Monday, 19 August 2013

Demand for IT security experts outstrips supply

Demand for information security experts in the United States is outstripping the available supply by a widening margin, according to a pair of recently released reports.
A report from Burning Glass Technologies, which develops technologies designed to match people with jobs, shows that demand for cybersecurity professionals over the past five years grew 3.5 times faster than demand for other IT jobs and about 12 times faster than for all other jobs.
Burning Glass said its report is based on a study of job postings for cybersecurity professionals placed by U.S. businesses and government agencies over the past five years.
In 2012, there were more than 67,400 separate postings for cybersecurity-related jobs in a range of industries, including defense, financial services, retail, healthcare and professional services. The 2012 total is 73% higher than the number of security jobs posted in 2007, Burning Glass said.
By comparison, the number of job postings for all computer jobs grew by about 20% between 2007 and 2012. Postings for all jobs grew by only 6% during the period.
The two most sought-after jobs by employers were information security engineers and security analysts. Close to one in three of all computer security jobs advertised last year were for information security engineers. Nearly 25% of the job postings were for security analysts.
Demand for cybersecurity professionals was especially strong in Baltimore, Dallas, Atlanta, Denver, San Diego and Richmond, Va., Burning Glass noted.
The number of cybersecurity jobs in each of those cities increased by more than 100% between 2007 and 2012. Large defense contractors and IT firms appear to have driven the demand increases in all of the cities except Atlanta.
Matt Sigelman, CEO of Burning Glass Technologies, said the soaring demand for information security professionals suggests that enterprises and government agencies are putting a lot more money and effort into protecting their data against attacks and compromise.
"The other thing that jumps out at me is the question of whether there is sufficient supply in the market to meet this demand," Sigelman said.
For instance, over the past two years the number of jobs requiring a Certified Information Systems Security Professional (CISSP) certification has jumped from 19,000 to more than 29,000. "When you see 10,000 new job postings in a two-year period in a field that has just over 50,000 CISSPs, there is a question of availability," he said.
Another indication of the increasing difficulty U.S. employers face in finding qualified information security professionals comes from their job posting behavior. Employers typically have to repost or duplicate security job posts almost 35% more often than other IT jobs to find someone qualified, according to Burning Glass.
"Posting behavior suggests the possibility of a particular shortage of managers and analysts with cybersecurity expertise," Burning Glass noted in its report.
Julie Peeler, director of ISC2 Foundation, the developer of the CISSP program, said there is no doubt that soaring demand is exacerbating an already difficult demand and supply situation for security experts.
Ove the next year, Peeler estimated that there will be a need for 330,000 more IT security professionals worldwide. It's not clear that close to that many new professionals are graduating each year, she said.
A recent ISC2 Foundation survey of some 12,000 information security professionals worldwide found that a shortage of talent has had a dramatic impact on the ability of organizations to defend against or recover from a cyberattack.
"[The shortage] is causing a strain on the existing workforce," Peeler said. "They are having to work harder and longer hours."
More than half of the respondents to the ISC2 survey said the shortage is the ability of their organizations to defend against cyberthreats, she said.
The growing shortage has meant better salaries for information security professionals compared to many other IT jobs.
According to Burning Glass, cybersecurity jobs on average offer a premium of about $12,000 over the the average for all computer jobs -- the advertised salary for cybersecurity jobs in 2012 was $100,733 versus $89,205 for all computer jobs.
People with security certifications appeared to be getting a modestly higher salary, the Burning Glass report found. In many cases, companies appear to require security certification as a way to filter experienced candidates from the non-experienced ones, Sigelman noted.
"Demand is high, but demand in and of itself does not create opportunity" for everyone, cautioned Roger Cressey, senior vice president at Booz Allen Hamilton.
While it is true that employers are looking for more information security professionals than ever, they only want workers with long experience in areas like network security governance, policies and procedures. "You got to have the right skills set" Cressey said.
He noted that U.S. universities today are not training enough people to deal with the explosive growth in demand for IT security specialists.
Pete Lindstrom, an analyst with Spire Security, cautioned against "irrational exuberance" on the IT security job market. "The need for security professionals should not be a cause for celebration. I worry that it is more emotional reaction than warranted pragmatism

Sunday, 18 August 2013

Perkele Android Malware Kit will Hack your Internet banking one time password

In this post, we’ll take a closer look at this threat, examining the malware as it is presented to the would-be victim as well as several back-end networks set up by cybercrooks who have been using mobile bots to fleece banks and their customers.
Perkele disguises itself as an various Android security applications and certiifcates.
Perkele disguises itself as various Android security applications and certificates.
Perkele is sold for $1,000, and it’s made to interact with a wide variety of malware already resident on a victim’s PC. When a victim visits his bank’s Web site, the Trojan (be it Zeus or Citadel or whatever) injects malicious code into the victim’s browser, prompting the user to enter his mobile information, including phone number and OS type.
That information is relayed back to the attacker’s control server, which injects more code into the victim’s browser prompting him to scan a QR code with his mobile device to install an additional security mechanism.
Once the victim scans the QR code, the Perkele malware is downloaded and installed, allowing the attackers to intercept incoming SMS messages sent to that phone. At that point, the malware on the victim’s PC automatically initiates a financial transaction from the victim’s account.
When the bank sends an SMS with a one-time code, Perkele intercepts that code and sends it to the attacker’s control server. Then the malicious script on the victim’s PC receives the code and completes the unauthorized transaction.
Web site security firm Versafe located a server that was being used to host malicious scripts tied to at least one Perkele operation. The company produced this report (PDF), which delves a bit deeper into the behavior and network activity generated by the crimeware kit.
Versafe’s report includes several screenshots of the Perkele application as offered to would-be victims. The malware is presented as a security certificate; it’s named “zertificate” because the victim in this case banked at a German financial institution.
Perkele disguised as a security certificate for a German bank. Source: Versafe.
Perkele disguised as a security certificate for a German bank. Source: Versafe.
A few weeks ago, I encountered the back end system for what appears to be a Perkele distribution, or perhaps some other mobile malware bot; I should note that disguising an Android banking Trojan as a security certificate is not a ruse that’s limited to Perkele: The Pincert SMS malware also employs this trick, according to F-Secure.
Anyhow, I scarcely had time to examine this particular mobile bot control panel before it was either taken down by German authorities or was moved elsewhere by the fraudsters. But it, too, was intercepting one-time codes from German banking victims using an Android malware component similarly disguised as a “zertificate.”
This Android SMS bot control panel targeted German bank customers.
This Android SMS bot control panel targeted German bank customers.
Apparently, it was fairly successful, stealing one-time codes from online banking customers of several German financial institutions, including Postbank and Comdirect.
Dozens of German banking customers were victimized by this Android bot control panel.
Dozens of German banking customers were victimized by this Android bot control panel.
In the screen grab below, we can see the main administrative page of this panel, which controls which banks should be targeted and from where the fraudulent text messages should be sent.

mobilemalware5
There seems to be a great deal of interest in the cybercrime underground for developing or procuring tools to trojanize Android devices. According to a recent report from security firm Trend Micro, the number of malicious and high-risk Android apps steadily increased in the first six months of 2013. According to Trend, the number of malicious and high-risk apps took three years to reach 350,000, a number that has already doubled in just the first half of 2013.
Source: Trend Micro
Android malware growth in the first six months of 2013. Source: Trend Micro
Fortunately, a modicum of common sense and impulse control can keep most Android users out of trouble. Take a moment to read and comprehend an app’s permissions before you install it. Also, consider downloading and installing apps only from Google’s Play store, which scans all apps for malware. Also there are numerous free and paid anti-malware applications available for Android.

Friday, 16 August 2013

Earn £8,000 a MONTH with bogus apps from Russian malware factories

DIY SMS-scam kits anyone can use - even your grandparents!

Just 10 professionally run malware-making workshops in Russia are responsible for 30 per cent of the Trojans, spyware and other nasties infecting smartphones globally. That's according to a study by mobile security outfit Lookout.
These underground crime labs churn out DIY kits ideal for scriptkiddies looking to make a fast buck: the tools can be used to distribute malware and earn money from it with little or no coding experience or hacking skills. Once installed on a device, the malware is typically disguised as a legit, popular app and secretly texts premium-rate numbers, thus racking up charges on the victims' phone bill.

The Russian development centres are skilled at releasing new Android builds and configurations of their code every two weeks; organising hosting for the malware; registering short-code phone numbers that victims' mobes text; and creating marketing campaign management tools — the malware developers' customers get paid for marketing and distributing the bogus apps.
These affiliates customise their copy of the malware to make it look like the latest Angry Birds or Skype utility, for example. Then they use social networks, such as Twitter, to draw people into downloading the booby-trapped software. Almost all the malware targets Android smartphones.
"We reviewed 250,000 unique Twitter handles and of those, nearly 50,000 linked directly to these toll fraud campaigns," Lookout researcher Ryan Smith explained in a blog post.
"The victim of the scheme is usually a Russian-speaking Android user looking for free apps, games, MP3s or pornography.
"The victim may have been using search engine or click through links in tweets or mobile ads, then unwittingly download the malicious app which secretly adds a premium SMS charge to their phone bill."
A research paper from Lookout on its Dragon Lady* investigation explains the malware creation centres have taken many ideas on how to run their businesses from legitimate small software houses.
"Organised groups of Android malware authors are operating like startups: tapping multiple individuals or organisations for specialisation in different business areas, leveraging online tools for promotion and developing affiliate programs," the Lookout team explained.
"We’ve seen evidence that these affiliate marketers have earned between $700/month to $12,000/month [£450/month to £7,800/month] from these scams, and estimate that there are thousands of individual distributors and potentially tens of thousands of affiliate websites promoting these custom SMS malware in the same manner as traditional affiliate web marketers."
More than 50 per cent of Lookout’s total malware detections during the first half of 2013 were Russian-based toll fraud. And 60 per cent of this activity can be traced back to just 10 centres in Russia.
Lookout has been actively tracking SMS fraud since the first example was found in the wild in August 2010. Lookout has been classifying Russian SMS-swindling malware in individual groups or “families” based on similarities in code and key features in the three years since. The data has also allowed the security biz to track individual malware families back to affiliates and the programmers' headquarters.

 

Hacking with new DIY Google Dorks based hacking tool

new version of DIY Google Dorks based hacking tool has been released, it is an extremely useful tool for reconnaissance of targets.

A Webroot blog post announced that a new version of DIY Google Dorks based hacking tool has been released in the wild and it could be used for mass website analysis, the power of the popular search engine could be exploited for information gathering during the reconnaissance phase of an attack. Similar tools could be used to acquire information on target environments by an attacker or by the pen tester to evaluate the architecture is starting to test. The availability of the DIY Google Dorks based hacking tool allows to ill-intentioned to acquire precious information on remotely exploitable websites, data that could be collected to compromise them for example deploying a malicious exploit kit or exploiting known vulnerabilities. The tool relies on Google Dorks the tools to allow a target evaluation, in particular the DIY Google Dorks based hacking tool has built-in features that can be used to evaluate the possibility to perform a SQL injection attack or to discover all the targets that aren’t protected by a CAPTCHA challenge mechanism. As usual the project appears under continuous development and the authors are still working on it to improve its capabilities with new features such as the possibility to evaluate the vulnerability to a custom malicious exploits. Composing specifically crafted queries in Google it is possible to reveal sensitive information essential for the success of an attack, thanks to the use of the advanced operator, the dorking, is possible to retrieve a huge quantity of information on a target such as:
  • User’s credentials.
  • Sensitive documents.
  • Admin login page.
  • Email lists.
The syntax for using advanced operator in Google is
Operator_name:keyword
Following some sample of keyword/advance operator:
Allintext Searches for occurrences of all the keywords given
Intext Searches for the occurrences of keywords all at once or one at a time
Inurl Searches for a URL matching one of the keywords
Allinurl Searches for a URL matching all the keywords in the query
Intitle Searches for occurrences of keywords in URL all or one
Allintitle Searches for occurrences of keywords all at a time
Site Specifically searches that particular site and lists all the results for that site
filetype Searches for a particular filetype mentioned in the query
Link Searches for external links to pages
Numrange Used to locate specific numbers in your searches
Daterange Used to search within a particular date range
Using more complex queries an attacker could obtain a series of information on the status of the target, for example to discover if it has been already “backdoored” and discovery which are the vulnerability that can potentially affect the system. The Google hacking database provides various examples of queries that can help a hacker to find vulnerable servers, to gain information on the target, to explore sensitive directories finding vulnerable files, to find password files or to find sensitive online shopping info.
inurl:”r00t.php”  – This dork finds websites that were hacked, backdoored and contains their system information allintext:”fs-admin.php – A foothold using allintext:”fs-admin.php” shows the world readable directories of a plug-in that enables WordPress to be used as a forum. Many of the results of the search also show error logs which give an attacker the server side paths including the home directory name. This name is often also used for the login to ftp and shell access, which exposes the system to attack. There is also an undisclosed flaw in version 1.3 of the software, as the author has mentioned in version 1.4 as a security fix, but does not tell us what it is that was patched. filetype:config inurl:web.config inurl:ftp – This google dork to find sensitive information of MySqlServer , “uid, and password” in web.config through ftp..filetype:config inurl:web.config inurl:ftp
The above dorks are just simple examples of the power of these search strings, just after 10 minutes playing with them user has the perception of the infinite possibilities that Google provides to an attacker. Now imagine a single DIY Google Dorks based hacking tool  that allows to automatize all this queries, without having particular knowledge on Google dorks … it’s the hacker heaven, what do you think about? The DIY Google Dorks based hacking tool proposed by Dancho Danchev offers a complete suite to automate the process of remote inspection of targets and their exploit, the instrument works on desktop and could be  also integrated with popular browsers to fool the search engines into thinking that generated traffic is legitimate traffic.
DIY Google Dorks based hacking tool 1
  The price for the DIY Google Dorks based hacking tool is very cheap compared to the advantage deriving from its use, one license costs $10 to pay using the Liberty Reserve currency, or $11 to pay using Western Union transfer. The license are linked to specific host due a hardware-based ID restriction, but the authors also offers an unlimited license for $20 in Liberty Reserve, or $20 in Western Union transfer.
DIY Google Dorks based hacking tool 2
 DIY Google Dorks based hacking tool 3
Cyber criminals can exploit hundreds of thousands of legitimate Web sites is various ways and tools such as the DIY Google Dorks based hacking tool facilitate attacks. Dancho Danchev in his interesting post described the principal techniques used to compromise website:
  • Use of search engine reconnaissance through DIY SQL/RFI (Remote File Inclusion) tools or botnets, the category includes a wide range of application that automatically exploit improper configured websites such as  blogging platforms or well known CMS.
  • Use of data mined or purchased stolen accounting data, cyber criminals could gather information on malware infected machine, looking for login credentials to be automatically abused with malicious scripts and actual executables getting hosted on legitimate websites in an attempt to trick a security solution’s IP reputation process.
  • Active exploitation of server farms – criminals try to infect the larger number of low profile websites as possible, a common practice observed by security researchers is the exploiting of servers that host large number of domains, for example using commercially available Apache backdoors.
Cybercrime underground is in offering all necessary to organize a fraud without having particular knowledge of various technological platforms (e.g. Mobile) and proposing a new efficient model of sales such as the FaaS… it is crucial to follow the black market evolution to avoid shocking surprises.

Thursday, 15 August 2013

Indian Government buying deep surveillance, monitoring equipment ---> Mobile is spy for Indians

Amid a raging global debate on privacy versus surveillance, monitoring and use of intrusive technologies by governments, the Directorate of Forensic Sciences in the Ministry of Home Affairs (MHA) is set to purchase a range of equipment and software that will allow it to conduct deep search, surveillance and monitoring of voice calls, SMS, email, video, Internet, chat, browsing and Skype sessions on an unprecedented scale.
The shopping list may help the government counter crime and terrorism but civil liberties advocates worry about the misuse of these technologies against ordinary citizens, especially given the absence of strong privacy protection.
The MHA document of July 12, 2013 also lists software-based tool kits for logical level analysis of GSM and CDMA mobile phones — which will comprehensively cover phones and SIMs used by India’s 860 million subscribers across 2G and 3G networks. This will be capable of extracting the phone’s basic information and SIM card data, including in your phonebook and contact list, call logs, caller group information, organizer, notes, live and deleted SMSs, web browser artifacts, multimedia and email messages with attachments, multimedia image audio and video files and details of installed applications, their data, traffic and sessions log. It will allow access to iPhone backup analysis, including those which are password protected. Blackberry, considered safe by unsuspecting users, will also be fair game, since it will support Blackberry IPD backup analysis, even when password protected.

Mobiles and SMS

The specialised hardware on the MHA’s list will be able to extract all data, including call logs, phone books, SMS, email messages along with attachments, MMS, calendars, including passwords and location information. It will be able to read SIM cards and extract SIM-card-related information along with all user information on the SIM card, like phone call register and text messages, even if they have been deleted. The software will be capable of data authentication by hashing algorithms, and will even access deleted phone information by recovering or bypassing passwords. Special forensic kits are being brought in for Chinese mobile phones.

Bypassing passwords

Hardware forensic imaging devices with the capability to acquire data from live systems and content-based images are being procured. The capabilities also include the ability to search for key words in the suspected media and to acquire data over a network. Essentially, this would mean blind, across-the-board search on mass data rather than a targeted search based on an authorised target phone number, email or IP address.
The MHA is also set to acquire software for forensic previewing, for analysis of digital media and smartphones. This can acquire date from various types of storage media including in multi-sessions. It can support Windows, Unix, Linux, Sun, Solaris, Macintosh, Apple’s iOS, Android, Blackberry, HP’s palm OS, Nokia Symbian, Windows Mobile OS, etc. The software will be capable of decrypting volumes, folders and files of suspected media including that which is subject to various types of encryption — including 32 and 64-bit systems.
Software is also being ordered for previewing, image mounting, password cracking and forensic analysis of digital media. This would allow recovering folders, expanding compounded files, saved email data bases, extracting artifacts, time line analysis, and registry log analysis. It will allow the government to auto-detect passwords of protected files and their decryption across a range of encryptions.
The new forensic tool will automatically check for disk encryption, including Truecrypt, PGP, Bitlock and Safeboot. This forensic tool will be capable of collecting and recovering artifacts from live and off-line systems when using cloud artifacts like Dropbox, Carbonite, Skydrive, Googledocs, Google Drive and Flickr. It will link into, and extract data out of, users’ social networking pages like Facebook, Twitter, Bebo Chat, Myspace Chat, Google+ and Linkedin. Similarly, webmail applications like Gmail, Yahoo, Hotmail and instant messenger chat can be targeted through this kit. Instant messenger chat like GoogleTalk chat, Yahoo chat, MSN/Windows Live Messenger, AOL, Skype, ICQ, World of War Craft, Second Life and Trillian, will all be open to collection of artifacts, whether live or offline. The system will also accurately target web browser activity on Internet Explorer, Firefox, Google Chrome, Apple Safari, Opera, Google Maps, etc.
The MHA is one of the nine authorised departments, along with IB and RAW, which is allowed to order surveillance and monitoring of citizens under the Indian law. It has been in the news for being closely involved in the implementation of a nationwide Central Monitoring System covering mobile and Internet users.