Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Wednesday, March 2, 2016

Wednesday, February 24, 2016

Usernix Enigma 2016 - Hacking Health: Security in Healthcare IT Systems

A great talk by Avi Rubin - slightly sarcastic at times - on the IT security in the healthcare industry, a particularly challenging industry when it comes to security. While it has become very good at safety, security is still lagging behind. Avi even mentions an argument I was opposed once when doing a security assessment for a hospital: "if it delays us by 5 seconds, it will cost lives."


Wednesday, February 17, 2016

Usenix Enigma 2016 - NSA/TAO Chief on Disrupting Nation State Hackers

This is not often that the chief of one of the biggest exploitation team from one of the biggest intelligence agency in the whole world gives a talk about his job, and more specifically about how to make his team's job harder.

Do not expect any ground shaking revelations: everything he says have been said before. But private companies and government agencies are still failing to implement the tools and steps he talks about.



Wednesday, February 10, 2016

This is what happens when you reply to spam (TED Talk)

What happens when you reply to a "too-good-to-miss-offer" coming in an e-mail? Good things? Bad things? Comedian James Veitch decided to find out for you. He went into a weeks-long exchange with a spammer and kept engaging his correspondant, and tells his story in this TED Talk.

This is hilarious and totally surrealistic. Most of all, this is really interesting.

James Veitch: This is what happens when you reply to spam email


Sunday, January 4, 2015

"Data Mining Tools for Malware Detection"

Here is a review by Jean: http://www.goodreads.com/review/show/1054850667

Monday, December 1, 2014

PoS malware found targeting mass transit systems

The security company InterCrawler has found a new malware strain that targets the mass transit systems. 

In the report, a sentence had both my eyebrows raise and my jaw drops at the same time:
"During ongoing POS investigations it was determined that some operators of Point-of-Sale terminals have violated their own internal security policies and have used their terminal for gaming and WEB-surfing, checking e-mail from it, sending messages, and viewing social networks. These cases have a common denominator of weak passwords and logins, many of which were found in large 3rd party credential exposures."
This is almost 2015 and still people operating Point of Sale terminals are still incapable of realizing that their actions can result in huge dramas. 

To the casual reader, this seems bad. To the security-minded, this is even worse: it means that these machines had, at the time of the breach, access to the Internet. This is in direct violation of the PCI standard. 

Last Friday was Black Friday in the US, I am curious to discover how many retailers were compromised and how much money cybercriminals have amassed.

Monday, March 3, 2014

Modelling Security Awareness

A nagging issue in security is to evaluate the level of a group or of a single person: does that person know? How well does she understand the concepts? Does she realise what the consequences might be? 

Traditionally, this is done through a series of tests/trainings: a company such as PhishMe offers a wide range of phishing tests, that lead to trainings or information pages. For example, if a user provides his credentials, he is sent to a video that explains he would have potentially given access to the corporate network to cybercriminals. While there is a huge value in doing these, it only assesses the ratio of people who failed the test, but not the depth of awareness of people who succeed: a person may pass the test because "providing my e-mail credentials when clicking on a link is wrong", but may fail to see that the PDF file attached to the next e-mail is malicious. 

In order to evaluate how well security concepts are understood, I suggest using a different scale, IKUC. This stands for

I - Ignore
K - Know
U - Understand
C - Care


Ignore - the base level: the person has no knowledge of it. The term or concept may have been heard or read about, but the person can, at best, vaguely formulate it.

Know - the level at which a person can quote a precise definition or explain what the concept is, but this sounds like a mechanical regurgitation.

Understand - not only the person knows the definition but also succeeds in explaining it and how the concept works.

Care - the goal level: the person understands the term or concept, but also the threat and impact that may result. This is the realisation that the term or concept is not merely words, but an actual attack that can affect the person or the company in various ways. 

This is a progression: in order to understand something, you have to know it. In order to care, you have to understand it. While one may argue that it is possible to care for something that is known but not understood, I think that this is inefficient, as it quickly turns to recognising scenarios instead of the broader, underlying concept. This may be seen as the "don't click on links in e-mails", which leaves the possibility for clicking on files or answering the e-mail with the information the attacker seeks.

By elevating the user from a basic knowledge to understanding, not only will the concept by clearer and easier to recognise, but also this enables the user to relate a variety of threats as being really the same "thing." In the long run, this saves time and money to the company by not having to develop a scenario for everything.

Caring is the next step, it is the realisation that not only there is a threat, but that threat has an impact on the person or the firm. That is the realisation that "bad things don't happen at random." This is, for me, the "true awareness" and is summed up in the idiom "once burned, twice shy." However, "cyberburning" can be persistent (think "credit score damage") or even fatal (DigiNotar, Mt. Gox and an article from Fox Business). This is by far the hardest step, as human being we tend to downplay the risks or impacts when we want something (either to possess it or as a mean to achieve a goal, such as performing one's duty), but to exaggerate the inconvenience of anything that may stand between us and these goals/things.

 Unfortunately, this "magnification of inconvenience" and "downplaying of risks" clouds the step from "Understanding" to "Caring": "if it is inconvenient and not that risky, why should I care?" Sounds familiar? For me, way too much.

A good security awareness program has to address both the K, U and C states. It has to make sure everyone knows what is being explained (the "K"): if it is phishing, does everybody know what phishing is? Can it be defined in a simple way and without requiring to drop various examples? From there, does everybody understand how this works and is everybody able to recognise such a scenario for what it is?

As I wrote, getting to the C is the hardest part, due to having to go "over the ledge of perception of the "rarity", "lack of danger" and "inconvenience of doing otherwise." It is also by far the most important step. This may be related to a speed limit on a street: we all know what a speed limit is, most of us understand why a speed limitation may be placed somewhere, but some of us fail to care and just disregard the limitation. From time to time, this leads to an accident, injuries and possible death.

I think this is where all the "phishing" companies fail: they focus on bringing people to the C directly, regardless of the previous state. A more comprehensive process would be to make sure that everyone attending such a training has gone through the K and is at the U state before leaping to the C state. 

Saturday, February 22, 2014

HHS Info for 2013

The human health services (HHS) publishes on its website the list of breaches that affected at least 500 people. This is a trove of information concerning the Health breaches.

For the year 2013, there are 217 breaches that either started or ended, totalling 7,636,544 records, an average of 35,191.45 records per breach. The minimum is 500 (the minimum to be publicly reported), the maximum 4,029,530 records. The first quartile is 1,127 records and the third 6,332 records.

The breach that resulted in 4,029,530 records compromised affected Advocate Health and Hospitals Corporation, d/b/a Advocate Medical Group and was due to the theft of a desktop machine.

The following graph shows the geographical distribution of these breaches, with green being the least and red the most. The "white" states reported no breach affecting more than 500 records for 2013, which doesn't mean there was none: either each breach affected less than 500 users or the breaches were not reported to the authorities, which would be a clear violation of HIPAA.



The five states with the highest number of breaches are California (23), Texas (17),  Florida (15), North Carolina (14) and Illinois (13). These five states represent 37.78% of all breaches.

In terms of number of records compromised, the map becomes

The five states with the most affected records are Illinois (4,112,982), California (940,541), New Jersey (852,953), Texas (781,771) and Indiana (218,084). These five states represent 90% of all compromised records. It is to be noted that Illinois inherits the title of "highest number of records compromised state" due to the "Advocate Health & Hospitals Corporation" breach.


The most cited cause for a breach is "Theft" and related, with 92 breaches or 42% of all breaches, totalling 5,923,705 records. Interestingly enough, all the "Hacking/IT Incidents" represents only 17 breaches, or a bit short of 8%, for a total of 532,230 records. The average number of records compromised through thievery is 64,388 and through IT Hacking 31,308.

There is already an interesting trend there: a breach is more likely to happen through a stolen device than through hacking and with more severe consequences. However, it is also important to keep in mind that the gigantic breach that affected more than 4 millions users drags that number way up. If it is removed, the average goes down to 20,815 records per breach on average, below the average for a breach resulting through IT Hacking.

Out of the 92 incidents that involved theft in a form of another, 52 of them mention that the location of the information was on a laptop, more than 56%. If we add to that the category "Other portable devices", the number rises to 57 (62%). On average, an incident involving the theft of a laptop resulted in the disclosure of 33,827 records. The maximum reported is 839,711 compromised records for such an event.

It is interesting to notice that these 52 incidents represents the vast majority of all the breaches involving laptops. The following graph shows the type of breach for all the events concerning a laptop.



Geographically, a breach through thievery happened 12 times in California (52% of all CA breaches), 8 times in Florida (53% of all FL breaches), 7 times in Texas (41% of all TX breaches), 6 times both in Ohio (55% of all OH breaches) and Georgia (55% of all GA breaches). It is interesting to notice that the proportion of breaches through theft amounts to half of the reported breaches, at least for the top 5.

But laptops and mobile devices are not the only ones susceptible to be stolen. These devices represent 57% of the stolen containers. The following graph shows the distribution for the non-laptop stolen devices/containers that led to a breach.


"Desktop Computer" and "Paper"represent the top two categories. There is no explanation on how these were stolen, but one could safely assume this resulted from a burglary or break-in.

But thievery is not the only cause of data breaches. The second most cited cause is "Unauthorized Access" with 58 occurences (27% of all breaches). All together, "Theft" and "Unauthorized Access" represent 69% of all breaches. From a number of records perspective, 435,880 records were breached due to improper access.

The location of the breached information changes dramatically: if the laptops were the main location in the thievery scenario, in the unauthorized access the most cited location is paper with 16 occurrences (28%), then E-mail and "Network Server",tied, with 11 occurrences (19%). A note: some reasons include multiple reasons, I counted them for each category.

'Unauthorized Access' happened predominantly in Florida (8 incidents), Montana and North Carolina (5 incidents each), in California (4 incidents) and in Texas, Puerto Rico, Oregon, North Carolina and Illinois with 3 incidents each. These 9 states are responsible for about 60% of this type of breach.

The "unauthorized access" on paper information accounts for 32% of all breaches involving paper documents. Unfortunately, the main reason is often described as "Other", which means that the details are not available in the HHS database.

The "type of breach" represents the issue that permitted the breach. Several rows include multiple reasons, such as "Theft, Other". It is possible to extract seven "major themes":

  • Improper Disposal
  • Theft 
  • Loss
  • Other 
  • Hacking/IT Incident 
  • Unauthorized Access/Disclosure
  • Unknown 
The following figure presents the number of occurrences of  each reason. A reason that includes multiple "simple" reasons will be counted for each category.





Clearly and as already described, "Theft" is biggest issue, then "Unauthorized Access/Disclosure." Unfortunately, the third one is "Other", which is not self explanatory. The "Hacking/IT Incident" comes fifth, between "Loss" and "Improper Disposal."

What can we conclude of this?

The Health industry ("HI") is still struggling with breaches, and more importantly, with "stupid" breaches such as theft and unauthorized access. Unfortunately, every time one happens, people's lives can be ruined. It is then of the uttermost importance that the HI gives the patient information the highest priority in terms of protection.

Almost a quarter of all breaches (in count or in number of affected individuals) results from the theft of a laptop. This is a lot! This points to the fact that some data is simply not meant to be carried on portable devices. However, it seems that the HI is still having difficulties with this concept. And this is not looking very promising in the light of the current BYOD craze...

This could be solved by adopting a number of simple rules, such as "if it touches the network of an hospital, it is encrypted. If it works for an hospital, it is encrypted. If it has an hospital in its client, it is encrypted." Yes, that means that lots of companies will have to invest in disk encryption technologies; I don't think this is a huge problem in 2014. This is more a no-brainer.










Monday, February 17, 2014

Phishing Techniques, Consequences and Protection Tips

Phishing is now a prevalent attack on the Internet, and several "big cases" started with someone being tricked into either providing information, or clicking on a link or a document.

Rohyt Belani, CEO at PhishMe, gave an interview to Help Net Security some time ago. This is very interesting.

Friday, January 31, 2014

Yahoo prompts users to change passwords

Yahoo prompted its users to change their password after a database of usernames and passwords was accessed by unnamed attackers. Yahoo claims that its own systems were not compromised, but that a third-party was.

More here.

Wednesday, January 15, 2014

An introduction to Firmware Analysis [30c3]


For  many, the term "firmware" refers to some kind of black box software that no one really has access to. This talk explains how to analyse such an image. For example, that's how recently it was found that certain consumer routers have a default hardcoded username/password, or that some administrative pages were accessible without authentication.

A very good talk from Stefan Widmann. Enjoy!





Monday, January 13, 2014

Target breach worse than initially thought

I guessed the Target breach would prove worse than initially thought, but that worse? Woaw! No.

In addition to the 40 million credit and debit cards records stolen, it seems that "at least 70 million PII records were also accessed." The Star Tribune also mentions the opinion of Jack Tomarchio, attorney specialized in cybersecurity and data protection, who claims that if the credit and debit cards breach was bad, the PII one is even worse: the banks can quickly revoke a credit or debit card, but people are usually unwilling to change where they live or their name.

And to have a good start for 2014, not only Target and Neiman Marcus were hit, but it appears that several other retailers suffered the same type of breach.

2014 already announces itself as the Year of the Permanent Credit Card Monitoring.

Monday, December 30, 2013

Using openDNS

One of the main alleys to distribute malware is through the Web: an e-mail contains a link, which is clicked and *bam* the machine is infected. The mechanisms behind that are usually similar across the various strains: the website is accessed, there is a client-side exploit that downloads a piece of malware, which executes and connects to a site to get its instruction or dump its payload.

A common theme is the use of DNS to resolve a name to an IP address: some names have hundreds of "A" records, corresponding to as many compromised machines. A freshly infected system will try to resolve one of these, then connect and proceed as explained above.

Numerous open source initiatives exist to establish lists of these "bad domains" or "malware domains". The most famous is the Malware Domain List, which has several options (csv, hosts, ...) that can be used to generate either a DNS or proxy black list, firewall rules and so forth.

However, this requires that you have either your own DNS or proxy server, or that your firewall supports an automated way of importing the list. Not always possible. In addition, this covers only malware, and for instance, there is no categorization. And unless you add more tools, you have little to no visibility on what is dropped.

This is where OpenDNS comes into play. The service is presented as a traditional DNS server, two in fact, and people can add it instead of their servers: as a forwarder in a corporate server, as a DNS server in a small router or host. Immediately, the known malware domains are dropped and returns the IP of a server operated by OpenDNS to inform that the attempted resolution was nefarious. This also includes typos (mircosoft.com instead of microsoft.com).

But the power of OpenDNS starts when you register with an account - even a free one. Then, you have access to domain filtering by categories - have you ever wanted to drop all these adware sites? - and to statistics. Note that by default the stat collection is disabled.

These consist in the number and type of resolutions, presented in an hourly format, the number of unique domains resolved, the list of resolved domains and how many times over the requested period (a day or multiple days), the list of blocked domains and the reason.

The OpenDNS team is constantly implementing new features, and there is an "idea bank" where users can submit proposals or requests, such as a filtering base on the geolocation of the IP returned, or more logging and alerting.

But what good does it do if the only thing you can see is that "a machine in your network has attempted to resolve a known bad name"? That's why they have developed an agent to install on the end machine: it forces the resolution to go through OpenDNS and provides some more information, allowing for the quick identification of systems.

OpenDNS also offers other services, such as a web filtering proxy and more.

All in all, this is a really nice service to use. It is not expensive at all and can really complement a security solution by providing an additional filtering layer.




Monday, November 11, 2013

PCI DSS 3.0 is out

The Payement Card Industry (PCI) Security Standards Council has released the version 3.0 of the Data Security Standards (DSS). These can be found in the Documents section.

Version 3.0 brings lots of changes: some controls have been rephrased for clarity, several controls related to policies and operational procedures have been added and some accent is put on the treatment of vulnerabilities. A summary of the changes can be found here.


Monday, September 2, 2013

Hacked through the mains!

A few months ago, I was confronted to an issue: my wireless network was not powerful enough to get to the very far confines of my office, and my desktop computer would periodically lose its connection to my small LAN. To solve this I went to a nearby computer store and I bought a pair of ethernet-to-mains modems from TP-Link, which I used for a few weeks. They are

As I didn't have a Windows machine at that time, I left the modems in their default configuration. Then, as I had a few disconnection issues and I didn't like the fact that the traffic was not encrypted, I replaced the pair with a very long cable.

Recently, I found them back and I decided to play a bit with them. To my surprise, as soon as I plugged the first one, it picked up a connection. Surprising as the other one was still in my hand ... I decided to plug the cable and check what network I was connected to.

The router is a Netgear's DGND3300B, an interesting model with a few cool features, such as a Traffic Meter, a built-in shared drive - provided that a USB device is plugged in -, a media server and much more. Well, it's also the case that the box has a default username/password combination of "admin/password".

This gave me access to my neighboor's router. So basically, I pwned his network: I could have disabled the DHCP server to install my own in order to play man-in-the-middle (MiTM), activated random features or even leeched on his network.

These little powerline modems are cool, but they are also very dangerous: in the same way as a wireless connection, it is very difficult to put an exact border to the network once it is extended through the power network, and it falls on the user to make sure the devices are properly configured to only talk to each other, and never to any other device that could be reachable.

Wednesday, August 14, 2013

Smartphone Experts notifies customers of hack

That's the usual story: a payment-processing site/application got hacked, customers' data lands in hackers'hands, company notifies customers. However, there is something that really shocks me:

Although stored customer data were encrypted, Diana Kingree, the Senior Vice President of Commerce, noted that the hacker may have been able to use a decryption feature of the system to view customers’ names, addresses, credit or debit card number, CVV, and card expiration date.
The PCI-DSS Requirements state in point 3.2.2

Do not store the card verification code or value (three-digit or four-digit number printed on the front or back of a payment card) used to verify card-not-present transactions. 
This code is meant to be used when the person executing and the card used to execute the transaction are not physically present where the payment takes place. This is, to some extent, a password or a PIN. Why companies still store that CVV code? Beats me.

Storing the CVV defeats its whole purpose: making sure that the person doing the payment possesses the card. By having it in the same database as the credit card number and expiration date, its role is completely negated.



Friday, August 9, 2013

Chinese Hacking Team Caught Taking Over a Decoy Water Plant

Not a surprise, but still, quite a shock: a security researcher set up a decoy water plant, simulating everything from the workstations to the industrial control systems and caught some hackers who infiltrated his systems. If they got in his system, chances are they are already inside other providers such as energy and telecommunications providers.

The article is here.

Friday, August 2, 2013

FACTBOX - Hacking talks that got axed

The struggle between security researchers and private companies is nothing new: there are numerous examples of researchers or hackers being coerced into not talking about a vulnerability found in a product, in a website or even in a hardware product. This also include not talking at hacker conventions.

There may be various reasons for that, such as "the company doesn't want its reputation to publicly suffer" or "black hats may get the information and turn it to their advantage." There may also be an unsaid reason: some companies develop exploits for these vulnerabilities and sell them to "trustworthy" Governments and Agencies. Examples include VUPEN and the (in)famous FinFisher, part of Gamma Group. It is to be noted that the latter doesn't explicitly mention that its products are reserved for the same "trustworthy" Governments and Agencies, and as a reminder, a Gamma Group offer was found among torture equipment in 2011 in Egypt, when rioters invaded the State Security Investigations Services HQ. Given that private companies do it, there is no reason to believe that governmental agencies around the world don't do the same.

In that light, any publication of any kind of vulnerability is a hindrance: not only it may force the vendor to take action and fix the vulnerability, but it also gives other security researchers a base on where to start looking for ways of detecting or mitigating the vulnerability.

The argument of "it may help the bad guys" is not entirely valid: the cybercrime world has shown many times it can find vulnerabilities on its own, be if for software Zero-days or hardware hacks. To believe that a security researcher is the only one to look for vulnerability for a given piece of technology is simply unrealistic: if it can lead to money - and most of the time it can - the bad guys will have an interest in it.

Remains the reputation concern, which may also be a poor excuse. A number of companies. mostly dealing in the Open Source movement, have opted to publicly disclose everything concerning vulnerabilities and breaches. As a result, some have actually gained recognition and the trust of their users, as they know what to expect. A real excuse is the cost of fixing a vulnerability: it may take a lot of work, which translates into hard cash for the companies, and that often for products available for free (think "Adobe Reader", "Adobe Flash" or "Oracle Java" to name a few of the usual suspects.) On the hardware side, it is even worse: if it is possible to distribute a patch, applying it to millions of cars or door locks is problematic, as this fix may need a special tech.

A concept that has been developed over the last few years is "responsible disclosure", a discussion between the security researcher who found the vulnerability and the company that makes the affected product. The "responsible" part is that a delay is negotiated before the vulnerability is made public. However, this has been slowly replaced by "vulnerability commercialization": a company, such as iDefense or TippingPoint, pays any vulnerability (with a proof of concept) discovered. The question is: "but what happens after?"

That concept of disclosure is very sensitive: it has been used in the past as a form of blackmail against the affected company, either to have them address the problem quickly or to simply extort money. These companies are no angels either, and often used the courts to threaten the security researchers.

As you see, this is a very difficult topic, and not one I expect to see settled in the near future.




Wednesday, July 31, 2013

Social Engineering as the Biggest Threat to Help Desk Security

From a recent SANS survey, 69% of respondents found that social engineering is the biggest threat to help desk security. Here is a link to the article on net-security.org and a link to the SANS white paper.

Monday, July 29, 2013

“NASDAQ is owned.” Five men charged in largest financial hack ever

I am not surprised: "NASDAQ is owned" are the words sent in a IM from an eastern Europe hacker just after he got some administrative credentials for one of NASDAQ's internal networks.

As I said in the past: "there are two types of companies, the ones that have been hacked and the ones that don't know it yet."