Showing posts with label vulnerabilities. Show all posts
Showing posts with label vulnerabilities. Show all posts

Friday, July 17, 2009

UK Investigation into Cyber Attack goes Global

UK authorities have launched an investigation into the recent cyberattacks that crippled Web sites in the U.S. and South Korea, as the trail to find the perpetrators stretches around the world.

On Tuesday, the Vietnamese security vendor Bach Khoa Internetwork Security (Bkis) said it had identified a master command-and-control server used to coordinate the denial-of-service attacks, which took down major U.S. and South Korean government Web sites.

Zombie PCs

A command-and-control server is used to distribute instructions to zombie PCs, which form a botnet that can be used to bombard Web sites with traffic, rendering the sites useless. The server was on an IP (Internet Protocol) address used by Global Digital Broadcast, an IP TV technology company based in Brighton, England, according to Bkis.

BKIS control

That master server distributed instructions to eight other command-and-control servers used in the attacks. Bkis, which managed to gain control of two of the eight servers, said that 166,908 hacked computers in 74 countries were used in the attacks and were programmed to seek out and download new instructions every three minutes, from designated random sites.

Miami Master Server

But the master server isn't in the U.K.; it's in Miami, according to Tim Wray, one of the owners of Digital Global Broadcast, who spoke to IDG News Service on Tuesday evening, London time.
The server belongs to Digital Latin America (DLA), which is one of Digital Global Broadcast's partners. DLA encodes Latin American programming for distribution over IP TV-compatible devices, such as set-top boxes.

VPN Connections
New programs are taken from satellite and encoded into the proper format, then sent over VPN (Virtual Private Network) to the U.K., where Digital Global Broadcast distributes the content, Wray said. The VPN connection made it appear the master server belonged to Digital Global Broadcast when it actually is in DLA's Miami data center.

Engineers from Digital Global Broadcast quickly discounted that the attacks originated with the North Korean government, which South Korean authorities have suggested may be responsible.

Digital Global Broadcast notified

Digital Global Broadcast was notified of a problem by its hosting provider, C4L, Wray said. His company has also been contacted by the U.K.'s Serious Organised Crime Agency (SOCA). A SOCA official said she could not confirm or deny an investigation.

Amaya Ariztoy, general counsel for DLA, said the company examined the server in question today and found "viruses" on it. "We are conducting an investigation internally," Ariztoy said.

Forensic Analysis
Investigators will need to seize that master server for forensic analysis. It's often a race against the hackers, since if the server is still under their control, critical data could be erased that would help an investigation.

"It's a tedious process and you want to do it as quickly as possible," said Jose Nazario, manager of security research for Arbor Networks.

Data Logs Audit
Data such as log files, audit trails and uploaded files will be sought by investigators, Nazario said. "The holy grail you are looking for are pieces of forensics that reveal where the attacker connected from and when," he said.

D-o-S MyDoom Variant
To conduct the attacks, the hackers modified a relatively old piece of malware called MyDoom, which first appeared in January 2004. MyDoom has e-mail worm characteristics and can also download other malware to a PC and be programmed to conduct denial-of-service attacks against Web sites.

The Evidence Trail
Analysis of the MyDoom variant used in the attacks isn't that impressive. "I still think the code is pretty sloppy, which I hope means they [the hackers] leave a good evidence trail," Nazario said.

Perpetrator Profile
It could also be that the perpetrator is either very confident that they will not be found, is trying to hide in the pseudo amateur world of the cyber geeks and cyber vandals, is not concerned or is immune from discovery.

Maybe, a virtual self destructive personality that is implementing a non fatal 'suicide' mission for yet to be revealed reasons.

Chinese Hackers Exploit Microsoft Internet Explorer Weakness!

Symantec, Sunbelt Software and SANS' Internet Storm Center (ISC) increased their threat level warnings yesterday, after Microsoft announced that attackers were exploiting a bug in an ActiveX control used by Internet Explorer (IE) to display Excel spreadsheets.

There is no patch for the vulnerability, nor will Microsoft release one later today when it issues its July batch of patches.

Temporary Fixes
A temporary fix that sets the "kill bits" of the ActiveX control is available, but experts believe it's likely most users won't take advantage of the protection.

Threat Ranking
Symantec raised its ThreatCon ranking to the second of four steps. "We're seeing it exploited, but currently on a limited scale," said Ben Greenbaum, a senior researcher with Symantec security response.

Sunbelt Ranking raised
Sunbelt also bumped up its ranking, to high, the company noted today. "We just set the Sunbelt Threat Level to high since our researchers and at least two other major organizations have found in-the-wild exploit code," said Tom Kelchner, malware researcher with the Florida-based firm.

ISC at Condition Yellow
Meanwhile, the ISC went to condition Yellow after discovering numerous sites hosting attack code. The ISC reported both broad and targeted attacks using exploit code against the new zero-day. "[There was] a highly-targeted attack against an organization earlier today who received a Microsoft Office document with embedded HTML," said the ISC in a frequently-updated blog post. "This one was particularly nasty.... It was specifically crafted for the target, with the document being tailored with appropriate contact information and subject matter that were specific to the targeted recipient."

China sites Compromised
Broader attacks are originating from compromised sites in China, the ISC added. "A .cn domain [is] using a heavily obfuscated version of the exploit, which may become an attack kit (think MPACK), and is similar to recent DirectShow attacks," said the center.

Unpatched Microsoft Bug
Last week, Microsoft confirmed that hackers were exploiting an unpatched bug in an ActiveX control that's part of DirectShow, a component of the DirectX graphics platform within Windows.

McAfee confirm attack code targeting
McAfee echoed the ISC late on Monday, confirming that attack code targeting yesterday's ActiveX bug has been added to a Web exploit toolkit and is being distributed from hijacked Chinese sites. The toolkit also contained attack code for last week's DirectShow vulnerability. Some computers in Spain, the U.K. and Germany also showed evidence of compromises, McAfee researcher Haowei Ren said in an entry to the company's security blog.

Early Days
Symantec's Greenbaum added that while his company is seeing only a small number of attacks currently "It's not in the top 500 attacks," he said. This has the potential to get big, and big quickly. "It's the kind of attack that can be very easily hosted on a Web server, and meets all the criteria for large-scale attacks in the relatively near future," Greenbaum said.

The number and diversity of attacks will likely increase because working exploit code is publicly available, he said.

Microsoft Patch
Although Microsoft is working on a patch for the new vulnerability, it's unclear when it will be ready. Users will definitely not receive any automatic protection today, however.

"Unfortunately, the comprehensive update for this vulnerability is not quite ready for broad distribution," a company spokesman said yesterday afternoon. "We recommend that customers follow the automatic 'Fix It' workaround ... to help secure their environment against this vulnerability while we finish up development and testing of the comprehensive update."

Manually Steer Browser
Fix It requires users to manually steer their browser to Microsoft's support site and download, install and run the tool to disable the ActiveX control.

That means many users won't currently be protected. "Most users won't [manually] mitigate," agreed Greenbaum. The message is clear 'Don't be in this vulnerable group.'

Thursday, April 30, 2009

Death comes to Queen's day: Serious security breaches


5 die and 13 are injured by a lone 'maniac' during Queen's Day

I have just witnessed the most apalling scenes at the Netherland's Queen's day celebration. It was disrupted and brought to a sudden and tragic end with the breakdown of weak security measures, quickly followed by poor crisis and incidence response measures. A complete abomination from a security risk and threat analysis, and from a public safety viewpoint. The time taken to respond and control the situation was woefully inadequate. If this had been a real incident, 'carnage' would have resulted. Whoever was responsible for the risk and threat assessment on this, is in the wrong business.

The incident today showed a complete lack of awareness for current threat reduction, vulnerability mitigation and crisis response management, prevalent in the rest of the world today. The arrogance and naivity inherent in providing this level of security to the NL Royal Family and the surrounding crowds, is both negligent and incompetent.

The ease by which a lone driver was able to breach the weak security measures was shocking but the response provided, during and following the incident was severely incompetent. If this had proved to be a real attempt to assasinate the Dutch Royal family by a cynical and trained group, then it would have been highly successful to a frightening degree and would have faced no serious resistance from the surrounding security forces.

Even following the incident there were no guns drawn; the car was not isolated to protect the Royal family and the surging crowd; there were no signs of protecting or rapid removal of the 'targets'; any anti-explosion measures were ignored; the 'containment' measures were non-existant, it was a dangerously embarassing and highly volatile situation that could have been easily exploited to a devastating effect.

I have studied the counter-terrorist measures of the Israelis, the South Afrikaans and the UK. I was online to the authortities in NY, both during the aftermath and the months following 9/11, offering support and advice.

The UK's own Royal Family has been at the centre of a number of attacks going back over several decades and have been a target of many such maniacs.

In 1974 a gunman tried to abduct Princess Anne as she and her first husband, Captain Mark Phillips, were being driven along the Mall in London after a charity film show. Would-be kidnapper Ian Ball forced the car to a halt and brandished a pistol. I had the pleasure of meeting the police detective that took 2 bullets for Princess Anne on this occasion and I have to say that he was a most modest and self-effacing man. The stuff that 'heroes' are made of.

Having spent the last 30 years of my life studying such incidents, with specific concern for the impact and consequences inflicted on civilian and security agencies. The effect of trauma on the victims, witnesses and spectators alike. It is with this close scrutiny of rare but extreme events and incidents perpetrated on the UK mainland by the IRA and others, that I am appalled at how easily the security today was compromised and how easily the Dutch Royal family could have been assailed and possibly assasinated. The transfer of trauma will be on an enormous scale.

When are the Netherland authorities going to realise that they have become a target for terrorism. Partly because they have proclaimed to the world that they are setting themselves up as the centre of justice for the war against international terrorists, organised criminals, sadistic dictators and mass murderers of all kinds.

Do not be mistaken, I applaude the Dutch in their stance against the evil that is so freely conducted. The establishment of the International Criminal Court against mass murderers wherever and however they manifest themselves, is a good and honourable achievement, even if it is somewhat tainted by the smell of the additional revenues that this will bring to local law firms and the other spin-off benefits that the NL authorities encourage. Unfortunately, in the eyes of the bad guys this also makes the NL a 'legitimate' target and by association the Duth people via the Dutch Royal family and other symbols of the 'establishment'.

The incident today was shocking and unbelieveable for a country that believes this sort of behaviour can only be perpetrated on them by others. I thought the world had already learned this harsh lesson. The US and the UK have certainly learned that the biggest threat comes from 'home grown' terrorist groups. Who else knows your weaknesses better than your close family and who else can get close to you to do you damage?

Let's not forget the victims in all this, and I offer them heart-felt condolenses to the victims of this incident and their families, they did not deserve this, no-one does. It will take them many years to rationalise this but clearly, they expected more protection from their guardians than was on offer today and they should demand better protection for the future. Substantial measures that go beyond the hype and rhetoric of politicians.

I also hope and pray that the NL authorites can contain the wave of xenophobia and the right-wing, anti-foreigner lobby that will spring up in the wake of this incident. Queen's day is already a symbol of white, Christian, conservative NL. There were few oriental or coloured faces on show in Apeldoorn. Marginalised and excluded from these occasions, it is easy for extremists to build on this 'pro-white' image and to corrupt the minds of the young people in NL. We must prevent this kind of backlash and counter-strike mentality that drives sectarianism and terrorism alike.

There are many serious questions here, and hard lessons to be learned. I hope everyone is open to them. The future is full of uncertainty and we need to be strong and determined to prevent terrorism and anti-social behaviour gaining ground. We have to be proactive and smart about it, not reactive and emotional. We need to address the cause of exclusion and dysfunction in this society and give the victims of this a voice to express themselves in a reasonable and rational manner. Otherwise they will find other ways to crash the party and express themselves in a dysfuntional way.

What is certain about the future, is that the 2010 Queen's day will be very different, perhaps more secure and less relaxed than previous years. The end of a dream, a childlike naivity and an optimistic but distorted perception of liberal NL. This may be a sad thing to propose but it is a more realistic approach, a practical sign of our times and the price we pay for the defense of civilisation, eternal vigilance.

Friday, April 17, 2009

Four Tele-commuting Security Mistakes


  1. Careless use of Wi-Fi and accessing unsecured open networks
  2. Letting family and friends use work-issued devices and attaching unauthorised peripherals
  3. Altering or deleting security settings to view Web sites that have been blocked by the company
  4. Leaving a work-issued device in an unsecured place or public location
Security is a good mind-set to adopt

For more information and assistance, speak to your IT Helpdesk and Security personnel . They have a range of proven and tested (approved) tools, which are closely aligned with simple operating procedures and guidelines to help you reduce the potential impact of threats and vulnerabilities. The effective use and implementation of these, is up to you.

Remember to check with the security guys regularly. There is always something new going on in their world that will directly affect your business world.

If in doubt give the Security doctor a shout!

As with most things, it is always easier to find security issues and threats before they escalate into a crisis. A mild infection can be treated quickly and effectively if brought to their attention early but, if left untreated, there is always the risk of cross-infection to other members of staff, with the potential loss of a limb or vital organ.

In your business world, it is your server, applications and your data that keeps you alive! You don't want to lose any of these or even break the arterial chain that holds them together.

3 Security Flaws in Google Docs?

Security Analysts find 3 Flaws in Google Docs!

1) One of the flaws allows images to be accessible even if a document has been deleted
2) The second problem allows users to see all versions of an image that's been modified
3) A third problem is perhaps the most serious of all; It appears to allow people who once had access to someone's Google Docs to still get access even if access rights have been changed. Details of this one have not been released yet.

Click on the dragon for more details

Thursday, April 9, 2009

Zombies Ahead! Spooks in the machines!

An electronic road sign was hacked and changed, to alert drivers to the potential hazard of 'hoards of the undead' jaywalking. This provides a nice example of why the status of the security on the US Grid and associated infrastructure is such a “big deal”.

The hack itself is trivial: an intrepid individual discovered that electronic road signs shared a common default password. The good news is; that the default password would have been discovered and publicized years ago if the systems were connected to the internet. They were only left alone or overlooked, for years because very few people had the initiative or twisted interest, to walk up to one of the signs and attempt what is essentially a simple dictionary attack against the authentication mechanism.

Without the motivation and justification of protecting installations from sustained and multiple attack, engineers saw no reason to improve the security of their systems. Following the threat response reasoning, that defense is only required where attack is likely or where expenditure restrictions veto and supress security issues. (Discuss!) You could also argue that the lack of protection in certain areas forms part of the overall strategy of the threat and those that threaten.

It seems that everyone laughed off the hack as a simple prank, but failed to consider the serious implications and security problems that exist in systems that are legacy-based, semi-automated and semi-attached to the National grid.

There are a large class of systems that are semi-attached to the grid and they also have similar security problems and vulnerabilities. Known as SCADA (Supervisory Control And Data Acquisition) Systems, these computers are responsible for controlling electro-mechanical devices and physical plant as found in nuclear reactors and oil refineries.

Many of these systems were deployed years ago in simpler times, well before the information security industry fully understood code quality problems and how they can be and would be, exploited by attackers. These systems are only safe from exploitation for as long as you can guarantee a substantial air-gap or secure firewall between the control network and anything a human being can touch.

Serious Vulnerabilities

Spies and government sponsored hackers have already been probing the U.S. electrical grid for months and planting software that is intended to be activated at a future date, according to a Wall Street Journal. The report highlights the latest non-physical, indirect threats and vulnerabilities facing the U.S. power infrastructure.

The Journal notes that the spies are from China, Russia and other countries who are more openly threatening. While the news is very disturbing, it isn’t all that surprising. The vulnerabilities of the U.S. infrastructure are well documented. It is also notable that the electrical grids were initially thought to be somewhat hacker proof, until recently. Why? because the grids run on old legacy software, which is often proprietary. This it turns out is its greatest weakness, along with apathy and complacency.

The barbarians are not at the door but they may have remote access to your infrastructure and life support systems! Prepare to repel boarders!

Microsoft Security Intelligence Report - Extracts

Here’s a look at the five most important aspects from the full Microsoft Security Intelligence Report.

1. Vulnerabilities (the response and reaction to them) vary, depending on whether the target is at work or home.

Based on data provided by its enterprise Forefront Client Security and consumer Windows Live OneCare, Microsoft found that vulnerabilities are very different. Why? A corporate user may have email and Internet limitations that reduce the attack surface. A home user has more software tools to be infected but less critical data at risk.

Simply put, a home user is more likely to get hit with a Trojan attack to extract bank and credit card details, etc. In the enterprise, the weapon of choice is the Worm attack, which is primarily destructive and disruptive.

The greatest difference between enterprise and home vulnerabilities is social engineering. Microsoft explains:

  • The Windows Live OneCare list also includes several families associated with rogue security software, such as Win32/Renos, Win32/FakeXPA, and Win32/Antivirus2008.
  • The social engineering messages used in connection with rogue security software may be less effective in an enterprise environment, where malware protection is typically the responsibility of the IT department…
  • By contrast, the Forefront Client Security list is dominated by worms, like Win32/Autorun, Win32/Hamweq, and Win32/Taterf.
  • Worms rely less on social engineering to spread than categories like trojans and downloaders do, does and more on access to unsecured file shares and removable storage volumes, both of which are often plentiful in enterprise environments.

2. Users don’t always remove unwanted software: There’s great appeal to the procrastinator in the “ignore” button.

  • Microsoft explains one nuance of the malware issue:Software cannot always be classified in binary terms as “good” or “bad.”
  • Some software inhabits a gray area wherein the combination of behaviors and value propositions presented by the software is neither universally desired nor universally reviled.
  • This gray area includes a number of programs that do things like display advertisements to the user that may appear outside the context of the Web browser or other application and which may be difficult or impossible to control.

Microsoft’s scans allow users to ignore a security alert, allow software to remain, issue a prompt, quarantine or remove it.

If software is really malicious it is removed without user input. The gray areas appear when users have a choice.

Microsoft adds:
  • These decisions are influenced by a number of factors, such as the user’s level of expertise, how certain they feel about their judgment regarding the software in question, the context in which the software was obtained, societal considerations, and the benefit (if any) being delivered by the software or by other software that is bundled with it.
  • Users make choices about what to do about a piece of potentially unwanted software for different reasons, so it’s important not to draw unwarranted conclusions about their intent.

Moderate or Low threats are often ignored by users, who think that there’s value in the software. These threats are keepers based on user behaviour:

3. Rogue security software (Scareware) gains momentum.

The concept of rogue security software is pure genius. Malicious hackers prey on the fears of users, cook up bogus security software and extract payments to keep your PC running. Microsoft notes that rogue security software is becoming a hot category.

Microsoft reports:

  • Rogue security software authors have long attempted to exploit this trust by giving their programs generic, anodyne names, like “Antivirus 2009,” and making them resemble genuine security software in many ways.
  • Recently, many threats have taken this approach a step further, posing as components of the operating system itself or as a familiar search engine.
  • One of the first families observed to exhibit this behavior was Win32/FakeSecSen, which was added to the MSRT in November 2008 and was the eighth most prevalent family in 2H08 overall.
  • Win32/FakeSecSen adds an icon to the Control Panel named Vista AV or MS AV and fraudulently uses the same four-colour shield icon as the Windows Security Center. Double-clicking the icon launches the rogue software, which claims to detect a large number of nonexistent threats and urges the user to “activate” the software by paying for it.

Win32/Renos is a longtime threat that delivers rogue security software. It was the most prevalent threat in the second half of 2008. Two new trojans–Win32/FakeXPA and Win32/FakeSecSen were the seventh and eight most prevalent family class.

4. Social networking phishing attacks represented less than 1 percent of attacks, but yielded a big chunk of phishing impressions.

Translation: Social networking sites will remain a big phishing target.

Microsoft explains:
  • A typical social network phish is likely to trick an order of magnitude more users than a typical financial phish. There are a number of explanations for this discrepancy.
  • While financial institutions targeted by phishers can number in the hundreds, just a handful of popular sites account for the bulk of the social network usage on the Internet, so phishers can effectively target many more people per site.
  • In addition, phishers often use the messaging features of the sites themselves to distribute their attacks, typically by gaining control of a user’s account and using it to send phishing messages to the victim’s friends.
  • These attacks can be much more effective than e-mail–based attacks, because they exploit the considerable level of trust users place in their friends.

Take a look at:

And.

5. Malware is dominant in the U.S. and accounted for 67 percent of all infected computers.

Trojans—the miscellaneous variety–were detected on 29.4 percent of infected computers. Among other items:

  • Five of the top 20 families detected in the United States in Q3 and Q4 of 2008 (Win32/Renos, Win32/FakeXPA, Win32/FakeSecSen, Win32/Antivirus2008, and Win32/Winfixer) download rogue security software or display misleading warning messages to convince users to purchase a program that supposedly removes spyware.

Here are the top five individual threats:

Trojan downloaders and droppers were detected on 24.4 percent of all infected computers.

I trust this was of interest to you and you will see the sense of protecting your computer(s) with known and trusted anti Virus software as well as setting up a good Firewall and Intrusion detection. The rise and rise of Malware across the globe means that you will also need to protect your system(s) from this menace.

Do your research, read the reviews and never be the first to try any new protection software.