Friday, 9 August 2013

Letting companies strike back at computer hackers is a bad idea - A byte for a byte


SECURITY experts like to say that there are now two types of company: those which know they have been hacked and those which have been hacked without realising it. An annual study of 56 large American firms found that they suffered 102 successful cyber-attacks a week between them in 2012, a 42% rise on the year before. Rising numbers of online attacks are stoking a debate about how best to combat cyber-crooks. One emerging school of thought holds that companies should be allowed to defend themselves more aggressively by “hacking back”—using hacker-like techniques to recover stolen intellectual property and frustrate their assailants.
The discussion has been sparked by the rise of a new generation of hacker, either working for criminal groups or with close links to the state in places such as China. Advocates of hacking back argue that the usual digital defences are no match for these attackers. Instead, firms need to go on the offensive, using everything from spyware that monitors suspected hackers’ activities to software that retrieves or deletes pilfered property (see article). If an aerospace firm spots the blueprints for its next plane flying off its database and into the computers of a foreign rival, it should be able to give chase.
The concept of hacking back has some prominent supporters, notably in America. In May a private commission on intellectual-property theft, whose members include Jon Huntsman, a former ambassador to China, and Dennis Blair, a former director of national intelligence, gave its support to technology that helps firms track stolen files and then reclaim them or prevent their use without damaging other networks. Another idea, floated more recently, is for governments to license private firms to hunt down and deal with hackers on businesses’ behalf. But encouraging digital vigilantes will only make the mayhem worse.
Hackers like to cover their tracks by routing attacks through other people’s computers, without the owners’ knowledge. That raises the alarming prospect of collateral damage to an innocent bystander’s systems: imagine the possible consequences if the unwitting host of a battle between hackers and counter-hackers were a hospital’s computer.
Endorsing the idea of hacking back would also undermine current diplomatic efforts to get China and Russia to rein in their hordes of unofficial hackers. America has been a cheerleader for an international convention on cyber-crime that prohibits private actors from striking out online. Letting American companies, or their hired guns, retaliate against hackers would undermine that effort.
Governments can still help firms battle cyber-criminals. They can spend more investigating online attacks on firms. Many are already on recruiting drives for digital sleuths. They should also share more intelligence on cyber-threats. Companies say the advice they receive is often too vague, perhaps because spooks do not want to reveal their sources. And greater clarity is needed about exactly what digital tools can be used to combat hackers. The American Bar Association says it plans to release a report on this issue in the autumn.
More intel inside
Companies should also take a long, hard look at themselves. The hackers may be getting more sophisticated, but the methods they use to get their hands on corporate secrets are often absurdly simple. A report released this year by Verizon, a telecoms firm, found that over three-quarters of network intrusions at companies were the result of weak or stolen user names and passwords. Instead of tooling up to fight the hackers, firms should focus on plugging the holes that let them in.

New cell phone case hides you from location trackers

A US technologist has designed a phone case that shields your mobile's cellular, Wi-Fi, and GPS signals, keeping your location from being tracked.

New York-based artist and technologist Adam Harvey, has just launched a Kickstarter programme to develop the signal-blocking phone case called Off Pocket.

Harvey also made headlines in January for his line of stealth clothing designed to hide wearers from the spying eyes of drones, 'Discovery News' reported.

According to PopSci, the case is based on the technology behind the electric field-blocking Faraday cage, which protects electrical equipment from lightning strikes.

Like the cage, the Off Pocket contains a metal fibre mesh that blocks the wireless signals (frequencies between 800MHz and 2.4 GHz) coming from cell phone towers, bluetooth and Global Positioning System (GPS) satellites as they attempt to communicate with the user's mobile.

The Off Pocket is waterproof and 100 times stronger than conventional signal blocking bags used in law enforcement, the report said.

Thursday, 8 August 2013

Remotely Exploitable Bug Affects Wide Range of Cisco TelePresence Systems


        There’s a serious vulnerability Cisco’s popular TelePresence system that could give an attacker complete control of the affected system. The vulnerability affects a broad range of TelePresence models, although there are workarounds available.
The vulnerability results from the fact that there are default credentials set up in the TelePresence systems. If a user account is created with the default credentials, an attacker would be able to exploit the bug and gain complete control of the Web server on which the system is running. Cisco has not yet made available patched versions of the TelePresence software.
“The vulnerability is due to a default user account being created at installation time. An attacker could exploit this vulnerability by remotely accessing the web server and using the default account credentials. An exploit could allow the attacker to log in with the default credentials, which gives them full administrative rights to the system,” Cisco said in its advisory.
“Cisco TelePresence System Software includes a password recovery administrator account that is enabled by default. Successful exploitation of this vulnerability could allow a remote attacker to use these default credentials to modify the system configuration and settings and take full control of the affected system. An attacker could use this account to modify the system configuration and settings via an HTTPS session.”
TelePresence is Cisco’s video and audio conferencing system that is designed to mimic the experience of being in the same room with the other participants. Cisco TelePresence System Series 500, 13X0, 1X00, 3X00, and 30X0 running CiscoTelePresence System Software Releases 1.10.1 and prior; and Cisco TelePresence TX 9X00 Series running Cisco TelePresence System Software Releases 6.0.3 and prior are affected by this flaw.
In addition to the patch, there are some workarounds that can mitigate the effects of this vulnerability. Here’s the guidance for products that are registered with Cisco Unified Communications Manager:
1. Proceed to Cisco Unified CM Administration and select Device > Phone, search and select the configured Cisco TelePresence unit.
2. Under the Secure Shell Information (ssh), change the ssh helpdesk user name from the default helpdesk to pwrecovery, and then choose an alternate password.
This will overwrite the pwrecovery account stored on the Cisco TelePresence unit, and permit changing the password from the default to one created by the Cisco Unfied CM administrator.
3. Reboot the Cisco TelePresence codec to download the updated Cisco Unified CM configuration.
Cisco has not said when the patch will be available.

Carna Botnet Analysis Renders Scary Numbers on Vulnerable Devices - 470 million users are affected

internetreport
           The Carna botnet, more formally known as the Internet Census 2012, stirred up a hornet’s nest of controversy when it was unveiled in March to a number of popular security mailing lists. An unidentified researcher had found more than 420,000 embedded devices that were accessible online with default credentials, uploaded a small binary to those devices and used them to conduct an Internet scan of the IPv4 address space.
Questions about the ethics and legality of the project quickly surfaced, as did the realization that there was a massive amount of data waiting to be analyzed, and potentially millions of vulnerable enterprise network devices, industrial control systems and home networking gear that needed patching.

Parth Shukla, a relatively new member of Australia’s AusCERT, was one of the first to pore through the data collected by Carna. He received an uncompressed 910 MB  file from the researcher that held approximately 1.2 million rows of information, and after restructuring the data in order to properly analyze it, he quickly realized that there was immediate need to share his findings publicly.
“Public awareness; it was my duty to get this information out there and make people aware that it’s pretty bad,” Shukla said.
Shukla presented his research last week at an AusCERT event in Australia last week and told Threatpost today that he has begun sharing country- and region-specific data with local CERTs that have made requests.
“I heard about the project about a week after it was published and my first thought was that this was a historic moment because we had captured the state of the Internet at the end of IPv4,” Shukla said. “That was my first reaction, that it was awesome. The information is out there; the bad guys know it and are using it, let’s do something with it.”
Several things immediately stood out as Shukla’s research progressed, most eye-popping was the speed and ease at which one could find vulnerable devices, not to mention the number of ownable machines that are sitting online.  For example, finding a vulnerable device worldwide scanning at a rate of 10 IPs per second would take just under five minutes. Narrowing the scope to China, for example—which had the largest number of IPs in the Carna data—a vulnerable device would pop up every 46 seconds scanning at the same rate of 10 IPs per second. Shukla found on average one vulnerable device for every 456 IP addresses and 1.79 subnets in China. And China may not be the worst offender, he said basing that theory on the fact that other countries have a worse infected-to-allocated-IP ratio.
“Of the 1.2 million devices, more than half are in China (57 percent),” Shukla said, adding that he understands his analysis could make China a target. But with tools such as the Shodan search engine that accomplish the same thing coupled with the realization that most of the devices in the Carna report are likely owned that it was imperative to share the analysis. “That’s an important figure to pitch at people. Fifty seconds and we have a device with a default credential over Telnet; admin/admin and you’re in.”
The creator of Internet Census 2012 developed a binary that was uploaded to the insecure devices found during the scan to look for other devices. The binary included a Telnet scanner that would fire different default login combinations at the devices such as root/root or admin/admin, or would attempt to access devices without a password. The binary also included a manager that would provide the scanner with IP address ranges and then upload them to an IP address.
“We deployed our binary on IP addresses we had gathered from our sample data and started scanning on port 23 (Telnet) on every IPv4 address. Our telnet scanner was also started on every newly found device, so the complete scan took only roughly one night. We stopped the automatic deployment after our binary was started on approximately thirty thousand devices,” the researcher said in his paper. “The completed scan proved our assumption was true. There were in fact several hundred thousand unprotected devices on the Internet making it possible to build a super-fast distributed port scanner.”
Shukla hopes that manufacturers of networking gear who send products to market with default credentials will be among the first to heed his call to change the current state of affairs. While he is sharing his data with other CERTs and ISPs/telcos, he’s finding some pushback because the data does not come with timestamp information restricting the means in which providers that use DHCP, for example, can address the issue.
“I’ve spent days giving people data and pointers on how to use it,” Shukla said, adding that he hopes manufacturers will be among the first to act. “Hopefully CERTs in those countries can go to manufacturers with this data and tell them that, for example, ‘50 percent of the devices in our country are yours, what are you going to do about it?’ ”
Shukla said his next step would be to analyze the traceroutes of the vulnerable devices, as well as some anomalous data such as some of the same IP records appearing in more than one country. He also hopes to deliver continent-specific data.
“I want to put together as much information for most of the CERTs to be able to do something about it,” he said. “There’s still quite a lot of analysis left to be done.”

Updated to correct the size of the uncompressed file received by Parth Shukla to 910 MB. The previous report of 9 TB is the size of the uncompressed public torrent.

Wednesday, 7 August 2013

78 government websites under hacking attacks till June - CERT IN

   
      A total of 78 government websites were hacked and 16,035 incidents related to spam, malware infection and system break-in were reported this year so far, Minister of State for Communications & IT Milind Deora said. "As per the information reported to and tracked by Indian Computer Response Team (CERT-In), a total number of 308, 371 and 78 government websites were hacked during the years 2011, 2012 and 2013 (up to June) respectively," Deora said in a written reply to the Lok Sabha. The Minister said 16,035 security incidents related to scanning, spam, malware infection, denial of service and system break-in including that of government, Defence and public sector undertakings were reported up to June this year. The number of security breach incidents stood at 13,301 in 2011 and 22,060 in 2012, he added.
"It has been observed that attackers are compromising computer systems located in different parts of the world and use masquerading techniques and hidden servers to hide the identity of actual system from which the attacks are being launched. It is difficult to attribute the origin of cyber attacks," he added. In order to detect and prevent cyber attacks, the government has taken various measures including release of a National Cyber Security Policy 2013, which addresses protection of information and infrastructure in cyber space and building capabilities to prevent cyber threats.
"All new government websites and applications are to be audited with respect to cyber security prior to their hosting," Deora said. It has also been mandated that all government websites to be hosted on infrastructure of NIC, ERNET or any other secure infrastructure service provider in the country. The Information Technology Act, 2000 provides legal framework to address the issues connected with cyber attacks, Deora added.