الأرشيف لـ '"فايروس و هاكر و تروجان"'تصنيف

الإخفاء بعد التشفير للنقل الآمن للمعلومات (ملخّص)

2007 / أكتوبر / الثلاثاء

قال الله تبارك و تعالى في سورة الحاقة: ((فلا أقسم بما تبصرون و ما لا تبصرون)).

المعركة بين علم الإخفاء وتحليل الإخفاء لا تزال محتدمةً وتمثِّلُ حجر الزاوية في حرب نقل المعلومات السرية . الوجه الاول لهذه المعركة يمثل الاتصالات السرية حيث يتم نقل معلومات و بيانات من دون إشعار أحدٍ أن هناك اتصالاً يجري ، بينما يمثل الوجه الآخر محاولة الوقوف ضد هذا النوع من الاتصالات.

ومن المهم التأكيد على ضرورة التشفير الآمن للمعلومات قبل إخفائها ، وذلك موضوع مستقل عن علم إخفاء المعلومات يسمى علم التشفير.

يعامل علم التشفير على أنه سلاح الكتروني -وهو كذلك- لأ نه أساس في تأمين الا تصالات وضمان سلامة المتصلين وحماية الأسرار. وليس هناك أخطر من أن يعتمد شخص على برنامج أجنبي لحماية أسراره وتأمين اتصالاته ، فربما اكتشف بعد فوات الأوان أن جميع اتصالاته كانت مخترقة من قبل العدو . قال عمر بن الخطاب رضي الله عنه (لست بالخب ولا الخب يخدعني)، فأول الاحتياطات الأمنية أن تؤمن جميع الاتصالات ببرامج موثوقة!!!
طيف الألوان
هناك عدة برمجيات تقوم بوظيفة الإخفاء ، (مثلاً : برامج للإتصالات السرّية تقوم بإخفاء الأسرار داخل الصور) ، ولكن أكثرها له برمجيات مضادة تستطيع الكشف عن احتمال وجود رسائل سرية.

وفي أكثر الحالات فإن إدعاء البرامج قدرتها على إخفاء المعلومات هو محض كذبٍ وخداع، وهذا ينبهنا أنه لا يجب استخدام أي برنامجٍ نقل سري أو تشفير للمعلومات من دون أن يكون لدينا تحليل ٌ تفصيلي دقيق لعمل البرنامج يبين قدراته وإمكانيات فشله أو إحباط مهمته.

و لهذا لا يجب استخدام البرامج الغربية فهي خداع محض، وكلها لها نوع من التوقيع (Signature) يكشف مثلاً أن الوسيط (صورة) وتم تعديله ببرنامج معين يدل عليه!!!

الإخفاء المتقدم يدمج عدة تقنيات متطورة بكفاءة عالية منها:

1- ضغط البيانات بنسب عالية
2- تشفيرها بخوارزمية 2048 بت
3- إخفائها

يمكن إخفاء رسائل قصيرة داخل ملفات صوتية قصيرة ، ومن برامج الإخفاء ما يستغلُّ عدداً محدوداً من طبقات الألوان الأساسية محاولاً الإفلات من احتمال كشف أي تغييرٍ عن طريق تحليل الإخفاء الذي يعتمد على التوزيع الإحصائي للألوان. وتقوم برامج أخرى بإخفاء البيانات أو الرسائل عن طريق استغلال أحدث التقنيات في عالم هندسة الاتصالات لتفلت من جميع الإجراءات المضادة لتحليل الإخفاء.

كما يجب اختيار مناطق الإخفاء سواء داخل الصور الفوتوغرافية أو الصور الطبيعية أو مقاطع الصوت أو الفيديو ضمن نطاقات الطيف العريض(Spread Spectrum) المناسبة التي يعجز التحليل البصري أو السمعي بالإضافة للتحليل الإحصائي عن الكشف عن احتوائها على رسائل خفية، مما يجعل الإخفاء يستحق بجدارة هذا الاسم وينفرد بنقل المعلومات السرية دون أن تراها الأبصار. قال الله تبارك و تعالى في سورة الحاقة: ((فلا أقسم بما تبصرون و ما لا تبصرون)).

مصطلحات
Steganography علم الإخفاء
(Steganos graphy) علم الإخفاء
Steganalysis تحليل الإخفاء
Multi-media وسائط متعددة
Digital رقمي
Morse Code شيفرة مورس
Digital Communication إتصالات رقمية
Digital Signal and Image Processing معالجة الإشارة و الصور الرقمية
Watermarking العلامة المائية
LSB البت ذي الدلالة الصغرى
(Least Significant Bit) البت ذي الدلالة الصغرى
MSB البت ذي الدلالة الكبرى
(Most Significant Bit) البت ذي الدلالة الكبرى
Pixel عنصور
(Picture element) عنصر صورة
Grayscale السلم الرمادي
Message Digest version 5 هضم الرسالة: تقنية خاصة بتشفير كلمة السر
(MD 5) هضم الرسالة: تقنية خاصة بتشفير كلمة السر
Byte ثمانية (بضم الثاء و تشديد الياء)
Bit بت
Hexadecimal سداسي عشري
Editor محرر
Concatenation الالصاق او الالحاق
Digital Fingerprint البصمة الرقمية
Data Redundancy تكرار بياني
Histogram) Frequency distribution of RGB) ( هيستوغرام) رسم بياني لتوزيع الالوان الترددي
One Way Encryption تشفير أحادي الإتجاه
Discrete Cosine Transform Coefficients معاملات التحويل الجيبي المتقطع
Enhanced LSB Layers Analysis التحليل الطبقي
Visual Analysis التحليل البصري
Statistical Analysis التحليل الإحصائي

المصدر : (منقول)

UAE cyber crimes law

2007 / سبتمبر / الأحد

 UAE cyber crimes law

04/30/2007 10:37 AM | Gulf News Report

Abu Dhabi: President His Highness Shaikh Khalifa Bin Zayed Al Nahyan has issued a federal law on combating cyber crimes.

* Law No.2 of 2006, issued last month, includes 29 articles, and shall take effect from the date of its issuance, and is to be published in the official gazette.
* Article No.2 considers any intentional act resulting in abolishing, destroying or revealing secrets or republishing personal or official information, as a crime. It says anyone convicted of logging onto information website or system shall be punished with jail term, or fine, or both. If the act resulted in abolishing, destroying, or revealing, changing or republishing information, he/she shall be sentenced to no less than six months in jail and be fined, or both. If such information are personal, a fine of not less than Dh10, 000 shall be imposed, and a jail term of not less than one year shall be handed out to the convict, or both punishments.
* The law also reads that anyone convicted of stimulating a male or female to commit adultery or prostitution via the Internet will be jailed up to five years and fined.
* Anyone convicted of abusing holy shrines or religious rituals or insulting them or inciting others to do so, shall be sentenced to five years in jail and be fined.
* Anyone convicted of opposing the Islamic religion will be jailed up to seven years. Anyone convicted of transcending family principles and values shall be jailed for one year and fined Dh50, 000. Anyone convicted of setting up a website for groups promoting programmes in breach of public decency and order shall be sentenced to five years in jail.
* Article No.3 reads that anyone convicted of committing any crimes stipulated in Article No.2 of this law, shall be sentenced to no less than one year in jail, and fined not less than Dh20, 000, or both.
* Article No.4 says anyone convicted of forging any document of Federal or local government?s documents, or any of federal or local institutions, shall be temporarily imprisoned, and fined, or both.
* Anyone convicted of using the forged document with knowledge it is forged, shall be handed out the stipulated punishment for forgery crime. Article No.5 of the law reads anyone convicted of hampering, blocking or preventing the reach of service or logging onto computer programmes, or information sources with any possible means whether via the use of internet or any information technology mean, shall be punished with a jail term, or a fine, or both.
* Article No.6 says anyone convicted of inserting certain information via the internet or using any IT or electronic mean for the purpose of stopping or breaking down, or destroying, deleting or amending programmes and information, shall be either jailed or fined, or both.
* Article No.7 says anyone convicted of using the internet or any electronic or IT means for changing or destroying medical tests or medical diagnosis, or medical treatment or healthcare, or even assisted others to do it, shall be temporarily jailed or fined.
* Article No.8 says anyone convicted of deliberately eavesdropping, or receiving or intervened information or messages sent via the internet by using any electronic or high-tech means, shall be jailed or fined.
* Article No.9 says anyone convicted of using the internet or any other high-tech means for threatening or black mailing another person, to incite him to carry out an act or not, shall be sentenced to no more than two years in jail and fined no more than Dh50, 000, or both.
* Anyone convicted of using the internet for threatening or black mailing another person, to incite him to commit lewd acts or honour crimes, shall be sentenced up to 10 years in jail and fined Dh50, 000.
* Article No.10 reads that anyone convicted of putting his hands on immovable funds, or a document to sign for himself or others, by using the internet or any high-tech means in a fraudulent way or by taking a nick name or assuming the identity of others with intent to defraud, shall be sentenced to no less than one year, and fined no less than Dh30, 000, or both.
* Article No.11 reads that anyone convicted of reaching data of credit card or any other electronic cards by the use of the internet or any high-tech means, shall be imprisoned and fined. If the act takes place with intent to use credit or electronic cards to get other?s money or their available services, the convict shall be jailed for no less than one year, and fined no less than Dh30, 000, or one of each punishments.
* Article No.12 says anyone convicted of producing, preparing, sending, or saving information with intent to exploit, distribute or providing others with information that causes harm to public decency, via the internet or high-tick means, shall be sentenced to no less than six months in jail and fined no less than Dh 30, 000.
* Article No13 says anyone convicted of inciting or luring a male or female to commit adultery or prostitution, by using the internet or high-tech means, shall be imprisoned and fined. If the victim is a juvenile, a jail term of no less than five years and a fine shall be imposed.
* Article No14 says anyone convicted of logging onto a website with intent to change the designs of this site, deleting it, amending its information, or taking its address, shall be jailed and fined.
* Article No.15 stipulates that anyone convicted of using the internet or high-tech means for the purpose of committing the following crimes, shall be imprisoned or fined.

* The crimes are as follows:

* 1-Abuse of any Islamic holy shrines or rituals
* 2- Abuse of holy shrines and religious rituals stipulated in other religious since such rituals are maintained in accordance to the rulings of Islamic Sharia
* 3- Insulting any recognised religion
* 4- 4-Inctiment or promotion of sins

* If anyone convicted of opposing the Islamic religion, or abusing its principles, or carrying out any missionary activities for the benefit of other religions, he should be sentenced to more than seven years in jail.

* Article No16 reads that anyone convicted of transcending family principles and values, or publishing news or pictures related to the private life of the family?s members, shall be jailed for no one year and fined Dh50, 000.
* Article No.17 stipulates that anyone convicted of setting up a website, or publishing information vi the internet or any other cyber means for the purpose of trafficking in human beings or facilitating human trafficking, shall be temporarily imprisoned.
* Article No.18 reads that anyone convicted of setting up a website or publishing information with the aim of promoting narcotics shall be temporarily jailed.
* Article No.19 says anyone convicted of transferring dirty money or concealing their sources, or transferring illegal properties via the use of internet or other cyber means, shall be sentenced to no more than seven years and a fine of no less than Dh30, 000 and up to Dh200, 000.
* Article No.20 reads anyone convicted of setting up a website or publishing information for groups calling for facilitating and promoting ideas in breach of the general order and public decency, shall be sentenced to nor more than five years in jail.
* Article No.21 says anyone convicted of setting up a website or publishing information for a terrorist group under fake names with intent to facilitate contacts with their leadership, or to promote their ideologies and finance their activities, or to publish information on how to make explosives or any other substances to be used in terrorist attacks, shall be sentenced to no more than five years in jail.
* Article No22 reads anyone convicted of logging onto government websites with intent to obtain secrete information shall be sentenced to jail. If the practice resulted in deleting, destroying or publishing such information, the convict shall be sentenced up to five years in jail.
* Article No.23 says anyone convicted of inciting, or assisting or agreed with other person to commit a crime of crimes stipulated in this law, he shall be punished with the same punishment stipulated in the law.
* Article No.24 says with no prejudice to others? rights, all devices, programmes and means used in committing any of the previous mentioned crimes will be confiscated.
* Article No.25 stipulates if the convict is an expatriate, he shall be deported after serving his term.
* Article No.26 says the implementation of penalties stipulated in this law does not contradict any other tougher punishment stipulated in the penal Code or any other laws.
* Article No.27 says law-enforcement officials are allowed to catch criminals and report violations.
* Article No28 says any provision contradicts the provisions of this law shall be abrogated.
* Article No.29 says this law shall take effect from the date of its issuance, and is to be published in the official gazette.

Old Eur0pe Wins The 2005 UCSB International Capture The Flag

2005 / ديسمبر / الأحد
The UCSB International Capture The Flag (also known as the iCTF) is a distributed, wide-area security exercise, whose goal is to test the security skills of the participants from both the attack and defense viewpoints.The Capture The Flag contest is a multi-site, multi-team hacking contest in which a number of teams compete independently against each other.Each team is given a virtualized server installation (for example, a virtual Linux server). The server provides a number of services. The services have a number of undisclosed vulnerabilities, which have been included in the server’s software by the contest organizers.The goal of each team is to maintain the set of services available and uncompromised throughout the contest phase. Each team can (and should) attempt to compromise other teams’ services. Since all the teams receive an identical copy of the virtual server, the task of each team is to find vulnerabilities in their copy of the server and possibly fix the vulnerabilities without disrupting the services. At the same time, the teams have to leverage their knowledge about the vulnerabilities they found to compromise the servers run by other teams. Compromising a service will allow a team to bypass the service security mechanisms and to “capture the flag” associated with a service.During the contest a scoring system keeps track, for each team, of which services are available, and which services have been compromised.The 2005 iCTF was scheduled Friday, December 9, 2005, from 8am to 4pm, PST (note: this was changed from the initial date of December 7th).The winner of the last edition of the competition (which was held in June 2005) was the team “The Tower of Hanoi”, from Politecnico di Milano, Italy.Read more at www.cs.ucsb.edu/~vigna/…