tag:blogger.com,1999:blog-131780362009-07-07T10:45:36.842-05:00antiwormThe <a href="http://intrinsicSecurity.com">Intrinsic Security</a> blog. <br />Sharing ideas and protecting networks from worms, malware, and botnets with intrusion suppression technology.Gary W. Longsinehttp://www.blogger.com/profile/05653813520423954538gary.w.longsine@gmail.comBlogger48125tag:blogger.com,1999:blog-13178036.post-66741563609829067282009-06-02T15:50:00.001-05:002009-06-02T15:50:02.636-05:00Master Lock Pickers and the Security Mirage<p>If you ever doubted that the lock on your door was in place to keep out the kids, doubt no more. This fascinating article details one of the world's top lock pickers.</p><br /><p><a href="http://www.wired.com/techbiz/people/magazine/17-06/ff_keymaster" title="wired on Tobias, the lock picker">The Ultimate Lock Picker Hacks Pentagon, Beats Corporate Security for Fun and Profit</a></p><br /><p>A good friend of mine has been picking locks as a hobby most of his life. This is a skill that can be learned by any bright, patient person.</p><br /><p>It's a safe bet there are more people around who know how to pick locks than there are people getting paid to rethink the lock and key.</p><br /><br /><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13178036-6674156360982906728?l=antiworm.blogspot.com'/></div>Gary W. Longsinehttp://www.blogger.com/profile/05653813520423954538gary.w.longsine@gmail.com0tag:blogger.com,1999:blog-13178036.post-22702625424084520022009-05-18T21:45:00.001-05:002009-05-18T21:55:58.603-05:00on cyber warfare, China, KylinYes, the Washington Times is not exactly a premier source of security information, but with analysis and reporting like this, who needs enemies? Two fascinating tidbits from this article: <a href="http://washingtontimes.com/news/2009/may/12/china-bolsters-for-cyber-arms-race-with-us/">China blocks U.S. from cyber warfare</a>.<br /><br />The first is an absolutely classic Freudian slip:<br /><br /><blockquote><em>U.S. offensive cyberwar capabilities have been focused on getting into Chinese government and military computers outfitted with less secure operating systems like those made by Microsoft Corp. (This observation isn't attributed in the article.) </em></blockquote><br /><br />That ought to have you rolling on the floor, laughing, until you realize that these are the very same "less secure operating systems like those made by Microsoft Corp." which the bureaucrats at every level of Federal, State, and local governance in the U.S. has been "standardizing" on. Then your sphincters pucker. <br /><br />The point of the article is that the Chinese have developed and deployed their own operating system and "hardened" CPU architecture to run it on, and have been deploying it on Chinese government and military systems, rendering substantial portions of the the U.S. strategy for cyber counter-attack irrelevant. Various security "experts" testified before Congress to raise some alarms. <br /><br />Perhaps it's just poor reporting, but these crack security experts seem to be under the impression that this Kylin thing is mysterious, and don't seem to have noticed that Kylin appears to be a hardened version of FreeBSD (an open source operating system), and that you can apparently download versions of it with a quick google search (see: <a href="http://www.honeytechblog.com/downlod-kylin-operating-system-by-chinaqingbo-wu/" title="Kylin ISO downloads">Some random blogger with links to Kylin iso images</a>.)<br /><br />Which makes the next bit from this article even more amusing. This statement is attributed to Kevin G. Coleman, but this is the Washington Times, who knows if poor Mr. Coleman actually said any such thing this silly:<br /><br /><blockquote><em>U.S. operating system software, including Microsoft, used open-source and offshore code that makes it less secure and vulnerable to software "trap doors" that could allow access in wartime, he explained</em></blockquote><br /><br />Of course, no real security expert would ever mean to imply that Microsoft's security issues were primarily, or even in any meaningful way at all, based on open-source software. Microsoft has used tiny amounts of BSD code in their network stack, but Microsoft's security problems are of their own, proprietary making, and everyone who can spell CISSP or SANS knows that.<br /><br />The take home lessons: <ol><li>do a google search before you try to panic the Congress, and</li><br /><li>if FreeBSD derivatives can be secured such that people panic when China deploys them, maybe U.S. government agencies ought to re-think their obsession and love affair with the less secure Microsoft systems, with which they have been utterly failing to protect U.S. Government assets, secrets, and infrastructure, according to other testimony reported in this and other articles, and perhaps<br /></li><li>rather than inciting panic, somebody ought to be downloading those ISO images, installing Kylin, and running some automated tools against its network services, looking for buffer overflow exploits.</li></ol><br /><br /><br /><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13178036-2270262542408452002?l=antiworm.blogspot.com'/></div>Gary W. Longsinehttp://www.blogger.com/profile/05653813520423954538gary.w.longsine@gmail.com0tag:blogger.com,1999:blog-13178036.post-19235037183627030362008-10-25T21:21:00.001-05:002008-10-25T21:21:14.557-05:00Gimmiv worm strikes WindowsThat didn't take long, did it? Apparently Microsoft released their "out of band" patch in a hurry because they had already seen exploits "in the wild" for this defect. They guessed a worm couldn't be far behind, and they were right.<br /><br /> <a href="http://www.nytimes.com/external/idg/2008/10/24/24idg-New-worm-feeds.html?em" title="Bimmiv work strikes Windows">Gimmiv: New worm feeds on latest Microsoft bug</a><br /><br />The cycle of patching will never fix this problem. If you are a CIO or manager of an enterprise or government network which has been hit by new worms this week, <a href="http://intrinsicSecurity.com/aboutus/contact-us/" title="Contact Intrinsic Security">contact Intrinsic Security</a> to discuss FireBreak AntiWorm. Worms are detected instantly and trapped without signatures. <br /><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13178036-1923503718362703036?l=antiworm.blogspot.com'/></div>Gary W. Longsinehttp://www.blogger.com/profile/05653813520423954538gary.w.longsine@gmail.com0tag:blogger.com,1999:blog-13178036.post-59361572091694267842008-10-23T10:16:00.001-05:002008-10-23T10:16:41.187-05:00Microsoft's "Out of Band" Security BulletinMicrosoft plans to issue an "out of band" patch today, e.g. a patch released on a day other than "Patch Tuesday". <br /><a href="http://www.microsoft.com/technet/security/bulletin/ms08-oct.mspx" title="microsoft notifies customers that wormable exploit exists">Microsoft Security Bulletin Advance Notification</a><br /><br />Thw defect, which hasn't been publicly described just yet, apparently exists in every version of Windows that anyone who is likely to patch anything actually uses:<br /><ul><br /><li>Windows 2000,</li><br /><li>Windows XP, </li><br /><li>Windows Server 2003,</li> <br /><li>Windows Server 2008, and </li><br /><li>Windows Vista.</li><br /></ul><br /><br />Microsoft describes this update as "critical" which means they know it can be remotely exploited without user intervention (and without exploit chaining, which they don't yet consider to be critical.) <br /><br /><br /><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13178036-5936157209169426784?l=antiworm.blogspot.com'/></div>Gary W. Longsinehttp://www.blogger.com/profile/05653813520423954538gary.w.longsine@gmail.com0tag:blogger.com,1999:blog-13178036.post-78275303805672361442008-08-07T13:42:00.001-05:002008-08-07T13:44:02.443-05:00DNS flaws expose many services (exploit chaining with old defects)The flaws discovered in DNS recently by Dan Kaminsky have existed for years. He linked several of them together, a concept known as "<a hre="http://antiworm.blogspot.com/2004/07/exploit-chaining-virus-worm-and.html">exploit chaining</a>" to reveal a much more serious flaw. His technique makes it possible to hijack and misdirect a user's web browser to a malicious web site, even in cases where the user types the correct URL. '<br /><br />That, of course, completely makes a fool of Verisign's Ken Silva, chief technology officer, who's been running around to the press saying irresponsible if not utterly foolish things like: <br /><blockquote>"We have anticipated these flaws in DNS for many years and we have basically engineered around them."</blockquote><br /><br />Kudos to Mr. Kaminsky, for working in private with the major vendors of DNS server software, who had patches ready to go before the flaw was announced. This kept the script kiddies from having a field day with the vulnerabilities, which were endemic to nearly all DNS servers. <br /><br />Apparently there remain some issues not yet addressed, as the vendors focused initially on HTTP and web browsers. <br /><br /><blockquote><a href="http://news.bbc.co.uk/2/hi/technology/7546557.stm" title="DNS flaw saga continues ">Net address bug worse than feared</a><br /><br />DNS attacks are not new but Mr Kaminsky is credited with discovering a way to link some widely known weaknesses in the system so that the attack now takes seconds instead of days or hours.<br /><br /><br />"Quite frankly, all the pieces of this have been staring us in the face for decades," said Paul Vixie, president of the Internet Systems Consortium, a non-profit that makes the software run by many of the world's DNS servers.</blockquote><br /><br /><br /><br /><br /><br /><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13178036-7827530380567236144?l=antiworm.blogspot.com'/></div>Gary W. Longsinehttp://www.blogger.com/profile/05653813520423954538gary.w.longsine@gmail.com0tag:blogger.com,1999:blog-13178036.post-7956545108155349732008-07-30T10:52:00.001-05:002008-07-30T10:52:51.486-05:00Secrets, Lies, and Email PasswordsBritish hacker Gary McKinnon apparently was able to crack over 90 computer systems at various government agencies of the United States, including NASA, the U.S. Army, the U.S. Air Force, and the Department of Defense in 2001 and 2002. He was apparently hunting for secrets about aliens. No, he wasn't searching for illegal immigrants, but rather, aliens from outer space. He believed that the U.S. government was hiding evidence that these aliens exist, and maybe hiding materials and bodies of dead aliens, as well.<br /><br />I hope that if he's extradited and then tried, the judge goes easy on him. Yes, he's guilty of embarrassing several U.S. government agencies by breaking into their computer systems and rifling through data. It shouldn't have been so easy for him to do. <br /><br />The layers of management who didn't take network and information system security seriously until 9/11 will not be on trial, and they certainly bear partial responsibility for contributing to this problem. Mr. McKinnon wasn't the only person to break into many computer systems at these (and other) agencies during the late 1990s and early 2000s, he just happens to be one of the very, very few who were caught. <br /><br />One could say that Mr. McKinnon is a victim here, too, as well as a perpetrator. That is to say, he's a victim of a free market in, and cottage industry of, ideas about conspiracy. Yeah, there probably are some government conspiracies. It's a big, big government that has done some embarrassing things they would like to hide. Most of those things are probably mundane. Hiding the bodies of aliens that crash landed in Roswell, New Mexico, is not likely to be among them. He should have been reading the Bad Astronomy blog. <br /><br /><a href="http://www.youtube.com/watch?v=c75N4reUpHs" title="Phil Plait on UFOs">Phil Plait (Bad Astronomer) on UFOs</a><br /><br /><a href="http://www.badastronomy.com/book/uforebuttal.html" title="Phil Plait rebuttal to a book review">Phil Plait's Bad Astronomy: Rebuttal to a Bad Boook Review from a UFO, uhm, enthusiast</a><br /><br />Apparently Mr. McKinnon was caught because some action of his was traced back to the email account of his girlfriend. <br /><br /><blockquote><a href="http://www.cnn.com/2008/WORLD/europe/07/30/uk.hacker.ap/index.html" title="British hacker Gary McKinnon was hunting for UFOs">Alleged Pentagon hacker loses extradition appeal</a><br />"McKinnon has acknowledged accessing the computers, but he disputes the reported damage and said he did it because he wanted to find evidence that America was concealing the existence of aliens.<br /><br />He was caught in 2002 after some of the software used in the attacks was traced back to his girlfriend's e-mail account."</blockquote><br /><br />If there is a lesson to be learned here, it's probably this: If your Significant Other is a UFO hunting nut job and a computer whiz, don't let him or her know your passwords, change them regularly, and for good measure, use a Macintosh. <br /><br /><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13178036-795654510815534973?l=antiworm.blogspot.com'/></div>Gary W. Longsinehttp://www.blogger.com/profile/05653813520423954538gary.w.longsine@gmail.com0tag:blogger.com,1999:blog-13178036.post-78650344825664028282008-02-23T19:28:00.001-05:002008-02-23T19:52:54.401-05:00Hands-on SQL Injection - Show me!Security training for application developers is an under-funded activity in most of the organizations that build software. Fixing security defects in custom applications remains an underfunded activity, even after defects are identified. Why does this continue to be the case? <br /><br />It can be easier to find defects for a customer in a security penetration test than it is to convince the customer that the problem is serious enough to fix. Sometimes this is because the incentives are messed up. I'm not the only person who has observed that the <a href="http://en.wikipedia.org/wiki/Federal_Information_Security_Management_Act_of_2002%23Issues_With_FISMA">Federal Information Security Management Act (FISMA)</a> seem to have given Federal agencies a much higher incentive to find problems and write lengthy, complicated reports on those problems, than to fix them.<br /><br />Other times, managers may not understand the technical details of various vulnerabilities, or may be interested in a certain category of defects, while wearing blinders to other types of defects, particularly outside their comfort zone. If the manager is familiar with viruses and worms from their experiences running their PC at home, then they might understand and be more interested in network configuration defects. This might come at the expense of less attention to application design or coding defects, like those that expose an application to <a href="http://en.wikipedia.org/wiki/SQL_injection">SQL Injection</a> attacks.<br /><br />Occasionally the problem, unfortunately, is a more active dismissal of some threats. People sometimes say things along the lines of, "if I don't understand it, it must be too difficult to exploit in practice, so it can't be much of a <i>real</i> risk." I've even heard managers lambast their security advisers while trying to look cool, tossing in the MTV phrase, "Keep It Real". Well, folks, I hate to be the one to break it to you, but <a href="http://www.realitytvworld.com/news/how-real-is-the-simple-life-2082.php">even allegedly unscripted reality television is sometimes scripted</a>. Just like exploits to complicated security defects. <br /><br />It only takes <i>one</i> person with the right combination of skills and maliciousness to write an exploit, and give it away. Suddenly the exploit is "zero cost" for the next attacker, and the flood of attackers after that. <br /><br />Exploits are "scalable" in this sense, or, as an economist or MBA might say, the marginal cost of each additional use of an exploit, after it is developed, approaches zero arbitrarily close. <br /><br />We see this pattern clearly in remotely exploitable buffer overflows, which might not be noticeably exploited for years after a product ships, and for months after the defect is discovered and publicized. Then, "suddenly" an exploit pops up. Within days there are dozens of worm or botnet variants exploiting the same defect. (We'll ignore for now the issue that some defects actually were exploited before the defect was publicized.) The same pattern applies to other types of defects that may not be exploited with quite the same high visibility. This type of scalability is inherent in software. <br /><br />If you're having trouble convincing your manager do devote resources to sanitizing your web facing application, or having trouble getting a budget to train your developers in secure coding techniques, consider sharing some of these links with your manager. <br /><br />This first one is a very clever web article by Gustavo Duarte, which demonstrates the attack using a simple online application built into the essay. Here you can see both the ease with which such defects can be exploited, and the relative complexity of the issues facing the defender. <br /> <a href="http://duartes.org/gustavo/articles/Hands-on-Sql-Injection.aspx">Hands-on SQL Injection</a> <br /><br />Here is some additional information on SQL Injections.<br /><a href="http://unixwiz.net/techtips/sql-injection.html">SQL Injection Attacks by Example</a><br /><br /><br /><br />Finally, here's an amusing cartoon that you can use to bring up the subject again, if you were given the smack down last time.<br /><a href="http://xkcd.com/327/">Exploits of a Mom (Little Bobby Drop Tables)</a><br /><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13178036-7865034482566402828?l=antiworm.blogspot.com'/></div>Gary W. Longsinehttp://www.blogger.com/profile/05653813520423954538gary.w.longsine@gmail.com1tag:blogger.com,1999:blog-13178036.post-78571589189927723362008-02-15T14:57:00.004-05:002008-02-15T15:16:31.799-05:00Microsoft Fingerprint Reader - The Fine Print<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_TBdWxFQAOeM/R7XwqO1-mvI/AAAAAAAAAA0/8oAM7CRc_gE/s1600-h/ms-fingerprint-reader.jpg"><img style="float:right; margin:0 0 10px 10px;cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_TBdWxFQAOeM/R7XwqO1-mvI/AAAAAAAAAA0/8oAM7CRc_gE/s320/ms-fingerprint-reader.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5167300755807181554" /></a><br />If you haven't noticed, somehow lately computer keyboards and laptops in the Windows PC world are sporting a little pad for reading fingerprints.<br /><br />Notice the fine print at the bottom of this page, which I'll quote here in case it goes away:<br /><br /><a href="http://www.microsoft.com/hardware/mouseandkeyboard/features/fingerprint.mspx">Microsoft Fingerprint Reader</a><br /><blockquote>"The Fingerprint Reader should not be used for protecting sensitive data such as financial information, or for accessing corporate networks. We continue to recommend that you use a strong password for these types of activities."</blockquote><br /><br />Why do you suppose Microsoft and all those hardware makers would go to all the trouble to add a fingerprint reader to laptops and keyboards, and then advise you not to use it?<br /><br />Probably because they know something that the average consumer probably doesn't: these devices can be spoofed.<br /><br />It's only a matter of time before there are clear, step by step instructions available on the internet for lifting a fingerprint and applying it to a model finger for spoofing purposes. Heck, there might be some online now, and I just haven't seen it yet.<br /><br /><a href="http://www.washjeff.edu/users/ahollandminkley/Biometric/index.html">Biometric Devices and Fingerprint Spoofing</a><br /><br /><a href="http://www.optel.pl/top.htm">Faking fingerprint readers (or other biometric devices)</a> - a collection of links and papers<br /><br /><a href="http://www.schneier.com/blog/archives/2005/09/fingerprint-loc.html">Failure of fingerprint locking system in prison in 2005</a><br /><br /><br />If you think about these things for a minute, you would never touch one without wearing a glove. Where is the digital fingerprint stored? That's right, on the same rootkit infested Windows PC prone to worm and virus attack.<br /><br />Will rootkits soon be intercepting the fingerprint data and adding that to your stolen profile information in that giant hacker database in the sky? You can bet they will, because you can be assured that not everybody read the fine print. These devices are so common on laptops now that there are undoubtedly some juicy bank accounts "protected" by the Microsoft Fingerprint Reader.<br /><br />The bad guys will have your biometric data in a database long before the FBI gets it done, because the bad guys do all this stuff with the lowest possible overhead. They just add another routine to their worm / virus / trojan / rootkit package and it flows out to all the zombie pc systems on the net that day. Since their data flows are mostly encrypted now-a-days, it might already be happening and we just haven't proven it yet.<br /><br />Friends don't let friends use fingerprint readers. At least not today, when they are so clearly pandering a false, and perhaps even criminally negligent, sense of security. The people selling these things ought to know better. Oh, that's right. They do know better. Hence the fine print.<div><br /></div><div>--</div><div>NOTE: Thanks to my good friend Joe S. in Tucson, Arizona for asking me, "would you touch one of these without a glove?"</div><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13178036-7857158918992772336?l=antiworm.blogspot.com'/></div>Gary W. Longsinehttp://www.blogger.com/profile/05653813520423954538gary.w.longsine@gmail.com3tag:blogger.com,1999:blog-13178036.post-14951565983433048622008-02-14T02:57:00.002-05:002008-02-15T17:25:33.865-05:00Rogue DNSI haven't seen the original paper, but this article claims that researchers at Google and Georgia Institute of Technology estimate that there are 68,000 rogue DNS servers on the net. <br /><br /><a href="http://www.physorg.com/news122144025.html">Use of Rogue DNS Servers on Rise</a><br /><br />Rogue DNS is one of the services provided by the zillions of malware, virus, worm, and rootkit infested zombie PC systems on the internet at any given time. The interesting part of this trick is that zombie PC systems might get "cleaned up" after an infestation has been detected, but their DNS configuration might (OK, probably does in nearly every case) remain pointing to a rogue DNS server, which occasionally, but not always, provides fraudulent data back to requesting clients. This is yet another reason why infested PC systems must be re-installed from clean original media whenever possible, in case you didn't have enough reasons already.<br /><br />The paper:<br /><br />Corrupted DNS Resolution Paths: The Rise of a Malicious Resolution Authority<br />David Dagon, Chris Lee, Wenke Lee - Georgia Institute of Technology; Niels Provos - Google Inc.<br /><br />was presented today at the annual <a href="http://www.isoc.org/isoc/conferences/ndss/08/">Network and IT Systems Symposium: NDSS 2008</a>.<br /><br />Better get cracking on DNSSec.<br /><a href="http://dnssec.net/">DNSSEC - DNS Security Extensions</a> <div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13178036-1495156598343304862?l=antiworm.blogspot.com'/></div>Gary W. Longsinehttp://www.blogger.com/profile/05653813520423954538gary.w.longsine@gmail.com0tag:blogger.com,1999:blog-13178036.post-90056339859050211512008-02-11T17:12:00.002-05:002008-02-15T15:20:49.933-05:00Swatting - 911 and telephony systems are defectiveSeveral publications are running stories this week about <a href="http://en.wikipedia.org/wiki/Swatting">Swatting</a>, an extension of a prank phone call, which has the aim of eliciting response from emergency response teams, including SWAT (Special Weapons and Tactics) teams. The prank calls are made to 911 operators, who are tricked into dispatching SWAT, police, or other response units on the basis of false information. Obviously social engineering is peformed as well, operators are told of bomb threats, killings or hostages. According to some accounts, some type of caller id spoofing might be used in some of the Swatting calls, which have been directed at 911 operators in over 60 cities by the five people arrested thus far.<br /><br />Several stories make a point to state that 911 systems are not defective, such as this otherwise excellent story, <a href="http://www.youtube.com/watch?v=LYAoPyyWYjQ&feature=related">Swatting - a dangerous new game</a> by KSBW TV in California which reports that the masochistic pranksters are not "exploiting any real technical flaws in the 911 system" and that these systems "are actually OK". It isn't necessary to know the intimate details to make a pretty safe bet that serious defects in the security of these systems do exist. <br /><br />Many of the calls were apparently placed using the assistance of computer systems, and the 911 operators were led to believe that the calls were local, despite their origin hundreds of miles away. That sure waddles and quacks like a defect. It's certainly possible that the defects exploited are in the underlying telephony systems, such as the Caller ID system, and not in the 911 system itself. However, if it can result in the 911 operator being unable to reliably determine the local vs. non-local origin of the call, it's a defect directly relevant to the 911 system as a functioning whole, and certainly a defect with the potential of being significantly reduced or eliminated, given some thought and effort.<br /><br />See this Wikipedia article for more information about <a href="http://en.wikipedia.org/wiki/Caller_ID_spoofing">Caller ID Spoofing</a>.<br /><br />According to widely publicized accounts, FBI agent Kevin Kolbye in Dallas indicated that Swatting seems at present to be a game played for bragging rights. The FBI and the Justice Department arrested and indicted folks a few months ago in Dallas, and made another announcement today. <br /><a href="http://dallas.fbi.gov/dojpressrel/pressrel07/fraud113007.htm">DOJ - Swatters plead guilty to conspiracy</a><br /><a href="http://www.upi.com/NewsTrack/Top_News/2008/02/04/fbi_catches_five_swatters/7930/">FBI Catches Five Swatters</a><br /><br />Swatting has the potential to be much more dangerous. As it stands, innocent people might be killed if they open their door to investigate suspicious noises with a weapon in their hand.<br /><br />It's a very short step from Swatting as a misguided or perverted game, to Swatting as a Denial of Service attack on emergency response units. A terrorist attack or other illicit activity might be coordinated with Swatting attacks, designed to slow response to the actual emergency, and thereby maximize damage, injury, and death from the attack, or increase the chances of a successful heist. <br /><br />I'm reminded of a scene from the movie Air Force One, where POTUS (President of the United States) played by Harrison Ford, must use an ordinary phone line to call into the White House from an "outside" line into the public switchboard. The operator doesn't believe it is the POTUS and he finally convinces her not of his identity, but to run her "standard" security procedure and trace the call, which works in record time and reveals that he is in fact calling from Air Force One. In our current telephony universe, things don't always work quite that smoothly. Imagine how much more difficult 911 calls would be, if you needed to convince the operator of your identity, location, and the fact that the emergency was real, before assistance was dispatched. <br /><br />Some of my colleagues design and build 911 systems. Undoubtedly Swatting will soon join the ranks of all-too-familiar terms in the field of information security.<div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13178036-9005633985905021151?l=antiworm.blogspot.com'/></div>Gary W. Longsinehttp://www.blogger.com/profile/05653813520423954538gary.w.longsine@gmail.com1tag:blogger.com,1999:blog-13178036.post-17453867081928030002007-06-16T12:24:00.000-05:002007-08-25T16:16:34.129-05:00Now Fear This: Phishers learn to craft a better spam emailPhishers appear to be using techniques learned from the targeted advertising industry. Security professionals have long wondered why phishing emails are, in general, so poorly crafted, and why they don't use a handful of basic techniques which would undoubtedly improve their hit rate, and lead to increased revenue generation from phishing. In the "Today @ PC World blog, Erik Larkin discusses an email which alarms the PC World analysts (see: <a href="http://blogs.pcworld.com/staffblog/archives/004662.html">Threat Alert: Sophisticated E-mail Attacks Spread</a> [PC World]). The email arrived with a well crafted text body which passed the usual "first glance" tests for spam or phishing: bad spelling, bad grammar, incorrect addressee name, mis-matched sender. It appeared to be a boring business email with a word document attached.<br /><br />Security researchers have known for many years that phishers typically don't employ a handful of techniques which would pretty clearly boost their success rates, techniques which are not entirely unknown in the related adware "industry". Today the following ideas might seem obvious, but it has only been recently that phishers show signs of interest in these techniques.<br /><br /><ol><li>Copy editing text and documents<br />Spam and phishing emails often contain many awkward phrases and other flaws which alert the intended victim that "something is amiss". Security researchers have long suspect that the simple step of using a word processor to perform spell checking and grammar checking the text of a phishing email would significantly increase the "hit rate" because many recipients cite poor grammar and spelling as the primary tip-off.</li><li>Matching the correct name to an email address for the recipient<br />Your email might be: "john.q.public@example.com"<br />but phishers and spammers will address their email to: "Sarah <john.q.public@example.com>"<br />rather than to the obvious: "John Q. Public <john.q.public@example.com>"</li><li>Internal consistency within the email of the spoofed sender<br />Spam and phishing often don't appear to be "From:" the same person who signed the bottom of the email.</li><li>Using modern software development tools and techniques to target their population of intended victims<br />Phishers often spam many millions of people with the same email. This allows anti-spam software both sufficient time and sufficient odds to capture, analyze, and block many, even the vast majority of those emails. If instead, phishers sent Wells Fargo phishing emails only to known Wells Fargo customers, then the time it takes to capture the emails goes up, and the number of potentially profitable victims (those with Wells Fargo accounts to be drained) who are reached in the critical first few days goes up, perhaps by a lot. Phishers and spammers have access to a great deal of data. They could use that data with the help of some custom software such as a web crawler, a few plugins to their existing bot, virus, and worm code, and a database, to dramatically improve their ability to target their phishing emails.</li></ol>Security researchers have pondered these issues for several years. Some of these steps are relatively simple, particularly as compared to some of the technical aspects of developing and managing a botnet without getting caught. Why don't phishers employ them?<br /><br />The answer, it has been thought, is simply that it wasn't necessary. Phishers were seeing a high enough hit rate and making enough money using their primitive spamming techniques. Spam was cheap to send, so sending millions of spam each time didn't cost them any more than sending a hundred spam. However, the techniques above required an expensive investment in software development.<br /><br />Once spam filtering became good enough, it was thought, phishers would probably see a hit to their income, and find it necessary to start improving these other aspects of their phishing systems.<br /><br />That time seems to have arrived. The big web mail providers, with a fire lit under them by competition from Google, have finally started to get better at spam filtering. Google and others are letting their users easily flag spam that does get through, and automatically feeding that back into their spam filters, thus protecting other users from spam and phishing.<br /><br />This has apparently spurred some spammers and phishers to start developing more advanced techniques for targeted spamming.<br /><br />Those techniques will include various ways to phish for the raw data which they can use to help map to other data already in their possession or collected in other ways. Phishers already have mountains of credit card numbers, stolen in various ways online, from compromised web servers like the recent TJX / TJMaxx incident, for example, but they may lack other details which make those numbers useful.<br /><br />Here is one recent example of such a data phishing email, and probably related scam, which I received in my inbox this morning. It made it past a few layers of very effective spam filtering.<br /><br />As you can see, the spelling and grammar of the email are not bad. Native speakers of English can pick out a few minor flaws, the most egregious of which I've noted by placing the correction in [] brackets immediately following the error. In general, however, this email is better crafted than many.<br /><br /><blockquote><hr />Attn:<br /><br />American Deaf Network has several projects planned and in the process, we [in process. We] also work along side National Organizations to build safer communities for those affected in these rural areas.<br /><br />American Deaf Network receives donations on a daily basses from all over the world. We are seeking your assistance to work for the foundation and get paid. We do not require your full time or effort<br /><br />All you will need to do is to receive donations on behalf of the foundation. Donation comes in Checks and Money Orders.<br />You will be paid a montly salary of $1,105.00. Please get back at us [get back to us] indicating your interest on making the world a better place for the deafs [the deaf].<br /><br />Send us the following information to immidiately process your application.<br /><br />First Name.<br /><br />Last Name.<br /><br />Address.<br /><br />Contact Phone<br /><br />Make sure you send the requested information to the below email.<br /><br />american_deaf2007@excite.com<br /><br />Have a nice day.<br /><br />American Deaf Network<br />30045 Alicia Parkway<br />#150 Laguna Niguel,<br />CA 92677 USA]<hr /></blockquote>The first thing I did upon receiving this was wonder if there was an organization silly enough to send out such an email. I thought it unlikely, but certainly not impossible. I Googled "American Deaf Network", and found only one reference to it, declaring it to be a scam, as suspected.<br /><br /><br />These two examples, from PC World and above, are undoubtedly the tip of what will be an iceberg of more sophisticated and polished phishing email scams.<br /><br />This is a new cycle in the phishing arms race.<br /><br />Additional details on the "proforma-invoice.doc email can be found here: <a href="http://www.avinti.com/proforma-invoice-malware.html">Avinti Security Briefing: Proforma Invoice</a> [Avinti.com].<br /><br /><!-- technorati tags start --><p style="text-align:right;font-size:10px;">Technorati Tags: <a href="http://www.technorati.com/tag/adware" rel="tag">adware</a>, <a href="http://www.technorati.com/tag/antivirus" rel="tag">antivirus</a>, <a href="http://www.technorati.com/tag/antiworm" rel="tag">antiworm</a>, <a href="http://www.technorati.com/tag/botnets" rel="tag">botnets</a>, <a href="http://www.technorati.com/tag/credit%20cards" rel="tag">credit cards</a>, <a href="http://www.technorati.com/tag/data%20broker" rel="tag">data broker</a>, <a href="http://www.technorati.com/tag/data%20loss" rel="tag">data loss</a>, <a href="http://www.technorati.com/tag/data%20security" rel="tag">data security</a>, <a href="http://www.technorati.com/tag/debit%20card" rel="tag">debit card</a>, <a href="http://www.technorati.com/tag/malware" rel="tag">malware</a>, <a href="http://www.technorati.com/tag/phishing" rel="tag">phishing</a>, <a href="http://www.technorati.com/tag/rootkit" rel="tag">rootkit</a>, <a href="http://www.technorati.com/tag/virus" rel="tag">virus</a>, <a href="http://www.technorati.com/tag/worm" rel="tag">worm</a></p><!-- technorati tags end --><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13178036-1745386708192803000?l=antiworm.blogspot.com'/></div>Gary W. Longsinehttp://www.blogger.com/profile/05653813520423954538gary.w.longsine@gmail.com0tag:blogger.com,1999:blog-13178036.post-45227336848740098992007-06-15T10:22:00.000-05:002007-06-15T10:24:53.001-05:00Identity Theft with a happy ending, sorta.The San Francisco Chronicle has an interesting tale describing how <a href="http://sfgate.com/cgi-bin/article.cgi?f=/c/a/2007/06/15/IDTHEFT.TMP">identity theft victim Karen Lodrick recognized a woman who had been using her stolen identity</a> in line at a Starbucks. She called 911 and pursued the woman, who was arrested, tried, convicted, and sentenced to time already served (44 days) plus probation. <br /><br />I'm curious about one of the details, however. Ms. Lodrick and apparently the police believe that her identity was stolen when the perpetrator stole unsolicited bank cards which "she had not requested". Were these unsolicited accounts? Probably not. They are described as "debit/credit cards" and other details of the story indicate that the cards were used to extract cash (or equivalent) from her accounts. Banks routinely send renewal cards to account holders. The term "unsolicited" in this context is typically not used to describe this situation. If the bank sent her a debit/credit card for an account that she didn't want such a card for, then the bank needs to evaluate its policies. <br /><!-- technorati tags start --><p style="text-align:right;font-size:10px;">Technorati Tags: <a href="http://www.technorati.com/tag/Banks" rel="tag">Banks</a>, <a href="http://www.technorati.com/tag/fraud" rel="tag">fraud</a>, <a href="http://www.technorati.com/tag/debit card" rel="tag">debit card</a>, <a href="http://www.technorati.com/tag/credit card" rel="tag">credit card</a>, <a href="http://www.technorati.com/tag/identity theft" rel="tag">identity theft</a>, <a href="http://www.technorati.com/tag/Karen Lodrick" rel="tag">Karen Lodrick</a>, <a href="http://www.technorati.com/tag/police" rel="tag">police</a></p><!-- technorati tags end --><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13178036-4522733684874009899?l=antiworm.blogspot.com'/></div>Gary W. Longsinehttp://www.blogger.com/profile/05653813520423954538gary.w.longsine@gmail.com1tag:blogger.com,1999:blog-13178036.post-33369664579979125502007-04-26T11:35:00.000-05:002007-04-26T11:41:01.576-05:00Class action bank lawsuit against TJX: When the levee breaksWell this may have seemed inevitable, but the uneasy truce between retail vendors and merchant banks (credit card providers) has broken. Banks are gearing up a massive class action suit against TJX, the parent company of TJ Maxx, which recently revealed the shocking extent of the break-in which resulted in the theft of 45 million credit card numbers and other data from their network. Forty million credit card numbers were stolen over a period of two years or more by crackers who had extensive access to systems handling sensitive data throughout that time. Investigations of consumer fraud revealed a pattern of exposure at TJ Maxx stores, leading in turn to discovery of the break-in. <br /><br /><a href="http://www.informationweek.com/news/showArticle.jhtml?articleID=199201456">Banks Hit TJ Maxx Owner With Class-Action Law Suit</a><br /><br />This is an interesting decision on the part of the banks, as the financial industry may one day find themselves on the receiving end of similar class action law suits brought about by other banks or consumer groups when data theft can be traced back to their own security foibles. <br /><br />In fact, the TJX event became the largest on record to date by displacing the 2005 cracking of CardSystems Solutions, a credit card transaction processing company who suffered a network intrusion which exposed 40 million credit card accounts. (<a href="http://www.nytimes.com/2005/06/22/technology/22cards.html?ex=1177732800&en=e371c36debf1544e&ei=5070">Regulators Start Inquiry in Data Loss</a>)<br /><br /><br /><blockquote><br />If it keeps on rainin' levee's goin' to break <br />If it keeps on rainin' levee's goin' to break <br />When The Levee Breaks, got no place to stay. <br />-- Led Zeppelin<br /></blockquote><br /><br /><br /><br /><!-- technorati tags start --><p style="text-align:right;font-size:10px;">Technorati Tags: <a href="http://www.technorati.com/tag/antivirus" rel="tag">antivirus</a>, <a href="http://www.technorati.com/tag/antiworm" rel="tag">antiworm</a>, <a href="http://www.technorati.com/tag/fraud" rel="tag">fraud</a>, <a href="http://www.technorati.com/tag/malware" rel="tag">malware</a>, <a href="http://www.technorati.com/tag/class action" rel="tag">class action</a>, <a href="http://www.technorati.com/tag/TJX" rel="tag">TJX</a>, <a href="http://www.technorati.com/tag/TJ Maxx" rel="tag">TJ Maxx</a>, <a href="http://www.technorati.com/tag/banks" rel="tag">banks</a>, <a href="http://www.technorati.com/tag/rootkit" rel="tag">rootkit</a>, <a href="http://www.technorati.com/tag/credit cards" rel="tag">credit cards</a>, <a href="http://www.technorati.com/tag/identity theft" rel="tag">identity theft</a>, <a href="http://www.technorati.com/tag/spyware" rel="tag">spyware</a>, <a href="http://www.technorati.com/tag/SSN" rel="tag">SSN</a>, <a href="http://www.technorati.com/tag/virus" rel="tag">virus</a>, <a href="http://www.technorati.com/tag/worm" rel="tag">worm</a>, <a href="http://www.technorati.com/tag/zero day worm" rel="tag">zero day worm</a></p><!-- technorati tags end --><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13178036-3336966457997912550?l=antiworm.blogspot.com'/></div>Gary W. Longsinehttp://www.blogger.com/profile/05653813520423954538gary.w.longsine@gmail.com0tag:blogger.com,1999:blog-13178036.post-1162847108625221732006-11-06T15:57:00.000-05:002006-11-06T18:48:45.480-05:00Punchscan voting systemThere has been a great deal of discussion about voting systems in the security community following the well documented problems with electronic voting systems in recent American elections, notably those of 2000 and 2004. A new system promises dramatic improvements in the security of voting systems. The <a href="http://punchscan.org/index.php">Punchscan voting system</a> looks like a big step in the right direction.<br /><br />For background information, see this primer by Bruce Schneier on <a href="http://www.schneier.com/blog/archives/2004/11/the_problem_wit.html">The Problem with Electronic Voting Machines</a>.<br /><br />To strike an even bigger blow for democracy, the Punchscan system should be extended so that it can support <a href="http://en.wikipedia.org/wiki/Instant-runoff_voting">Instant Runoff Voting (aka Ranked Choice Voting)</a>.<br /><br /><br /><!-- technorati tags start --><p style="text-align:right;font-size:10px;">Technorati Tags: <a href="http://www.technorati.com/tag/democracy" rel="tag">democracy</a>, <a href="http://www.technorati.com/tag/election" rel="tag">election</a>, <a href="http://www.technorati.com/tag/encryption" rel="tag">encryption</a>, <a href="http://www.technorati.com/tag/punchscan" rel="tag">punchscan</a>, <a href="http://www.technorati.com/tag/voting" rel="tag">voting</a></p><!-- technorati tags end --><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13178036-116284710862522173?l=antiworm.blogspot.com'/></div>Gary W. Longsinehttp://www.blogger.com/profile/05653813520423954538gary.w.longsine@gmail.com0tag:blogger.com,1999:blog-13178036.post-1151620054948521222006-06-29T17:22:00.000-05:002006-06-29T17:36:34.740-05:00tip of the data loss iceberg: worms == automated large scale intrusions Recently there have been a spate of incidents in which U.S. federal government agencies reported data theft or loss, particularly data which could result in identity theft. The losses include the contact information and social security numbers of, literally, millions of federal employees and contractors. Most of these recent incidents were the result of stolen laptop hardware, USB Key fobs, or other computer hardware, although at least two involved unspecified intrusions (electronic theft of the data following a break-in to an online system). <br /><br />In the past several months, as the reports of stolen servers, hard drives, laptops, and USB key fobs have mounted, I've only seen two disclosed instance of an intrusion (in one case apparently targeted) which resulted in the theft of identity data concerning 1,502 people at the Department of Energy: <a href="http://www.gcn.com/print/25_16/41047-1.html">Energy ups security efforts after loss of employee data</a> and 26,000 people at the Department of Agriculture: <a href="http://www.securityfocus.com/brief/235">U.S. Department of Agriculture hacked</a>. Despite the sparse reports of such intrusions, we know that government PC systems are not uniquely protected from these threats. <br /><br />Although it hasn't been reported, there is ample reason to believe that significant data loss has also occurred over the past several years through worm, botnet, spyware, trojan and rootkit infestations. Such malware routinely scans the infected PC and mounted network drives or shares and uploads files and data into the arms of organized crime. This type of loss is harder for organizations to detect and remains underreported as a result. However, it has has undoubtedly resulted in many more exposures of similar magnitude than have theft of laptops. <br /><br />Many tens of thousands of computers in government agencies are infected with worms, bots, adware, spyware, viruses, trojans, and rootkits every year. The infection rates of many government agencies are not radically different from private industry. <br /><br />Why do we see so few reports about data loss from these types of large scale intrusions? <br /><br />The difference is that when a laptop is stolen, a bit of government-owned equipment goes missing. This produces a few unique circumstances that malware infections don't produce. Missing hardware:<br /><ul><br /><li> can't be ignored due to strict property accounting requirements,</li><br /><li> can't be denied due to the loss of a physical device,</li><br /><li> and is more easily understood by all levels of oversight and management.</li><br /></ul><br /><br />If hardware went missing, and bad guys have the hardware, they have the data that was on the hardware, too. People understand that.<br /><br />Malware infections on the other hand (really, these are often large scale intrusions) are complex, involving many layers of abstraction. Just mitigating the spread and cleaning up often consumes all available resources of a given IT shop, and when the cleanup is over, they are crushed under the catch-up load of the regular duties which were postponed to battle the worm, bot or other malware. Analysis is often limited to finding and plugging the security hole that let the malware in. Few organizations have the ability to demonstrate conclusively that a worm uploaded files to a remote server. Worms and botnets have begun using encrypted tunnels, so even if organizations have the ability today, it won't be effective for very much longer.<br /><br />We were able to uncover evidence of a large scale intrusion at a customer last year. It was clear that from the earliest moments of the outbreak remote attackers were under direct control of the infected PC systems on our Federal client's network. It was also clear that the techniques used were well-honed. Our client faced several variants of a particular worm within a short span of time, and one of those variants had a defect. Were it not for the defect, there would have been no direct evidence. Most of the time with automated large scale intrusions like worms and botnets, it's very easy for weary IT staff to assume that no real damage was done. The complexity of the attacks makes it easy for management and oversight to ignore the problem, too.<br /><br />Many tens of thousands of infected PC systems are cleaned up each year on government networks. Those systems include servers and desktop and laptop computers with large amounts of valuable and sensitive data. The organizations performing the cleanup are understaffed and overworked and typically don't have the skills, processes, tools, and budgeted time in place to analyze the data loss which occurred. <br /><br />Consequently, the problem is even bigger than it seems from the recent headlines. <br /><br /><br /><br /><br /><!-- technorati tags start --><p style="text-align:right;font-size:10px;">Technorati Tags: <a href="http://www.technorati.com/tag/adware" rel="tag">adware</a>, <a href="http://www.technorati.com/tag/antivirus" rel="tag">antivirus</a>, <a href="http://www.technorati.com/tag/antiworm" rel="tag">antiworm</a>, <a href="http://www.technorati.com/tag/data loss" rel="tag">data loss</a>, <a href="http://www.technorati.com/tag/data security" rel="tag">data security</a>, <a href="http://www.technorati.com/tag/identity theft" rel="tag">identity theft</a>, <a href="http://www.technorati.com/tag/malware" rel="tag">malware</a>, <a href="http://www.technorati.com/tag/rootkit" rel="tag">rootkit</a>, <a href="http://www.technorati.com/tag/security" rel="tag">security</a>, <a href="http://www.technorati.com/tag/spyware" rel="tag">spyware</a>, <a href="http://www.technorati.com/tag/worm" rel="tag">worm</a>, <a href="http://www.technorati.com/tag/zero day worm" rel="tag">zero day worm</a></p><!-- technorati tags end --><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13178036-115162005494852122?l=antiworm.blogspot.com'/></div>Gary W. Longsinehttp://www.blogger.com/profile/05653813520423954538gary.w.longsine@gmail.com0tag:blogger.com,1999:blog-13178036.post-1151509672446985602006-06-28T10:42:00.000-05:002006-06-29T16:57:25.920-05:00OMB laptop security guidelines: implications for transparency in government?Within a few years it's possible that encryption will be the norm in government data storage, and probably large organizations, too. The historical inevitability of this process was given a boost recently. The OMB has provided guidance requiring Federal agencies to take the security of desktop and laptop systems more seriously (see: <a href="http://www.washingtonpost.com/wp-dyn/content/article/2006/06/27/AR2006062700540.html">OMB Sets Guidelines for Federal Employee Laptop Security</a>)in the wake of recent disclosure of several massive losses of data which could lead to identity <a href="http://www.consumer.gov/idtheft/">identity theft</a>.<br /><br />Here are a few stories describing recent incidents which have prompted the concern and gained the attention of the OMB:<br /><a href="http://www.washingtonpost.com/wp-dyn/content/article/2006/06/23/AR2006062301493.html">Navy Finds Data on Thousands of Sailors on Web Site</a><br /><a href="http://www.theregister.co.uk/2006/04/18/afghan_market_security_breach/">Afghan market sells US military flash drives</a><br /><a href="http://www.foxnews.com/story/0,2933,200724,00.html?sPage=business.foxnews/pe">FTC Loses Personal Data on Identity-Theft Suspects</a><br /><a href="http://www.theregister.co.uk/2006/05/23/va_data_security_breach/">US veterans' data exposed after burglary</a><br /><a href="http://www.securityfocus.com/news/11393">Veterans Affairs warns of massive privacy breach</a><br /><a href="http://www.foxnews.com/story/0,2933,199465,00.html">Officials: Veterans Affairs Department Ignored Repeated Warnings on Data Security</a><br /><a href="http://www.firstgov.gov/veteransinfo.shtml">Latest Information on Veterans Affairs Data Security</a><br />Additional background reading on the recent OBM security guidance: <a href="http://www.gcn.com/print/23_15/26276-1.html">OMB targets desktop hole in cybersecurity</a><br /><br />Before we leap headlong into encrypting everything in the government, however, we should really ponder the technology and its other implications. Earlier this week, President Bush chastised the North Koreans, who have been preparing to test an ICBM (Intercontinental Ballistic Missile), saying that it is worrisome that a "<a href="http://www.globalsecurity.org/wmd/library/news/dprk/2006/dprk-060621-voa01.htm">non-transparent regime</a>" is developing such a capability. Transparency in government is a valued characteristic of modern democratic governments. <br /><br />Consider, however, that even in a modern democracy there exists a tension between disclosure and transparency on the one hand, and the desire of government organizations to restrict information flow for a variety of purposes on the other. Also this week, the disclosure of further domestic spying activity highlights that very issue. <br /><br />More directly, even one of the agencies hit by recent data theft ran aground on the sand bar of public relations spin control run amok: <a href="http://edition.cnn.com/2006/US/05/23/vets.data/">Source: Theft of vets' data kept secret for 19 days</a>. <br /><br />At least some organizations will opt to encrypt most data in most databases, most documents, and most filesystems, because it will be easier and cheaper to comply with directives like this by defaulting to encrypted storage for everything than it will be to analyze this mountain of content to determine if it should be encrypted or not. (Most of the stolen data that upsets people is personnel data, which is "sensitive but unclassified," for example.)<br /><br />Although this may help prevent massive loss of data as seen recently, it might also reduce transparency in government. It may well be legitimately more difficult and expensive to satisfy a FOIA (Freedom of Information Act) request for organizations which rely on office documents and distributed (ad-hoc) content creation and storage. Most policy setting organizations do exactly that.<br /><br />The recent OBM guidance is a welcome step in helping to limit the damage. (It should also be noted that encrypted storage doesn't completely solve this problem, as people tend to leave passwords laying about in plain text files to help them access their protected data, and passwords can be cracked with common tools, given sufficient CPU power and time to perform the crack.)<br /><br />Congress should consider the implications of encryption as a response to data theft problems upon the desirable characteristic of transparency in governance, and should attempt to mitigate the potential damage to transparency before it occurs. They might require that all encrypted archvies be searchable, for example, similar to the way email applications search encrypted mail files. Some thought on this issue would undoubtedly produce a few basic guidelines which would help preserve transparency in governance. <br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><!-- technorati tags start --><p style="text-align:right;font-size:10px;">Technorati Tags: <a href="http://www.technorati.com/tag/Afghanistan" rel="tag">Afghanistan</a>, <a href="http://www.technorati.com/tag/arms control" rel="tag">arms control</a>, <a href="http://www.technorati.com/tag/Army" rel="tag">Army</a>, <a href="http://www.technorati.com/tag/data loss" rel="tag">data loss</a>, <a href="http://www.technorati.com/tag/data security" rel="tag">data security</a>, <a href="http://www.technorati.com/tag/encryption" rel="tag">encryption</a>, <a href="http://www.technorati.com/tag/identity theft" rel="tag">identity theft</a>, <a href="http://www.technorati.com/tag/North Korea" rel="tag">North Korea</a>, <a href="http://www.technorati.com/tag/OMB" rel="tag">OMB</a>, <a href="http://www.technorati.com/tag/rootkit" rel="tag">rootkit</a>, <a href="http://www.technorati.com/tag/security" rel="tag">security</a>, <a href="http://www.technorati.com/tag/spyware" rel="tag">spyware</a>, <a href="http://www.technorati.com/tag/transparency" rel="tag">transparency</a>, <a href="http://www.technorati.com/tag/Trojan" rel="tag">Trojan</a>, <a href="http://www.technorati.com/tag/USB" rel="tag">USB</a>, <a href="http://www.technorati.com/tag/USDA" rel="tag">USDA</a>, <a href="http://www.technorati.com/tag/veterans affairs" rel="tag">veterans affairs</a>, <a href="http://www.technorati.com/tag/virus" rel="tag">virus</a>, <a href="http://www.technorati.com/tag/worm" rel="tag">worm</a></p><!-- technorati tags end --><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13178036-115150967244698560?l=antiworm.blogspot.com'/></div>Gary W. Longsinehttp://www.blogger.com/profile/05653813520423954538gary.w.longsine@gmail.com0tag:blogger.com,1999:blog-13178036.post-1150519600728040022006-06-16T23:42:00.000-05:002006-06-26T15:34:19.943-05:00Microsoft Excel exploit: Let's be careful out there?A new zero-day exploit of Microsoft Excel has me pondering a standard bit of security advice, "be careful what you click." This <a href="http://en.wikipedia.org/wiki/Meme">meme</a> survives to be repeated at nearly every outbreak, yet it simply isn't very effective.<br /><br />You've probably seen a story or blog post about this already, but in case you haven't here's the alert from the Microsoft technet blog which got me thinking:<br /> <br /><blockquote><a href="http://blogs.technet.com/msrc/default.aspx">Reports of new vulnerability in Microsoft Excel</a><br />" In order for this attack to be carried out, a user must first open a malicious Excel document that is sent as an email attachment or otherwise provided to them by an attacker. (note that opening it out of email will prompt you to be careful about opening the attachment) So remember to be very careful opening unsolicited attachments from both known and unknown sources."</blockquote><br /><br />Many online article and blog postings repeated this advice, unquestioningly. Some folks even praised it, including the respected security professional Brian Krebs. In his post about the issue at the <a href="http://blog.washingtonpost.com/securityfix/">Security Fix</a> blog, he says it's "always good advice" that one be very careful opening unsolicited attachments.<br /><br />Recently similar advice was given to users of various Instant Messaging systems, as a "worm" affected users of Yahoo's system. In fact, the "worm" required the user to click it, meaning that its spread couldn't possibly achieve the "every vulnerable machine got hit" levels of a real automatically propagating network worm. <br /><br />However, these Instant Message viruses and email viruses can affect large numbers of systems in a short amount of time. A year or so ago I saw an outbreak of an email virus hit 1.5% of the systems at a large customer. It hit so many people (over 500) so fast (within an hour or two) that we at first thought it was exploiting an automatic execution hole in the email client. In fact, it had just been a little more clever than average at social engineering—tricking people to click it.<br /><br />I briefly interviewed a few of the victims, some of whom were trained IT professionals, who spent a lot of time during the course of the year explaining to users that they shouldn't click unexpected attachments. Well, the virus in question was somewhat clever. It nearly always appeared to be from someone you know. It sent an attachment which appeared to be a spreadsheet (it was instead an executable virus). It used cleverly mundane subject lines. <br /><br />Nearly all of the victims had received a virus pretending to be a spreadsheet which appeared to be from someone that they regularly receive a spreadsheets from via email.<br /><br />How careful must people be? Scanning a file first wouldn't have protected the victim against zero-day threats like the current Excel threat. <br /><br />We give the same advice to people about web surfing. Be careful where you surf, be careful what you click. It doesn't work there, either. Corporate and home PCs alike see anywhere from 1% to 20% ambient levels of adware and spyware infestation. <br /><br />But the web is a treasure trove of useful and wonderful things you might never discover if, sometimes, you don't click with essentially reckless abandon. <br /><br />The sentiment is pure, but most users are not able to easily tell what to click from what to avoid. Only the most rudimentary of email viruses or phishing can most people filter out at a glance. <br /><br />I've given this advice myself many times, trying to carefully explain how to tell good from bad emails, and good from bad free downloads. I think in general the advice hasn't been helpful to most people most of the time. High levels of ongoing infestation from adware and spyware, widespread damage from Instant Message "worms" and rampant identity theft all tell us that the advice isn't working.<br /><br /><br /><br /><br /><!-- technorati tags start --><p style="text-align:right;font-size:10px;">Technorati Tags: <a href="http://www.technorati.com/tag/adware" rel="tag">adware</a>, <a href="http://www.technorati.com/tag/antivirus" rel="tag">antivirus</a>, <a href="http://www.technorati.com/tag/antiworm" rel="tag">antiworm</a>, <a href="http://www.technorati.com/tag/identity theft" rel="tag">identity theft</a>, <a href="http://www.technorati.com/tag/malware" rel="tag">malware</a>, <a href="http://www.technorati.com/tag/security" rel="tag">security</a>, <a href="http://www.technorati.com/tag/spyware" rel="tag">spyware</a>, <a href="http://www.technorati.com/tag/virus" rel="tag">virus</a>, <a href="http://www.technorati.com/tag/Windows" rel="tag">Windows</a>, <a href="http://www.technorati.com/tag/worm" rel="tag">worm</a>, <a href="http://www.technorati.com/tag/zero day worm" rel="tag">zero day worm</a></p><!-- technorati tags end --><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13178036-115051960072804002?l=antiworm.blogspot.com'/></div>Gary W. Longsinehttp://www.blogger.com/profile/05653813520423954538gary.w.longsine@gmail.com1tag:blogger.com,1999:blog-13178036.post-1149832593237774552006-06-09T00:51:00.000-05:002006-06-26T16:08:06.776-05:00Beware of Your AuditorsSecurity Auditors can be a clever lot, sometimes a bit too clever. You really need to have someone on staff looking over their shoulder throughout the entire audit, from planning through probing, and reporting. If you don't have someone on staff qualified to watch them, you need an independent consultant. A very sharp generalist would do, but someone experienced in security would be better. Basically you need a check and balance system in place, to keep stories like the following from happening to your organization. <br /><br />First the context. The auditors created a custom Trojan, planted it in amidst various other files on USB drives, and seeded them in parking lots and areas of the client's work area where they would likely be discovered by customers. Which, of course, they were. Here's what they say about the experience:<br /><br /><a href="http://www.darkreading.com/document.asp?doc_id=95556&WT.svl=column1_1">Social Engineering, the USB Way</a><br /><blockquote><em>I had one of my guys write a Trojan that, when run, would collect passwords, logins and machine-specific information from the user’s computer, and then email the findings back to us.<br />...<br />I immediately called my guy that wrote the Trojan and asked if anything was received at his end. Slowly but surely info was being mailed back to him.<br />...<br />After about three days, we figured we had collected enough data. When I started to review our findings, I was amazed at the results. Of the 20 USB drives we planted, 15 were found by employees, and all had been plugged into company computers. The data we obtained helped us to compromise additional systems, and the best part of the whole scheme was its convenience. We never broke a sweat. Everything that needed to happen did, and in a way it was completely transparent to the users, the network, and credit union management.</em></blockquote><br /><br />Yes, you read that right. Their custom trojan emailed the client's account names and passwords and other (presumably important) data out to the auditors' off-site email accounts.<br /><br />Now, unless these guys put rather a lot more effort into their custom trojan than they described, email is a plain text protocol. So, any fifteen year old kid with a summer job sitting on a router or an SMTP gateway at an ISP between the client and the auditor's email basket can read that email. <br /><br />Of course, it's possible the trojan was equipped with an X.509 certificate and encryption system, but it seems to me that if the auditors had thought of this, they would have mentioned it. It would have been a source of pride. For either forgetting to encrypt the data, or failing to mention it in their storytelling, they will undoubtedly be punished by the flood of email they are bound to get from every GSEC and CISSP certified security analyst on the planet. <br /><br />I don't want to be too critical, because they seem to have the best intentions, and their effort served to illustrate a point that clients often don't take seriously -- USB drives really can be dangerous, even if you don't inhale one. However, in their excitement to put the clever idea to the test, these auditors seem to have overlooked one important layer of the security cake and the important dictum, useful to all consultants, "<a href="http://www.geocities.com/everwild7/noharm.html">first, do no harm</a>."<br /><br />Of course, this isn't the most egregious error ever committed by an auditor. Far from it, in fact. I've personally seen Auditor's laptops spewing worm traffic on a client's network. Of course, it's likely that the auditor's systems were infected by a worm on the client's network, rather than the other way around, but running 3 systems known to be vulnerable to the same defect that they were spanking the client for was, pardon the pun, an oversight. <br /><br />In the last year or so, several incidents of auditors losing valuable client data including identity information have been reported, notably more than once incident involving <a href="http://www.theregister.co.uk/2006/06/01/ey_hotels_laptop/">Ernst & Young</a>.<br /><br />So, have someone on your staff work closely with the auditors as a sponsor of the audit, or have an independent consultant watching over their shoulder for you. People sometimes get carried away in their exuberance to do great work, and other times are following bureaucratic procedures that just don't make sense. In either case, your sponsor should have veto power over any actions during the audit, to protect your data from accidental exposure.<br /><br />In case you're wondering, you don't need an "auditor for the auditor for the auditor" up an infinite chain. What we're really talking about here is a sponsor with veto power who isn't part of the audit team. This kind of outside watchdog can break the pattern of groupthink that causes people to run off with a half-baked idea and accidentally expose the data they are ostensibly trying to help you protect.<br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><!-- technorati tags start --><p style="text-align:right;font-size:10px;">Technorati Tags: <a href="http://www.technorati.com/tag/antivirus" rel="tag">antivirus</a>, <a href="http://www.technorati.com/tag/auditor" rel="tag">auditor</a>, <a href="http://www.technorati.com/tag/security" rel="tag">security</a>, <a href="http://www.technorati.com/tag/Trojan" rel="tag">Trojan</a></p><!-- technorati tags end --><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13178036-114983259323777455?l=antiworm.blogspot.com'/></div>Gary W. Longsinehttp://www.blogger.com/profile/05653813520423954538gary.w.longsine@gmail.com0tag:blogger.com,1999:blog-13178036.post-1145329365982605702006-04-17T21:59:00.000-05:002006-04-25T09:11:29.593-05:00McAfee out of ideas - blames internet for rootkits. The recent article <a href="http://www.networkworld.com/news/2006/041706-open-source-rootkits.html">Does open source encourage rootkits? [NetworkWorld]</a> discusses a McAfee report, "Rootkits", in which McAfee lays the blame for rootkits at the door of the open source community by name, security researchers by implication, and unwittingly at the very doorstep of information sharing -- books, libraries, and printed material. The report was issued due to a large jump in the number of rootkits they detected (nine times as many this quarter as the year ago quarter - a dramatic increase). They specifically blame <a href="http://rootkit.com">rootkit.com</a>.<br /><br />The unstated basis for their argument is a classic tension between open sharing of information about security vulnerabilities on the one hand and secret cabals of security research on the other. McAfee is clearly coming down for the "keep it secret to be safe" camp. Most independent security researchers reject this argument, because industry has a very long track record of totally ignoring security issues until they are made public. Most researchers also practice a policy of advanced notification -- give the vendor a reasonable notice before publishing the findings to the world and attempt to work with them so that a fix is available when the notice is published. However, the threat of publication is sometimes the only thing that motivates software companies to fix security problems. <br /><br />Blaming open source, web sites, and information sharing by implication is misguided. <br /><br />The folks who are writing the real malware could (and do) use secret members-only web sites to share ideas and code and whatnot in their pursuit of malfeasance. It's better for the community of researchers to have open sites sharing these ideas.<br /><br />The fact is that you don't need a web site. There are books that do a pretty good job of explaining how rootkits work and how to build them. Are libraries now to blame? Is the publishing division of McAfee's competitor, Symantec Press to blame? (<a href="http://www.awprofessional.com/title/0321304543"> The Art of Computer Virus Research and Defense</a>). <br /><br />No. Information sharing is not to blame. Symantec is not to blame (at least not in this respect). Books are not to blame. The internet isn't to blame, web sites are not to blame, security researchers are not to blame. <br /><br />I wonder if instead we can attribute the continuing and expensive thorn of malware to humanity's continuing struggle to ride a rapid wave of expanding technology while simultaneously attempting to preserving civil liberties and limit the destruction and damage that can be caused by Evil Doers(TM)? Frankly, we're not very good at it, and we will soon face analogous problems in the much more serious realm of biological engineering. Recall that open source specifications for the 1918 influenza have already been published. We need to get better at this stuff pretty quick, because the clock is ticking. The information genie can't be put back in the bottle, we had better figure out how to tame it.<br /><br />* NOTE: Evil Doers is a Trademark of The Bush Administration. <br /><br /><br /><!-- technorati tags start --><p style="text-align:right;font-size:10px;">Technorati Tags: <a href="http://www.technorati.com/tag/adware" rel="tag">adware</a>, <a href="http://www.technorati.com/tag/antivirus" rel="tag">antivirus</a>, <a href="http://www.technorati.com/tag/antiworm" rel="tag">antiworm</a>, <a href="http://www.technorati.com/tag/botnets" rel="tag">botnets</a>, <a href="http://www.technorati.com/tag/identity theft" rel="tag">identity theft</a>, <a href="http://www.technorati.com/tag/malware" rel="tag">malware</a>, <a href="http://www.technorati.com/tag/rootkit" rel="tag">rootkit</a>, <a href="http://www.technorati.com/tag/puppy" rel="tag">puppy</a>, <a href="http://www.technorati.com/tag/spyware" rel="tag">spyware</a>, <a href="http://www.technorati.com/tag/Windows" rel="tag">Windows</a></p><!-- technorati tags end --><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13178036-114532936598260570?l=antiworm.blogspot.com'/></div>Gary W. Longsinehttp://www.blogger.com/profile/05653813520423954538gary.w.longsine@gmail.com3tag:blogger.com,1999:blog-13178036.post-1150520491658360632006-04-17T18:22:00.000-05:002006-06-17T00:01:31.663-05:00Cyberstalking & identity theftThe New York Times today features an interesting article today, "<a href="http://www.nytimes.com/2006/04/17/technology/17stalk.html?_r=1&oref=slogin&pagewanted=all">A Sinister Web Entraps Victims of Cybrerstalking</a>" [annoying but free registration probably required].<br /><br />The article does a nice job of describing the problem, but it doesn't say much about how to protect yourself. Unfortunately, it's pretty difficult. <br /><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13178036-115052049165836063?l=antiworm.blogspot.com'/></div>Gary W. Longsinehttp://www.blogger.com/profile/05653813520423954538gary.w.longsine@gmail.com0tag:blogger.com,1999:blog-13178036.post-1142479507188169592006-03-15T22:22:00.000-05:002006-03-25T11:51:38.523-05:00Identity Theft and the Torn Up Credit Card ApplicationYou should never throw out any piece of paper with any contact information on it. Any such papers should be shredded, rather than tossed out. In particular, never throw out credit card statements, always shred them, preferably in a cross-cut shredder.<br /><br />If you are not taking the risk of identity theft seriously, this article on "<a href="http://www.cockeyed.com/citizen/creditcard/application.shtml">The Torn Up Credit Card Application</a>" should strike an appropriate amount of fear, just enough to convince you to buy a small home-office shredder.<br /><br /><br /><br /><br /><!-- technorati tags start --><p style="text-align:right;font-size:10px;">Technorati Tags: <a href="http://www.technorati.com/tag/identity theft" rel="tag">identity theft</a></p><!-- technorati tags end --><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13178036-114247950718816959?l=antiworm.blogspot.com'/></div>Gary W. Longsinehttp://www.blogger.com/profile/05653813520423954538gary.w.longsine@gmail.com1tag:blogger.com,1999:blog-13178036.post-1142456505250250812006-03-15T15:59:00.000-05:002006-03-18T13:35:08.710-05:00Virus Vulnerability for RFID (Radio Frequency ID tags)?The breeding ground for the computer virus will be expanding continually and rapidly over the next decade as appliances, automobiles, and all manner of other things become equipped with wireless networking and miniature computers. Cell phone and similar networks may enable worms to leap between devices over long distances and other networks over short distances.<br /><br />Researchers have recently demonstrated that RFID tags may be vulnerable next.<br /><br />Articles on the topic:<br /><a href="http://www.newscientist.com/article/dn8854-rfid-worm-created-in-the-lab.html">RFID worm created in the lab [NewScientist.com]</a><br /><a href="http://news.bbc.co.uk/2/hi/technology/4810576.stm">Viruses leap to smart radio tags [BBC.co.uk]</a><br /><a href="http://www.securityfocus.com/brief/163">RFID tags could carry computer viruses [SecurityFocus.com]</a><br /><br />The details for the curious:<br /><a href="http://www.rfidvirus.org/index.html">RFID Viruses and Worms</a><br /><br />The AntiVirus paradigm that we [the IT community and industry] have foisted upon PC users is already breaking down under the strain of too many virus variants and too many non-technical PC users. The paradigm probably won't work at all for cell phones and the paradigm is completely broken for the typical RFID device which typically lack an end user administration interface of any kind. <br /><br />The AntiVirus paradigm was invented for Enterprise users who were expected to be paid to devote time to protecting a valuable asset, and technical hobbyist users who loved tweaking their PC. It's not designed for users who want to use their PC as a simple household tool, like a television or a refrigerator. <br /><br />The stuff people want to do with RFID technologies is truly amazing. It starts with automating inventory in retail stores, but goes all the way down to things like "washable RFID tags equipped with sensors on all my clothes will allow me to check to see if my favorite suit is at the cleaners, at home in the laundry bag, or at home ready to wear" and "RFID tags will enable my home pantry to let me check from work to see if I have all the ingredients needed to bake a birthday cake, or if I need to stop at the store on my way home". <br /><br />If this stuff is going to work, we will need to be careful that we don't turn the average home into the administrative nightmare that is the average enterprise network. RFID would flop because consumers can't afford to hire an IT staff to maintain IDS and AntiVirus systems for their pantry, wardrobe, stereo, library and toolshed. <br /><br /><br /><br /><br /><!-- technorati tags start --><p style="text-align:right;font-size:10px;">Technorati Tags: <a href="http://www.technorati.com/tag/adware" rel="tag">adware</a>, <a href="http://www.technorati.com/tag/antivirus" rel="tag">antivirus</a>, <a href="http://www.technorati.com/tag/antiworm" rel="tag">antiworm</a>, <a href="http://www.technorati.com/tag/botnets" rel="tag">botnets</a>, <a href="http://www.technorati.com/tag/RFID" rel="tag">RFID</a>, <a href="http://www.technorati.com/tag/virus" rel="tag">virus</a>, <a href="http://www.technorati.com/tag/worm" rel="tag">worm</a></p><!-- technorati tags end --><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13178036-114245650525025081?l=antiworm.blogspot.com'/></div>Gary W. Longsinehttp://www.blogger.com/profile/05653813520423954538gary.w.longsine@gmail.com5tag:blogger.com,1999:blog-13178036.post-1142266990828540862006-03-13T11:22:00.000-05:002006-03-13T11:25:06.593-05:00McAfee AntiVirus false positives - older, "reliable" signatures pose risk tooFalse positives are the bane of AntiVirus and IDS/IPS systems. On the one hand, hundreds and even thousands of new threats are released each week, where they must be discovered, submitted to vendors, analyzed by vendors, definitions, signature files or heuristic algorithms must be tweaked, tested, released to customers, and finally deployed to customer systems. All of this must be done in as short a time as possible, since the threats often spread in minutes and hours. AntiVirus signatures are often available within two days from the first appearance of a threat on the network. Polymorphic techniques, even simple ones like automatically generating dozens or more variants at the threat's compile time, are becoming more common making it more difficult for AntiVirus vendors to keep up with the expanding threat pool every year.<br /><br />Today we learned that an error in a signature file caused the McAfee AntiVirus system to delete good files from production systems. This unfortunate accident affected at least a hundred of their customers and probably thousands of PC systems. The final tally of affected systems probably won't be announced. (A similar problem recently caused <a href="http://news.com.com/Microsoft+flagged+Symantec+software+as+spyware/2100-1002_3-6038852.html?tag=nl">Microsoft AntiSpyware to zap Symantec AntiVirus from systems</a>.)<br /><br />This incident is receiving more press attention than they usually do. The real wonder is that things like this don't happen more often.<br /><br /><a href="http://news.com.com/McAfee+update+exterminates+Excel/2100-1002_3-6048709.html?tag=nefd.hed">McAfee update exterminates Excel</a><br /><blockquote>Such problems with security software are called false positives and they happen occasionally. McAfee typically has to do an emergency release of a virus definition file once every three months because of a false positive issue, Telafici said. "This is our once for the quarter I think," he said.</blockquote><br /><br />Similar rates of false positives are probably seen from other vendors, but this might be the first time that an AntiVirus vendor publicly disclosed information about their false positive rate. Not every customer is affected by every false positive. Many affect 3rd party applications which were previously unknown to the AntiVirus vendor. In cases like these, a DLL from a valid production software system accidentally matches a signature file developed by the AntiVirus vendor, who doesn't have the system to test against. Tracking down these problems sometimes includes a finger-pointing exercise between the AntiVirus vendor and the 3rd party application vendor -- the AntiVirus companies sometimes uncover viruses in shipping code, too, and it may be difficult to tell where the problem lies at first.<br /><br /><a href="http://news.com.com/McAfee+update+exterminates+Excel/2100-1002_3-6048709.html?tag=nefd.hed">McAfee update exterminates Excel</a><br /><blockquote>However, this time around it was a particularly big goof, because the company faulted Excel, Telafici admitted. "Usually, it is either custom applications or applications that did not exist at the time we wrote the signature file," he said.</blockquote><br /><br />That bit is particularly interesting. The implication is that after the initial creation and testing, a given signature may not be tested as thoroughly or as often down the line. Several months later, an update to your application software might cause a signature file to break, causing catastrophic damage. In retrospect it makes some sense, as full-on testing of this stuff takes time and resources, and the pressure to test and ship the newest definition or signature files is quite high. <br /><br />However, this revelation probably indicates that the ongoing risks from signature or heuristic approaches may be somewhat higher than previously thought. With the number of threats multiplying every year, and with the number of signature files which require testing increasing concomitantly, older signatures which have been "thoroughly tested and validated in the customer environment" may no longer be assumed to be benign beyond doubt.<br /><br />The current McAfee false positive incident is discussed here:<br /><a href="http://it.slashdot.org/article.pl?sid=06/03/13/1322215">McAfee Anti-Virus Causes Widespread File Damage [Slashdot]</a><br /><a href="http://www.realtechnews.com/posts/2802">Excel = Virus ... At Least to McAfee [RealTechNews]</a><br /><br /><br /><br /><br /><!-- technorati tags start --><p style="text-align:right;font-size:10px;">Technorati Tags: <a href="http://www.technorati.com/tag/adware" rel="tag">adware</a>, <a href="http://www.technorati.com/tag/antivirus" rel="tag">antivirus</a>, <a href="http://www.technorati.com/tag/antiworm" rel="tag">antiworm</a>, <a href="http://www.technorati.com/tag/botnets" rel="tag">botnets</a>, <a href="http://www.technorati.com/tag/malware" rel="tag">malware</a></p><!-- technorati tags end --><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13178036-114226699082854086?l=antiworm.blogspot.com'/></div>Gary W. Longsinehttp://www.blogger.com/profile/05653813520423954538gary.w.longsine@gmail.com0tag:blogger.com,1999:blog-13178036.post-1142098180835562052006-03-11T12:27:00.000-05:002006-03-11T13:26:58.163-05:00Citibank PINs and the botnet arms raceI noticed this tidbit from a Gartner researcher quoted in a story about the recently disclosed PIN theft.<br /><br /><blockquote><a href="http://techweb.com/wire/security/181502468">PIN Scandal "Worst Hack Ever;" Citibank Only The Start</a><br />"That's the irony, the PIN was supposed to make debit cards secure," Litan said. "Up until this breach, everyone thought ATMS and PINs could never be compromised."<br /> - Avivah Litan, Gartner</blockquote><br /><br />I wish the reporter or Gartner researchers would have checked with me or someone else who has direct experience auditing software systems. I've been warning my clients for years about the security exposure from data retention for e-commerce and credit card transaction systems and I know a number of other security professionals who've been doing the same.<br /><br />In fact, given the number of thefts of credit card data stolen from 3rd party web sites that have occurred in recent years it's unlikely that this is the first PIN number theft to have occurred, counter to the implication in this story. It might be the first that has occurred since legislation obligated disclosure of such thefts, but even that seems unlikely.<br /><br />There are literally thousands if not tens of thousands of different bits of software involved in credit card transaction processing, custom made, derived from free code available on the internet, purchased from third parties, custom made by third parties. Most of those systems originate in the web development world where robust software development and testing practices are not fully realized and security inspection or auditing is an afterthought if it's a thought at all. <br /><br />PIN numbers and the special security codes printed on credit cards are intended by the vendors to be "transient" data, used but not stored at the point of presence -- e.g. the cash register or web site where the transaction is initiated. However, it's impossible to audit all of the custom made systems in the world. <br /><br />In a recent article here discussing the Verified by Visa program, I speculated that proxy agents could be placed in front of an e-commerce engine on a compromised web server to defeat the Verified by Visa security measures. This technique could be used to harvest PIN numbers and security codes even more transparently. <br /><br />Without conducting a survey, I can tell you from my experience it appears that most organizations with e-commerce shopping carts on their web sites are not prepared to detect such an intrusion. <br /><br />Shopping cart systems are only the tip of the iceberg. I've seen dramatic, gaping security problems in systems that existed for years and were easy to discover by accident through ordinary use of the system. One such system provided full identity information for all accounts within the system, including bank account information, phone numbers, addresses, date of birth and other information -- matched to Social Security Number. The system's entire database could be enumerated by fetching them one at a time, simply by poking a randomly generated Social Security Number into a field. By poking them all in, one at a time, one could fetch the entire database. This could be easily accomplished by a "script kiddie" in a very short time. The system was not instrumented with any logging which would reveal that this type of enumeration has been performed. The system's database included many members of Congress and the Senate. (Surprisingly, all of the information in this paragraph doesn't narrow down the field of applications enough to give away what the application was, nor the agency which ran it.)<br /><br />Oftentimes when such issues are encountered it is a struggle to get the owners of the system to understand the exposure and act upon it. I spent two days trying to convince the Federal Agency that owned this system to act. I was only able to get the hole closed by identifying the private contractor who implemented the system and calling their CEO, who immediately understood the importance of the issue.<br /><br />If you find holes like these that are relatively easy to discover and exist in systems for extended periods of time, you must assume that they have been discovered before. In some cases you may be legally obligated to notify the persons whose data has been exposed. <br /><br />The complexity of e-commerce and other online software systems which handle sensitive data is high, and the cost of securing them and auditing them is very high. An audit performed by a commodity consulting shop may cost tens of thousands of dollars and take a couple weeks. Even then, the auditors will often be ill equipped to discover many of the weaknesses that exist in these systems. If you hire a specialty security firm which brings highly skilled and experienced security engineers and programmers to the table, the cost will likely be even higher.<br /><br />Contrast that with the money that firms typically spend on these systems. Oftentimes they don't spend much at all. They got the internet and find a "free" shopping card, don't audit the code so they really have no idea of how it works internally or even if it has already been instrumented with a data harvesting routine, and slap it up on a web server. Even large corporations are guilty of this, as the division with the need may not be given the budget to "do it right". <br /><br />Conventional wisdom says that the west won the Cold War by outspending the Soviet empire, leading to the eventual bankruptcy and collapse of the Soviet system. The economic principles behind this problem are similar to the issues with security and online software systems storing sensitive data like credit card, debit card, and identity information. The barrier to entry for the attacker is low. The cost to defend is high. <br /><br />The botnet arms race continues, and this time the stakes are your identity information, and your bank account balance. <br /><br /><!-- technorati tags start --><p style="text-align:right;font-size:10px;">Technorati Tags: <a href="http://www.technorati.com/tag/adware" rel="tag">adware</a>, <a href="http://www.technorati.com/tag/antivirus" rel="tag">antivirus</a>, <a href="http://www.technorati.com/tag/antiworm" rel="tag">antiworm</a>, <a href="http://www.technorati.com/tag/botnets" rel="tag">botnets</a>, <a href="http://www.technorati.com/tag/Citibank" rel="tag">Citibank</a>, <a href="http://www.technorati.com/tag/Gartner" rel="tag">Gartner</a>, <a href="http://www.technorati.com/tag/hacker" rel="tag">hacker</a>, <a href="http://www.technorati.com/tag/identity theft" rel="tag">identity theft</a>, <a href="http://www.technorati.com/tag/malware" rel="tag">malware</a>, <a href="http://www.technorati.com/tag/puppy" rel="tag">puppy</a></p><!-- technorati tags end --><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13178036-114209818083556205?l=antiworm.blogspot.com'/></div>Gary W. Longsinehttp://www.blogger.com/profile/05653813520423954538gary.w.longsine@gmail.com0tag:blogger.com,1999:blog-13178036.post-1142096479459794062006-03-11T11:58:00.000-05:002006-03-11T12:01:19.503-05:00Total Cost of 0wn3rsh1pThis whitepaper spoof was written a couple years ago. I tripped over it by accident, and was rewarded with health boosting laughter.<br /><br /><a href="http://www.immunitysec.com/downloads/tc0.pdf">Microsoft Windows: A lower Total Cost of 0wnership</a><br /><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13178036-114209647945979406?l=antiworm.blogspot.com'/></div>Gary W. Longsinehttp://www.blogger.com/profile/05653813520423954538gary.w.longsine@gmail.com0