Showing posts with label Compromise. Show all posts
Showing posts with label Compromise. Show all posts

Saturday, 13 May 2017

The Anatomy of Ransomware - and How to Prevent from Impacting You

After the global cyber attack with ransomware, there is much advice out there suggesting the problem would have been prevented with point products, training or procedures.  I'm going to outline a generic ransomware attack below, so that the defences can be understood.  I'm going to outline what you can do as a home user, corporate user, or corporate IT team.


Delivery of Ransomware


Depending on the research you read, you can see that 93-98% of ransomware is delivered by email.  The remaining delivery methods can be via websites, whether a drive by download, malvertising or malicious website; or via removable media.

As a home user, a good quality endpoint protection solution would be recommended.  Try not to click on email attachments, dubious weblinks or using removable media you are unsure about.  Look to only have standard user profiles and not administrator rights on your everyday profile, and enter the admin credentials when needed.

As a corporate user, the advice is similar to a home user, try not to click on email attachments, dubious weblinks or using removable media you are unsure about.

As a corporate IT team, email and web gateway solutions should be protecting the email and web traffic.  The endpoint should have good quality multi layered protection.  Ensure that users do not have local administrator rights.  Sandboxing solutions on the network would analysis the unknown traffic coming into the network and ensure the email, web and endpoint vectors are covered.  Consider device control solutions if removable media is a big entry point into the network.  User education can help, but it needs to short and regular, and not many hours once a year.

Exploit the Endpoint


The ransomware's next task is to find a vulnerability on the endpoint, in order to exploit it and install the ransomware.  This is when the advice is to patch your operating system, or check and install the updates to your machine.  It's lesser known that the other software on your machine also has vulnerabilities, such as the third party software, like Java, Adobe Reader, etc, as well as the internet browsers and add-ons.

As a home user, change the settings on the operating system and software to automatically check and install the updates. Consider removing applications that are rarely used, as some may not check for updates until they are used.

As a corporate user there is typically little you can do, as this should be controlled by the administrators.  If you are able to run the updates, check regularly.  If you are able to install applications, consider what you are installing and switching on auto updating.

As a corporate IT team, ensure there is a robust patching regime.  Ensure patches are deployed to Microsoft operating systems as close to "Patch Tuesday" as possible, to prevent there being a "Hack Wednesday".  Ensure the patching regime goes beyond operating systems, covering off the third party applications, browsers and add-ons.  Consider Application Control solutions to limit the applications on the endpoints.  With the server environment, consider using IDS/IPS or "Virtual Patching" solutions in order to protect the servers until patch remediation can be carried out in a scheduled maintenance windows, allowing for testing of patches prior to deployment.


Installation of Ransomware


The installation of the ransomware will typically be disguised as a system process, so can go undetected by traditional or single layers of defence.

As a home user with the administrator rights removed as mentioned before, the software may not be able to install.  Again a good quality anti-malware solution may help prevent the ransomware from being installed.

As a corporate user there is typically little you can do, as this should be controlled by the administrators.

As a corporate IT team, look to Application Whitelisting, so unknown applications can't be installed.  Also giving the known good software will check fingerprints of applications, so even if the ransomware is masquerading as a system process, it will not be allowed to execute.  Again good multi layered anti-malware protection and limited local admin rights will help.  Sandboxing solutions should detect this traffic, and consider tools that can monitor file integrity, analyses the memory or offers memory injection protection.

Command and Control


Once installed, the ransomware will typically talk back to the "Command and Control" servers, communicate with the ransomware and customise what the machine will do, such as detect language settings of the computer and then get the correct interface installed in the matching language.  A Chinese demand for a ransom would not be very effective to a machine using Russian language.  There can be communication of the unique encryption key as well.

As a home user, beside the reliance on the endpoint protection having a good malware detection and possibly a host based firewall, there is very little that can be done at this point.

As a corporate user, the situation is much the same as the home user, as there is little that can be done.

As a corporate IT team, the use of Next Generation Firewalls and/or web gateway solutions should be able to see this traffic travelling to and from the network, and prevent the communication.  Logging or SIEM solutions should be able to take the feeds from various point throughout the network to detect this activity.


Data Encryption


The ransomware will now start to encrypt a portion of each of the files, allowing it to work quickly through all the files.  It will check for connected devices, so it will be able to encrypt network file shares and removable media connected to the machine.  It also knows to leave the operating system files, so the machine is still able to run and demand the ransom.

As a home user, beside the reliance on the endpoint protection having a good malware detection and possibly a host based firewall, there is very little that can be done at this point, aside from ensuring that there are system backups.

As a corporate user, the situation is much the same as the home user, as there is little that can be done.

As a corporate IT Team, the anti-malware solution may be able to detect this and stop it from running, or the use of application control could have prevent the application from executing as mentioned before.  Beyond that the the dependence will be on having system backups.


Ransom Demand


At this point, whoever you are, all is lost with out system/data backups.

The advice is not to pay as research currently shows that the payment of the ransom will to the decryption of the data around two thirds of the time, and increases your possibility of being targets again.


The Advice

As a home user, don't click on links without validating if they are legitimate, get a good quality endpoint protection solution and patch your computer regularly.  Remember to backup your data, whether to the cloud, portable hard drives or USB devices, and try not to physical devices connected when not in use.  Make your account a standard user, so the administrator password is required for tasks that are altering the configuration of your computer.

As a corporate user, don't click on links without validating if they are legitimate, but work with IT, if you think you have.

As a corporate IT Team, ensure the endpoints have good quality malware protection that can be centrally managed and centrally logs information.  Ensure there web and email gateways installed and configured.  If you don't have a NGFW, consider getting one and using the features available.  Patch the operating systems, applications and browsers on endpoints and servers.  Consider investing in Device and Application Control solutions, if you don't already have them.  Sandboxing solutions will help deal with the unknown and new threats, so are well worth the investment.  Review the rights the users have on their devices, as they typically don't need to be local administrations.  SIEM solutions with security features will help detect this early on.  End user training is important, but keep it short and regular for it to be effective.


Conclusion


Ransomware attacks will continue to happen, but stopping the chain of events as soon and as quickly as possible will minimise the damage.

I hope this guide has been useful in helping understand how ransomware works, and the measures that can be taken to prevent if from impacting you.  If you have any questions, please feel free to email me: blog@andytang.com

Wednesday, 1 June 2016

Have your online accounts been compromised?

Millions of accounts from various websites have been exfiltrated and shared online.

Some of the largest compromises of personal accounts, include 359 million MySpace accounts, 164 million LinkedIn accounts, 152 million Adobe accounts, 65 million tumblr accounts, but the list goes on.

Despite all these high profile comprises being reported in the news; have you ever wondered if any of these compromised accounts were yours?

You can check here: https://haveibeenpwned.com/ 

This is a website created by Troy Hunt, a Regional Director at Microsoft and more information about him can be found here.

Monday, 26 October 2015

TalkTalk Breach

On Friday 23rd October 2015, it came to light that TalkTalk, the telecommunications and internet provider was subject to a significant cyber-attack.

Some facts have come to light since the disclosure of the attack:

Third time’s a charm
The latest attack was the third cyber-attack in the past 12 months.  It is believe that that this attack has allowed the attacker to steal four million records.  It may also have been up to ten weeks, since the cyber-attack had occurred. 

DDoS as a cover
A DDoS (Distributed Denial of Service) attack was used to overwhelm the existing perimeter solutions.  The large volume of traffic will overwhelm perimeter solutions such as firewalls and IDS/IPS solutions which are there to scan and protect an organisation from malicious traffic.  It seems there was either no or an inappropriate/inadequate DDoS mitigation solution in place.  DDoS attacks are often used as a subterfuge to mask the real nature of the attack.  In this case, it looks like the attacker is flooding a website, whereas the underlying attack is to exfiltrate customer data.

SQL Injection?
It is widely believed that the attack was on the application available on the internet, and using web application testing tools, such as a form of SQL injection attack, were able to access the data.

SQL is a database application, and an SQL injection is the ability to run a query on a database.  Although very useful for database administrator, it gives malicious attackers the ability to query and export a whole database.  The ability to run SQL injection attacks, are typically due to bad administration practices and not properly protecting the database.

Comprehensive data on people
The customer data lost is incredibly comprehensive.  The list below shows the data the attacker was able to obtain.
  • Name
  • Address
  • Email Address
  • Telephone Number(s)
  • TalkTalk Account Number
  • TalkTalk Password
  • Bank Details
  • Partial Credit Card Details

Encryption?
The TalkTalk data wasn't encrypted, meaning the attacker was able to read all the above information.  The data was in clear text, offering no protection to the customer.

Aftermath
It is believed that the Police and BAE Systems are carrying out a forensic investigation on the attack, but this relies on how much of a digital footprint was left during the attack and whether it was recorded at the time.

BEFORE THE ATTACK
As an organisation handling customer information, there are many actions that would help prior to an attack:

Identification of Data
With numerous databases, server shares, cloud storage solutions and user created data; identifying important information, such as customer’s PII (Personal Identifiable Information) and financial information is paramount.

Protection of Data
Once the important information has been identified, methods of protecting the data should be used.  Encryption of data, where the data is encoded using a unique key and can only be decoded with this key, makes the data useless without it.

Testing of Systems
As applications are exposed the internet, such as customer portals, these need to be tested by a third party organisation with little or no knowledge of the application.  A Web Application Penetration Test could have highlighted some of the shortcomings of the web facing applications, including testing for SQL injections.

DURING THE ATTACK
When an organisation is under attack, a number of solutions could have prevented an attack similar to TalkTalk’s. 

Administrative Rights
It is often said that 100% of attacks have used administrative rights.  There are Privileged Access Management solutions, which will safeguard the administrative accounts, and will offer full traceability of which administrator has done what.  A typical attack will either use administrative credentials they have gained, or to elevate the administrative privileges of a normal user.

Protection from DDoS
A DDoS (Distributed Denial of Service) is normally used by a malicious attacker to take a web presence offline, making a web service inaccessible.  In the case of TalkTalk’s attack, it was use to cloak the underlying attack.  A hybrid DDoS mitigation solution could have prevented such an attack.

Intrusion Detection
There are Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) which is used to detect and identify malicious activity on the network, then try to block or stop that traffic, and report back.  These are available as standalone solutions or as part of a UTM (Unified Threat Management) or Next-Generation Firewall solution.  Sometimes the early warning of an attack can help prevent the loss from being so great.

Data Exfiltration
The data will need to be taken for a breach to have occurred, so a DLP (Data Loss Prevention) solution will monitor the vectors from which data can leave, such as web, email, USB, screenshots, printers, etc and if the monitored data leaves in an atypical fashion, it will be quarantined and administrators alerted.  

AFTER THE ATTACK
After the compromise, what options are available?

Logs & Forensics
Post attack, it’s important to know what has been lost and preventing it from happening again.  A SIEM (Security Information & Event Management) solution would be able to aggregate the logs from the various components of the network, and apply a level of intelligence to the data.  Some will be able to carry out a forensic analysis on the logs.

Understanding the attack will allow a more effective remediation plan to be created.

What now TalkTalk?
Reading the press following the TalkTalk attack, there is no understanding to the significance of the data loss.  Although there is no demand to encrypt the data, it doesn't mean that the information of your customers should not have been encrypted.

As a minimum, by pentesting the application to prevent the vulnerability, and encrypting the data so it's useless to the attacker, would have prevented TalkTalk from the media attention. 

There is a call for the government to do more to prevent the cyber-attacks, but as highlighted here the technologies are available to help prevent, gain visibility or slow down the attack.  The onus should not be on governments to protect the customer’s data, it should be the service provider.

Wednesday, 22 July 2015

Morality vs Criminality: Ashley Madison Hack

As you may have read in the press, that the Ashley Madison website was hacked.   What's the big deal, you may think, it's another compromised website.  Ashley Madison,as it says on their website, "is the online personals & dating destination for casual encounters, married dating, discreet encounters and extramarital affairs", with the tagline is "Life is short, have an affair".  There are 37 million users, across over 50 countries, with around 1.2 million of whom live in the UK.


What was lost?

Personal data that was lost includes, names, postal addresses, credit card numbers and sexual fantasies.  Made worse is the organisation charged a $19 fee to carry out a "full delete" on user accounts, which appears to have not been the case.


Who did it?

The hackers taking responsibility are the Impact Team, where the database was comprehensively stolen.  In a recent article from The Guardian, it states that it was an insider threat, where the compromise was carried out by someone who had access to the systems, but was not an employee, highlighting the need for control on third party access.


Morality?

I've read a few comments that said that people should not be using these sorts of sites.  A crime has been committed in the database being stolen, but we are judging the victim for the crime.  Who is to blame if your house is broken into?  The criminal or the victim?  


Advice

Be aware that there is no safe place on the internet.  The internet is effectively a public place, where a majority of people will have access.  You are entrusting a third party to look after your data, so in this case, a secure and unique password would not have helped the users.

The fault here lies with Ashley Madison.  Some security technologies would have prevented this from happening:  

  • A Privileged Account Security solution would have prevented the third party from recycling their access to the system, and with some solutions recorded the sessions of compromise.
  • A database encryption solution would have prevented the data from being used.
  • A Data Leak Prevention (DLP) solution would have prevented the data from exfiltrating the organisation.
  • A Security Analytics solution would have seen and prevented this.
I have mentioned the Cyber Kill Chain in the past, and these solutions would have stopped the compromise, and the data leaving the organisation.

For me, this is not a case about morality, but we allow that to cloud our thoughts and allow a criminal act to be downplayed because of it.  This is a crime, but worse a crime that could have been prevented.  The right solutions configured correctly, supported by polices and procedures would have prevented this hack from happening.

Friday, 26 September 2014

Shellshocked!

What is Shellshock?


It has been widely reported in mainstream news that vulnerability dubbed Shellshock could affect 500 million devices, which over shadows the 500,000 devices that were affected by the Heartbleed vulnerability. 

Shellshock exploits a vulnerability in a command line shell used by many UNIX computers, called the Bourne Again Shell, more commonly known by its acronym Bash.  This affects computers and devices using the Linux and Mac OS, including some appliance based devices such as firewalls, which are commonly built on Linux.

Bash is a common component in webservers, but even if Linux is not being used, Apache also uses Bash.  It could also be used as a background component for web browsers, email clients and file transfer applications.

Whereas Heartbleed was a vulnerability that allowed the traffic to be sniffed, the Shellshock vulnerability allows direct access on to the vulnerable machine and with potentially three lines of code.

More technical details around the vulnerability CVE-2014-6271 aka Shellshock is linked.

What can be done?


Patch the Linux and Mac OS machines to the latest version.  There are rumours that due to the speed of patch dispatch, they may not have been QA’d as thoroughly, but it is still better than being vulnerable.

Remember that devices other than computers and servers running Linux or Mac OS can be affected.  Ensure your client software is up to date, regardless of the operating system.  With devices such as firewalls, check regularly on the vendor websites for their advice.

Here is the latest government advice on the Bash vulnerability

I’m checking the vendor sites that MTI Technology partners with and slowly creating a list of useful links here:
Cisco
WatchGuard
Websense

Last updated: 11:45 01/10/2014

Thursday, 25 September 2014

Securing the virtual you

I blogged recently about the Cyber Kill Chain where I look at each of the steps.  Many of the steps can be dealt with using technology, except one stage, the reconnaissance stage.

Who's the target?

As the bad guys need to be more specific in targeting individuals, research is the key.  Knowing who someone works for, who their friends are, their hobbies and pastimes, they all help construction a picture of the target.  If you know your target, you can try to exploit it by sending emails with specific topics and links to lure your target to click on a link which can compromise their machine.

Spear-Phishing

People who are normally target to a "spear-phishing" (if phishing is a wide indiscriminate attack to get users details, spear phishing is targeting a very group or an individual person) are people who will have more rights than a typical user.  Why?  Well I mentioned in previous posts that a compromise will involve administrative credentials 100% of the time.  So the target will often be members of the executive team (who often have more rights than a user) or members of the IT team.

Research/Googling?

How would I find out more about someone?  Use Google (other internet search engines are available) and search for them.  As an example, I'll use me and see what's available out there...


LinkedIn

The second hit is for LinkedIn and most of the posts that follow are for a Singaporean racing driver (I'll give you a hint, I'm not a racing driver!).  For those who are unfamiliar with LinkedIn, it's a social networking site for "professionals" effectively giving a CV online.

So following the link, it takes me to a number of people called Andrew or Andy Tang internationally, but LinkedIn handily gives a link at the top to refine this list to Andrew or Andy Tangs based in the United Kingdom.  



So if you knew who I worked for (MTI by the way), then you'd know to click on the top link.  If you didn't, then you probably won't target me!  So now I can see a public profile of Andrew Tang, and even without a LinkedIn account I can gather a lot of information.



Now you know who I work for and have worked for, along with people who I must be linked with in some fashion, as people looking for my profile have also looked at these profiles.  That already creates links with people or organisations I would potentially trust, or would not find odd if I received a communication from them.  Additional information such as company websites and blogs may also be there and give more clues.

Google+/Blogger

Following out to the blog, it can be seen that the URL to my blog (that you're reading by the way, thank you) is http://blog.andytang.com which gives us similar information to the LinkedIn profile, as well as a link to my public LinkedIn profile.  There is also a link to my Google+ profile as the blog use Blogger which is a Google company.  

Twitter

Information we already have like company and LinkedIn details.  There is a link to Twitter, along with some people who have put me in their circles.  Again, more people that I would not find odd if I received communications from them.  Let's follow the link to Twitter...


No real insights here, except that I say I live in Surrey.  That may have been assumed as current and previous employers are in Surrey as well.  

WhoIs?

Maybe time to get a little cleverer!  We know the domain I own andytang.com, so there must be some information around that domain.  A WhoIs will find out who has registered this domain:


No real information here either!  

Facebook

I've tried looking for a Facebook page, but struggle to find myself, even if I spread the net wider with more information than can be found above.  None of the profiles below are me, but then I have locked down my privacy settings.


I thought I'd try a different way to get to the profile.  I know who Andrew Tang works for and I know they have a Facebook page.  Having a quick look through would show up any posts Andrew Tang may have liked, and from there I can access the profile and gather more information:


This shows my Facebook privacy settings work!

Corporate Website

Most corporate websites have a who's who on it, but I'm not currently on it.  Although if I were, it would probably show a photograph and a brief about me, which  could uncover hobbies or pastimes.

So what?

A lot of information can be uncovered very quickly about people.  If I were a target to an attack, I would hope that my privacy settings and IT awareness would help.  If the communication was more targeted from people I know or around a hobby or pastime, I may well click on them.

Our virtual presence keeps growing, but do we keep tabs on what's out there.  I did the above with no special access or logins.  The only site that needed an account was Facebook, but the rest is there to be discovered.

Take the time to secure and protect your information, and make sure there's not too much out there.

Googling yourself is no longer about vanity, it's about security!

Monday, 15 September 2014

Lockheed Martin Cyber Kill Chain

When I first saw the the Cyber Kill Chain, it wasn't actually the Cyber Kill Chain.  What I saw was the Websense 7 Stages of Advanced Threats.

The Lockheed Martin Cyber Kill Chain states there are seven stages of a cyber attack, and your organisation can be protected, if the chain is stopped at any of the stages.  The higher up the chain it can be stopped, the better the protection to your network.

The stages are as follows:

  1. Reconnaissance
  2. Weaponise
  3. Deliver
  4. Exploit
  5. Install
  6. Command & Control
  7. Act on Objectives

Websense 7 Stages of Advanced Threats


Websense have taken the phases above, and mapped them to the Websense 7 Stages of Advanced Threats.

Recon

Prior to a breach, some research (or recon) will need to be done.  This research will include the company and its people.  By way of checking yourself, a quick internet search of your organisation or you will bring up a lot of information.  The use of LinkedIn helps pinpoint people to organisations, as well as organisations that work together.  While Facebook and Twitter will help with hobbies and out of work activities.

Lure

If hobbies or working relationships are known, the lure containing information regarding hobbies or an organisation you work with will be of interest.  The lures can use email and social media from seemingly trusted sources.

Redirect

Emails and social media can contain links, which then redirect the target, scan a system or prompt for software to be installed.

Exploit Kit

The links can be for compromised websites, where an exploit kit located there can scan the users computer for vulnerabilities.  The exploit kit is effectively looking for a path into the computer.

Dropper File

The dropper file is the malware that is used to infect the users computer.  The software when executed can immediate start gathering data, it can sit dormant for a period of time to mask it's true intentions, or may be used to deliver malware in the future.

Call Home

The malware can then call home, contacting a Command & Control server to receive instructions, or additional software and tools.

Data Theft

What as the point of all of this effort?  To steal data!

Stopping the Attack


Not all attacks will contain will seven stages.  Some attacks will only involve three of these stages, but it highlights the sooner in the chain the attack is prevented, the less damage that will be done to the network.

Working in a technical environment, I see a number of solutions that only focus on some of these stages, which is no good if the attack skips those steps.  I have worked with the Websense solutions for over seven years, and see that their solutions can prevent attack at all levels (expect the "Recon", but no technical solution can prevent an attacker from carrying out an internet search on people or organisations!)

MTI is a Websense Platinum Partner in the UK, and can help secure your network against cyber attacks.

Compromise the security (looking back at the RSA breach)

I had an interesting conversation with family this weekend, where I was talking about securing iCloud using two-step verification.  Someone mentioned that with personal data it's not really important, but from a work perspective (they use to work for a large US company based globally) that RSA tokens protected them.

Back in 2011, RSA was compromised and is pretty much well documented.  As a summary, here's happened:

  • Targeted emails were sent to the HR team at RSA
  • Prior to the compromise only 11 emails were sent, but all of them were caught by the SPAM filtering solution
  • One of these emails were released to the HR team as it looked important
  • When the attachment was opened, it installed malware onto the computer exploiting a vulnerability in an Adobe product
  • With this access, the hackers were able to pivot onto other servers, eventually getting to the token database, allowing them to generate the "secret" code of a token with a specific serial number
This breach is said to have cost RSA $66 million, but beyond the actual costs, there reputation of RSA as a security vendor was brought into question.  It seems that this wasn't the end goal of the hackers, but rather the start to something much more spectacular!

Lockheed Martin is supplies military and aerospace technology to a number of organisations, including the Pentagon.  This in itself would make Lockheed Martin an obvious target for attackers, but as an organisation concerned about security, they used RSA tokens to protect their network.

It would seem that Lockheed Martin were potentially victim to a state-sponsored attack from the Chinese government.  Knowing that the target organisation were protected with RSA tokens, make it difficult to compromise them.  Much easier would be have access to the RSA tokens, or at least the codes it would generate.

I appreciate that it is speculation that the Chinese nation state were behind the attack, but I would suggest that you do an internet search for two images and play "spot the difference":
  • Lockheed Martin F-22
  • Chengdu J-20
After the breach, Lockheed Martin created the Cyber Kill Chain, which shows the various steps of a compromise to your network.  Many security vendors have taken this methodology on board, and their solutions can be seen to help during certain stages of an attack.  I'll blog about this in more detail soon.

Monday, 28 July 2014

Hacking humans...

There is undoubtedly more news coverage on security breaches or hacks into some well-known companies.  When large retail chains like Target in the States, or massive online websites like eBay get breached, the concerns about losing data and the impact on the consumer is massive.

Technology will protect us…

There are many technical solutions that can protect organisations, from traditional security solutions such as anti-virus software, web filtering solutions, email filtering solutions, firewalls, intrusion detection and prevention, encryption, secure authentication and endpoint lockdown solutions.  There are new technologies, which use sandboxing technologies, behavioural analytics, data analysis tools, and next generation technologies refining and enhancing the traditional security solutions.

With all these solutions in place, it would be difficult to believe that organisations are still being breached, but yet most of these technologies are in and running in these organisations.  These systems are not infallible as a number of technical solutions were subject to a major security flaw, when the Heartbleed bug was highlighted.

Legislation will protect us…

There are many legislations when looking at Information Security, but although many are there to protect information, such as the Data Protection Act, Freedom of Information Act, Privacy and Electronic Communications Regulations, Computer Misuse Act, Terrorism Act, Official Secrets Act, Malicious Communications Act and even the new Data Retention and Investigatory Powers Bill.

Although these acts look after the information of the individual, an organisation or what the people can see, these are not safeguards to protecting organisations.  These legislations would have done little or nothing to prevent the breaches that typically occur.  

ISO 27001 and ISO 9001 are framework standards which can help safeguard the data through good practices, as can the PCI standard, but again organisations can adhere to these standards and still face the organisation being compromised.

Our people will protect us…

It is commonly joked within IT departments that "the problem is between the chair and the keyboard", implying that users are the weakest links.  It's not surprising as social engineering and more targeted attacks have the "look and feel" of legitimate communication.  When a large security organisation like RSA is breached it brings into question the users education.  In this situation, the spear phishing (specifically directed email) attack was launched and captured by the organisation's email SPAM filter.  The technology had worked, but the release of an important looking email and clicking on it, gave way to a breach that reportedly cost RSA $66 Million.

It is also believed that only 11 malicious spear phishing emails were received, all of which were caught by the SPAM filter, but it only took one person to instigate this PR nightmare.

User Education

It is often said that all compromises have used elevated privileges, which means the threats are targeting individuals because they have specific administrative rights or access to specific system.  Do not overlook the importance of user education and awareness.

The technology may to there capture some of the security threats, and legislations to help safeguard practices, but vigilant and well trained users will help organisations more.


Wednesday, 21 May 2014

eBay compromised...

Today, eBay made the news as it was announced that their database had been compromised.  Personal information had been stolen, including names, addresses, email address, phone numbers, date of birth and an encrypted copy of the users password.  The breach was believed to have occurred between late February to early March.

If you have an eBay account, the first thing to is change your password.  

Depending on the level of encryption, all that is needed to crack the password is time and processing power.  Although the PayPal database is separate and has not been compromised, I would highly recommend changing that password, if it matches your eBay account.

Although my PayPal account rarely has much money left in it, it was only protected with a password.  After today, this was changed to send me a code via SMS when I log in, so I require my password and my mobile phone to gain access to the account now.  You can activate that on your account here,

How was eBay compromised?  Some of the eBay user credentials were obtained and used to carry out the compromise.

We've yet to find out how, but I suspect that it was either someone aware of the eBay way of working, or it obtained via a spear-phishing attack.  Spear-phishing is where specific people are targeted, where the people are either known, or information has been gathered from public sources, such as social media.  Once aware of information relating to the user, they can be targeted by many means, including email.  Typically when the user falls for the trap, software will be deployed onto their computer and the target monitored.  Credentials can be gathered and then used against the organisation the hacker is targeting.

Lockheed Martin pioneered the Cyber Kill Chain where there are seven steps to the potential compromise, and the aim is to break the chain at any one of the seven points.  The sooner, the better.

Another concern is that most organisations would require users to have privileged (such as system administrator) access to be able to access such information.  There are solutions out that that can could have prevented this by managing the password on behalf of the user. 

I'm sure more information regarding the compromise will come to light over next few weeks.  It's surprising that more protection and prevention hasn't been deployed, but being a large organisation like eBay they will always be targeted.