Showing posts with label Security Threats. Show all posts
Showing posts with label Security Threats. Show all posts

Friday, August 8, 2014

Basic Security for Personal Cloud Storage

Avoid using Personal Cloud Storage for confidential/sensitive data

Dropbox and other file-storage and sharing applications like it are incredibly helpful to business travelers. Not having to lug along a laptop or risk misplacing a thumb drive certainly add to the enjoyment of time away from the office.

However, these applications do come with some risks. This is especially true when users generate links to share information with others. Several basic flaws within Box and Dropbox specifically allow the shared documents to be viewed by third parties.

It comes down to this: Many people do not take basic security steps, even when communicating highly sensitive information. Worse, they may even mix their personal communications and information with confidential workplace data.

For its part, Dropbox disabled all access to public links and created a patch to keep shared links from becoming public. However, this is the third security breach for Dropbox in as many years, so diligence on the site and others like it has to be considered among users.

When considering a file-sharing service site, follow these rules of thumb:

  1. Use a strong password.
  2. Encrypt files in storage ("files at rest").
  3. Encrypt files sent to and obtained from the site ("files in motion").
  4. Look for a third-party security and privacy audit or some other validation that the site truly is secure.
  5. Do an online search to see if the service has been breached in the past year or two.
  6. Make sure that you can completely remove all files from the site when you stop using it.

Monday, April 21, 2014

WARNING! Your Flash Player may be out of date.

Adobe Flash Malware driven by infected "Router" The Moon Malware

Few days ago, I started to receive a pop-message "WARNING! Your Flash Player may be out of date". Please update to Continue., when I was trying to access websites like Facebook, YouTube, Google, etc.

If you're receiving a similar message then continue to read but make sure you don't click on anything nor try to update the flash player from the pop-window. You may check your current version of the "Adobe Flash Player" by visiting "Adobe" official website. If you're using Google Chrome browser, it already includes Adobe Flash Player built-in. Google Chrome will automatically update when new versions of Flash Player are available.

You will also notice that the same message is poping-up on all the devices which are connected to the same router (mobile phones, laptops etc.).



Now even the dumbest person should know it is not coming from computer but from the network which means your router is infected. It's commonly happening with Linksys, Asus and few other manufacturers.

How to fix this?

  • Reset your router (by holding down the reset button under the router for 6 seconds). Note after restart all your ISP settings will be lost.
  • Configure your router again with the ISP settings (username and password also required).
  • Clear your browsers cache and pop-up message will not appear again.
Refer here for some basic tips on hardening your router to avoid such things happening again.

Monday, March 24, 2014

Three of the Biggest Threats to Company’s Cyber Security

Phishing, Malicious Political Attacks & Monetary Fraud

Every business needs to address the ever-changing cyber threats that now make their way the Internet. It is not enough to merely install anti-virus software and believe that this will solve all of a business’ problems. Here are three of the biggest threats to company’s cyber security that you should know.

Phishing

Phishing is a practice in which hackers gain access to private consumer data. Frequently, a hacker creates an email to look like it was issued by your company. A customer may then respond to the email and provide his or her personal information. The hacker then preys upon this disclosure and uses it to open credit cards, make unauthorized charges and take advantage of the consumer’s identity. The essence of a phishing crime is that the hacker gains the trust of the customer. They may use sophisticated tactics to learn information about your customers, such as the names of relatives. The hacker then may pretend to be one’s distant relative to ask for financial assistance from the consumer.

Businesses have a duty to protect their customers from phishing attacks. Businesses should realize that information even like consumer names can be private information. If a hacker gains access to consumer names, then he or she may use social networks like Facebook to learn more information about the customer. Businesses need to be aware of these practices and work with cyber security firms to prevent information disclosures.

Malicious Political Attacks

Businesses should also be aware that not every hacker is motivated by profits. Some hackers are residents of foreign nations and discontented with the notion of capitalism in general. These hackers are very sophisticated and using numerous methods to target specific businesses. One example of a recent attack included an attack on a satirical news company by the Syrian Electronic Army. The Syrian Electronic Army was able to hack into the servers for the news company and then make its own postings on the site. One mistake that businesses make is underestimating the abilities and sophistication of enemy nations or politically-motivated hackers.

The best way for businesses to handle attacks from politically-motivated data hackers is to be proactive in preventing attacks. Businesses should not use a reactive method of dealing with politically-motivated data hackers. A reactive method does not solve the actual issues that lead to the hacking of business accounts. A reactive method also does not provide security to a business, because a business may still be attacked by army hackers in the future.

Monetary Fraud Hackers

Unlike the Syrian Electronic Army, some hackers are only motivated by financial gain. These hackers only seek to gain access to checking accounts, savings accounts, trust funds, Social Security information and credit card information. These hackers attempt to gain access to the internal data systems of highly-profitable companies. They are very sophisticated in the tactics that they use to hack corporate accounts.

Businesses need to take preventative measures in protecting internal corporate data systems. Many businesses are realizing this and are now working with sophisticated firms to protect their internal data systems. A company can also be very selective in the access that it provides to internal information systems. If many employees have access to internal data systems, then a company may be jeopardizing the information of its customers.

More than ever, companies need to be proactive in addressing cyber security threats. Cyber threats can cause serious legal issues for companies in the event of a hack or leak. Taking time to improve a company’s data system security is an investment in the future of the company. Cyber threats are only likely to increase in the future years, and businesses must be ready to prevent these attacks.

Wednesday, January 22, 2014

Did you get an email from Target?

Are you one of the roughly 70 million people who got an email from Target last week about the store's mega security breach? If so, be careful.

Target did indeed do a blast to customers to offer one year of free credit monitoring. The problem is scammers are also on the prowl and are sending out similar emails.

Target even says it has identified and stopped at least 12 scams preying on consumers via email, Facebook and other outlets.

The Target emails went to customers whose personal information was in the Target database. Cyber thieves penetrated the records during the holiday shopping season breach discovered last month and stole info like names, phone numbers and email addresses. The full extent of the hacking is still under investigation.

In the meantime, here's what to do if you see an email from Target pop up in your inbox.

If you've already opened the email: Target has posted a copy of the email it sent out online. So go here to make sure the email you opened, the address it came from, and the link you clicked all matches up.

If it doesn't match, and especially if you clicked a link to an external website and entered personal information, you need to take action quickly.

First, get a copy of your credit report, check your bank and credit card activity on a daily basis and call the credit reporting agencies to tell them what happened. You can ask to have a fraud alert placed on your account, meaning it will be flagged to lenders if someone attempts to open credit in your name.

If you're really worried, you can request a credit freeze, which prohibits any credit from being extended under your name. But that's a big step because you will have to go through the process of undoing this whenever you need credit again.

If you entered a credit card or debit card number, reach out to those institutions to warn them of potential fraud as well.

If you haven't opened the email: To avoid any chance of a virus or of falling prey to a potential scam, it is  recommended to go directly to Target's website to view the letter you believe has landed in your inbox -- since even opening a fraudulent email could lead malware to be installed on your computer. And if you do open the email, don't click on any links.

All other correspondence from Target can be found here. The retailer emphasizes that it will never email a consumer and ask for personal information like a Social Security number or credit card information.

But it's not just emails claiming to be from Target that customers need to worry about.

If your personal information was compromised in the breach, that means scammers could contact you pretending to be anyone -- like another retailer.

Monday, July 29, 2013

The Risk of Data on Mobile Devices & in the Cloud

Ponemon Institute research finds that 69% of respondents listed mobile devices as posing the greatest risk

A recent study by the Ponemon Institute, The Risk of Regulated Data on Mobile Devices and in the Cloudsponsored by WatchDox, reveals a stunning need for improvement on managing the risks of mobile devices and cloud computing services.

The survey involved 798 IT and IT security practitioners in a variety of organizations including finance, retail, technology, communications, education, healthcare, and public sector, among others.

The study concluded that “[t]he greatest data protection risks to regulated data exist on mobile devices and the cloud.” 69% of respondents listed mobile devices as posing the greatest risk followed by 45% who listed cloud computing.

Some other key findings include:

  • Only 16% of respondents said their organization knew how much regulated data “resides in cloud-based file sharing applications such as Dropbox, Box, and others.”
  • Only 19% said their organization knew how much regulated data was on mobile devices.
  • Only 32% believed their organizations to be “vigilant in protecting regulated data on mobile devices.” Nearly three quarters said that employees didn’t “understand the importance of protecting regulated data on mobile devices.”
  • 43% of organizations allow “employees to move regulated data to cloud-based file sharing applications.”
  • Although 59% of organizations permit employees to use their own mobile devices “to access and use regulated data,” only about a third have a bring your own device (BYOD) policy.
  • In the past two years, the average organization had almost 5 data breaches involving the loss of theft of a mobile device with regulated data on it.

What are the risks?

  1. Unsafe Security Practices: With their own mobile devices and with their own cloud service provider accounts, employees might engage in unsafe security practices. Mobile devices might not be encrypted or even password-protected. When using cloud services, employees might not have the appropriate settings or an adequately strong password. They might not understand the risks or how to mitigate them.
  2. Choice of Cloud Service Provider: There are many cloud service providers, and they vary considerably in terms of their privacy and security practices. Cloud service providers may not have adequate terms of service and may not provide adequate privacy protections or security safeguards.
  3. Regulatory Troubles: If an employee of a HIPAA covered entity or business associate shares protected health information (PHI) with a cloud service provider, a business associate agreement is likely needed. Employees who just put PHI in the cloud might result in their organization being found in violation of HIPAA in the event of an audit or data breach.
  4. The Ease of Sharing: Sharing files is quite easy with many cloud providers – sometimes too easy. All it takes is a person to accidentally put regulated data into a shared file folder, and . . . presto, it will be instantly shared with everyone with permission to view that folder. One errant drag and drop can create a breach.
  5. The Ease of Losing: If you don’t carry an umbrella on an overcast day, it surely will rain. And if you put regulated data on a mobile device without adequate protection, that device will surely be lost or stolen. Call it “Murphy’s Mobile Device Law.”

What should be done?

  1. Educate the Cs: The C-Suite must be educated about these risks. These are readily-preventable risks that can be mitigated without tremendous expense.
  2. Develop Policies: The study indicates that there is often a lack of policies about the use of mobile devices and cloud. There should be clear written policies about these things, and employees must be trained about these policies.
  3. Educate the Workforce: Everyone must be educated about the risks of mobile devices and cloud and about good data security practices. According to the Ponemon Study, “Respondents believe that most employees at one time or another circumvent or disable required security settings on their mobile devices.” Employees must know more about the risks of using unapproved cloud service providers, as well as the special risks that cloud service applications can pose.
  4. Instill Some Fear: The study reveals that almost systemically at most organizations, the risks of mobile and cloud are underappreciated and often ignored. There needs to be a healthy sense of fear. Otherwise, convenience will win.

The Ponemon Study reveals that there is a long way to go before most organizations adequately address the risks of mobile and cloud. The problem runs deeper than the fact that these risks are hard to redress.

The problem seems to stem from the fact that the risks are woefully underappreciated by many in organizations, from the top to the bottom. That has to change, and soon.

Saturday, July 20, 2013

Cyber Threats: Trends in Phishing and Spear Phishing

Phishing is a global problem for businesses as well as individuals, targeting 37.3 billion people globally in the past year

Most of us have wisened up to basic scams and know better than to accept a Nigerian prince's offer of money, or a miraculous win on a Spanish lottery that you can't quite remember entering. But cyber criminals are raising their game and have evolved their tactics to target the more cyber-aware for greater returns.

Sophisticated 'spear phishing' attacks can be hard to spot by the experts; even the largest of organisations is not immune. What chance does this provide the average company or employee, let alone those who use computers infrequently?

Spear phishing is not random – cyber criminals identify employees within a target organisation and use social engineering tactics to construct a legitimate looking email. The FBI have warned business to be more aware of spear phishing tactics, as hackers target employees with administrative rights or access to critical systems.

91% of APTs (advanced persistent threats) start with phishing attacks and success could give cyber criminals the 'keys' to bypass security and initiate further attacks. Clicking a link doesn't mean that you are immediately compromised; phishing is part of a larger attack.

Hackers need to expose a system vulnerability and be able to install software quickly and quietly. However, cyber criminals use advanced tactics to disguise malicious attachments and sites to trick users into further action.

This infographic by Via Resource highlights trends and targets in phishing attacks.



Thursday, July 4, 2013

New Targets for Hackers - Plane Cockpit/Voice Hijacking?

Criminal hackers can generally be divided into two groups - thieves and showboats

They breach secure systems either to steal or simply to demonstrate that it can be done. A few recent hacking incidents indicate the showboat sector may be picking up steam.

Smartphone used to hack into a plane cockpit

The power and rapid evolution of technology is exposed by a security researcher armed with an Android.

"By using a Samsung Galaxy handset, Teso demonstrated how to use ACARS to redirect an aircraft's navigation systems to different map coordinates. He was able to insert code into a virtual aircraft's Flight Management System, and by passing the code between the aircraft's computer unit and the pilot's display, Teso was able to take total control of what the aircrew would see in the cockpit.

Scientist's voice hijacked during high-profile presentation

Hackers accessed the computer synthesizer controlling Stephen Hawking's voice during a public speak he was making to a large audience, overriding his control and forcing him to make statements against his will.

"It wasn't until hours later when the Syrian Electronic Army - a group of hackers working in support of Bashar al-Assad - claimed responsibility for the attack, breaking into Stephen Hawking's voicebox one last time to announce "the Syrian Electronic Army was here" just as the scientist was leaving the stage."

Wednesday, January 30, 2013

ENISA Identifies Top Cyberthreats

What are the emerging threats and vulnerabilities, and how should organizations globally respond to them?

ENISA, the European Union cyber-agency, is out with its first-ever Threat Landscape report.

Drive-by exploits, worms/Trojans and code-injection attacks are the three top cyberthreats to organizations, according to the new Threat Landscape report published by the European Network and Information Security Agency.

The ENISA Threat Landscape provides an overview of threats, together with current and emerging trends. One of the key objectives of this report is to give the information security community a comprehensive look at risks.

It is based on publicly available data and provides an independent view on observed threats, threat agents and threat trends. Over 140 recent reports from security industry, networks of excellence, standardisation bodies and other independent institutes have been analysed. 

Among the top 10 threats ID'd by the report:

  • Drive-by exploits (malicious code injected to exploit web browser vulnerabilities) Worms/Trojans;
  • Code injection attacks;
  • Exploit kits (pre-packaged software to automate cybercrime);
  • Botnets (hijacked computers used in attacks such as DDoS).

Among technology trends, mobile gets the most attention because that's the platform where users, data and adversaries increasingly converge.

Please refer here to download the report.

Tuesday, October 23, 2012

FBI Warns of Mobile Malware Risks

Android Devices Hit by Two New Trojans

The Federal Bureau of Investigation has issued a consumer alert warning of malware attacks against mobile devices that run the Android operating system. Trojans pose serious risks for any personal and sensitive information stored on compromised Android devices, the FBI warns.

But experts say any mobile device is potentially at risk because the real problem is malicious applications - which in an open environment are impossible to control. And anywhere malicious apps are around, so is the potential for financial fraud.

Two Trojans

The alert from the Internet Crime Complaint Center, a unit of the FBI, addresses two new Android Trojans known as Loozfon and FinFisher.

Recent attacks showed Loozfon has the ability to steal a mobile user's phone number as well as contact details. In one type of Loozfon attack, unsuspecting consumers were lured in by advertisements promoting fraudulent work-at-home opportunities.

The alert does not specify how those ads were promoted - through e-mail, SMS/text or both. But the FBI warns that links within the ads lead to websites designed to push Loozfon to users' device.

FinFisher, on the other hand, is spyware that targets Android smart phones, hijacking specific components that enable hackers to remotely control and monitor a compromised device, regardless of its location. The spyware is transmitted to a smart phone by clicking infected web links or by opening SMS messages sent directly to the mobile user, usually falsely appearing to provide links to system updates, the FBI states.

Bad Rap for Android?

The Android operating system is not the cause of the problem. It's the openness of the app marketplace that allows malware to run rampant, not the Android OS itself. This is one of the first consumer-focused, security-oriented lists for mobile I've seen. That's a good thing, but it also is a pretty definite signal that security is becoming a problem.

Until the mobile industry can figure out a way to better control or vet readily available apps, mobile malware concerns will mount. I'm not saying there should only be one store, but there does need to be some sort of reputational measure, akin to what SSL [secure socket layer] site certificates can help provide.

Monday, September 3, 2012

How Critical Is To Keep Your System Upto Date?

Only 9 of 22 virus scanners block Java exploit

According to an analysis conducted by the AV-Comparatives, less than half of the 22 anti-virus programs tested protect users against the currently circulating Java exploit that targets a highly critical vulnerability in Java version 7 Update 6.

Two versions of the exploit were tested: the basic version that was largely based on the published proof of concept and started the notepad instead of the calculator, and, for the second variant, heise Security added a download routine that writes an EXE file to disk from the internet.

The test system was Windows XP that, except in the case of Avast, Microsoft and Panda, had the full versions of the security suites installed. For Avast, Microsoft and Panda, the researchers used the free versions of the products. Only 9 of the 22 tested products managed to block both variants of the exploit (Avast Free, AVG, Avira, ESET, G Data, Kaspersky, PC Tools, Sophos and Symantec).

Twelve virus scanners were found to be unsuccessful (AhnLab, Bitdefender, BullGuard, eScan, F-Secure, Fortinet, GFI-Vipre, Ikarus, McAfee, Panda Cloud Antivirus, Trend Micro and Webroot). Microsoft's free Security Essentials component at least managed to block the basic version of the exploit. It should be pointed out that these results are based on a snapshot taken on 30 August at 1pm and don't represent the overall quality of these anti-virus programs. 

The tested version of Java was current at the time, and the exploit code had been in circulation for several days. These findings demonstrate that it is unwise to base the protection of a system on a virus scanner alone. To prevent installed applications and plugins from becoming malware hideouts, these must also be kept up to date. Oracle appears to have now closed the critical Java hole with the release of Java version 7 Update 7 on Thursday evening. Those who have Java installed on their systems should update to the new version as soon as possible.

The exploit is bound to be a highly popular item in the armouries of cyber crooks for years to come because it is platform-independent and highly reliable. Just how reliable it is becomes clear when examining the statistics of an installation of the BlackHole exploit toolkit: after the integration of the exploit, the Java exploits achieved a success rate of between 75 and 99 per cent. Overall, BlackHole managed to infect every fourth computer – the usual success rate is one in ten.

Monday, May 7, 2012

New Study Shows Internet Vulnerabilities Drop, Yet Risks Rise

Symantec 2011 Security Trends: Beware Insider Threats


There's some good news on the cybersecurity front, for a change: The number of Internet vulnerabilities identified by Symantec dropped 20 percent last year, according to the security technology company's just-released annual Internet Security Threat Report.


The tone of the rest of the report, however, isn't so optimistic. In fact, it's downright gloomy, as the company cautioned the IT security community about an 81 percent uptick in malicious attacks and the expectation of more to come in 2012.


IT managers jittery about defending their organizations' information systems should look over their shoulders from time to time. The insider, as we've been told time and time again, remains - and is likely to continue to be - one of the biggest threats.
"While external threats will continue to multiply, the insider threat will also create headlines, as employees act intentionally - and unintentionally - to leak or steal valuable data," Symantec notes.
Why? Because we're not doing enough to educate employees and customers about security and risk. Symantec's Global Intelligence Network monitors hacking and Internet attacks in more than 200 countries and territories. It also maintains a database that holds almost 48,000 recorded vulnerabilities from nearly 16,000 global vendors.


So, Symantec's analysis is one of the best available, at least where Internet security threats and trends are concerned. The actual number of Internet vulnerabilities identified by Symantec dropped 20 percent from 2010, and Symantec, for its part, blocked more than 5.5 billion malicious attacks in 2011 -- 81 percent more than it blocked the previous year.


Hacking exposed more than 187.2 million identities last year, Symantec found. But the root of most data breaches is not linked to hacks; it's linked to old-fashioned theft and/or sloppy security, such as through the loss of a laptop.


Symantec does offer advice, such as keeping antivirus software up-to-date and enforcing effective password policies. All important, but without the education piece, we won't have a fighting chance.


Refer here to download the report.

Thursday, April 26, 2012

The Risks Of Cloud Computing in Plain English

Know the Risks Before You Head to the Cloud


A "cloud" solution is generally typified by remote access to computing resources and software functionality and frequently involves the storage and maintenance of related data. Today, cloud computing facilitates applications, e-mail, peer-to-peer communication, content sharing, and electronic transactions or storage for nonprofits. 


In many respects, the “cloud” has become a synonym for the “Internet” as cloud computing now encompasses nearly all available computing services and resources. Cloud offerings utlilized by nonprofits tend to come in three flavors. Infrastructure as a Service (IaaS) offerings deliver information technology infrastructure assets, such as additional computing power or storage. 


Platform as a Service (PaaS) offerings provide a computing platform with capabilities, such as database management, security, and workflow management, to enable end users to develop and execute their own applications. And, Software as a Service (SaaS) offerings provide software applications on a remotely accessible basis. SaaS offerings are probably the most commonly understood type of "cloud" solution.


These benefits create flexibility and potentially lower costs for the cloud customer. It is therefore not surprising that this type of computing solution has rapidly become a key component to the operation of many nonprofit organizations. Despite these potential benefits, cloud computing doesn't come without risk.


Below is a list of legal risks and issues for a nonprofit to consider when procuring or using a cloud solution. These risks and issues can appear as either a contractual or an implementation issue. 


Take It or Leave It: Many cloud solution agreements are non-negotiable or more favorable to the provider than the end user, which places a greater emphasis on pre-negotiation analysis in order to work around inflexible contracts.


All Services, All the Time: All computing and software providers are morphing into service providers, and this change may impact the fee structure, term length, and available warranties.


Law Is Behind the Times; Contracts Even More Important: Existing laws and governance models have not kept pace with technological development, and this may leave the contract as the only means for dispute resolution.


It's All Online: Privacy and information security concerns will only increase with cloud usage.


Less Control of Subcontractors: Cloud providers tend to use subcontractors for hosting, storage, and other related services, and these subcontractors may not be readily known or otherwise liable or responsible for performance under the agreement.


Some Things May Not Be Worth the Risk: The inherent risks associated with cloud computing may make its utilization inappropriate for mission-critical I.T. services or resources.


Not Everybody is on the Same Page: Different cloud solutions on different hardware may increase the possibility of incompatibility with outside software or network systems, i.e., compatibility will be dictated by the provider and not by the customer.


Know Your SLAs: Service level agreements (SLAs) vary and may be inadequate and unchangeable.


General Outages May Be Likelier: Shared resources may increase susceptibility to a single-point of failure. 


Only What You Need: The terms of a license agreement may not fit the service being offered, e.g., cloud providers may grant themselves a greater right to use a customer’s data or materials than necessary to provide the cloud solution.


Own Your Data: It will be more imperative than ever to hold on to the ownership and secrecy of data and materials used with the cloud solution in order to retain rights and ensure confidential treatment.


Don't Allow a Vendor to Have Zero Responsibility: Be wary of excessive disclaimers and limits and seek the implementation of a credit or refund structure to address outages and downtime.


Am I Covered? Check available insurance policies and consider the insurance policy of the cloud provider to determine if it covers business interruption caused by vendor failure. Know the Exits. Know how to terminate a relationship with a cloud provider and plan for how such termination will unfold in order to minimize disruption caused by transitioning to a new service provider.


Where's Your Data? Understand where a copy of all stored data is physically located.


Seek Jurisdictional Clarity: Data transfer is easy and can create jurisdictional issues because the sites where data is located or transferred and where the related services are performed or received can and will typically be different.


You Need Access to Your Data: Know how to access, audit, hold, and retrieve all data or understand the limits on such data access because regulations and e-discovery rules may mandate particular data storage, protection, and transfer protocols.


Don't Forget Compliance with Law: Regulatory compliance may extend to the cloud provider, particularly, for health, financial, educational, or children’s data, and laws and regulations governing privacy and information security.


Rules Are Different Overseas: The United States has more permissive data and database rules than many other countries, particularly by comparison to Europe, where greater restrictions and rights exist.


Will It Still Be There When Disaster Strikes? Understand the cloud providers' business continuity and disaster recovery practices.


Incorporate Overall Risk Management Strategies: Cloud computing risks may expand the notion of risk from I.T. management to operational management or regulatory compliance.


Everybody Is a Renter: Limited-term software licenses will become the norm with customers not having any ownership rights in the software copy being licensed.

Summary


Courts, governmental authorities, and industry standard-setting bodies may address some of the foregoing concerns. But, until then, organisations considering cloud computing solutions will need to look to their written contracts as the primary vehicle to protect their rights and ensure performance.


Moreover, careful due diligence of cloud providers becomes key. Organisations therefore should consider multiple providers and should not make decisions based purely on cost. Instead, organisations should seek references and involve their key decision-makers and outside advisors to assist with the procurement process in order to ensure a thorough evaluation of the potential risks and issues with cloud computing.   

Tuesday, April 24, 2012

Managing The Threat Landscape for SAP Systems

A Ten Step Guide to Implementing SAP’s New Security Recommendations


SAP issued a revamped version of the whitepaper Secure Configuration of SAP Netweaver Application Server using ABAP, which is rapidly becoming the de-facto standard for securing the technical components of SAP.


According to SAP, the guidance provided in the whitepaper is intended to help customers protect “ABAP systems against unauthorized access within the corporate network”. In fact, many of the recommendations can also be used to protect SAP systems against remote attacks originating outside such a network. These attacks are targeted at the technical components of SAP Netweaver that are responsible for managing user authentication, authorization, encryption, passwords and system interfaces, as well as underlying databases and operating systems.


Breaches in these components can enable attackers to take complete control of an SAP environment. The following is a quick guide to help you comply with SAP’s recommendations.


1. Disable unnecessary network ports and services. In most cases, this means blocking all connections between end user networks and ABAP systems other than those required by the Dispatcher (port 32NN), Gateway (33NN), Message Server (36NN) and HTTPS (443NN). NN is a placeholder for your SAP instance number. Administrative access should only be allowed through secure protocols such as SSH and restricted to dedicated subnets or workstations through properly configured firewall rules.


2. Install the latest version of SAP GUI. This should be 7.10 or 7.20 with activated security rules configured with the ‘Customized’ setting and the ‘Ask’ default action.


3. Implement strong password policies, restrict access to password hashes in tables and activate the latest hashing algorithms. SAP does not specify the exact settings for password policy parameters but you should use frameworks such as the PCI DSS as a proxy. Refer to section 8.5 of the standard. Default passwords should be changed for standard users and the password hashing mechanism should be upgraded to the latest version available for your system. Wherever possible, downward-compatible hashes should be removed from the database.


4. Enable SNC and SSL. SAP client and server communication traffic is not cryptographically authenticated or encrypted. Therefore, data transmitted within SAP networks can be intercepted and modified through Man-In-The-Middle attacks. Secure Network Communication (SNC) should be used for mutual authentication and strong encryption. This can be performed natively if both servers and clients run on Windows. You will need to use a third party product to secure connections between heterogeneous environments such as AIX to Windows. SNC will secure network communication using the SAP DIAG and RFC protocols. For Web-based communication, you should switch to HTTPS/ SSL and restrict access to the relevant cryptographic keys.


5. Restrict ICF services. Many of the services enabled by default in the Internet Communication Framework (ICF) are open to abuse and could enable unauthorized and malicious access to SAP systems and resources. At a very minimum, you should deactivate the dozen or so services mentioned by SAP in the white paper. This can be performed through transaction SICF.


6. Secure Remote Function Calls (RFC). Wherever possible, remove trust relationships between systems with differing security classifications and hardcoded user credentials in RFC destinations. The belief that RFC connections using SAP_ALL privileges is fine as long as the user type is set to dialog is a myth. This represents a serious risk to the integrity of information in SAP systems.


7. Secure the SAP Gateway. The Gateway is used to manage RFC communications which support SAP interfaces such as BAPI, ALE and IDoc. Access Control Lists (ACL) should be created to prevent the registration of rogue or malicious RFC servers which can lead to the interruption of SAP services and compromise data during transit. You should also enable Gateway logging and disable remote access.


8. Secure the SAP Message Server. The Message Server is primarily a load balancer for SAP network communications. Similar to the Gateway, it has no default ACL which means it is open to the same type of attacks. You should filter access to the Message Server port using a firewall and create an ACL for all required interfaces.


9. Regularly patch SAP systems. Implement missing SAP Security Notes and patch systems at least once a month. Security Notes can be downloaded from the SAP Service Market Place.


10. Regularly monitor the SAP security configuration. Standard SAP services such as EarlyWatch (EWA) and the Computing Center Management System (CCMS) can be used to monitor some security-relevant configurations. However, they do provide the same coverage as professional-grade security tools such as those used to perform SAPSCAN, a vulnerability assessment specifically engineered for SAP systems. SAPSCAN automatically reviews the configuration of your SAP environment against SAP security recommendations and hundreds of other vulnerabilities not included in the SAP white paper.


Reference: Layer Seven Security 

Friday, April 6, 2012

10 Threats to IT over the Next Two Years

Threats Seen Intensifying as They Combine with Other Ones


Providing IT security will only get tougher over the next couple of years as digital threats become more numerous and complex. That's the gist of a new report from the Information Security Forum entitled Threat Horizon 2014: Managing Risks When Threats Collide.
"While individual threats will continue to pose a risk, there is even more danger when they combine, such as when organized criminals adopt techniques developed by online activists," Steve Durbin, global vice president of the Information Security Forum, said in announcing the report. 
"Traditional risk management is insufficiently agile to deal with the potential impacts from activity in cyberspace." 
The report categorizes 10 threats in three basic areas: external, regulatory and internal, including: 


External Threats 


1. Cyber criminality increases as the malware space matures: The sophistication and scale of the global industry that has evolved to commit cybercrime, espionage and other malevolent activity will grow and develop. 


2. The cyber arms race leads to a cyber cold war: Nations developing more sophisticated ways to attack via cyberspace will get better at it, those who haven't will start, and organizations will suffer collateral damage. Targets for espionage will include anyone whose intellectual property can turn a profit or confer an advantage. 


3. More causes come online; activists get more active: Anyone not using the Internet to advance their cause will start: customer affinity groups, community associations, terrorists, dictators, political parties, urban gangs - the list is endless. Online organizing will become easier and protest channels will be available to greater numbers. 


4. Cyberspace gets physical: The increasing convergence of cyber and physical worlds will bring more attacks on physical systems, from attempts to turn out lights or climate control systems to disrupting manufacturing systems. Whether attacks are successful or not, credible publicised threats will cause disruption and panic.


Regulatory Threats 


5. New requirements shine a light in dark corners exposing weaknesses: Further movement toward increasingly transparent security disclosures will publicize weaknesses, making organizations more vulnerable to attack. Organizations forced to report security risks may have as much to fear from customers and business partners as they do from hackers and regulators. 


6. A focus on privacy distracts from other security efforts: New privacy requirements from consumers, business customers and regulators impose a heavy compliance burden. Organizations will need to decide whether to invest in the necessary security and legal controls, outsource to someone who can or exit certain markets. They will also need to consider the message their actions send to their customers. Internal Threats 


7. Cost pressures stifle critical investment: An undervalued function can't keep up. It would be normal to see investment increase after the prolonged downturn, but some economies are still struggling. Even organizations that are increasing security spending have a legacy of under-investment that can't be corrected overnight. But cyber criminals have been investing, and it will become easier and less expensive to buy criminal technology and services. 


8. A clouded understanding leads to an outsourced mess. Continued cost pressure will lead to a new form of digital divide: between organizations that understand the marriage between IT and information security - and everyone else. Leading organizations will appreciate the strategic value of channels, systems and information and will invest; the others will suffer competitive disadvantage and heightened risk of damaging incidents. 


9. New technologies overwhelm: Organizations are unlikely to slow their adoption of new technology or decrease their participation in cyberspace. Along with business benefits come potential vulnerabilities and methods for attack, and organizations will continue to be hit. Organizations that don't understand their dependence on technology may have a nasty surprise if it leads them astray or suddenly goes offline. 


10. The supply chain springs a leak as the insider threat comes from outside: A modern organization's data are spread across many parties, and more organizations will fall victim to incidents at suppliers. This will increase as organizations further digitize supply chains, outsource functions and rely on external advisers. 3D printers create three-dimensional products from digital blueprints - increasing the theft of intellectual property, the frequency of attacks and the amount of counterfeit product on the market. 


Organizations are being left behind, with some seeing their finances and reputations damaged because of the speed and complexity of the threat landscape. They need to take stock now to ensure they are fully prepared and engaged.

Sunday, March 11, 2012

Organizations Often Fail to Fend Off the Obvious Risks

10 Tips to Fight Insider Fraud

Regardless of industry, insiders always pose the greatest threat to an organization's security. Insiders are risky, especially ones with axes to grind.

Researchers within CERT's Software Engineering Institute at Carnegie Mellon have reviewed internal threats for the last decade, examining the threats posed by so-called malicious insiders. Now CERT offers some new insights, about the threats posed by unintentional breaches - those that happen by accident.
"About 50 percent of all companies out there experience at least one malicious insider attack," said Cappelli, who co-authored The CERT Guide to Insider Threats with two other CERT researchers. "And an internal attack has more of an impact than an external attack."

When companies break down breaches, about one-third are directly linked to insiders, and more probably have some link to an insider that the organization simply has not identified. "A lot of the attacks we've seen this year, with cyberattacks, were unintentional," Cappelli says.
CERT is focused on helping companies and organizations with what it calls pattern analysis, which ultimately provides a more scientific way of identifying potential threats before they lead to breaches.

Top 10 Tips

Here are top 10 tips for fighting the insider threat:

1.Repeat Offenders and Offenses: Learn from past incidents. Most organizations get hit more than once because they fail to address their weaknesses.

2.Focus on the Crown Jewels: You can't protect everything, so identify what information is most important and focus on protecting and securing that information first.

3.Use Existing Technology: Don't rush out to buy new systems; just learn to use your existing technologies differently. The same fraud-detection systems used to detect and prevent external attacks can be used to monitor internal behavior.

4.Mitigate Threats from Business Partners: Anyone with access to your systems and databases poses risk.

5.Recognize Concerning Behavior or Patterns: Incidents don't happen in isolation. If you pay attention to the signs, you can often prevent a breach.

6.Recruited Employees: Many internal threats are posed by employees who have either been planted or those who are disgruntled and have been recruited to commit fraud.

7.Watch Behaviour During Resignation or Termination: How much access and information does the individual have, and what can you do to secure it?

8.Be Mindful of Employee Privacy Concerns: Bring your general counsel in to the discussion. You want to monitor behavior, but you don't want to violate employee privacy policies and laws.

9.Cross-Department Involvement: Make the fight against internal fraud an organizational initiative. Create an insider threat program. It's a very complex issue. It involves management and HR, and even the janitor, who could plant malicious code on your network.

10.Get Buy-In from the Top: Executives have to understand the threats, so then they can support your initiatives to mitigate the risks.

Friday, December 16, 2011

What does it really take to exploit a printer?

Printer Hack: Researchers Can Set Media’s Pants on Fire

In the past couple of weeks, there has been quite a bit of press and blogging about a security vulnerability in HP printers that was discovered by researchers in the Intrusion Detection Lab at Columbia University.

In a nutshell, the researchers found a way to replace the operating firmware on an HP printer with firmware of their own design that can do bad things, and they also found a way to do it to a printer that is on a private network behind a firewall.

MSNBC ran an “exclusive” story about it calling it a “devastating attack” to which “millions of printers” could be subjected. Its lede suggested that hackers could cause the printer to catch fire, or be used for identity theft, or be used to take control of entire networks.

In practice, this isn’t an easy vulnerability to exploit on a large scale.

Let me explain:

First, you need to target a printer that supports PJL and its largely undocumented remote firmware update (RFU) function. Many printers support PJL, but RFU is less commonly supported. Many printers don’t have any mechanism for remote updates, and many others use something other than PJL’s RFU function for remote updates.

Once you've found a printer that supports PJL and its RFU function, you'll need to make sure that it will apply a firmware update without checking its authenticity. I can’t speak for other manufacturers, but my employer’s products have been using digital signature verification for firmware updates for at least the seven plus years that I have worked for them.

Next, you need to be able to create new firmware to do your bidding. To do that, you need to know what is the manufacturer and model of your target. The researchers demonstrated exploitation of a victim’s printer that was on a private, firewalled network, but didn’t mention how they determined which make and model of printer would be used by a particular victim. They would need to know that in order to send the correct firmware image to the victim.

And then there is the matter of reverse-engineering printer firmware. It is certainly possible, but not very practical when you consider that there are thousands of different printer models to contend with.

The researchers say that “rewriting the printer’s firmware takes only about 30 seconds”, but they are referring to the time it takes for the printer to update its flash memory and not how long it takes for someone to reverse-engineer a printer to do something malevolently useful.

Next, you need to get the victim to print a document that contains the firmware update code, and of course they need to print it on the printer that you targeted. I don’t know if it is possible to embed an RFU in a printable document in such a way that isn’t obvious when the document is viewed, as most people do before they print something. Perhaps they will disclose that detail at the Chaos conference.

Now, finally, you own the victim’s printer.

Saturday, December 10, 2011

Beware of SCAMMERS on dating websites!

Heartless SCAMMERS

Don't give your heart away online, at least not before you've met that special somebody in person. Some Aussies have been stung for more than $100,000 in online dating and romance scams by "lover" claiming to be desperate for money because of an accident or robbery overseas.

A common scenario is to pretend to be a soldier or aid worker on an overseas mission in need of extra cash to pay costs and get a "leave pass" to visit.

The Australian Competition and Consumer Commission (ACCC) is working to create new guidelines to combat scams. They received more than 1600 complaints about online dating scam relating to more than $17 million in losses between January and October this year.

And of those, more than 200 people have lost $10,000 or more. ACCC deputy chairman Dr. Michael Schaper said more people lost money in dating scams than any other type of scheme.

If you have been talking or communicating with them (Scammers) for a period of time, it can be hard to say no. Please beware of such scams and never give money or share private information. Other red flags can include bad punctuation and spelling.

Dating website operators have until December 16, 2011 to comment on draft guidelines before they are launched next year.

Sunday, November 27, 2011

Department of Homeland Security (DHS) Cyber Security Audit FAIL

The DHS US-CERT office is currently plagued by at least 600 vulnerabilities

A new report warns that the Department of Homeland Security (DHS) is falling short on some cybersecurity protocols.

The news of cybersecurity shortcomings at the agency are more than slightly concerning, as DHS has been tapped to lead information security efforts nationally for both the public and private sectors.

The report, titled DHS Needs to Improve the Security Posture of Its Cybersecurity Program Systems, indicates that the DHS has failed a security audit conducted by the agency's own Inspector General:

The objective of our audit was to determine whether adequate physical and logical access controls are in place to secure the cybersecurity program systems utilized by US-CERT and safeguard the data collected and disseminated by US-CERT. Specifically, we:
  • Determined what and how cybersecurity data is collected and maintained by US-CERT

  • Evaluated the adequacy of physical security controls implemented to protect NCSD’s cybersecurity program systems

  • Determined whether US-CERT has implemented effective system security controls to safeguard the confidentiality, integrity, and availability of cybersecurity data.

  • Determined whether the system documentation for DHS’ cybersecurity program systems has been completed in compliance with DHS and FISMA requirements
"Adequate security controls have not been implemented on the [Mission Operating Environment] to protect the data processed from unauthorized access, use, disclosure, disruption, modification, or destruction," the IG concluded.
The report indicates the DHS US-CERT is grappling with more than six hundred network vulnerabilities, with more two-hundred of them having been identified as critical.

"The results of our vulnerability assessments revealed that [National Cyber Security Division] is not applying timely security and software patches on the [Mission Operating Environment]," the report continued.

DHS indicated that the agency has implemented "a software management tool [to] automatically deploy operating-system and application-security patches and updates to mitigate current and future vulnerabilities," according to a statement by DHS spokeswoman Amy Kudwa.

Tuesday, September 27, 2011

Skype for iPhone may leak Address Book

A vulnerability could see your entire Address Book uploaded to a remote system

A cross-site scripting vulnerability in Skype for iOS has been used to remotely extract the victim device's Address Book. In the proof of concept (PoC) described on the Superevr blog, a piece of JavaScript is inserted in the Full Name field of the attacker's profile.

When a message is received by the victim, the JavaScript runs and initiates a connection to a server, which sends the real payload. That payload instructs the device to upload the entire Address Book file, which can then be read using SQLite-based programs.

The author of the PoC says there's no indication on the device that anything untoward is happening. The issue is said to affect Skype 3.0.1 and earlier, and the PoC was demonstrated on iOS 4.3.5.

The author of the PoC says he reported the issue to Skype in late August, and was told an update would be released early this month. He made a public disclosure this week after the update did not materialise.

The only current mitigations appear to be to ensure that Skype is set to accept messages only from existing contacts, and to be careful to only accept contact requests from people you trust.