not include their contents.  It was a "massive and unprecedented intrusion"
into newsgathering activities, wrote the AP's president Gary Pruitt in a
May 13 letter.

The Justice Department denied that the action deviated from established
policy.

"We understand your position that these subpoenas should have been more
narrowly drawn, but in fact, consistent with Department policy, the
subpoenas were limited in both time and scope," wrote Deputy Attorney
General James M. Cole in a May 14 reply.

The  move arose from an AP story about a disrupted bomb plot originating
in Yemen that led to the revelation of a classified counterterrorism
operation and the existence of a valued agent. "This is among the top two
or three serious leaks that I've ever seen" said Attorney General Eric
Holder. He did not elaborate.

Meanwhile, the upshot is that any presumption of confidentiality in the
source-reporter relationship has been compromised across the board,
especially but not only in national security reporting.

        http://www.npr.org/templates/story/story.php?storyId=183984442

"Reporters who might have previously believed that a confidential source
would speak to them would no longer have that level of confidence, because
those confidential sources are now going to be chilled in their
relationship with the press," Rep. Lofgren said yesterday.

Last year, congressional leaders harshly criticized the Obama
Administration for supposedly failing to aggressively combat leaks of
classified information, including in the present case.

"The Administration's disregard for the Constitution and rule of law not
only undermines our democracy, it threatens our national security," said
Rep. Lamar Smith, at a hearing of the House Judiciary Committee on June 7
of last year. "The Justice Department has not taken the initiative to
prosecute leaks of national security secrets. Recent leaks about a foiled
bomb plot out of Yemen and a cyberattack against Iran are, in the words of
Senate Intelligence Chairwoman Dianne Feinstein, quote, 'very detrimental,
very concerning, and hurt our country,' end quote."

The irony was not lost on Rep. Jerrold Nadler.

"I think we should put this in context, and remember that less than a year
ago this committee's Republican leadership demanded aggressive
investigation of press leaks, accusing the administration itself of
orchestrating those leaks," he noted. "Then, members of this committee
wanted the reporters subpoenaed, put in front of grand juries and
potentially jailed for contempt. Now, of course, it is convenient to attack
the attorney general for being too aggressive or the Justice Department for
being too aggressive."

"But this inconsistency on the part of my Republican colleagues should not
distract us from legitimate questions worthy of congressional oversight,
including whether the Espionage Act has been inappropriately used looking
at leakers, whether there is a need for a greater press shield,... and
Congress' broad grants of surveillance authority and immunity," Rep. Nadler
said.

Rep. Lofgren said that the damage done to freedom of the press by the
clandestine seizure of AP phone records "will continue until corrective
action is taken."

GPO SUSPENDS PUBLIC ACCESS TO SOME NASA RECORDS

The Government Printing Office is blocking public access to some
previously released records of the National Aeronautics and Space
Administration, while the records are reviewed to see if they contain
export-controlled information.  The move follows the controversial
disabling and partial restoration of the NASA Technical Reports Server
(NTRS) ("NASA Technical Report Database Partly Back Online," Secrecy News,
May 9.)

"GPO has been asked to suspend any activity related to making these
documents available if they have not been reviewed," GPO said in a notice
today.

        http://beta.fdlp.gov/news-and-events/

"During this time, PURLs that GPO has created for the electronic versions
of NASA Technical Reports found in cataloging records accessed through the
Catalog of U.S. Government Publications (CGP) may not link to the documents
that the catalog record describes."

US-CHINA MOTOR VEHICLE TRADE, AND MORE FROM CRS

"In 2009, China overtook the United States to become both the world's
largest producer of and market for motor vehicles," a new report from the
Congressional Research Service notes.

That is not altogether bad news. "Every year since 2010, General Motors
has sold more cars in China (through exports and its joint ventures there)
than in the United States," CRS said. "On the other hand, China maintains a
number of trade and investment barriers that affect trade flows in autos
and auto parts."

See U.S.-Chinese Motor Vehicle Trade: Overview and Issues, May 13, 2013:

        http://www.fas.org/sgp/crs/row/R43071.pdf

Other new and updated reports from the Congressional Research Service that
Congress has declined to make publicly available include the following.

Regulation of Fertilizers: Ammonium Nitrate and Anhydrous Ammonia, May 9,
2013:

        http://www.fas.org/sgp/crs/homesec/R43070.pdf

Haiti Under President Martelly: Current Conditions and Congressional
Concerns, May 10, 2013:

        http://www.fas.org/sgp/crs/row/R42559.pdf

Women in Combat: Issues for Congress, May 9, 2013:

        http://www.fas.org/sgp/crs/natsec/R42075.pdf

The Peace Corps: Current Issues, May 10, 2013:

        http://www.fas.org/sgp/crs/misc/RS21168.pdf

Proposals to Eliminate Public Financing of Presidential Campaigns, May 10,
2013:

        http://www.fas.org/sgp/crs/misc/R41604.pdf

The Federal Budget: Issues for FY2014 and Beyond, May 9, 2013:

        http://www.fas.org/sgp/crs/misc/R43068.pdf

_______________________________________________
Secrecy News is written by Steven Aftergood and published by the
Federation of American Scientists.

The Secrecy News Blog is at:
     http://www.fas.org/blog/secrecy/

To SUBSCRIBE to Secrecy News, go to:
     http://blogs.fas.org/secrecy/subscribe/

To UNSUBSCRIBE, go to
     http://blogs.fas.org/secrecy/unsubscribe/

OR email your request to saftergood@fas.org

Secrecy News is archived at:
     http://www.fas.org/sgp/news/secrecy/index.html

Support the FAS Project on Government Secrecy with a donation:
     https://members.fas.org/donate

_______________________
Steven Aftergood
Project on Government Secrecy
Federation of American Scientists
web:    www.fas.org/sgp/index.html
email:  saftergood@fas.org
voice:  (202) 454-4691
twitter: @saftergood