Showing posts with label APT. Show all posts
Showing posts with label APT. Show all posts

Wednesday, November 23, 2011

Will hackers continue to dominate in 2012? Join the discussion by participating in live webinars

Hackers and Threats Summit l Free Online Event

Calling 2011 the year of hackers would not be an overstatement. With high-profile system intrusions constantly making headlines worldwide, hackers, good and bad, exposed security system vulnerabilities across every industry, proving the necessity to better protect and monitor networks and data.

Will hackers continue to dominate in 2012? Will organizations be better prepared by then? Join the discussion by participating in live webinars with industry experts to prepare for a smarter 2012.

Sign up to attend the live interactive webcasts on December 7, 2011, or view them afterward on demand here: http://www.brighttalk.com/r/FLP.

PRESENTATIONS INCLUDE:

‘Advanced Persistent Threats - The Hacker's Latest Weapon or Just Marketing Spin?’

Ron Condon, Editor, SearchSecurity.co.UK (Moderator); Warwick Ashford, Editor, ComputerWeekly.com; David Perry, Trend Micro

‘Exploring the Digital Underworld: Botnets, Zero Day Threats and Phishing’
Daniel Ayoub, SonicWALL

‘Global Info Sec Landscape: Recapping 2011 and Looking Ahead to 2012’
Jay Bavisi, President, EC-Council

‘Surviving the Mobile Device Invasion – When Mobile Tries to Connect to IT’
Cameron Camp, ESET

You can view the full lineup and sign up to attend any or all presentations at
http://www.brighttalk.com/r/FLP.

This summit is part of the ongoing series of thought leadership events presented on BrightTALK(TM). I hope you are able to attend.

Wednesday, June 8, 2011

Hacker breaches the security of Australian Tax Office, Defence and Banks


The security of hundreds of thousands of security tokens (SecurID) used by Australian banks and their customers, the Defence Force and organisations such as the Tax Office to access computer systems is in doubt after a cyber attack.

RSA said yesterday it would reissue an unknown number of the estimated 40 million RSA SecurID fobs used worldwide. SecurID fobs are small, portable devices that generate a digital security code that changes every 60 seconds. They are most commonly used with a static PIN or password to access a computer system.

In March RSA customers were told the company had been the victim of "an extremely sophisticated cyber attack". But it was not until recently that full details were known. RSA's admission follows an attack on the defence contractor Lockheed Martin. The contractor said an attacker had tried to access its network using information about the fobs stolen from RSA in the March attack. But it had stopped the attacker stealing information.

Certain characteristics of the attack on RSA indicated the perpetrator's most likely motive was to obtain an element of security information that could be used to target defence secrets and related intellectual property.

David Kenny, the deputy secretary of the Department of Parliamentary Services, said the department had 1800 of the SecurID tokens used by staff and MPs. The department was arranging replacement.

The Department of Veterans' Affairs was considering RSA's offer to replace SecurID tokens at no cost. Westpac bank confirmed that it did not see an immediate need to replace its customer fobs as it had not been compromised. The Tax Office was arranging replacements.

The attack meant many organisations would see a need to beef up their security. To be successful an attacker would need certain information from the SecurID token, such as the username and PIN or password.

This can often be swiped by a user handling over their details in an email to a hacker pretending to be from the organisation that issued the fob. Without some of these details it would be difficult for a hacker to gain entry to a network.

Refer here for further details.

Tuesday, May 3, 2011

'Tricked' RSA Worker Opened Backdoor to APT Attack

Threat Landscape is CHANGING!
A well-crafted e-mail with the subject line "2011 Recruitment Plan" tricked an RSA employee to retrieve from a junk-mail folder and open a message containing a virus that led to a sophisticated attack on the company's information systems.
An Excel spreadsheet attached to the e-mail contained a zero-day exploit that led to the installation of a backdoor virus, exploiting an Adobe Flash vulnerability, which Adobe has since patched, writes Uri Rivner, head of new technologies, identity protection and verification at RSA, in a blog posted Friday.
RSA unveiled on March 17 that an attacker targeted its SecurID two-factor authentication product in what it termed an advanced persistent threat breach. An APT refers to sophisticated and clandestine means to gain continual, persistent intelligence on a group such as a nation or corporation. Rivner's blog is the first substantial public comment on the breach since Coviello's statement.
The exploit injected malicious code into the employee's PC, allowing full access into the machine. The attacker installed a customized variant of a remote administration tool known as Poison Ivy, which has been used in APT attacks against other companies. Such tools set up a reverse-connect model, which pulls commands from the central command and control servers, then execute the commands, rather than getting commands remotely, making them harder to detect.
The attacker gained access to staging servers at key aggregation points to prepare for extraction. Next, the attacker accessed servers of interest, moving data to internal staging servers to be aggregated, compressed and encrypted for extraction. Then, the attacker used file transfer protocol to transfer many password protected RAR files from the RSA file server to an outside staging server at an external, compromised machine at a hosting provider. The files were subsequently pulled by the attacker and removed from the external compromised host to remove any traces of the attack.
APT is characterized as a new attack doctrine built to evade existing perimeter and endpoint defenses, and analogized an APT attack to stealth jet fighters that circumvent radar.