Below evidence that the security review made by an anonymous hacker on http://infosecurityguard.com is in facts a dishonest marketing plan by the SecurStar GmbH to promote their voice crypto product.
I already wrote about that voice crypto analysis that appeared to me very suspicious.
Now it's confirmed, it's a fake independent hacker security research by SecurStar GmbH, its just a marketing trick!
How do we know that Infosecurityguard.com, the fake independent security research, is a marketing trick from SecurStar GmbH?
1) I posted on http://infosecurityguard.com a comments to a post with a link to my blog to that article on israelian ministry of defense certification
2) The author of http://infosecurityguard.com went to approve the comment and read the link on my own blog http://infosecurity.ch
3) Reaching my blog he leaked the IP address from which he was coming 217.7.213.59 (where i just clicked on from wordpress statistic interface)
4) На http:// 217.7.213.59/panel есть IP-интерфейс АТС SecurStar GmbH корпоративной АТС (открыто достижимы корыто в интернете!)
5) имена внутренних АТС на 100% подтвердить, что это SecurStar GmbH:
6) Существует 100% доказательства того, что анонимный хакер http://infosecurityguard.com от SecurStar GmbH
Ниже данные и ссылки, которые позволяют нам узнать, что это все, но нечестные маркетинговые советы, а не независимые исследования безопасности.
Престижность Маттео Флора для его поддержки и за его статью в Разоблачение Infosecurityguard личность !
Трюки HTTP направления
Когда вы читаете ссылка будет с веб-сайта на другой есть заголовок HTTP-протокол, "Направление", которые говорят вам, с какой страницы кто-то собирается на другую страницу.
Направление показало, что авторы http://infosecurityguard.com читал мое сообщение, потому что он шел от http://infosecurityguard.com/wp-admin/edit-comments.php это веб-страницы Вы используете в качестве автора WordPress / Редактор одобрить / отказать комментариев. И здесь была ссылка.
Вот запись в журнале:
217.7.213.59 - [30/Jan/2010: 2:56:37 -0700] "GET / 20100129/licensed-by-israel-ministry-of-defense-how-things-really-works / HTTP/1.0" 200 5795 "http://infosecurityguard.com/wp-admin/edit-comments.php" "Mozilla/4.0 (совместимый; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB6.3;. NET CLR 1.1.4322;. NET CLR 2.0.50727;. NET CLR 3.0.4506.2152;. NET CLR 3.5.30729; InfoPath.2) "
АТС открыты в интернете говорят нам, что это SecurStar GmbH
SecurStar GmbH АТС открыта в интернете, содержит имена всех своих сотрудников и подтвердить, что автор http:/infosecurityguard.com в том, что компания и анонимные хакеры называют Notrax.
Здесь есть свой форум, где после SecurStar GmbH ребята отладки IPCOPfirewall и Asterisk вместе (так мы видим также детали того, что они используют), где есть IP 217.7.213.59.
Это тоже очень интересно!
Они продают безопасный телефонии, но их компания телефонии открыто уязвимыми в интернете. :-)
Я думал назвать генерального директора, Хафнер, через SIP на его внутренней АТС рабочем столе, чтобы объявить, что мы обнаружили его трюки .. : ->
Они измерили их маркетинговой деятельности
Глядя на журналы моем сайте я обнаружил, что они были зондирования Google распространения информации по следующим ключевым словам, для того, чтобы понять, насколько эффективно они были в состоянии напасть на конкурирующие продукты. Это разумно, если вы вкладываете деньги в маркетинговые кампании вы хотите увидеть результаты :-)
Они дошли до моего блога, и я вошли их поиска:
infosecurityguard + CryptoPhone
infosecurityguard + золотой замок
217.7.213.59 - [30/Jan/2010: 2:22:42 -0700] "GET / HTTP/1.0" 200 31057 “Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB6.3; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; InfoPath.2)”
217.7.213.59 – - [30/Jan/2010:04:15:07 -0700] “GET HTTP/1.0″ 200 15774 “Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB6.3; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; InfoPath.2)”
The domain registration data
The domain have been registered on 1st December 2009, just two months to start preparing the dishonest marketing campaign:
Domain Name: INFOSECURITYGUARD.COM
Registrar: GODADDY.COM, INC.
Updated Date: 01-dec-2009
Creation Date: 01-dec-2009
The domain is anonymously privacy protected trough a whois privacy service:
Administrative Contact: Private, Registration INFOSECURITYGUARD.COM@domainsbyproxy.com , Domains by Proxy, Inc. DomainsByProxy.com
Notrax hacker does not exist on google
As you know any hacker that get public usually have presence of it's activity on google, attending mailinglists, forum, homepage, past research, participation to conferences, etc, etc.
The fake hacker that they wanted us to to think was writing an independent blog does NOT have any trace on google. Only some hit about an anonymous browser called Notrax but nothing about that hacker.
Maybe when SecurStar provided the anonymity tool to their marketing agency, to help them protecting anonymity for the fake research, their provided them the anonymous browser notrax.So the marketing guy thinking about the nickname of this fake hackers used what? Notrax! :-)
The “independent review”completely oriented in publicizing PhoneCrypt
Of the various review don the phonecrypt review is only positive and amazing good feedback, while the other are only bad feedback and no single good point.
As you can imagine, in any kind of independent product evaluation, for all products there are goods and bad points. No. In this one there are only product that are good and product that are bad.
They missed to consider the security of the technology used by the products
They completely avoided to speak about cryptography and security of the products.
They do not evaluated basic security features that must be in that kind of products.That's in order not to let anyone see that they did not followed basic security rules in building up their PhoneCrypt.
The technology is closed source, no transparency on algorithms and protocols, no peer review.Read my new comparison (from the basic cryptographic requirement point of view) About the voice encryption analysis (criteria, errors and different results) .
The results are somehow different than their one .
UPDATE: Who's Wilfried Hafner (SecurStar founder) ?
I got a notice from a reader regarding Wilfred Hafner, SecurStar founder, CEO and security expert.
He was arrested in 1997 for telephony related fraud (check 2nd article on Phrack) earning from telephony fraud 254.000 USD causing damages to local telcos trough blueboxing for 1.15 Million USD.
He was not doing “Blueboxing” for the pleasure of phreaking and connecting with other hackers, but to earn money.
Hacking for profit (and not for fun) in 1997… brrr…. No hacker's ethic at all!
All in all, is that lawful?
Badmouthing a competitor amounts to an unfair competition practice in most jurisdictions, so it is arguable (to say the least) that SecurStar is right on a legally sound ground here.
Moreover, there are some specific statutes in certain jurisdictions which provide for a straightforward ban on the practice we are talking about. For example in the UK the British Institute of Practitioners in Advertising - in compliance with the Consumer protection from Unfair Trading regulation – ruled that:
”falsely claiming or creating the impression that the trader is not acting for the purposes relating to his trade, business, craft or profession, or falsely representing oneself as a consumer” is a criminal offense .
We have no doubt that PRPR (which is the UK-based *PR company for SecurStar GmbH, led by Peter Rennison and Allie Andrews as stated in SecurStar Press Release ) did provide their client with this information. Heck, they *are* in the UK, they simply cannot ignore that!
IANAL, but I would not be surpised if someone filed a criminal complaint or start civil litigation for unfair competition against SecurStar GmbH.
Whether this is going to be a matter for criminal and/or civil Courts or not is not that important. However, it is clear enough that SecurStar GmbH appears to be at least ethically questionable and not really worth of trust.
Nice try, gentlemen… however, next time just do it right (whether “right” for them means “in a honest manner” or “in a fashion not to be caught” I will let them choose)”
Fabio Pietrosanti (naif)