December 29, 2009

Another Win for the Good Guys: Bye Bye Mega-D Botnet

I just read this great piece of news over at the Sunbelt Software Blog about a top 10 botnet. The botnet, called Mega-D, was said to have 250,000 bots which has been responsible for nearly 12 percent of the world spam. Wow, this is a great win.

The takedown was coordinated by a researcher at FireEye who working with others in the industry and Internet Service Providers, provided U.S. law enforcement with the information needed for the shut down.

Kudos to the FireEye team and others involved on this win! Keep fighting the good fight.

Check out the Sunbelt Blog entry here.

December 18, 2009

Satellite Sniffing Software Used to Monitor Drone Video

According to the New York Times, insurgents in Iraq are using cheap satellite sniffing software to monitor the video feed coming from Drone fighter airplanes. This was discovered when laptops from captured insurgents were analyzed. The software they used is called Sky Grabber and costs only $26. It was designed to download music and movies off of satellite transmissions.

What's very disappointing with all this is that the Drones are not using encryption to secure the video feed. I've heard some reports that they aren't equipped to use encryption which if that's the case it's shameful. I don't see any good reason why we would want the insurgents to see the video data showing what the Drones are seeing. C'mon encrypt the data people!

Article here: http://www.nytimes.com/2009/12/18/world/middleeast/18drones.html?scp=1&sq=drone&st=cse

October 28, 2009

Local northeast Ohio security conference: Summit


It's been a long while since I've posted to my blog, it's been super busy lately. Apologies to my 3 readers - I promise to post more frequently.

This week I'll be at the 7th annual Information Security Summit. This is a 2-day conference held in northeast Ohio, this year it's in Warrensville Heights at Corporate College East, and features over 30 speakers from around the US covering security topics in the areas of governance/risk/compliance (GRC), threats, application security, incident response, network security monitoring, malware, wireless, open source tools, forensics, contingency planning, BCP, phyiscal security, etc. A long list indeed. See complete agenda here.

My role at the Summit is along with several others we help organize, plan, and run the event. I will also be working the NEO Info Sec Forum booth. This is a group I founded 4 1/2 years ago. If you are at the Summit stop by our booth (in room 124 off the atrium) and say hi. Try your hand at a crypto challenge where you can win some cool prizes.

Hope to see you at the Summit.

Side Note: For those of you who can't make it check out the live stream of the conference that Security Justice Podcast is providing!

August 27, 2009

Banks Receive Fake Training CDs from NCUA...oh wait...

As reported by the SANS Internet Storm Center, some banks reported receiving what appeared to be letters and training materials from the National Credit Union Administration (NCUA). The training materials consisted CDs.

Then you hear this over the PA system:
This was a test of the emergency broadcast system. This was only a test.
Closer inspection reveals that the letters were fake and the CDs contained malware. Pretty interesting scam involving physical world and computer security.

Ha. So Brent Huston from Microsolved contacts the SANS folks letting them know that he sent those as part of a penetration test his company was performing. Wow, good test and probably was successful. I bet some people put those CDs in their computers.

This was a great awareness event for training our users. I fully expect to see the criminals start using this technique more. :(

July 27, 2009

Advertising on social media site raises privacy concerns

Quick post about an interesting story I just read...

One day a married man (important to mention) logged into his Facebook account to check his messages. While on his page he was presented with an ad that entised him to visit a singles site. The ad said "Hey Peter. Hot singles are waiting for you!!" So what you ask? Well it just happens that along with the ad was a picture of a woman, that woman happened to be his wife. See below:


As it turns out, a 3rd party advertiser scraped her picture and others off Facebook profiles and used them in their ads. The victim, Cheryl Smith, talks about the incident on her blog.

According to Facebook officials this violates their policy and they have removed this advertiser. They even kicked off two whole advertiser networks for terms-of-service violations (not necessarily related to this particular case).

At first this story gave me a great laugh, but that quickly turned to shock and concern. Shock that an advertiser would use such a tactic, well I guess I've seen worse but still shocked. Concern regarding privacy on social media websites.

The folks at DownloadSquad have a writeup about this incident here and Sunbelt Software talks about it as well.

Want to protect yourself from the scrapers? Read Tom Eston's Facebook Privacy & Security Guide.

July 13, 2009

More Blackhat SEO, Pelosi is Target

The blackhats continue to push their rogue security programs via Search Engine Optimization techniques. This time I ran across a site using US Congress House Speaker Nancy Pelosi's name. It appears to be all sorts of headlines and keywords such as:





pelosi says surge did not work

And there's also some not so flattering phrases:



pelosi insane
pelosi is an idiot
pelosi is a communist

Some well worded SEO there bound to attract search engine hits.

The site contains some Javascript code in it (well not anymore but it was there) which after traveling through a couple redirect sites ultimately takes the visitor to some rogue security software sites. One of which uses drive-by fake scanning tactics. The redirect sites contain quite sophisticated Javascript code to hide their purpose. They also appear to redirect you based on where you came from.

The two rogue websites by the way are:

  • protectionbenefits.cn (83.133.123.113 Germany)
  • securedvirusscan.com (94.102.48.29 Netherlands)
This is in no way "new news" as reported by me earlier this year Ford was a target of these fraudsters and Panda Security has numerous siteings. This surely will continue for as long as they have the ability to operate the sites.
:(

June 18, 2009

Various interesting news and posts


The Web's most dangerous keywords to search for
http://blogs.zdnet.com/security/?p=3457
I've long known that some 75% of all screensavers found on the Internet via Google search contain malware but thought that some of these words were interesting: free games, work from home, iphone, barack obama. Something else interesting is the finding that when searching for lyrics keywords or phrases with the word 'free' in them one of four sites contain malicious code. Talk about blackhat SEO.

Building an Automated Behavioral Malware Analysis Environment using Open Source Software by Jim Clausing
http://www.sans.org/reading_room/whitepapers/tools/building_an_automated_behavioral_malware_analysis_environment_using_open_source_software_33129
Looks very promising. On my reading list.

Ex-DOS and Microsoft Exec Heading Up DHS Cyber Post
http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9133855
Earlier this month Secretary Napolitano of the U.S. Department of Homeland Security named Philip Reitinger as Director of the National Cyber Security Center in DHS. This is a newly formed office in DHS. Previously Philip had held positions in DOD Cyber Crime Center and was leading the Trustworthy Computing initiative at Microsoft. Philip replaces Rod Beckstrom who vacated the post earlier this year citing lack of funding and internal support. I wish Philip all the best and hope he's able to get what he needs to get things done there.

June 6, 2009

ICANN grilled by Congressional subcommittee


Event:
Oversight of the Internet Corporation for Assigned Names and Numbers (ICANN)
Hearings - Subcommittee on Communications, Technology, and the Internet
June 04, 2009
The Subcommittee on Communications, Technology, and the Internet held a hearing titled, "Oversight of the Internet Corporation for Assigned Names and Numbers (ICANN)" on Thursday, June 4, 2009, in 2123 Rayburn House Office Building. The hearing examined issues related to ICANN, including the expiring Joint Project Agreement between the Department of Commerce and ICANN, as well as ICANN's proposed introduction of new generic Top Level Domains (gTLDs).

I found this event very interesting. It is a hearing to discuss the renewal of the Joint Project Agreement (JPA) between the US Dept of Commerce and ICANN. Among other things the JPA provides the US Govt (through NTIA) oversight of ICANN's operations. This agreement expires in September this year.

There were several people testifying during this event including the President of ICANN, GoDaddy's General Council, representative from Verizon, representative from NTIA, and a couple others who I missed their names.

There were several concerns put on the table: accountability, transparency, efficacy, stability and security. Many had sharp criticism of ICANN's progress toward a safe and stable Internet domain name governance system. They along with the Congressional subcommittee were not satisified with ICANNs response to shutdown malicious domains and questioned why they aren't taking more action against domain Registrars who violate their policies and agreements with ICANN. ICANNs President did not seem to have good answers which led the hearing chair to ask for written proof of the actions they have taken. I suspect this will lead to more probing by the subcommitte because it's my opinion, as well, that ICANN is not doing their job here! As I continue to see bad Registrars allowing new malicious domain names to operate.

Concerns over the additional gTLD (global Top Level Domain) proposal were expressed. If you aren't aware, ICANN is proposing to allow new long gTLDs be created and sold. For example .MOVIE, .LEGAL, etc. The main concern had to do with trademark protection.

All panelists who testified, with the exception of the ICANN President, wants to see Congress renew the JPA. The overridding concern if it isn't was the lack of transparancy and security of the system. Several stated a concern that a nation who is not friendly with the US might take over of ICANN and threaten the US' national security. I share this concern.

If you are involved in fighting malicious websites or spam or curious about ICANN's operations I recommend watching the videos of the hearings. You'll find downloadable files here:

http://energycommerce.house.gov/index.php?option=com_content&view=article&id=1642&catid=134&Itemid=74

Let's hope this helps drive ICANN to take the necessary measures to dramatically improve their measures when fighting malicious domains. In other words, do what they should be doing anyway!!!

May 20, 2009

Criminals force Google to change algorithms

According to reports Google is about to or has already changed their search algorithms as a response to the increased exploitation by criminals using black hat search engine optimization attacks. See article here.

That's great news, assuming they are successful, as I've been discovering and reading about so many black hat SEO attacks that I'm starting to worry about non-security users utilizing Google for search. I'm not satisfied with Google's response to these attacks because in my opinion they have been much too slow and in some cases don't tag the offending searches as a security risk.

Based on the typical information security cycle (or arms race) this won't be the last time they will have to change their algorithm but let's hope this makes it extremely difficult for the criminals to continue using Google as an attack platform.

May 11, 2009

New information security bill to replace FISMA

There's yet another cyber security bill introduced in the US Senate; this one is called the 2009 U.S. Information and Communications Enhancement Act. While the others affect both government and private industry this one aims to strengthen information security within government offices.

It's an update to FISMA which has long been criticized for the lack of requiring agencies to demonstrate compliance. This bill focuses more on measuring actual security rather than on report writing, which is FISMAs focus. It requires the Commerce Department to establish standards for securing government systems. It will take away information security management away from the DOD and NSA and limits DHS' role to incident response and defenses provided by US CERT. I'm not sure I agree with that as there are some talented folks at DHS and US CERT.

You can read the whole bill here http://www.govexec.com/nextgov/042809/ICE_Bill.pdf