Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

Saturday, November 28, 2009

Avoiding Botnets

Banging the drum for security awareness never gets old. As much as CSOs try to get folks to bone up on safe practices (both online and in the office), there are always going to be some who need reminding.

Online, the biggest battle these days is against botnets: networks of infected computers which hackers can use -- unbeknownst to the machine's owner -- for online crimes including sending out spam or launching a denial of service attack.

Unfortunately, the black-hat techniques employed to snare users into a botnet web have evolved to a level that makes them often undetectable by even the most sophisticated security products. Combine that with a lack of user knowledge, and the threat of infection becomes very high. (See: Botnets: Why it's Getting Harder to Find and Fight Them).

"The frustrating thing is they can make their chances of getting infected much, much smaller," said Steve Santorelli, who sees how users fall prey to easily avoidable traps every day. Santorelli, director of global outreach with the non-profit security investigations firm Team Cymru, spends his days monitoring malicious online activity, particularly botnets.

Santorelli notes that while just one strategy probably won't cover you, with several tools in the tool box, the rate of infection within an organization significantly drops.

Tip 1: Have work AND home machines regularly updated with patches and antivirus software

The average user doesn't necessarily have a lot of technological knowledge, said Santorelli. They might not realize the importance of working with IT to ensure they are up to date with patching and software upgrades. This problem may be especially prevalent among workers who are exclusively remote.

In fact, a study conducted by security firm Sophos last year found most computer users ignore security updates and turn off their firewalls. Sophos scanned 583 computers for 40 days and found that 81 percent of the machines failed one or more basic security checks. Most machines, 63 percent, were lacking security patches for the operating system, office application and programs like Windows Media Player and Adobe Flash. More than half, 51 percent, had disabled their firewall and another 15 percent had outdated or disabled antivirus and anti-spam software.

Those are exactly the folks that criminals love.

"These people are going to go for the low-hanging fruit and unfortunately there is a lot of it out there," said Santorelli. "There are so many machines without updated AV on it."

If your patching system isn't automated, your users need to be made aware of the risks they are taking by working with unpatched and out-dated security technologies. And while security updates are not the cure-all for malware infection, Santorelli said they certainly serve as a strong deterrent.

"If you are walking down the street as a burglar and you see a house with a Rottweiler, and a visible sign from a security company, you probably won't attack that house," he noted.

Tip 2: Use the latest browser versions

Staying away from dubious sites and sticking to known brands used to offer reasonable online safety. Unfortunately, that's less and less foolproof.

"It used to be that if you surfed to places like CNN, or the Weather Channel, you weren't going to come across great deal of malware," said Santorelli. "That isn't the case anymore. We've seen a number of cases recently where people have gone to a legitimate web site and there is an advertisement up there hosting some kind of malicious code."

That is where the latest safe browsing technologies can help, said Santorelli. The latest versions of today's browsers will often flag potentially dangerous content.

"Browsers are so much more secure now that so many of the holes that existed in these browsers have been patched. There is also a great deal of anti-phishing and anti malware that goes into them now. So if you try and go to a link that contains malware, your AV might not pick it up. But your browser will say: "Are you sure?"

The good news is most browsers are free. You can download the latest version of Internet Explorer or Firefox fairly easily and quickly, too (See: IE or Firefox: Which is More Secure?).

"It will only take you five minutes to have the latest browser technology," said Santorelli. "It is just another string to your bow, so to speak."

Tip 3: Be a little more careful when you get a link or an attachment.

"Don't just blindly click on things and rely on other people to protect your computer," noted Santorelli. "You've got to take some responsibility for your own security."

Team Cymru research reveals that the most common attack vectors for installing malware continue to be links in emails, or drive-by downloads.

"We know from our recent investigations that there is a great deal of success to be had [for hackers] by just sending links out," he said.

Just because you receive the email from someone you know and trust, it doesn't mean it is safe. This includes friends and family, whose systems or accounts may have been compromised, and also well-known web sites you use, like social networking sites or banks. See Five More Facebook, Twitter Scams to Avoid for examples of current attempts to exploit social media sites. And large banks, such as Bank of America, often find their name is used in email phishing scams where thieves send out messages warning that customers their account has been compromised with a link that leads to a fake, but very legitimate-looking login screen.

Of course, whether or not you should click any link or attachment also depends on if you have complied with steps 1 and 2 above.

"You're going to have to take it on a case-by-case basis," said Santorelli "And my concern would be significantly raised if I didn't have my computer up to date with antivirus and browsing technologies."

Tuesday, November 24, 2009

China: Ramps up Cyberwar against USA

A US government report warned Thursday that China is sharply stepping up espionage against the United States as the rising Asian power invests in cyber warfare and grows more sophisticated in recruiting spies.

"China is changing the way that espionage is being done," said Carolyn Bartholomew, the chair of the US-China Economic and Security Review Commission.

In its wide-ranging annual report to Congress, the commission reported a steep rise in the disruption and infiltration of websites of the US government and perceived Beijing rivals such as Tibet's exiled leader the Dalai Lama.

Colonel Gary McAlum, a senior military officer, told the commission the US Defense Department detected 54,640 malicious cyber incidents to its systems in 2008, a 20 percent rise from a year earlier. The figure is on track to jump another 60 percent this year.

While the attacks came from around the world, the commission said China was the largest culprit. Some Chinese "patriotic hackers" may not receive official support, but the report said the government likely planned to deploy them in a conflict to disrupt a foreign adversary's computers.

The bipartisan commission found that China was the most aggressive nation in spying on the United States and was trying to recruit more American spies.

While China historically tried to tap Chinese Americans -- believing, often incorrectly, that they would be sympathetic -- it was now turning to the Soviet model of seeking to bribe informants with cash and gifts, the report said.

It said the Chinese were expanding "false flag" operations, in which sources are deceived into thinking they are providing information elsewhere.

It pointed to the case of Tai Shen Kuo, a furniture salesman in New Orleans arrested last year after persuading two retired US military officials to give sensitive information by telling them it was headed to Taiwan, not mainland China.

The commission also found that China has launched an effort to influence US think-tanks and academia by rewarding scholars with access and depriving visas to more critical voices.

"It becomes self-censorship. If you're in graduate school and want to become a China scholar, you need to go to China. And if you criticize the Chinese government on certain things, you won't get in," said Bartholomew, a former top aide to House Speaker Nancy Pelosi.

"What it means is that we have a generation of China analysts who are being created who don't necessarily have the freedom or the ability to think through a broader range of questions," she said.

The commission also criticized China on its trade policy, recommending that the United States press Beijing to make its yuan more flexible and to turn to the World Trade Organization to fight what it termed predatory trade practices.

Shortly after the release of the report, two lawmakers called for an investigation into China's "currency manipulation," which would set the stage for slapping import duties on Chinese goods.

President Barack Obama this week paid his first visit to China, which is now the top holder of the ballooning US debt. His administration has sought cooperation with China on battling the global slowdown.

The commission paid a field trip to Rochester in upstate New York, where it said core industries such as machine tools, auto parts and optoelectronics were struggling against Chinese competition that often enjoys state support.

"For 20 years we have watched China policy be controlled really by a handful of large multinational corporations. They're the ones who determine the interests," Bartholomew said.

"But there are a lot of constituency interests out there -- particularly small and medium-sized enterprises -- that are being hurt by the current US-China policy," she said.

Separately, the report recommended that the United States "continue to work with Taiwan to modernize its armed forces," saying China was rapidly expanding its military advantage despite easing tensions with the island.

The Obama administration has yet to decide on Taiwan's requests to buy arms, including F-16 jet fighters. Such a step would almost certainly anger China, which considers the island its territory.

Friday, August 7, 2009

Cyber criminals can empty business accounts in minutes

Modern Methods to move and transfer Money, ensure that it moves fast and it can be equally fast going from your account with Automated Clearing House (ACH) fraud.

These criminals are not stupid. They knew what they were doing when they hit the US Western Beaver County School District and they knew when to strike.

They waited until school administrators were away on holiday, and then during a four-day period between Dec. 29 and Jan. 2, siphoned US$704,610.35 out of two of the school district's bank accounts. Western Beaver's financial institution, ESB Bank, managed to reverse some of the transfers, but the Pennsylvania school district was out more than $441,000.


On July 9, Western Beaver sued ESB to try and recover the money, but security experts say that it's just one of many organisations that have been hit in recent months by a disturbing new type of financial fraud that can often leave the victim holding the empty bag.

Fraudsters are taking advantage of the widely used but obscure Automated Clearing House (ACH) Network in order to pull off their attacks. This financial network is used by financial institutions to handle direct deposits, checks, bill payments and cash transfers between businesses and individuals.
In April, ACH fraudsters moved $1.2 million out of a Sugar Land, Texas, importer called Unique Industrial Products, according to a report in the Houston Chronicle. They did this by hacking into the company's computers and then authorising 39 transfers to move the money out of Unique Industrial's account. Although the bulk of the money was recovered, scammers made $150,000 from the attack -- not bad for 30 minutes of work.