April 3, 2011

Major breach exposed customers of major brands

There's been a data breach (article 1, article 2) at one of the largest marketing services companies around and your email might have been exposed. The breach occurred at a company called Epsilon which handles email communications for many big brands such as Capital One, Citi, Disney, etc. Their website boasts over 2,500 clients including 7 Fortune 10 companies.

At this time the list includes about 15 companies but it's been growing, so even if you've not done business with one of the companies listed below, one that you have done business with might have been exposed.

Criminals are using the emails to send malicious software (in the form of PDFs or other documents) and/or links to websites that lead to malicious software and/or phishing scams. Be alert. Here's the list of companies confirmed to have been exposed at this time (some have links to notifications):

UPDATE 06-APR-2011 (LIST UPDATED):
1800-Flowers
Abe Books
AbeBooks
Air Miles CA
Ameriprise Financial
Barclays Bank
Beachbody
Bebe Stores Inc.
Benefit Cosmetics
BestBuy
Brookstone
Capital One
Charter Communications (Charter.com)
Citibank
City Market
Dillons
Disney
HSN (Home Shopping Network)
Eddie Bauer
Eurosport/Soccer.com
Food 4 Less
Fred Meyer
Fry's
Hilton Worldwide
JP Morgan Chase
Kroger
Jay C
King Soopers
Kroger
LL Bean Visa Card
Lacoste
Marriott International
Marriott Rewards
McKinsey & Company
Moneygram
New York & Company
QFC
Ralphs
Red Roof Inns Inc.
Ritz-Carlton
TiVo
Robert Half
Smith Brands
TD Ameritrade
TIAA-CREF
Target
The College Board
The Home Shopping Network
TiVo
US Bank
Verizon
Walgreens
World Financial Network National Bank

April 2, 2011

NSA to investigate NASDAQ hack


Several sources are reporting that the National Security Agency (NSA) is looking into the breach of the company that runs NASDAQ experienced back in October of 2010.

Bloomberg News interviewed former head of U.S. counterintelligence in the Bush and Obama administrations, Joel Brenner, who stated “By bringing in the NSA, that means they think they’re either dealing with a state-sponsored attack, or it’s an extraordinarily capable criminal organization.”

It's being reported that other U.S. Federal Govt agencies (FBI, Secret Service) are assisting as well.




Kim Zetter (@KimZetter) over at Wired Magazine has a good article on this topic:
http://www.wired.com/threatlevel/2011/03/nsa-investigates-nasdaq-hack/

Happy Birthday Portable PC

April 3, 2011: On this day 30 years ago something occurred in the PC industry that started what I'll call a revolution: the portable PC was introduced. In 1981 journalist and book author Adam Osborne released the 24 pound Osborne 1 computer. The machine was state of the art back then with a 5-inch CRT, disk drives that stored 102KB of data, 64KB of RAM, and a full size keyboard. It could even fit under the seat on a plane. But it was heavy and could not be used without plugging into AC socket; it did not have a battery.

An interesting piece of history is that one of the co-designers, Lee Felsenstein, theorized that the concept might have been borrowed from a couple of Apple employees who failed to sell the idea to Steve Jobs.

More information about the Osborne 1 can be found here.

Happy Birthday Portable PC

March 9, 2011

Malware targeting Blackberry's



According to Trend Micro, a ZeuS banking trojan is targeting Blackberry mobile devices. Previously ZeuS variants targeting only mobile devices running Symbian and Windows Mobile had been spotted.

This story just helps bolster the point that malware's growth will occur in the mobile device world. Strap in your seatbelts, we're in for a rough ride!

http://www.finextra.com/news/fullstory.aspx?newsitemid=22336

February 9, 2011

Great Cleveland Security Event: BSidesCleveland

I wanted to direct your attention to a great security event being held in Cleveland next week: BSidesCleveland. It's a one-day event on Friday February 18, 2011 filled with interesting speakers and topics and great opportunities to network with your peers.

A local security group that I founded, the Northeast Ohio Information Security Forum, is one of the sponsors. The other local sponsor is SecureState.

Seating is limited and to if you don't have a ticket you are out of luck because it's sold out. You can still follow the goings on there via Twitter @BSidesCLE.

You can find out more about BSidesCleveland here:
http://www.securitybsides.com/w/page/27427415/BSidesCleveland

November 6, 2010

HTTP DDOS May Be in Your Website's Future

I found some interesting research work recently. Attackers have a new technique that can be used against your websites: HTTP DDOS.
Researcher by Wong Onn Chee discovered a way to cause a website to be slow and even take it down via a technique where POSTs are sent to a website slowly causing gridlocks the connection. It's similar to the Slowloris HTTP DDOS attack by RSnake, however this slow POST attack can't be mitigated by load-balancers like the Slowloris one can.

Check it out:
http://www.darkreading.com/vulnerability_management/security/attacks/showArticle.jhtml?articleID=228000532

August 24, 2010

Malware authors have their own con now, MalCon

Interested in WRITING malware? Go to MalCon.

Heh. I've heard it all. Now the malware authors have their very own conference where they can learn and teach about writing malware. Their website claims to bring together "Malware and Information Security Researchers from across the globe to share key research insights into building the next generation malwares." Okayyyyy.

I'm not sure whether this is a hoax or legit but according to Brian Krebs of Krebs on Security fame it's legit, or at least he spoke with the organizer of the event about it. The word is that Bruce Schneier is one of the leading speakers. This is interesting and seems to lend credence to its legitimacy.

Not sure who will be attending but my guess at the very least there will be a few LE and government security types "hanging" around this conference.

August 7, 2010

Google CEO says no anonymity on future Internet


Google CEO Eric Schmidt stated in a talk at the Techonomy conference in Lake Tahoe that 'true transparency and no anonymity' are required to combat identity theft. He said the increase of information generated every day has helped social interaction but created a condition that helps identity theft thieves. He said there needs to be a verified way to identify people and that Governments will demand it.

My concern would be the procedures and policies surrounding the protection and use of this identity information. The information will need to be protected and how it will be accessed will be critical to whether the system is successful. If run poorly it could actually increase identity theft cases.

See more about the speech here: http://www.thinq.co.uk/2010/8/5/no-anonymity-future-web-says-google-ceo/

July 31, 2010

Even security conferences suffer from vulnerabilities


Whoops, it looks like the folks who developed the registration website for the Blackhat security conference have a little security issue themselves. As Michael Coates reported, the website that is used to register for access to some of the live talks from the conference is vulnerable to a hack where an attacker could obtain free access to paid content.

For a fee the conference offers access to select talks that are streamed live. Well Micheal found a vulnerability where he was able to access the stream without providing his credit card. Oops.

The good news out of all of this is the response from the company who developed the website responded quickly to Michael's call and within 4 hours had a fix installed. Further Michael followed responsible disclosure and did not disclose the issue until after the site was fixed.

July 15, 2010

Rootkit targeting embedded devices in SCADA systems?


A recent malware discovery has many of us security pros very concerned: rootkits targeting embedded devices. The discovery is a rootkit called Rootkit.TmpHider that came with a trojan that infects systems via USB drives. This in itself is not all that concerning, what *is* very concernful is that the driver files that make up the rookit have a legitimate digital signature from....wait for it...an embedded device maker Realtek. Worse it appears to targeted at SCADA control systems. Not good.

Several are discussing this new trojan that has rootkit technologies built into it: Wilders Security, The H-Security site, The Elder Geek.

Why are we concerned you ask? These embedded devices are everywhere controlling everything including critical systems such as water system, power grids, etc. AND in a scary finding made by malware analyst Frank Boldewin of www.reconstructer.org, this rootkit has database queries that target WinCC SCADA systems by Siemens. That's bad news.

To add to this concern is the fact that these devices rarely get updated, if at all, so all bugs and vulnerabilities that existed when they were designed still exist. Furthermore, the trust model in these devices is usually quit open, making it very easy for worms to propagate.

Here's hoping that new embedded systems have stronger security built into them.