Monday, March 4, 2013

Dishing-Off Your Old Device?

Did you know that in the wrong hands that "old" device can mean "new" problems for you?

Have you, like many adults, given a child in your life a hand-me-down mobile device? Maybe it's a "disabled" cell phone or your old iTouch that you let them play around on.

Savvy criminals are increasingly targeting mobile devices (even outdated ones) because they are very often loaded with personal data, including bank and credit cards numbers cached on mobile browsers, passwords, contact information, email and GPS histories.

If you are dead-set on letting your children play with these devices, be sure they have been wiped completely clean of your personal and business information. For tips on how to do this, give this eHow Tech post a thorough read.

Monday, February 25, 2013

AusCERT - Cyber Crime and Security Survey Report 2012

Over half of respondents have increased their expenditure on IT security in the previous 12 months

The recently released Cyber Crime and Security Survey Report 2012 conducted by CERT Australia, in partnership with the Centre for Internet Safety at the University of Canberra, is readily available from CERT Australia’s public website – see www.cert.gov.au.

It is highly recommended reading for IT & Information Security professionals within Australia.

Some 450 businesses were approached to participate in the CERT Australia Cyber Crime and Security Survey, from which the report was developed. It is suggested that you share the report with your IT colleagues (and vice versa).

The report highlights cyber security issues and may be suitable for referencing as external source - providing justification for funding of IT/control system security initiatives.

The inaugural Survey was designed to obtain a better understanding of how cyber incidents are affecting the businesses that form part of Australia’s systems of national interest – the businesses that partner with CERT Australia.


The survey consisted of 24 questions, both closed and open ended, to ascertain:

  • business description
  • types of IT security used
  • types of cyber security incidents experienced, and
  • industry reporting of incidents.


The findings from the survey provide a picture of the current cyber security measures these businesses have in place; the recent cyber incidents they have experienced; and their reporting of them.

Refer here to download the report.

Friday, February 22, 2013

Six Types Of Information Commonly Leaked

Mandiant Highlights Broad Range of Information Stolen from Victims

IT security provider Mandiant lists six categories of information that's commonly pilfered from business and government computers by hackers from a Chinese military unit it dubs APT1.

Mandiant's findings appear in a comprehensive report issued Feb. 18 that the security firm contends documents how APT1 has breached computers in enterprises that conduct business mostly in English, especially in the United States [see map below]. China denies the allegations presented in the report.  

According to Mandiant, the data stolen relate to:

  • Product development and use, including information on test results, system designs, product manuals, parts lists and simulation technologies;
  • Manufacturing procedures, such as descriptions of proprietary processes, standards and waste management processes;
  • Business plans, such as information on contract negotiation positions and product pricing, legal events, mergers, joint ventures and acquisitions;
  • Policy positions and analysis, such as white papers, and agendas and minutes from meetings involving high-ranking personnel;
  • E-mails of high-ranking employees;
  • User credentials and network architecture information.

Mandiant says it's often difficult to estimate how much data APT1 has stolen during its intrusions because the People's Liberation Army unit deletes the compressed archives after it pilfer them, leaving only trace evidence that is usually overwritten during normal business activities.


Tuesday, February 19, 2013

How Facebook Got Hacked?

Zero-Day Exploit Bypassed Java Protections to Install Malware

Even the most savvy information technologists aren't immune from cyber-attacks. Just ask Facebook. The social-media titan says it fell victim to a sophisticated attack discovered in January in which an exploit allowed malware to be installed on employees' laptops.

In a blog posted by Facebook Security on Feb. 15, the company said it found no evidence that Facebook user data was compromised.

Here's what happened at Facebook, according to its blog:

Several Facebook employees visited a mobile developer website that was compromised.

The compromised website hosted an exploit that then allowed malware to be installed on these employees' laptops. "The laptops were fully-patched and running up-to-date anti-virus software," the blog says.

"As soon as we discovered the presence of the malware, we remediated all infected machines, informed law enforcement and began a significant investigation that continues to this day." Facebook Security flagged a suspicious domain in its corporate DNS (Domain Name Servers) logs and tracked it back to an employee laptop.

The security team conducted a forensic examination of that laptop and identified a malicious file, and then searched company-wide and flagged several other compromised employee laptops.

The social-media company says it is working with law enforcement and the other organizations affected by this attack. "It is in everyone's interests for our industry to work together to prevent attacks such as these in the future," Facebook says.

The Facebook attack is reminiscent of the 2011 breach at security provider RSA, when a well-crafted e-mail tricked an RSA employee to retrieve from a junk-mail folder and open a message containing a virus that led to a sophisticated attack on the company's information systems

Wednesday, February 13, 2013

In-House App Stores is MUST for Enterprise?

A Do-it-Yourself Approach to Ensuring Mobile Security

As personal mobile devices become ubiquitous in corporate networks - even in organizations without official bring-your-own-device policies - IT and security personnel are implementing new approaches to prevent malware and ensure data integrity. 

One approach beginning to take root is the creation of in-house corporate app stores, where organizations offer users access to custom-built, secure applications designed specifically for that organization, along with access to approved public apps for smart phones, tablets and other personal devices.

Tackling Application Insecurity

With malware infesting the authorized commercial app stores, including the two largest - Google Play for Android and to a lesser extent, the Apple iOS App Store - corporate security and IT executives are exploring new strategies to limit the use of unauthorized applications on devices connected to corporate networks.

Because of the rapid growth in the use of personal devices for work-related tasks, IT departments generally do not permit users to install any application on corporate computers but many companies still have not yet established similar policies for personal devices. 

Companies that opt for a private app store can minimize much of that risk by requiring users to select only from applications that are certified by their employer as safe.

Any suggestions or ideas?

Wednesday, February 6, 2013

Need To Invest Time In Facebook Privacy


An Embarrassment is Coming

If they don't invest the time in reviewing the information that's been published about them, Facebook users are in for a potentially embarrassing surprise. That's because Facebook is working toward making more of its content searchable with its Graphs Search feature. 

What will be searchable? All the information (personal, professional, pictorial) you post, and that other Facebook users post about you. Additionally, your likes, and in many cases simply the websites you've visited that have hooks back into Facebook, will be searchable.

This article explains it well, and in it, writer Meghan Kelly gives one of the best analogies for Facebook I have read:
Facebook is like a safe containing a ton of your personal information - which you've purposefully and willfully cracked with an axe.
Beyond searching for what's already out there about you, commit to practicing good social etiquette. Don't "check in" your friends for them (without their knowledge!), post pictures of them they may not appreciate or tag them to one of your posts without their permission. Even the tamest of details may cause trouble for them, not to mention, trouble for your relationship. 

Tuesday, February 5, 2013

How To Control "Tagging" on Facebook?

Tame the "Tagging"

Being "tagged" on Facebook means another user has added content and publically associated you with that content. A friend may post a picture of you at the beach. By tagging you, that photo will show up on your profile (if your settings allow).

There is a setting in Facebook that allows users to approve any tags before they are posted to their timeline. This blog post on Business2Community does a great job of showing readers exactly how to set Facebook to alert them to requests for tags.

This isn't just a good way to easily give friends permission to tag you; it's an excellent way to keep track of the content in which you've been tagged. Who needs to have someone else associate them with things to which they have no legitimate connection?

The post goes on to explain the difference between Facebook Profiles (now known as "Timelines") and Facebook Pages. There are some unique features about Pages that make these tags post differently, so if you manage a Product, Brand or Person Facebook Page, this will be an especially good article for you. 

For more emerging tagging concerns, see: 

Sunday, February 3, 2013

New PCI Guidelines for E-Commerce

New PCI Guidelines for E-Commerce

A new set of card data security guidelines for merchants and payments providers aims to address increasing risks unique to e-commerce environments. On Jan. 31, the Payment Card Industry Security Standards Council issued its PCI DSS E-commerce Guidelines Information Supplement, a set of guidelines for e-commerce security.

The guidelines relate to online infrastructures and how merchants work with third-party providers. Developed by the PCI E-commerce Security Special Interest Group, the 39-page resource includes recommendations about topics ranging from online risks associated with payments gateways to often-overlooked security gaps Web-hosting providers can inadvertently create.

Securing the Payments Chain
  • The guidance offers a checklist of security recommendations and reminders, such as:
  • Know where cardholder data is located within the merchant's infrastructures and those of the processors and vendors to which they outsource.
  • Regularly test software and applications to detect if card data or other information is being stored unintentionally.
  • Evaluate risks associated within e-commerce technology.
  • Review the network and database risks posed by outsourcing functions, such as payments processing and Web hosting to third parties.
  • Hire PCI-approved website scanning vendors to validate, on a regular basis, Internet-facing environments for compliance with the PCI Data Security Standard.
  • Define best practices for online payment application security.
  • Implement security training for internal staff.
  • Establish best practices for consumer awareness.
Evaluating Third Parties

The guidance reviews how merchants can work with third parties to address those risks and provides a checklist for easy-to-fix vulnerabilities related to: 
  • Online injection flaws;
  • Cross-site scripting, or XSS;
  • Online cross-site request forgery, or CSRF;
  • Buffer or temporary data storage overflows, which result when programs or processes attempt to store more data than they were designed to hold;
  • Weak authentication and/or session credentials; and
  • Application and software misconfigurations.

Wednesday, January 30, 2013

ENISA Identifies Top Cyberthreats

What are the emerging threats and vulnerabilities, and how should organizations globally respond to them?

ENISA, the European Union cyber-agency, is out with its first-ever Threat Landscape report.

Drive-by exploits, worms/Trojans and code-injection attacks are the three top cyberthreats to organizations, according to the new Threat Landscape report published by the European Network and Information Security Agency.

The ENISA Threat Landscape provides an overview of threats, together with current and emerging trends. One of the key objectives of this report is to give the information security community a comprehensive look at risks.

It is based on publicly available data and provides an independent view on observed threats, threat agents and threat trends. Over 140 recent reports from security industry, networks of excellence, standardisation bodies and other independent institutes have been analysed. 

Among the top 10 threats ID'd by the report:

  • Drive-by exploits (malicious code injected to exploit web browser vulnerabilities) Worms/Trojans;
  • Code injection attacks;
  • Exploit kits (pre-packaged software to automate cybercrime);
  • Botnets (hijacked computers used in attacks such as DDoS).

Among technology trends, mobile gets the most attention because that's the platform where users, data and adversaries increasingly converge.

Please refer here to download the report.

Monday, January 28, 2013

US FFIEC: Proposed Guidance on Social Media

Regulators Address Emerging Social Media Risks to Banking Institutions

The US Federal Financial Institutions Examination Council has issued proposed risk management guidance for the use of social media.

"Social Media: Consumer Compliance Risk Management Guidance," was posted on the Federal Register Jan. 23. It provides an overview of the impact social media sites have on compliance with consumer protection and other applicable laws, especially when interactions between institutions and consumers take place on social media sites such as Facebook and Twitter.

Employees could be using social media from different devices or from home at night. If their accounts are taken over, then a criminal could be posting on that site, giving advice to steer customers to do something they shouldn't, or posting a link that leads them to a malicious site.

There certainly are a lot risks banks need to think about when they start to use social media. The proposed guidance is really about risk assessment. The guidance is intended to help financial institutions understand potential consumer compliance, legal, reputation and operational risks associated with the use of social media, along with expectations for managing those risks.

Although the guidance does not impose additional obligations on financial institutions, the FFIEC expects financial institutions to take steps to manage potential risks associated with social media, as they would with any new process or product channel.

The FFIEC will accept comments on the proposed guidance through March 25. It will publish a final version once it reviews comments received.

Saturday, January 26, 2013

Documentary: A Gift for the Hackers

Privacy is becoming antiquated

Increasingly devices like printers and scanners are being connected directly to the Internet. It’s all very convenient, bit is it safe?

Your mobile, your printer, your hard drive, everything is connected… but it’s like a Swiss cheese. Medical files, financial information, and trade secrets, they’re all there for the taking. It’s shocking, it should not be allowed. It’s a design flaw.

Is this vulnerability in tens of thousands of devices compromising your security and your privacy? Computer security has become a big concern for companies and individuals.

As a result it has also become a big business. The world’s number one producer of computers and printers, Hewlett – Packard (HP), has an annual turn over of 127 billion dollars.

Wednesday, January 23, 2013

Security audit finds Developer OUTSOURCED his JOB to China

Pro-active Log Review Might Be A Good Idea

A security audit of a US critical infrastructure company last year revealed that its star developer had outsourced his own job to a Chinese subcontractor and was spending all his work time playing around on the internet.

The firm's telecommunications supplier Verizon was called in after the company set up a basic VPN system with two-factor authentication so staff could work at home. The VPN traffic logs showed a regular series of logins to the company's main server from Shenyang, China, using the credentials of the firm's top programmer, "Bob".

"The company's IT personnel were sure that the issue had to do with some kind of zero day malware that was able to initiate VPN connections from Bob's desktop workstation via external proxy and then route that VPN traffic to China, only to be routed back to their concentrator," said Verizon. "Yes, it is a bit of a convoluted theory, and like most convoluted theories, an incorrect one."

After getting permission to study Bob's computer habits, Verizon investigators found that he had hired a software consultancy in Shenyang to do his programming work for him, and had FedExed them his two-factor authentication token so they could log into his account. He was paying them a fifth of his six-figure salary to do the work and spent the rest of his time on other activities.

The analysis of his workstation found hundreds of PDF invoices from the Chinese contractors and determined that Bob's typical work day consisted of: 

9:00 a.m. – Arrive and surf Reddit for a couple of hours. Watch cat videos 

11:30 a.m. – Take lunch

1:00 p.m. – Ebay time

2:00-ish p.m – Facebook updates, LinkedIn 

4:30 p.m. – End-of-day update e-mail to management 

5:00 p.m. – Go home

The scheme worked very well for Bob. In his performance assessments by the firm's human resources department, he was the firm's top coder for many quarters and was considered expert in C, C++, Perl, Java, Ruby, PHP, and Python.

Further investigation found that the enterprising Bob had actually taken jobs with other firms and had outsourced that work too, netting him hundreds of thousands of dollars in profit as well as lots of time to hang around on internet messaging boards and checking for a new Detective Mittens video.

Bob is no longer employed by the firm. ®

Source from The Register

Refer here to read further details.

Thursday, January 10, 2013

The dangers of USB drives

What makes USB drives so great at carrying malware?

Stuxnet, which was discovered in June and has since spread to millions of machines around the world, is the most sophisticated computer attack we've ever seen.

Though its true purpose is unknown—teams of experts across the globe are poring through the code in an effort to divine its intentions—the deviousness of its design has prompted many researchers to call it a "cyber-weapon," one perhaps created by the United States or Israel to disrupt Iran's nuclear program.
What's most interesting about Stuxnet isn't how smart its authors were; it's how dumb they guessed we all would be. 
How did the worm's creators expect to get it inside some of the most secure installations in the world?
After all, sensitive machines often operate behind an "air gap"—that is, their networks are physically separated from the Internet and other dangerous networks where viruses can roam freely.

Getting anything inside one of these zones requires the complicity of an employee. That's exactly what Stuxnet got, because its authors designed the worm to piggyback on the perfect delivery system—the ubiquitous, innocent-looking USB flash drive, the planet's most efficient vector of viruses, worms, and other malware.

What makes USB drives so great at carrying malware?

They're the mosquitoes of the digital world—small, portable, and everywhere, so common as to be nearly invisible

Funny story: At a conference in Australia last year, IBM handed out thumb drives that turned out to be infected by malware. It was a computer-security conference.

We know we shouldn't click on e-mail attachments from strangers, and we know we should be wary of typing our passwords into shady sites online. But the USB disk has somehow evaded our suspicion; few of us look at them and recoil at the dangers that could be lying within.

Indeed, USB sticks evoke exactly the opposite emotion—if you saw a stray one on the street or lying around your office, wouldn't you pick it up and put it in your computer to try to identify the rightful owner? If a company wants to ratchet up security, it's not as simple as banning all thumb drives.

To be extra careful, you'd have to ban iPods, cameras, and every other USB-based doohickey—all of those devices are capable of carrying Stuxnet-like viruses, too.

The only hope is education: Don't trade USB sticks, don't stick an unknown one into your machine, and don't pick one up off the street and plug it in your machine just to see what's inside.

But I don't know if we're ever going to win that battle. It's human nature. If I were a normal person and I didn't work in this bubble of security? If I found a USB drive, the first thing I would want to do is want to plug it in, too.

Saturday, January 5, 2013

Term Of The Month: "Geotagging"

Commonly used via social media applications such as Twitter, Facebook etc.

Geotagging, in general, means geographical identification has been added to various media you may have created, such as a geotagged photographs, videos, websites, SMS messages, QR Codes, or RSS feeds, just to name a few.  

Look at a recent Facebook post you made. Was your location included with it, such as shown in this example?



That is one type of geotagging.

Simply by posting a photo of a meal you have just been served or the great trick your kid performed on the playground, you are potentially broadcasting your whereabouts.

This can be very dangerous if you think someone is stalking you, so consider disabling your smartphone's and/or mobile device's GPS embedding feature.

Thursday, January 3, 2013

How to Catch a Phish?

Helpful hint on spotting a phishing-scam email before it's too late!

You can detect a fake email very quickly simply by focusing on the "From" field in your email header.

Most malicious e-mails say they are from a legitimate company, but the address in the "From" field does not match that in the signature. If you are unsure of the sender's legitimacy, you can also use free tools on the Internet to verify any email address quickly.

Be aware, however, that some of these phishing artists are very adept at masking their identities.