After first Anon hack, PR firm failed to update other .gov websites

By Mike S

While it’s idiotic to refrain from updating your servers, it is doubly-idiotic to refuse to update your servers after they’ve been hacked.

Under the terms of the provisioning service that the servers were provided under, Fleishman-Hilliard was responsible for the administration and security of the servers, including operating system updates, software installations and backups, and had set up the servers—but “had chosen not to update their applications,” Brubeck said.

via After first Anon hack, PR firm failed to update other .gov websites.

categoriaCloud Computing, Security commentoNo Comments dataFebruary 18th, 2012
Leggi tutto

Crypto shocker: four of every 1,000 public keys provide no security

By Mike S

via Crypto shocker: four of every 1,000 public keys provide no security (updated):

An astonishing four out of every 1,000 public keys protecting webmail, online banking, and other sensitive online services provide no cryptographic security, a team of mathematicians has found. The research is the latest to reveal limitations in the tech used by more than a million Internet sites to prevent eavesdropping.

Which is bad – collisions are supposed to be rare, or else it’s much easier to guess the key.

“Our only conclusion is that there is not just one cause for all of these problems,” Hughes said. “This leads to our conclusion that unless you can totally trust your random number generator, RSA is not a good algorithm to choose.”

I thought computer RNGs couldn’t be trusted to be random.

categoriaSecurity commentoNo Comments dataFebruary 15th, 2012
Leggi tutto

Breaches galore as Cryptome hacked to infect visitors with malware

By Mike S

If your site is hosted, make sure your host and CMS keep patches current:

Cryptome founder John Young said in an e-mail that he believes the attackers were able to infect his website with a poisoned PHP file by exploiting a weakness in security or server software provided by Network Solutions, which hosts the Cryptome website.

via Breaches galore as Cryptome hacked to infect visitors with malware.

categoriaSecurity commentoNo Comments dataFebruary 13th, 2012
Leggi tutto

Anonymous exposes e-mails of Syrian presidential aides

By Mike S

Anonymous again demonstrates the importance of strong passwords:

Along with the release of these e-mails, Anonymous also exposed the passwords of 78 accounts on the Ministry’s servers. Of the passwords revealed, 31 were “12345″ and a number were minor variations on that. Some of the other passwords in the set included:

  • iloveyou
  • 123vivasyria
  • system
  • honda2011
  • testing

via Anonymous exposes e-mails of Syrian presidential aides.

categoriaSecurity commentoNo Comments dataFebruary 8th, 2012
Leggi tutto

Top German cop uses spyware on daughter, gets hacked in retaliation

By Mike S

via Top German cop uses spyware on daughter, gets hacked in retaliation: It’s sad how frequently law enforcement officials bend or break the law to achieve their ends.

Problem 1: This guy forgot he was a father, and treated his kid as just another suspect.

Problem 2: The story reveals the Germans have a program for tracking individuals’ locations via cell phone and car GPS systems, and they had to take it offline because this guy’s home security sucked so hard.

Fortunately for connoisseurs of the weird, Der Spiegel revealed a stranger story in its magazine yesterday. According to the report, a top German security official installed a trojan on his own daughter’s computer to monitor her Internet usage. What could possibly go wrong?

Nothing—well, at least until one of the daughter’s friends found the installed spyware. The friend then went after the dad’s personal computer as a payback and managed to get in, where he found a cache of security-related e-mails from work. The e-mails, in turn, provided the information necessary for hackers to infiltrate Germany’s federal police.

 

categoriaSecurity commentoNo Comments dataJanuary 9th, 2012
Leggi tutto

Antisec hits private intel firm; millions of docs allegedly lifted

By Mike S

In another great example of What Not To Do, the intelligence firm Strategic Forecasting, Inc, apparently made no attempt whatsoever to comply with PCI DSS.

via Antisec hits private intel firm; millions of docs allegedly lifted:

Antisec breached Stratfor’s networks several weeks ago, according to sources within the group that attacked the firm. On Saturday, Antisec began posting credit card details of a few Stratfor customers on Internet Relay Chat. But that’s just the start of a much larger data dump, the group claims. Anonymous is planning to release much more information—up to 200GB worth, in parts throughout the week leading up to New Year’s Eve. That trove allegedly includes 860,000 usernames, e-mails, and md5-hashed passwords; data from 75,000 credit cards, including security codes used for no-card-present transactions; and over 2.5 million Stratfor e-mails, internal Stratfor documents from the company’s intranet, and support tickets from it.stratfor.com.

[...]

According to Antisec, Stratfor was using the e-commerce suite Ubercart to handle customer information. The software has built-in encryption, but Stratfor apparently used custom modules that stored customer data in cleartext. Additionally, Stratfor appears to have stored the card security code of its customers, a practice generally prohibited by credit card companies.

So they stored the security code, stored the entire unencrypted credit card number, used plain-jane md5-hashed passwords, and left everything wide open, and disabled what security features were built-in to the software they were using.

Very Bad Practice.

categoriaCompliance, Security commentoNo Comments dataDecember 30th, 2011
Leggi tutto

How hackers gave Subway a $3 million lesson in point-of-sale security

By Mike S

One thing I really enjoy about computer sercurity is learning from other peoples’ mistakes.

via How hackers gave Subway a $3 million lesson in point-of-sale security:

While the scale of this particular ring may be significant, the methods used by the attackers were hardly sophisticated. According to the indictment, the systems attacked were discovered through a targeted port scan of blocks of IP addresses to detect systems with a specific type of remote desktop access software running on them. The software provided a ready-made back door for the hackers to gain entry to the POS systems. The PCI Security Standards Council, which governs credit card and debit card payment systems security, requires two-factor authentication for remote access to POS systems—something the applications used by these retailers clearly didn’t have.

“With PCI compliance, those apps shouldn’t be on those systems,” said Konrad Fellmann, audit and compliance manager for SecureState, an IT security firm with a practice in retail security auditing, in an interview with Ars. But small retailers who don’t store credit card data are not required to have the same level of auditing as larger companies, Fellmann said.

It’s hard to believe a corporation as large as Subway put so little effort into PCI compliance, but this could have easily been discovered with an external scan, log monitoring, in-scope review, systems change monitoring, malware scanning, and so on and so forth.

So will Subway now have to post the Black Mark of Shame in every franchise?

categoriaSecurity commentoNo Comments dataDecember 26th, 2011
Leggi tutto

FBI using Carrier IQ info for “law enforcement purposes,” refuses to release records

By Mike S

It’s amazing how much data our cell phones provide to so many different parties.

As we noted in several stories in the past few weeks, Carrier IQ software is installed on more than 140 million phones, including various Androids and iPhones, although Apple says it is in the process of stripping it out. Carrier IQ, handset manufacturers and wireless service providers have said the software is used only for diagnostic information to improve service, and that it is not used to record keystrokes or read users’ messages. However, the companies have faced questions from Sen. Al Franken D-MN and class-action lawsuits. How much data Carrier IQ collects from smartphones and what happens to it have not been fully answered, and the FBI’s statement does not clarify whether it is investigating Carrier IQ to determine if its software violates any federal laws, or if it is using data from Carrier IQ for other investigations.

via FBI using Carrier IQ info for “law enforcement purposes,” refuses to release records.

categoriaSecurity commentoNo Comments dataDecember 13th, 2011
Leggi tutto

Suspension of Disbelief: magicians’ friends targeted by new phishing scam

By Mike S

The old wisdom said “Don’t trust any e-mail or attachment from someone you don’t know.”  Unfortunately, your friends are pretty likely to click any old link they receive from anywhere, so be extra suspicious of suspicious e-mails from people you do think you know.

Last week, friends of Kyle and Kelly Peron got a disturbing email that appeared to be from the couple, a husband-and-wife magic act. It told of trouble overseas, claiming that the two had been mugged while vacationing briefly in the Phillipines. “We’ve been to the Embassy and the Police here but they’re not helping issues at all and our flight leaves in few hours from now but we’re having problems settling the hotel bills and the hotel manager won’t let us leave until we settle the bills,” the email pleaded. “Please, let me know if you can help us out?”

If the email had been from the Perons, it would have been some serious magic—seeing as they were at home in the Philadelphia area at the time. Like many people who use social media to promote their businesses and keep in touch with colleagues and customers, the Perons’ personal information was easily converted into a bit of social engineering that could fool the less skeptical.

The email, which asked for the pair’s friends to wire $2,500 by Western Union to the couple at an address in Manila, turned out to be an example of the latest mutation of the sort of friend-stranded-overseas scam that has run rampant through Facebook for years. Because of new password recovery schemes and other counter-fraud schemes being used by Facebook to prevent the social network from being used directly by fraudsters, the new modus operandi is much more subtle—and much more difficult for those being impersonated to stop. And once a scam’s been exposed, they quickly move on to another target.

via Suspension of Disbelief: magicians’ friends targeted by new phishing scam.

categoriaSecurity commentoNo Comments dataDecember 5th, 2011
Leggi tutto

Wikileaks docs reveal that governments use malware for surveillance

By Mike S

The worst offender against privacy and security is always government.

The latest round of documents published by Wikileaks offers a rare glimpse into the world of surveillance products. The collection—which Wikileaks calls the Spy Files—includes confidential brochures and slide presentations that companies use to market intrusive surveillance tools to governments and law enforcement agencies.

A report that Wikileaks published alongside the documents raises concern about the growing use use of mass surveillance tools that indiscriminately monitor and analyze entire populations. The group also points out that some of products described in the documents are sold to authoritarian regimes, which use them to hunt and track political dissidents.

via Wikileaks docs reveal that governments use malware for surveillance.

categoriaSecurity commentoNo Comments dataDecember 1st, 2011
Leggi tutto