Showing posts with label SANS. Show all posts
Showing posts with label SANS. Show all posts

Tuesday, March 9, 2010

Vodafone Android Phone Comes With Mariposa Malware

It's always helpful when vendors ship malware right to your doorstep with the products you've purchased.

Panda Security has reported that they've discovered Mariposa malware on a brand new Android phone purchased from Vodafone.

From SANS:

It didn't infect the phone proper, but it did have autoexec.inf and autoexec.bat files designed to infect whatever Windows machine the phone was plugged into via USB cable.

 If you haven't disabled autorun on your Windows machines, and if you don't have some sort of malware protection on your mobile devices, you're a sitting duck.

You've been warned.


Tuesday, October 27, 2009

SANS - Social Engineering Computer Attacks

SANS has a timely diary entry on their Internet Storm Center page entitled Social Engineering in Real-World Computer Attacks in which they posit the following:

Why bother breaking down the door if you can simply ask to be let in? Social engineering works, both during penetration testing and as part of real-world attacks. This note explores how attackers are using social engineering to compromise computer defenses.

For all the millions spent on hardening systems and networks, there's always someone volunteering to open the door to allow attackers inside. Defense-in-depth as a strategy only works if the control mechanisms are left in place and not circumvented.

Would you install an alarm system in your house and write the passcode on the outside wall? Or would you give the code to someone who called or emailed you, claiming to be from the alarm company demanding that you validate your code for them or they would cut off your access?

Most people would answer "no" to those two questions, but history has shown that there's a real problem with people responding to phishing and vishing schemes and giving out their credentials willy-nilly. Look at some of the examples pointed out by SANS:
  • Bogus parking violation notices on cars directing people to visit a web site to resolve that turns out to be a malicious site
  • Voicemails left for customers to "call back" and verify their banking information
  • People plugging in USB drives or CDs left in public places or sent via the mail or post
Firms that have your credentials should never be asking you to validate your credentials. Your bank doesn't need your account number, PIN, mother's maiden name, or answer to your secret question, because your bank already has that information.

Remember how your mom told you not to pick things up off of the ground and eat them because she didn't know where it came from? Yes? Then why would you pick up a USB drive or CD and stick it in your computer?

Never, ever give out information or data based on a phone call, message, or email you've received. Always contact firms and companies, such as banks, credit card companies, retailers, etc., using the contact information in your statements or using the "Contact Us" information that's posted on their official web site, which does not include following links that come via email or text messages.

There's an popular adage that you can't cure stupid. When it comes to computer attacks, the level of sophistication is increasing exponentially, so it's no longer a question of being smart. Attackers are targeting human nature, and that's a difficult challenge to overcome.

Image via Wikimedia Commons


Tuesday, September 15, 2009

SANS Releases Top Cyber Security Risks

SANS has released their annual overview of top cyber security risks, and there are few surprises to be had by those who follow the topic on a regular basis.

Two significant areas of opportunity are called out - client-side applications (think Adobe, QuickTime, Flash, etc.), and Internet-facing web sites. Both suffer from the same root problem - poor coding practices and beleaguered IT admins who struggle to keep up on the continuous vulnerability patching treadmill.

SANS opines that there are less OS-targeted exploits floating around, which probably has more to do with the low-hanging fruit of client apps than it does any significant hardening of operating systems. Vista was marginally better than its predecessors, but since Vista never really took off in the enterprise, there's still a lot of XP deployed in the corporate world, and after a half-decade of vulnerabilities and flaws, XP has been patched so often that it looks like a pair of my Sears Toughskin jeans from 1973. And yet, each month, Microsoft releases a couple of new advisories with fixes that include XP as an impacted OS.

Attackers have decided that it's much easier to crawl in through an open window caused by a faulty, unpatched application than it is to brute force their way in through the front door of the OS. Once inside, the bad guys are still able to compromise a system, harvest credentials, steal personal information, and otherwise take full control of the machine without needing to assault the OS directly.

People are very trusting of video and Flash content, PDF files, Word docs, and other files associated with some of the weaker, flawed apps, and they will click on these file types all day long if they show up in email, instant messenger, or on a compromised web site. In many cases, the content will autorun, because users have allowed their systems configurations to be set for convenience, not security.

Web apps continue to be plundered via a combination of SQL injection and cross-site scripting attacks typically associated with poor coding practices and insufficient vulnerability assessment and remediation processes. Combined with happy-go-lucky users who will click on any url that comes within their reach, you have a perfect storm of ignorance and negligence that results in malware propagation and infected systems.

What's the answer? Aside from unplugging from the Internet and leading a Puritanic technology existence, the solution is better application development practices, enhanced and timely vulnerability assessment and remediation processes, and using system lockdowns and controls to protect users from themselves.

Not using Microsoft products can also be helpful, but that's my bias - even though my background is an a Microsoft engineer and certified trainer. Redmond is undoubtedly relieved that Apple, Adobe, and others are finally in the crosshairs as often as Microsoft has been. Misery loves company.

Tuesday, August 18, 2009

MS09-039 WINS Exploit in the Wild?

The SANS Internet Storm Center (ISC) is noting increased port 42 scans as reported by DShield. TCP 42 is typically used for WINS replication, so it makes sense that if someone is trying to exploit the vulnerabilities associated with MS09-039, they would target this particular port.

ISC also had someone who wished to remain anonymous report that there is an MS09-039 exploit in the wild.

If you have WINS-enabled servers out there and haven't rolled out the patch yet, it sounds like you're running out of time.


Saturday, June 20, 2009

Good Security: Defense in Depth

I was having a delicious lunch of mini-cheeseburgers and sweet potato chips the other day with my pal KL, and we were having a spirited discussion about defense-in-depth when it comes to network and infrastructure security for the enterprise.

K has posted some good thoughts on the topic in his handler's diary at the SANS Internet Storm Center, so I'll link to them rather than recounting them here.

It's apparent that as the size and complexity of a firm's infrastructure grows to accommodate mergers and acquisitions, organic business growth, and technology refresh, the complexity of the security threats change too, and not always in direct proportion to the attack vectors present or the evolving threats themselves.

As a business changes - whether it's pushing into previously unexplored markets, setting up shop in new countries, marketing and driving to pull more or different client bases into the fold, or taking over some other firm's infrastructure as part of an M&A strategy - it's short-sighted and reckless to think that your prior strategy will suffice unchanged, or that your tactical approach will just need more of the same bells and whistles that you already use, just more of them.

Security professionals who fail to see both the opportunity and value of viewing their space holistically will soon be faced with a myriad of problems not easily solved, including scalability issues, obstacles in allowing the business units to be agile and dynamic, compatibility nightmares, and a continuous feeling of dread that comes with not really having confidence that you know everything you need to know.

Much like info security staff develop a sixth sense when presented with a series of circumstances that leads them to make good judgements, it's imperative that IS leadership forges and maintains solid relationships with key business leaders, not only to understand their current goals and challenges, but also to provide core risk-benefit analysis in a dynamic manner.

If the business in planning to introduce change (location, scope, market, etc.), what issues does this raise in the IS space, and what's the best way to address them? What are the costs associated with these issues, and has that been factored into the overall resource requirements for the business?

If the changes entail new or different technologies, what are the threats to those technologies, and how prepared are we to meet those threats on Day 1? Do we need to introduce new security controls, and if so, what gaps might those new controls open in our existing coverage, and how are we going to ensure all gaps are rapidly identified and remediation plans are in place?

The successful infrastructure security organizations will not only have depth in the core skills needed (IDS, firewall, AV, data leakage, anomaly detection, and so on), but will also be highly conversant and hungry to understand the business drivers that make the firm run. Without this business acumen, the IS organization is operating with an incomplete picture, and it's greatest threat will be that it doesn't know what it doesn't know.


Thursday, January 1, 2009

SANS 2009 Security Predictions

The SANS Technology Institute has released version 1.7 of their 2009 Security Predictions.

Assorted experts from various fields collaborated to produce this collection about the future of security for computers, networks, and information.

It's a wide-ranging piece that frankly lost some focus as more data was collected. It's hard for me to find actionable intelligence for my day job in this compilation, but it's a valuable as a digest of what's expected to transpire over the next twelve months.


One thread that I happen to agree with is a future-looking view that a significant data breach will occur at a firm shown to be PCI/DSS compliant.

As we learned in 2008, several breaches were reported via the Open Security Foundation Data Loss db that involved organizations with varying levels of PCI/DSS programs implemented.


Government regulation tends to be a trailing indicator of effective security and control. What typically happens is that a flurry of incidents becomes public, and the industries involved are either slow to react by redesigning their programs or in re-evaluating the effectiveness of their controls, so politicians clamor for regulations and directives to force widespread compliance to a set of requirements so cookie-cutter that they can't possibly be effective in companies of various sizes, degrees of complexity, or breadth of information and infrastructure.


The number of reported data breaches hasn't been reduced, even after the introduction of significant regulation such as HIPAA, SOX, PCI, and others. Many regulations have been targeted to specific data sources or business types, which has led to irregular approaches to data privacy and protection tailored to meeting regulatory requirements rather than improving security posture.
Data Loss statistics indicate the following breakdown of incidents by industry type:
  • 36% business
  • 28% education
  • 24% government
  • 12% medical
HIPAA standards for the health care industry have been in effect for years, and some would like to point to the 12% as evidence that the focus has worked. However, are we certain that all breaches are being reported, or has the increased attention simply made hospital administrators and other professionals more careful about what they release publicly?

Massive breaches at companies like TJMaxx (45.7 million credit card numbers and transactions), US Dept. of Veteran's Affairs (26.5 million veteran's personal information stolen) and Hannaford (4.2 million credit and debit card numbers exposed) get all the attention, but there are substantially more people affected by the thousands of other breaches that, if made public at all, drop from the media's radar within hours.


Hannaford's breach occurred in 2008, and one of their first statements of defense was that they were PCI compliant. They soon dropped that approach when it failed to buy them any measure of sympathy from an outraged public, indignant security professionals, or embarrassed government officials who designed PCI in an incestuous partnership with the credit card industry.

In October 2008, Brian Krebs reported in his
Security Fix blog that The Identity Theft Resource Center found that 2008's data breach tally had already exceeded 2007's 446 incidents, with at least 680 breaches predicted by the end of the year. 30 million customer records had been exposed through October.

There are differing explanations for these results, depending on which group of experts you're dealing with. Some believe the issue is simply that there are more breaches. Others opine that organizations are getting better at detecting breaches - not preventing them, which should be the goal, but detecting them. The third explanation is
that more organizations are complying with state data breach notification laws.

Regardless of the explanation, it's clear that we're not seeing a statistically significant improvement in the privacy and protection of information. There's too much data being retained, too little documentation on where the information is located, how it's protected, and who has access to it, and too little attention paid to destroying data when it's no longer needed for legitimate purposes.