Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Thursday, March 21, 2013

Metasploit - Entire Internet probed for insecure devices - Millions Discovered

A surreptitious scan of the entire internet has revealed millions of printers, webcams and set-top boxes protected only by default passwords.

An anonymous researcher used more than 420,000 of these insecure devices to test the security and responsiveness of other gadgets, in a nine-month survey.

Using custom-written code, they sent out more than four trillion messages.

The net's current addressing scheme accommodates about 4.2 billion devices. Only 1.3 billion addresses responded.

The number of addresses responding was a surprise as the pool of addresses for that scheme has run dry.

As a result, the net is currently going through a transition to a new scheme that has a vastly larger pool of addresses available.

The scan found half a million printers, more than one million webcams and lots of other devices, including set-top boxes and modems, that still used the password installed in the factory, letting almost anyone take over that piece of hardware. Often the password was an easy to guess word such as "root" or "admin".

"Whenever you think, 'That shouldn't be on the internet, but will probably be found a few times,' it's there a few hundred thousand times," wrote the un-named researcher in a paper documenting their work.

HD Moore, creator of Metasploit, carried out a similar survey in 2012, said the results looked "pretty accurate".

He added he had seen malicious hackers exploiting the security failings of these devices to run criminal networks known as botnets that are used to send out spam, mount phishing attacks and bombard websites with deluges of data.

Thursday, October 27, 2011

Our security paradigm is out of date

At a recent Cloud Security event, the president of the UK & Ireland chapter of the Cloud Security Alliance (CSA UK & Ireland) said that the perception of security as a concept is out-dated.

According to Des Ward, the current focus on complying with the myriad of assurance frameworks is taking focus away from the obligations placed on organizations to identify and manage the risks to their information assets; which, in turn, places an inordinate and inappropriate burden on external service providers to satisfy the concerns of organizations with no common terms of reference.

“The discussion following my presentation was very interesting as it highlighted that, whilst security in the cloud services environment is clearly a concern for many IT security professionals, there is still a lack of assurance within the external supply chain as whole,” said Des Ward, President, CSA UK & Ireland.

“What this tells me is that, whilst the message on security is getting through to businesses, there is no consistent language to determine whether the service provider will operate the controls to a level that assures the client that their risks are managed appropriately.

This proves to me that the current security mindset is little more than managing risks to achieving compliance rather than empowering organizations to understand the controls required to manage the risks to their information.”

“It is important”, says Ward, “to understand that all organizations in the UK and Ireland, on both sides of the public/private sector divide, have an explicit obligation under law to ensure that personal and corporate information is managed in a safe manner.

“The current compliance overload over the past four or five years has led to an inordinate focus on managing risks to compliance rather than understanding the risks to information – and this focus has meant that we look to overuse of technical controls to show due diligence to ensure that when a breach occurs, that penalties will not be levied; it is not designed to reduce the likelihood of breaches themselves,” he adds.

“This approach is, in my humble opinion, unsustainable, as it does not look to the implementation of the controls and fails to address the business risk management issue that exists in most organizations.

This is turn has no more benefit to the business than placing money in the shredder.” he explained.

“A classic case of these issues”, he says, “was the ICO's recent engagement with Lush after the cosmetics retailer suffered a payment card breach; although the outcome was favourable for all concerned, the key lesson to be learnt is that the current compliance boundaries can now be crossed by another interested party.

What stops the ICO from looking beyond the compliance scope of PCI and entering its own jurisdiction which is the entire business?

“The current lack of corporate information governance in today's businesses will soon result in increased penalties and I feel that this case will be a tipping point; despite the clamour for more prescription from assurance frameworks, my own experience is that many implementations of the PCI DSS are tightly scoped and shows there is little appetite for additional level of prescription that comes with little more benefit than a licence to undertake business on the internet.

This proves to me that the current focus on compliance risk management as we know it is nearing an end, and something else is required to assist organizations to understand and manage the risks to their information going forward.”

Thursday, March 4, 2010

Mariposa Botnet Authors and Distributors Caught

Three Spanish men were arrested last month for allegedly building an international network of more than 12 million hacked PCs that were used for everything from identity theft to spamming.

But according to Spanish authorities and security experts who helped unravel the crime ring, the accused may very well never see the inside of a jail cell even if they are ultimately found guilty, due to insufficient cyber crime legislation in Spain.

According to Spanish security firm Panda Security, the massive botnet, dubbed “Marioposa” (Spanish for “butterfly”), was rented out to criminals as a delivery platform for installing malicious software such as the data-stealing ZeuS Trojan and pay-per-install toolbars.

Panda said the gang, also stole directly from victim bank accounts, using money mules in the United States and Canada, and laundered stolen money through online gambling Web sites.

Panda said Mariposa helped crooks steal sensitive data from more than 800,000 victims, including home users, companies, government agencies and universities in at least 190 countries.
Spanish police estimate that at least 600,000 of the victimized PCs belong to Spanish citizens, and yet they concede it may be extremely challenging to put the men in jail if they are convicted at trial.

“It is almost impossible to be sent to prison for these kinds of crimes in Spain, where prison is mainly for serious crime cases,” said Captain Cesar Lorenzana, deputy head technology crime division of the Spanish Civil Guard.

“In Spain, it is not a crime to own and operate a botnet or distribute malware. So even if we manage to prove they are using a botnet, we will need to prove they also were stealing identities and other things, and that is where our lines of investigation are focusing right now.”

Spain is one of nearly three dozen countries that is a signatory to the Council of Europe’s cybercrime treaty, but Spanish legislators have not yet ratified the treaty by passing anti-cybercrime laws that would bring its judicial system in line with the treaty’s goals.

The Mariposa botnet takedown was orchestrated by a working group comprising Panda, the Georgia Tech Information Security Center, and Canadian security firm Defence Intelligence, which first detailed the workings of the bonnet in a white paper released in May 2009.

On Dec. 23, 2009, the working group was able to “sinkhole’ the botnet by hijacking the command and control networks that were being used to orchestrate the botnet’s activities. But according to Defense Intelligence CEO Christopher Davis, a few days later, the alleged ringleader of the Mariposa botnet gang who goes by the hacker alias “Netkairo,” bribed an employee at a Spanish domain name registrar that the gang had been using to register Web site names that helped them control the botnet.

Armed with those domains, Netkairo was able to rebuild the botnet, as the individual PCs enslaved by the Mariposa botnet were still programmed to regularly connect to those sites and download updated marching orders.

Davis said that on Jan. 22, the hacker launched a distributed denial of service attack against Defense Intelligence’s Web site, using more than a million PCs the gang had managed to corral back into the Mariposa botnet.

That assault, which forced the infected PCs to flood the company’s site with junk Web traffic, not only knocked Defense Intelligence offline, but took out networks of several other organizations that were using the same Internet service provider, including a local university and a few government agencies in Ottowa.

Lorenzana said the three men haven’t been named publicly because they haven’t yet been charged with a crime. Until that happens, which will probably be in a couple of weeks, the men are all free on their own recognizance.

In the meantime, they are free to hoover up as much stolen data as they please, as the Mariposa working group has not yet been able to shutter the Web sites that served as the repository for personal and financial data stolen from people whose systems were ensnared by the bot.

“The main problem is that even though the botnet itself has been taken down, these bots are all still infected, and these guys who operated the botnet can still go and download all the details of the data they have stolen,” Lorenzana said.

Juan Santana, CEO of Panda Security, said he hopes this case will spur Spanish lawmakers to amend the penal code to more specifically punish cyber crime activities.

“I don’t think these guys will go to jail, especially if it is the first time they have committed a crime,” Santana said. “The government needs to pass laws that are enforceable and enforced afterward.

In the vast majority of countries, malicious hackers do not fear that if they do get caught that they will go to jail, because the benefit for them is far higher than the risk right now.”

Monday, February 22, 2010

Mobile phones become pocket banks in poor countries

An Afghan police officer gets his salary in a text message on his mobile phone. A Kenyan worker dials a few numbers to send money to his family.

The rise of banking transactions through mobile phones is giving a whole new meaning to pocket money in parts of the developing world that lack banks or cash machines.

Mobile money applications are emerging as potent financial tools in rural and remote areas of the globe, allowing people with no bank accounts to get paid, send remittances or settle their bills.

"One billion consumers in the world have a mobile phone but no access to a bank account," said Gavin Krugel, the director of mobile banking strategy at GSM Association, an industry group of 800 wireless operators.

"We see it as very big opportunity," he said this week at the Mobile World Congress in Barcelona, Spain, the industry's annual four-day event that ended on Thursday.

Mobile banking began to emerge six years ago in the Philippines and South Africa, where 8.5 million and 4.5 million people, respectively, use such services.

Today, 40 million people worldwide use mobile money, and the industry is growing, according to the GSMA.

"Africa and Asia are the most active regions right now," Krugel said. "We expect Latin America pick up this year."

There are 18,000 new mobile banking users per day in Uganda, 15,000 in Tanzania and 11,000 in Kenya, he said.

Mobile phones can offer a wide range of banking solutions, from sending transfers to a relative to buying goods in a store or putting money aside for a rainy day -- all by dialing a few numbers on one's handset.

Mobile banking can also make life easier for people in parts of Africa where paying a simple bill can be time-consuming, said Reg Swart, regional executive of Fundamo, a company that makes banking applications.

"It takes one day to pay one bill. You have to physically go to the bank, then you must queue, a long queue," he said.

In Afghanistan, the national police has been testing a service from mobile operator Roshan to pay its officers -- a system that helps to limit corruption, the company said.

"We are currently moving from a trial to a full launch in paying the Afghan national police," said Roshan's head of mobile commerce, Zahir Jhoja.

Every month, police officers receive a text message in the language they prefer informing them they have received their salaries, Jhoja said.

A voice message is also left on the phone "because a lot of them are illiterate and cannot read," he said. The officer can then go get his money from an authorised Roshan agent.

Wednesday, January 6, 2010

Cybersitter is suing the Chinese government for piracy and breach of copyright

A US software maker is suing the Chinese authorities and seven major computer maker, including; Sony, Toshiba, Lenovo, etc. Cybersitter is accusing China of openly pirating its Cybersitter content filtering software and using it for their own purposes.

The federal lawsuit has been filed in Los Angeles by Cybersitter and the compensation demanded is $2.2 billion (£1.37 billion).

The company alleges that the Chinese authorities have blatantly copied its codes and incorporated them into their 'citizen security' software. This software is used to monitor and block Chinese citizens' ability to access sites deemed politically undesirable by the government.

Cybersitter software was originally designed to help parents monitor and filter content seen by children.

The seven computer manufacturers, including Sony, Lenovo, and Toshiba, that are also being cited in this lawsuitsued, have been distributing the Chinese 'citizen security' software program with PCs sold in the country.

This was forced on PC manufacturers who wanted to distribute their products in China. It was done to comply with a mandate from the Chinese authorities to ensure that no computers were sold in China without the 'security' software bundle on it. This mandate was later amended.

Monday, January 4, 2010

GSM encryption key revealed | IT PRO

GSM encryption key revealed | IT PRO

The encryption key used to protect the privacy of calls on 80 per cent of the world's mobile phones has been made freely available – in order to highlight its vulnerability


Mobile phone security

A German security expert has published details of how to break the encryption algorithm used by GSM mobile phone technology, highlighting the ageing system's increasing vulnerability.

Karsten Nohl, 28, used a hacker conference in Berlin to publish the work of a collaborative research project to crack the 21-year-old GSM algorithm, a 64-bit encryption function known as A5/1, in a “code book” containing the the encryption key used in a GSM call.

Global System for Mobile Communications (GSM) is the standard form of digital voice encryption that keeps conversations on more than three billion handsets private – more than 80 per cent of the world's mobile phones.

Nohl and research partner Chris Paget said their research proves that with relatively modest funds and some widely available open-source tools, GSM encryption can be cracked, allowing virtually anyone – in theory – to listen in on phone calls.

However, the GSM Association (GSMA) played down the demonstration. It pointed out that the practical complexity of the so-called hack made it highly difficult both to set up and to perform unnoticed, and in any case – it said – the newer, far stronger A5/3 algorithm was in the process of replacing A5/1.

“We consider this research, which appears to be motivated in part by commercial considerations, to be a long way from being a practical attack on GSM,” a spokeswoman said. “A5/1 has proven to be a very effective and resilient privacy mechanism.”

Monday, December 14, 2009

IRAN: Iran and Afghanistan, threaten Gulf security

The Afghan war and the Iran nuclear crisis are among the threats to security in the Gulf region, Kuwaiti foreign minister and deputy prime minister Sheikh Muhammed Sabah al-Salem al-Sabah said Friday.
Sheikh Muhammed was addressing delegations from more than 25 countries in the Gulf Cooperation Council at the opening of the sixth Manama Dialogue security conference in Bahrain.
Threats to GCC security ran from "Afghanistan and neighbouring Pakistan, go through Iran's confrontation with the international community, to the reality of Palestine and the suffering of the Palestinian people, down the Horn of Africa, to the crisis in Yemen," he said.
In additional and implicit swipe at Iran, he spoke of "when people call for rebellion against the regime, challenging the government and calling for the overthrow of the government in place."

Gulf officials "should recognise the risks of abusing ideologies in the relations between states," he added. Iran has been accused by the West and various Gulf states of interfering in the affairs of its neighbors and attempting to foment instability.
Sheikh Muhammed also discussed what he described as mid-term problems: the threat posed to Gulf countries by international economic downturns, and the risk of relying primarily on oil for revenue. And he added: "We must look closely at the demographic situation of our six GCC countries, and we will note that there are real demographic challenges in the mid- and long-term."
These challenges included the projected 30 percent rise in the population of the GCC countries by 2020; the large percentage of young people; and the large number of foreign workers in the Gulf.

The consequently large remittances being sent out of the Gulf and the growing number of children of foreign workers in GCC countries also posed a problem, he added. "This generation has no other home than the GCC countries -- they were born, have lived and worked here, and they represent a great challenge in terms of absorption into society from a cultural and a social viewpoint," he said.
The Manama Dialogue conference is sponsored by the International Institute for Strategic Studies. This year's conference, which lasts through Sunday, will focus on Afghanistan, Pakistan, Yemen and Iran.

Saturday, November 28, 2009

EU Security Agency Highlights Cloud Computing Risks

Cloud computing users face problems including loss of control over data, difficulties proving compliance, and additional legal risks as data moves from one legal jurisdiction to another, according to a assessement of cloud computing risks from the European Network and Information Security Agency (ENISA).
Comments By Mikael Ricknäs

Fri, November 20, 2009 — IDG News Service — Cloud computing users face problems including loss of control over data, difficulties proving compliance, and additional legal risks as data moves from one legal jurisdiction to another, according to a assessement of cloud computing risks from the European Network and Information Security Agency (ENISA).

The agency highlighted those problems as having the most serious consequences and being among the most likely for companies using cloud computing services, according to ENISA.

ENISA examined the assets that companies put at risk when they turn to cloud computing, including customer data and their own reputation; the vulnerabilities that exist in cloud computing systems; the risks to which those vulnerabilities expose businesses, and the probabilities that those risks will occur.

When moving to cloud-based computing services, companies have to hand over control to the cloud provider on a number of issues, which may affect security negatively. For example, the provider's terms of use may not allow port scans, vulnerability assessment and penetration testing. At the same time, service level agreements (SLAs) may not include those services. The result is a gap in defenses, ENISA said in the report.

Compliance could also prove to be a big problem if the provider can't offer the right levels of certification or the certification scheme hasn't been adapted for cloud services, the report said.

One of the advantages of cloud services is that data can be stored in multiple locations, which could save the day in the event of an incident in one of the data centers. However, it could also be a big risk if the data centers are located in countries with a shaky legal system, according to the report.

Other areas of concern are vendor lock-in, failure of mechanisms separating different companies, management interfaces that get accessed by hackers, data not deleted properly and malicious insiders.

To minimize these risks the report proposes a list of questions that a company needs to ask potential cloud providers. For example, what guarantees does the provider offer that customer resources are fully isolated, what security education program does it run for staff, what measures are taken to ensure third-party service levels are met, and so on.

In the end a good contract can lessen the risks, according to the report. Companies should especially pay attention to their rights and obligations related to data transfers, access to data by law enforcement and notifications of breaches in security, it said.

ENISA's report isn't all doom and gloom, though. Using cloud computing services can result in more robust, scalable and cost-effective defenses against certain kinds of attack, according to the report. For example, the ability to dynamically allocate resources could provide better protection against DDoS (distributed denial-of-service) attacks, ENISA said.

Thursday, October 22, 2009

Caution! Rise in Scareware Tactics - Rough Security software

Rogue security software, also dubbed scareware, is an "ongoing threat" that is impacting largely users from English-speaking markets, according to findings from a year-long study by Symantec.

Released Tuesday, Symantec's report on rogue security software noted that 250 rogue security programs launched some 43 million attempts to prompt user installation between July 2008 and June 2009.

Read also: Fake 'Conflicker.B Infection Alert' spam campaign drops scareware

Further analysis on the top 50 most reported scareware was carried out between July and August this year, during which Symantec found that 38 of the programs had been detected prior to Jul. 1, 2008.

"The continued prevalence of these programs emphasizes the ongoing threat they pose to potential victims, despite efforts to shut them down and raise public awareness," the security vendor said in the report.

The five most commonly reported rogue security applications during the study were SpywareGuard 2008, AntiVirus 2008, AntiVirus 2009, Spyware Secure and XP AntiVirus.

For more info read ZDNet Asia Security Blog.........

Fake Conficker.B Infection Alerts Impersonate Microsoft

An ongoing spam campaign is once again attempting to impersonate Microsoft’s security team — the same campaign was first seen in April — by mass mailing Conficker.B Infection Alerts (install.zip), which upon execution drop a sample of the Antivirus Pro 2010 scareware.

Whereas the theme remains the same, the botnet masters have slightly modified the message:

“Dear Microsoft Customer,

Starting 18/10/2009 the ‘Conficker’ worm began infecting Microsoft customers unusually rapidly. Microsoft has been advised by your Internet provider that your network is infected. To counteract further spread we advise removing the infection using an antispyware program. We are supplying all effected Windows Users with a free system scan in order to clean any files infected by the virus.

Please install attached file to start the scan. The process takes under a minute and will prevent your files from being compromised. We appreciate your prompt cooperation.

Regards,
Microsoft Windows Agent #2 (Hollis)
Microsoft Windows Computer Safety Division”
The use of email as propagation vector for scareware campaigns (The ultimate guide to scareware protection), and in particular the use of email attachments is an uncommon practice, compared to the single most effective way of hijacking traffic through blackhat search engine optimization where the cybercriminals rely on real-time news events.

The campaign is an example of a — thankfully - badly executed one in the sense that with Microsoft’s Security Essentials recently gained momentum, even the average Internet user would notice the suspicious timing of the offered “antispyware program”.

Wednesday, October 21, 2009

China: 43 Uighur men have 'disappeared'

Months after security forces seized them in the wake of ethnic riots in July, at least 43 ethnic Uighur men from far western China have disappeared, an advocacy group said in a report released on Wednesday.

The report, by Human Rights Watch, asserted that the number of vanished Uighurs was likely higher, although the group could conclusively document only 43 cases during weeks of secret investigations in the Xinjiang region of China.

At least 197 people died and another 1,600 were injured during three days of protests and rioting by thousands of Uighurs in early July in Urumqi, the capital of Xinjiang. The riots, the worst ethnic violence in recent Chinese history, led police and security forces to round up hundreds of Uighurs, mostly men, in subsequent weeks.

State-run newspapers have reported that more than 200 persons were charged with crimes in connection with the protests, and 19 Uighur men were sentenced this month — 11 to death, 3 to life in prison — for their roles in the violence. In a separate trial, one man with an ethnic Han surname received a death sentence and another was given a prison term of 10 years.

The government has insisted that those accused of violence have been treated in accordance with Chinese law, which requires authorities to give detained suspects access to lawyers and to tell suspects’ families where they have been detained and why.

The Human Rights Watch report disputes that, stating that in most cases, “the men and boys detained in the course of these sweeps and raids have been missing since the security forces took them away.”

“Their families’ attempts to inquire about the relatives at local police stations or with other law-enforcement agencies proved futile,” the report stated. “The authorities either said they had no knowledge of the arrests, or claimed the inquiry was still ongoing without admitting the fact of detention, or simply chased the families away.”

The report called the 43 cases “enforced disappearances,” saying they “are serious violations of international human-rights law” as well as Chinese law.

A request for Chinese government comment on the report, sent by fax at the government’s request, was not immediately answered.

The 48-page report involved random interviews with “many dozens” of Uighur residents of Urumqi and at least two dozen Urumqi residents who were Han, the ethnic group that makes up 90 percent of China’s population. Most of the violence in the July riots was directed at the Han who have become the more prosperous majority in what was once a Uighur-dominated city.

The report states that while almost every Uighur interviewee claimed to know a friend, relative or acquaintance who had gone missing after being detained by security forces, only a few were willing to give detailed accounts of the disappearances for fear of punishment by authorities.

The unaccounted-for detainees, all males, were as young as 14, but most were in their twenties, the report stated. Many were said to have disappeared during large-scale roundups of Uighur men conducted by security forces in Urumqi neighborhoods in the days after the riots. But others were seized in what the report called “targeted raids” in ethnic Uighur parts of the capital.

Witnesses were sometimes uncertain who had detained the suspects, but other people interviewed for the report mentioned the Chinese military, the local police and the People’s Armed Police, a national paramilitary force that often responds to natural disasters and public disturbances.

The report cited witnesses’ accounts of the detentions of 11 Uighur men, none of whom has been seen since. In one case, witnesses were quoted as saying that some 150 police officers and soldiers sealed off a street in Saimachang, a predominantly Uighur neighborhood, on July 6, the day after the protests began.

“Women and elderly were told to stand aside, and all men, 12 to 45 years old, were all lined up against the wall,” one witness was quoted as saying. “Police and the military were examining the men to see if they had any bruises or wounds. They also asked where they had been on July 5 and 6. They beat the men randomly, even the older ones — our 70 year-old neighbor was punched and kicked several times.”

The witnesses said that 17 men were taken away, including the 25-year-old husband of one of the witnesses. “She has not heard anything about her husband’s fate since then,” the report stated.

A woman in a second Uighur neighborhood, Erdaoqiao, said that three men in civilian clothes came to her home July 28. Identifying themselves as police officers, they took away her 18-year-old son for questioning, saying he would be freed in a couple of days.

“It’s been more than three weeks and I have no idea where he is and whether he is still alive,” she said. “I went to the local police station twice — they did not say whether he was there or not, but said the inquiry was still ongoing.”

Another witness said the soldiers seized her 14-year-old brother, apparently injuring his leg, after he left his Erdaoqiao home to go to his father’s shop on the morning of August 7. Family members said they tracked the boy to a local hospital, where he was treated, but he was then placed in a truck and driven away.

The boy has not been seen since, the report said. Police officers in the neighborhood told the family that he is not on their list of detained people.

Human Rights Watch said the Chinese government has not responded to an August 24 request to give an account of the deaths, arrests and detentions stemming from the Urumqi riots. The group urged Navanethem Pillay, the United Nations high commissioner for human rights, to investigate the events in Xinjiang.

The group has posted its report on its Web site, which the Chinese government blocks its citizens from accessing.

Friday, October 16, 2009

Recession hit Cyber-crime just doesn't pay like it used to.

Recession hits Cybercrime! With botnets everywhere, DDoS attacks get cheaper $30 will buy a one-day DDoS attack now!

Security researchers say the cost of criminal services such as distributed denial of service, or DDoS, attacks has dropped in recent months. The reason? Market economics. "The barriers to entry in that marketplace are so low you have people basically flooding the market," said Jose Nazario, a security researcher with Arbor Networks. "The way you differentiate yourself is on price."

Criminals have gotten better at hacking into unsuspecting computers and linking them together into so-called botnet networks, which can then be centrally controlled. Botnets are used to send spam, steal passwords, and sometimes to launch DDoS attacks, which flood victims' servers with unwanted information. Often these networks are rented out as a kind of criminal software-as-a-service to third parties, who are typically recruited in online discussion boards.

DDoS attacks have been used to censor critics, take down rivals, wipe out online competitors and even extort money from legitimate businesses. Earlier this year a highly publicised DDoS attack targeted U.S. and South Korean servers, knocking a number of Web sites offline.

Are botnet operators having to cut costs like other businesses in these troubled economic times? Security researchers don't know if that's been a factor, but they do say that the supply of infected machines has been growing. In 2008, Symantec's Internet sensors counted an average of 75,158 active bot-infected computers per day, a 31 percent jump from the previous year.

DDoS attacks may have cost hundreds or even thousands of dollars per day a few years ago, but in recent months researchers have seen them going for bargain-basement prices.

Nazario has seen DDoS attacks offered in the US$100-per-day range, but according to SecureWorks Security Researcher Kevin Stevens, prices have dropped to $30 to $50 on some Russian forums.

And DDoS attacks aren't the only thing getting cheaper. Stevens says the cost of stolen credit card numbers and other kinds of identity information has dropped too. "Prices are dropping on almost everything," he said.

While $100 per day might cover a garden-variety 100MB/second to 400MB/second attack, it might also procure something much weaker, depending on the seller. "There's a lot of crap out there where you don't really know what you're getting," said Zulfikar Ramzan, a technical director with Symantec Security Response. "Even though we are seeing some lower prices, it doesn't mean that you're going to get the same quality of goods."

In general, prices for access to botnet computers have dropped dramatically since 2007, he said. But with the influx of generic and often untrustworthy services, players at the high end can now charge more, Ramzan said.

Thursday, September 24, 2009

It Takes the 'Right Stuff' to be a Good Leader. Do you have it?

You see here the Fantasy character Buzz Lightyear, recently returned from a tour of duty in the ISS. Carried there and back by one of the NASA astronauts, in the Shuttle Discovery. Science Fiction Fantasy meets Science Reality. The one a parody of the other.

We all know that there are many paths to follow that lead from Fantasy to Reality. The story of science fiction evolving into science fact can only happen when dedicated visionaries lead the way.

What do we look for in our leaders and how often do we find the 'right stuff'.


In depth knowledge, self confident and self-awareness has always been necessary to build good leaders but it was never enough. You also had to have the 'right stuff'. You need the ability and character to inspire, support and motivate before you can ultimately lead.

It may not be fashionable and it may not be 'the new, new thing' but the adage that the Leadership Model follows a hierarchy similar to that of Maslow's hierarchy of needs, is still relevant and very pertinent today.

Maslow's Hierarchy of Needs starts at the lowest level, with meeting basic neeeds before moving on to addressing issues with Safety and Security. Once that has been achieved, you can take into consideration the higher goal of finding and sharing Love, Affection and the sense of Belonging. The next step is to achieve Status and Esteem before finally climbing up to and sitting on the top of the world, brim full of Self Awareness, sometimes known as Actualisation.

Organisations still need Self-Aware leaders but there are no shortcuts. We need leaders who are able to progress through all the stages and completely fulfill the lower level needs. It's not acceptable to be a self confessed leader if you do not fully understand and accept the 3 dimensional nature of leadership and the voyage to the top that took you there.

Let's look back at the precipitous journey you are on or possibly, you have already completed.

1) Basic Wants/ Physiological Needs
At the base root of all organisation some core wants have to be addressed. They include the tools needed to survive and thrive. This is the core technical skills, in the leadership model. Clearly, if you want to be a Finance Manager, you need to know how to perform accounting tasks and understand the associated practices. Many skills are needed to sel but the main one will be the ability to be erudite.

All one needs to demonstrate, to future employers is that you have the core skills to do the job. Most leaders get promoted to successive levels of leadership through technical mastery but by being technically competent alone does not give them the skills or ability to be exceptional and charismatic leaders.

2) Safety & Security
Leaders need to provide their organisational units with structure and a competent framework to operate in. They need to develop the hierarchy, roles and responsibilities and, most importantly they need to provide the organisational employees with the criteria and opportunity to be successful.

To clamber up to the second level of leadership, a good leader must provide his team with the precise operational model that will make them not only feel secure but also instil a philosophy of positive attitude and how to approach success.

Poor leaders rely heavily on their ego to direct them. They believe that they can be the all powerful king in the midst of disarray and chaos. They think they are controlling and directing the masses but in reality they are burning valuable resources, whilst lurching from crisis to crisis.

A good leader creates the framework where every employee not only feels secure operating in and focusing on his job but also has a repeatable chance of being creative and successful. They have the chance to stretch themselves and not fear the consequences of loss or failure because their leader is there to guide and support them, throughout. They do their job well and the organisation benefits.

3) Love, Affection and Belonging
This builds on from the creation of a safe and secure environment and leads us into the need and ability to foster cohesive teamwork. The basic requirements here is that the leader needs to ensure that his team players are working well together but he also has to ensure that his team plays well within the whole organisation and can work well with 'others'.

You are not provided with the chance to model a team from a single piece of clay. you have to build this team from the wide assortment of characters and personalities that this world provides. Even after the skilled HR department has carefully filtered,selected and processed the candidates.

You have a team of disparate (or desperate) people from different backgrounds, brought together for a common purpose and it is your challenge to make them interact in a positive, productive and interactive way by building good, strong relationships.

Poor or weak leadership can easily create divisions, within and without your locality. It is so easy to create a self-protective silo mentality that spends too much energy and time defending itself from outside 'influences' and gets caught up in 'power' struggles. What you don't want is to be a stressed out head of a dysfunctional family unit that is feuding with it's neighbours. You need to actively create a common sense of purpose that transcends boundaries and divisions.

4) Esteem
As we mature in our organisational interactions with others, professional respect and appropriate response, may be all that really matters. For a leader to be considered a good leader, this respect has to be born of an independent outlook and a strong vision. Discard fear and intrepidation, actively and sincerely appreciate what every person is bringing to the table.

A good leader will not give respect lightly. You will need to prove your worth through your commitment and your actions. Talk alone does not do it. A good leader looks at the role you play in the organisation and will treat you with the respect the role commands, unless or until, you prove unworthy of it.

5) Self-Awareness
Do you consider yourself to be a 'good well balanced, human being'. Self Awareness is 'presence', 'authority', 'charisma', 'qudos', etc. The ability a leader possess, by the sheer power of his positive presence. One in which he is able to hold a clear vision, taking a higher road that puts the interests of his organisation to the fore.

The self-aware leader never takes credit for the actions of their team, there is no 'gray area of interpretation' on morals or ethics. A self-aware leader is in the spotlight 24x7, laid bare before the organisation, always on call for their people.

A good leader is inspiring and consistent in their judgement. They are fair, balanced and trustworthy. People are driven and motivated by a good leader. They respect them but are not diminished or intimidated by them.

If you know a good organisations that is looking for good leaders. Tell them to clearly and honestly, examine their true requirements and goals. The 3 dimensional levels of needs that they want to meet and satisfy.

Remember that truly successful organisations must be led by thoroughly 'good human beings', people of good character. These are the only people who will lead us from deception and fantasy into the harsh reality of the future, and they will deal with it appropriately, when we get there.

Saturday, August 29, 2009

Beware Trojan Horse Laptops bearing Gifts: Security Risk

The FBI has launched an investigation to find out who is sending unsolicited laptops to state governors across the country.

The Service is reporting that governors and state officials in at least 10 US states have received mysterious computers in the mail.

The mystery began in West Virginia earlier this month when Gov. Joe Manchin’s office received five Compaq computers on Aug. 5. A week later, Manchin’s office received a sixth notebook, a Hewlett-Packard model.

The Charleston Gazette, which first reported the story, said Manchin’s office didn’t turn on the machines for security reasons. Very wise! West Virginia state police said HP confirmed the notebooks were ordered online for delivery to the governor’s office, but didn’t reveal who made the purchase.

Wyoming and Vermont have also reported similar incidents, which has led to the FBI investigation.

The incidents are raising concerns that hackers are taking advantage of low-cost laptops to circumvent digital security and anti-virus controls to infiltrate high-value targets. It’s an intriguing and ingeniously simple idea, provided that they actually take possession of a machine in the supply chain.

The entire idea of having an inside, physical component to a hack is nothing new. Security history is replete with stories of hackers using social engineering techniques to enter buildings to gain access to unsecured workstations, plant bugs and monitoring devices and steal information necessary for remote access.

If you have seen the movies “Hackers,” “Sneakers,” “Mission: Impossible,” “Eraser” and others, with similar plot lines, then you know how this works. While it's possible for people to don janitor and Fedex uniforms to gain access to offices, the most common, cost-effective and likely way of making such an attack is 'Dumpster diving'. Simply, sifting through other people's trash to find discarded clues that may lead to establishing remote access.

Putting malware on a free machine that just shows up in the office, is different and arguably ingenious. Notebook, desktop and hardware costs have shrunk to the point where everyday hackers can afford the investment of buying a dozen for planting in high-value targets and the pay-off would be well worth th eeffort.

Saturday, August 22, 2009

Symantec and Norton Produce list of 100 Dirtiest Websites

Symantec and Norton have produced a definitive listing of 100 of the dirtiest websites i.e. the websites to avoid.

These websites are most likely to damage your PC or laptop system and /or to install viruses, Malware and Mal-bots, intended to cause major disruptions to all web users.

Click here to see the Report.....

Sunday, August 9, 2009

US Marines Ban Facebook and Twitter: Use of Social Network Sites

The U.S. Marine Corps made it official this week: Social networking sites such as Facebook and Twitter are banned from military networks.

This new administrative directive doesn't change very much but clarifies the use of social networks from a security perspective.

Marines have never been allowed to access non-official sites like Facebook, MySpace or Twitter from military networks because it is classed as improper use of government property.

In this new or revised directive, the Marines have simply put an official stamp on the ban. At the same time, they are also laying out the process to be followed by any Marine who wants to officially access such a site, as part of his or her job.


A Haven and Conduit for Adversaries
"These Internet sites in general are a proven haven for malicious actors and content and are particularly high risk due to information exposure, user generated content and targeting by adversaries," the directive noted.

Increased Threat
"The very nature of social networking sites, creates a larger threat, attack and exploitation window, exposes unnecessary information to adversaries and provides an easy conduit for information leakage."

Improper use of US equipment
The ban, however, is only for people using Marines' equipment and networks while they are working. Marines may still Twitter or post to Facebook on their own time and on their own computers but they should do so with a raised level of awareness.

The military isn't against using sites like Facebook and Twitter, said 1st Lt. Craig Thomas, a Pentagon-based spokesman for the Marine Corps.

Facebook, YouTube and Twitter
The U.S. Central Command has a Facebook page, a channel on YouTube and a Twitter account to get out information regarding operations news. The Army is using MySpace to recruit new soldiers and the U.S. Forces Afghanistan page on Facebook has more than 24,000 fans.
A Balanced Approach
"The Marine Corps has got to find a balance between security and letting Marines capitalise on the technology," Thomas said in a recent interview. "We don't want information leaks. We want to keep Marines focused on their mission at work and we also wanted to save critical bandwidth. We're trying to find the fine line."
Measured Progress
Thomas noted that 30 years ago, soldiers were warned about revealing too much information in letters home. Then 10 years ago, they were warned about how they used e-mail. Today, the focus is on social networks.

Tight Lips
"You can't have someone posting, 'Hey, we're leaving on this date and at this time,'" he added. "Believe me, the enemy is checking out what you guys are reporting and what service men and women are saying online.

The Marine Corps instills tight operational security. They need to be cognizant of what they're saying, whether verbally or what they're saying on social networking sites."

Wednesday, August 5, 2009

Rejoice! Latvian ISP linked to online criminal activity booted out of Internet

IDG News Service — A Latvian ISP linked to online criminal activity has been cut off from the Internet, following complaints from Internet security researchers.

Real Host, based in Riga, Latvia was thought to control command-and-control servers for infected botnet PCs, and had been linked to phishing sites, Web sites that launched attack code at visitors and were also home to malicious "rogue" antivirus products, according to a researcher using the pseudonym Jart Armin, who works on the Hostexploit.com Web site.

"This is maybe one of the top European centers of crap," he said in an e-mail interview.

"It was a cesspool of criminal activity," said Paul Ferguson a researcher with Trend Micro.

The ISP was disconnected from the Internet by its upstream provider, Junik, on Monday, after its provider, TeliaSonera told it to stop servicing Real Host or face sanctions Armin said.

Real Host was considered a "bullet proof" hosting provider, that would allow customers to remain online even after they had been linked to malicious activity. It had been linked to the Zeus botnet-making software.

This isn't the first time this type of hosting provider has been knocked offline. In the past year, at least three U.S. ISPs: Atrivo, McColo and 3FN have been unplugged after security researchers built cases against them. Atrivo and McColo were also taken offline by their upstream providers. 3FN was shut down by the U.S. Federal Trade Commission.

But according to Armin, this may be the "first time an international group has achieved this across borders and in Eastern Europe."

In the past, these takedowns have had a serious affect on spam. And while some observers reported a noticeable drop in spam over the weekend, security experts say that this was probably not attributable to the Real Host takedown.

Observers expect to see the criminal activity linked to Real Host resume soon, but they say that the takedown puts some pressure on the bad guys and the networks that provide service to them. "The precedent that's being set right now is that you need to take some responsibility for your network," said Lawrence Baldwin, owner of security research firm Mynetwatchman.

"There actually are some consequences now for allowing an obviously heavy concentration of criminal activity on your networks. It's just not going to be accepted anymore."

Thursday, July 30, 2009

Social Engineering - The biggest Threat to Security is still You and your People

Social Engineering - Are you Tempted?
Whether they are going through the eTrash, dumpster diving, pod slurping, or impersonating other people, our constant companions, the hackers know that social engineering is still the best way to by-pass security.

People Skills
Social engineering finds and hits directly at our weak spot, you're a nice gal /guy, a people person and people are still the weakest link in security. Yes, it is difficult to change this because it means changing people's attitude and behaviour. Plus you have just spent 10's of thousands of Dollars, Pounds and Euros, to give them better customer facing skills.

Why? It Works!
Why are hackers still using social engineering to gain access to organisations? Because it still works better than anything else and it provides quicker results. It's easier to infiltrate an organisation via the people because the security is focused elsewhere, on the building and on Technology. Plus your guard is down, your complacent because you 'think' you are secure.

Who? People!
Front-of-House contact people are the most succeptible to intrusions. Partly because they form the first barrier but also because they are often bored, busy, isolated. Almost certainly, the least aware, uninformed or not adequately trained, concerning social engineering techniques and their risk to security. After all, who doesn't like to help a nicely dressed, sexy gal /guy and be rewarded by a smile, a compliment or just some friendly attention? What 'bait' would work on you?

What are the most likely vulnerabilities versus bad behaviours:

1. People want to be, and are trained to be helpful and co-operative. Sometimes this help can go too far and they give away too much information. - Make it clear to them what they can and cannot reveal, in writing.

2. People want to avoid confrontation and are trained towards compromise. It's difficult for some people to ask others to prove who they are. They don't like or want confrontation, especially with a possible 'authority' figure. Support your staff's doubts and back them up, review and clarify their decisions.

3. People like convenience and easy options. No one wants to take the complex additional security check route because they are busy or distracted, even if it may protect or benefit the organisation. Make the secure route the easy option for your staff.

4. People are messy, unorganised and easily distracted. They leave paper around, leave screens open to view, copy multiple people on e-mails, gossip and leak data. Provide them with pleasant incentives to change their behaviour and give them other, more positive things to talk about.

5. People are curious, inquisitive creatures. A great example is an employee who finds a USB drive in the parking lot. The first thing they do when they get to their desk is plug it in to see what's on it. You have to tell them why this is a threat to security and also a violation of someone else's privacy.

Is there light?
Social engineering attacks are some of the most difficult to defend against, but not all is darkness. Your greatest weapon is training and education. Maintaining awareness of current threat profiles and passing those on as a simple and easy to implement 'cheat sheet' or guidelines. Address all of peoples' senses, sight, sound and listenning. Use the technology Podcasts, MP3s, YouTube Videos, Twit and Facebook them. Whatever it takes.

Technical Barriers
There are very few technical solutions to people problems but here are some technical controls that are sensible to put in place:

* Lock down or limit capability of all peripheral devices, especially USB ports. There are now many commercial products that allow security administrators to completely lock down USB ports. This might be difficult but not impossible, because many devices are connected via USB ports.
* Use Data Loss Prevention techniques and products. Know who has access to your data, when they access it, and what they are accessing. Not very effective if someone's profile has been duplicated, stolen or access has been incorrectly allowed.
* Use encryption on every device and wherever systems talk to systems.

Remember 'If your employees don't know what social engineering is and how it operates, why should they change their behaviour?" You are the Agent of Change! Make it so!

Friday, July 17, 2009

Surf the Internet Freely and Safely: Care of Symantec

Everything you wanted to know about safety and security on the Internet but were afraid to ask!
Symantec have created a really friendly easy to use web page that provides basic information and advice on Internet and Credit card security, etc.

Wednesday, April 22, 2009

Risk Management - 5 steps to success

What does it take to get Stakeholder attention and for IT initiatives to be acknowledged and accepted in today's lean mean enterprise?

In most cases it means making a compellingly attractive business case, getting the pertinent information to the right decision makers and being sure that its written in a language they can understand.

Executive suite
IT risk management initiatives are most definitely aimed at executive attention and for good reasons. The economy has become increasingly dependent on the Internet and IT systems (the Cloud). this makes the inherent risks in these systems far more visible and potentially more significant than ever.

Risk management is a discipline with a myriad mix of interests groups and stakeholders: CIOs, CFOs, enterprise risk management teams, compliance and regulation staff, and both internal and external auditors.

Choose your words wisely
You need to aim your plan at CIO level and there are generally two types of CIOs; the executive infrastructure managers and the strategic business thinkers. The latter will succeed with their IT risk management agenda because they speak in terms of business advantages, not technology outages (Business Impact Analysis). Par example;

  • Instead of talking about a "zero day threat," consider the impact of a potential incident, in terms of potential business losses. (Quantify in general terms)
  • Instead of talking about RTOs and RPOs, speak in terms of lost revenue and customers during an outage. (Sales, turnover, throughput, etc)
  • Instead of highlighting unimplemented ISO controls, speak about the lost communication and effectiveness of employees who need to collaborate and share information both inside and outside the firewall.
  • It also doesn't hurt to point out the impact on productivity when the critical path and workflow is disrupted.

Use a High-Medium-Low spectrum of potential business loss

Part of using the right language is to help you move away from absolutes. Inevitably, a single prediction of loss will start a battle of statistics and probability debate, with the risk that your request will get lost or bound up in the process. Instead, provide stakeholders with a variety of realistic scenarios and have some good data to back it up.

Start by considering whether you are a low risk company, moderately tolerant, or highly tolerant and then you can go to work with some calculations. Be prepared to back up your recommendations with numbers. Understand that you probably won't get exactly what you are asking for, but by presenting accurate potential scenarios, you might get your mid-range goal.

Use headlines to your benefit

All of today's business leaders have been shocked by the recent headlines regarding corporate scandals and the sudden loss of freedom or career prospects that this may bring. They dread the thought of the "orange jumpsuit retirement program." and there is still a steady stream of privacy and data leakage issues that will continue to feed into the headlines.

Those held responsible, willingly or otherwise, have ranged from; unsuspecting backup administrators and employees who unwittingly left laptops in car trunks; to mid-level managers involved in publishing quarterly financial reports and executives operating with full and certain knowledge of potential breaches.

You can make good use of these "publicly displayed sacrificial offerings" to illustrate and re-enforce the real risks at stake. This will help you move away from the discussion regarding the siza, shape and probability of an incident or event and break the statistical deadlock.

Move your message up and around the chain

Identify and consider the strong players and potential champions involved. Work hard to win them over to yor way of thinking. Rememeber, IT risk management isn't an exclusively IT-driven discipline. Work with the compliance team, the IT group, the legal group, the auditors, the enterprise risk management group, and the business leaders. Create cross-company initiatives to align each of these groups. This will require as much time communicating outside of IT as inside.

Identify your milestones

Before going into an executive meeting with your precious ember of a request, identify up to three milestones you expect to meet and explain in business terms how these milestones will provide real benefits and payback to both the business and IT.

If you can, start with a proof of concept e.g. for a content filtering project. This will have much more value if users from audit, legal and a line of business are involved in choosing terms to flag, track and quarantine events. A security 'incident reporting' process may get more enthusiastic response, if users understand that increasing their awareness will help to save the company money and protect the corporate image.

Conclusion:
IT risk management will become increasingly important as key organisational stakeholders begin to see the importance and effectiveness of an ongoing program. For now, IT risk professionals and their associated colleagues can continue to work to establish a baseline program by using the right language and the right information to ensure continued support internally.