In a Russian Conflict: Cybersecurity another Dimension of Attack

In that cybersecurity is another Dimension of attack  (versus Dimensions: Land, Air, Sea, and Space) how would we be affected by this dimension?

In Land one sees their foe most of the time, and if the enemy wants to take your stuff they have to physically take it.  (Or they try and send munitions instead via Artillery with limited range).

In Air one can take troops up and over your land and enemy land forces to drop them and take stuff. Munitions are able to  drop from remote areas, but one has to send missiles and airplanes where radar can see them.

In Sea one can move around with ships or submarines to drop people to take stuff. The munitions are sent via devices as well which are physical.

Space is also a dimension which although in a unique area, is also a physical dimension with physical munitions.

In Cyber how do you know if the enemy is not already in your  systems.  There is no need for enemy soldiers to leave their homes or their barracks, they can attack your infrastructure without moving. Control of your computers can be done automatically and it can look like a third party attacked.  Cyber has an electronic dimension so the fact that it is not as physical “or real” has made understanding this dimension more difficult for some.

So what does this mean? It means if you understand how to navigate a command line or can read custom code you can understand this phenomenon (Cyberwar) in ways a non speaker is not capable:

Maybe this analogy will help:

You know in Physics there is Height, width, and length?

What about the fourth dimension(and not time) :

It is hard for us 3D people to think 4D.  So that seems to be the same for people who do not live in Cyber, they just DO NOT get the details!!!   It does not matter how much I try to explain the details, 4D is too much of a leap for some.

 

So I think Cyber is just too difficult or maybe a better word is ‘strange‘ of a concept for many people.

 

 

The compliance departments are reverse engineering the effects of a breach and Cyber understanding.   It is too difficult to decipher code, so we say don’t perform CC processing without encryption.  We don’t say what the encryption is and how it should be sent. There are many more pitfalls for a manager without technical knowledge.

If Hackers can steal data of your prized customers with a thermometer, then what else can they do?

So what to do? Create Cyber audits to review the IT world in your entity. Otherwise you will see headlines that you will not like.

Contact Us to discuss

 

 

The Real Problem With Facebook Privacy Issues

We can easily read the latest news on Facebook’s transgression of not protecting privacy of 50 million users on the CNN website ,  on 2015 this ‘hack’ supposedly happened and Facebook ‘let’ it happen.

I guess the media and the rest of the world was not paying attention, as in 2009 Dark Reading story: “Private Facebook Info exposed By Simple Hack”

Apparently a blog called FBHive was able to view supposedly private information .

How about this:

In 2008 a Sophos video about how to view everyone’s birthdate on Facebook, even if it claims to be “secure”.

So all one needs to do is hack Facebook. So what do I mean by that? Well, all one has to do is to play around with the URL settings of Facebook.

I.e. https://www.facebook.com/<FirstInitialLastname> for  main account lookup, but then you need security username and password.

If you use https://www.facebook.com/photo.php?fbid=

Then use a set of numbers, which you can modify to look at other people’s  information. What all these hackers found out is that Facebook has some settings that are public no matter what Facebook Privacy settings are. (we are not going to ‘hack’ Facebook on this post) .

So, what to do? The only thing one can do is to have a sufficient red team and make many tests from outside Facebook. It is obvious that Facebook does not have the capability to review its own security flaws.

So if one is a programmer then one can create quick programs to cycle through all numbers and place them in your own database, thus creating your own database of all the Facebook userbase.

There are more problems, one programmer was able to delete other user’s photo albums. The specific details are at zerohacks.com  “Deleting any photo albums – How I hacked Your Facebook Photos”

Needless to say the enterprising programmer was able to delete another photo album and received $12.5k from Facebook’s bug bounty program. (He released to Facebook first not to the criminal hackers).

 

 

A serious Cybersecurity Audit must be performed by known attackers, call the ethical hackers or certified Information Systems Auditors (CISA).  The price for this audit is cheap compared to the damage being done to Facebook today (many billion$ in stock price and reputation). The estimates are that Facebook has over 2 Billion monthly active users (Zephoria Digital marketing).

Even as some younger users disconnect due to shifting moods, there are still quite a few users on Facebook. I suspect this is only a beginning of the blowback to the Facebook reputation. As this latest election related snafu has created quite a big spotlight.

The point of this post is to be careful what you post, as if you post, it is public no matter the safeguards. Hackers are always out there probing for weaknesses, and it is better to find them yourself rather than have the criminals tell you after a defining Cybersecurity event for your company.  TonyZ says: “Do not post anything that you are embarrassed for the world to know!”

Contact Us to discuss your Cybersecurity audit program.

 

Replace your Wi-Fi Router if 2yr+ old

Insignary had some research and created a report that looked into the binary code of most of the routers on the market. Technewsworld has  a story…

And Business Insider has a story

The short story is that many router companies do not update their devices which would mean customers would have to upgrade firmware, which is also doubtful, but at least it is possible to update and secure your router.  Many people do not update because it is difficult or time consuming, and the router upgrades require a technical skill missing in most home users anyway. It seems that all of the vulnerabilities of the routers:

WPA2(KRACK) – Key reinstallation attack

ffmpeg – DoS attack

openssl – DoS attack, and remote code exec

Samba – remote code exec

OSS components have weaknesses which are also open source.

New components that are secure have been created but have not been created to coexist with the Wi-Fi devices (within their firmware). If they would have been created you would have to download the firmware and then you would have to update this firmware. So the process of updating firmware in Wi-Fi routers differs with each manufacturer, I would go to your manufacturer website and try to find out if a new firmware has been released.

But as a safety precaution (with security in mind) it is probably best just to buy a new Wi-Fi  router (which has  software that does not have these old vulnerabilities.

So it depends on your level of risk and what you are protecting. Myself I always like to update my computers and wifi devices every year or every two years anyway.  If you are in the habit of doing this as a standard way of doing business you will not be affected by these vulnerabilities.

 

Contact Us to discuss your risk exposure and decide what upgrade standards you might need.

Attack Life Cycle Changed By Cloud

Great video from BSides Columbus Ohio 2018 :

“Zero to Owned in 1 Hour”

That is an interesting review of how the new potential weaknesses are in the Cloud itself.

Human Access to the cloud can be a weak point.

AWS (Amazon Web Services)

Does Multi-factor Authentication work with multiple people running things?

Service Provider (cloud company) – has a main login, here is where the hacker can get the keys to the kingdom.  what if the hacker can figure out to get the main account login somehow? we are so busy locking down all the desktops and more, it is the easy items that we seem to fall down on.

The comparison with the old life cycle is interesting, as we were so focused on denying system access last year (or pre-cloud).

Today  if the main account somehow is taken over the hacker does not need to escalate privileges or keep access in the network since the main control account can do all of that and more.

So due to the big beacon of if you capture this item then you have keys to kingdom, what can we do to prevent this?

You have to review how the system administration and ownership of the cloud account is handled.

  1. How many people are managing the main account
  2. How is the password/authentication performed?
  3. Who is reviewing the security of this important account?

I.e. who should be at fault if there is a security problem? The Cloud company (or service provider)  or our own IT people? At first blush, you would think it depends on the problem, but the interesting thing about this is that some cloud companies want to push that responsibility to the client.   Check this post by CSOonline.com :

12 top cloud Security threats  “Treacherous 12”

  1. Data Breaches
  2. Insufficient Identity, credential and access management
  3. Insecure interfaces and application programming interfaces (APIs)
  4. System vulnerabilities
  5. Account hijacking
  6. Malicious Insiders
  7. Advanced Persistent Threats (APTs)
  8. Data loss
  9. Insufficient Due Diligence
  10. Abuse and nefarious use of cloud services
  11. Denial of Service (DoS)
  12. Shared Technology vulnerabilities

 

This is a nice list, so which threats could be classified “service provider”, and which would be more the client fault?

All of them could be both or either , except for System vulnerabilities which  is just Service provider. Denial of Service ought to be service provider as well.

The problem is that the client can affect almost all of them as the client drives the applications and thus the technological trail. Or the client really controls most of the issue like account hijacking (main account)

As usual someone has to review and check (technical Audit) to make sure that the technology is doing what it is supposed to be doing “securely”.

Contact to discuss

CyberAttacks More Sophisticated

The attackers are getting better, they are not sitting still.

If you are hoping no one will notice you in your personal world … not likely, everyone is a target.

In this post lets connect a few dots:

SCmagazine story:“Social Media and Engineering Used to spread tempted cedar spyware”

So a fake Facebook profile method is infecting unsuspecting Facebook users (also called social engineering) using a fake app called kik. This app is actually designed to steal information from unsuspecting users that click on links or download the app.

So what do the criminals actually want? In the articles about this particular spyware is that the targets were in the middle east. So the criminals are looking for information – which can be used to make money with other information that they already have. I.e. if for example they stole a database  with partial information, then would want to fill in the blanks.

(Image from hackread.com)

As the phones get more powerful with more apps and capabilities we have more information stored everywhere. So it should not be a surprise as health data will be more important (here is a picture of the new Samsung S9 unveiled in Spain Mobile World Congress 2018):

How about when you go to major newspaper like Los Angeles Times? Did you ever wonder if you could get hacked just by going to a website? Yes it can happen. Apparently cryptojacking code was found on the website by a security researcher. The cryptominer was based off Monero Cryptocurrency, which is an open source Cryptocurrency.

This hack at LA times was more sophisticated (than some others) as they kept the miner from taxing the visitor phones(sometimes can be set to use 100% of resources) so as to stay unnoticed.

Apparently the LA Times had a misconfigured  website setting allowing anybody to upload code to a section of their cloud account on Amazon Web Services (AWS).  So why not upload some crypto mining code and make some extra Monero’s when you can, that is what the criminal said?

 

So, now there are fake Facebook profiles, just like fake Twitter accounts. When you go to some websites it may unknowing to you download some software that uses your CPU, the idea is to find information about certain individuals so as to make more sophisticated attacks.

Notice the IRS hacks have become more sophisticated: KrebsOnSecurity has a story “IRS Scam Leverages hacked Tax preparers, Client bank accounts”.

So if you have a specific profile that the criminal is looking for, then there are a variety of ways that the criminal can get to you to make more and more money.

Here is a unique attack scenario:

“We’re having customers getting refunds they have not applied for,” Dodd said, noting that the transfers were traced back to a local tax preparer who’d apparently gotten phished or hacked. Those banks are now working with affected customers to close the accounts and open new ones, Dodd said. “If the crooks have breached a tax preparer and can send money to the client, they can sure enough pull money out of those accounts, too.”

Tax preparers and accountants are going to be targeted by  criminals, especially in the next couple of months (March-April 2018). If your security is not up to par, then you will get a visit from a criminal in ways you have not thought of – including social media ‘friends’ videos and links to click on.

There are also Fake IRS websites that criminals have set up and if you find yourself on them, enter any of your personal data now the criminals can create your tax return and take your money.

Remember some of these attacks can be put together to target somebody that criminals want (accountant at a prominent company for example). We must prepare ourselves mentally and in other ways.

How about this – If you are wanting services from a tax preparer have they done the security audits to ensure as much as possible to reduce chances of hackers succeeding?

Ask them when doing your taxes – have them contact us.