Monday, 22 April 2013

CBS Got Twitter-Hacked And Spat Out Virus-y Links



Twitter hacks are an unfortunate reality of everyday social media life. Today, it was CBS's 60 Minutes, 48 Hours, and CBS Denver accounts that took the hit and started dishing out some linkbait-y tweets with a virus-laiden garnish. Careful what you click.
Unlike other Twitter hacks of late, this one wasn't particularly funny, and instead leaned towards the straight-up malicious end of the spectrum. The hacktastic payload included not only misinformation, but a viral payload as well, though that's not uncommon for the spammier side of Twitter.
The offending tweets are gone now, but All Things D managed to get a couple of screen grabs. And really, who wouldn't click these? Of course all this could just go away if Twitter would roll out some two-step verification, but who knows how long that'll take. Any bets as to how many more high-profile hacks we'll have to see?

Share This on Twitter | Share This Link on Facebook | Share This on Linkedin

Friday, 19 April 2013

How to Spot Android Malware and Keep Your Data Private


            A new, growing risk that's just as devious as malware is now disguised as adware. While malware is often designed to hide on your device, minimizing impact while nabbing personal files and passwords, adware can operate in plain sight while it collects almost everything else on your smartphone. Much like a burglar, stealthy capabilities combined with security loopholes heighten the danger of malware. Bringing in adware, though, is like recklessly inviting a total stranger for dinner. The conversation may be pleasant, but he may be walking around the house and learning everything there is to know about you.

There is money to be made in using adware to gather personal data from your phone. This attracts legitimate advertisers, and more dubious characters. Keeping a close eye on your device to make sure that it behaves properly is highly recommended. With both personal and work data on your device, imagine what would happen if someone were to gain complete access to it. For instance, if you notice a spike in data consumption without doing anything out of the ordinary, it might reveal that something is smuggling data out of or onto your device. The best way to stay ahead of the problem is to set up a data meter to plug the leak before it causes too much damage.

With smartphones used in online shopping by charging purchases to your carrier phone bill, some malware actually reaches into your pockets and starts sending text messages to premium-rated numbers. You won't know what happened until you get slapped with a phone bill that might make your head spin. A sudden loss in battery performance could also hint that something is running in the background. If it's nothing you can pinpoint and switch off, some nasty piece of malware may be at work. Of course, aggressive adware could also be a culprit here, as location tracking or the constant monitoring of your browser activities could drain more juice than usual. Watch out for apps that display too many ads or send push notifications - they're not only annoying but they also take a toll on your battery. In some cases, you might even experience full performance clogging as too many apps try to feed you push notifications. Your device is biting off more than it can chew, leading to reboots caused by sluggish performance.

With Android malware emulating many features we've seen on PC malware years back, somebody could even eavesdrop on your conversations. If you start noticing call drops although you have plenty of cellphone coverage, or if you hear a strange echo during calls, contact your local carrier and make sure it's not their fault. Malware might be tapping into your conversations and saving them as audio files on your smartphone, waiting for the chance to upload them to an attacker-controlled server. This might sound like science fiction, and you might think it could never happen to you. However, take a step back and think about how many smartphones are there on a global level and how many in your own family. Your personal information is valuable to criminals, and they will go to some serious effort to steal it from you.

There's nothing wrong with a little paranoia when it comes to keeping data on your smartphone safe. Thankfully, an award-winning mobile security software will keep you safe from unnecessary headaches and will let you know when you're about to install apps with aggressive advertising or even malware. If your device is giving you some of the signs outlined above, perhaps it's a good time to give it a quick checkup.


Share This on Twitter | Share This Link on Facebook | Share This on Linkedin

Thursday, 18 April 2013

Largest gathering of offensive hackers converges on Miami


Formidable American offensive security hackers are meeting in Miami with other top hackers from all over the world to hone their technical expertise, swap war stories – and compete in a little digital jiu-jitsu. And real jiu-jitsu. Really. INFILTRATE’s annual summit, focuses entirely on the technical aspects of offensive security issues, bringing together the best and brightest in the hacker community. It’s largest gathering of purely offensive information security experts on the planet, with more than 200 hackers from as far away as Israel, India, Sweden and China.

Organized and sponsored by Immunity, an education firm founded by former NSA hacker Dave Aitel, the conference ran April 11 and 12. Aitel stressed that it was just for offensive work. “Defensive information security tends to focus on potential protective measures,” he told FoxNews.com. “Offensive information security looks purely at getting into computers -- and staying there undetected.”

The hacker way
Offensive techniques are used by a wide range of people from governments and banks through to researchers working on protecting critical national infrastructure. “INFILTRATE is important because it is the only conference dedicated to offensive information security techniques. Deep down this is about the attendees, who all share a technical competence in the area, and a burning interest in learning more about it. There are, of course, plenty of security teams here. For example, Blackberry announced on their twitter feed they are here,” Aitel said. If you don’t understand what TTF Font Fuzzing and Vulnerability means, this is the wrong conference for you, in other words.

The show covers the latest in the field, from computer and network exploitation and vulnerability discovery through to rootkit and trojan covert protocols. And while it sounds esoteric and dry, it has profound ramifications for ordinary Americans. For example, legendary hacker “RenderMan,” also known as Brad Haines, gave an opening keynote on  “Attacking the Next Generation Air Traffic Control System” -- hacking the FAA’s monitoring system. “I came to INFILTRATE to spread knowledge of vulnerabilities in air traffic control in hopes that the attention and collaboration with other hackers would result in a safer and more secure air traffic control system,” 

“Ironically, I'm speaking about vulnerabilities in air traffic control and I have to fly home.  It’s in my best interests to help make it secure. The next generation air traffic control scares the hell out of me,” he added.
Other speakers include Chris Eagle, a lecturer in computer science at the Naval Postgraduate School, and Stephen Watt , a former cybercriminal convicted in 2008. While still under a court-ordered restriction that prohibit him from a wide range of ordinary tech, including owning an iPhone and running a non-Windows operating system on his government-monitored laptop, Watt continues to speak out against computer the commercialization of vulnerability. In addition to briefings by the rock stars of hacking, Immunity offers Master Class training courses in web hacking and unethical hacking. Attendees have also been competing in a wireless + web challenge to win the grand prize -- a free wireless penetration testing tool called SILICA.
Off the keyboard

It may come as some surprise to those outside the hacking community, but many of INFILTRATE 2013's attendees are avid practitioners of the Brazilian martial art jiu-jitsu, sometimes described as “physical chess.”
“Brazilian jiu-jitsu is a shared passion for many in the offensive information security field,” Aitel told FoxNews.com. “It combines large-scale strategic thinking with fast paced tactical technique. For every attack, there is a defense, and for every defense, a counter-attack.” Away from keyboards, INFILTRATE also provides the opportunity for hackers new to the sport to have a go under the supervision of an experienced blackbelt.


Share This on Twitter | Share This Link on Facebook | Share This on Linkedin

Wednesday, 17 April 2013

The latest wave of Denial of Service attacks


Hackers have been able to weasel their way into computer networks from nearly every direction. From malware to ransomware, and everything in between, cyber crooks are always looking for new ways to steal information and disrupt business-as-usual for monetary gains. While most companies understand the importance of securing their corporate networks, there is one area that is often overlooked, but is becoming an easy target: VoIP systems. VoIP systems are dynamic, complex, and oftentimes require different tools than what a legacy firewall can provide, making the issue of telephony security a challenging one. Companies need to ensure that lines of communication are open and working well, so many are reluctant to put too many layers of defense on top of their telephony solution.

Unfortunately, hackers have become aware of this likely gap in defense, and have started to take advantage of it. A new class of attack targeting call centers, called telephony denial of service (or TDoS), have started appearing by the dozens. Like other denial of service (DoS) attacks, TDoS attacks seek to clog lines and interrupt regular business with a flood of false traffic. In the case of TDoS attacks, the attacker floods telephone (VoIP or traditional) lines at a call center with repeated calls from spoofed numbers, clogging lines for up to several hours and inhibiting real users from connecting. The goal of these attacks may differ. In some cases, they could be the work of activists or pranksters just trying to cause trouble.


In other cases, attackers try to monetize the attack by first extorting the victim. In a recent case, attackers posed as collections agents and dialed a call center, demanding payment of thousands of dollars for a false debt when someone answered. When the victim refused to pay and hung up, the TDoS attackers started. As compared to large bandwidth DDoS attacks, TDoS attacks don't take many computing resources or technical know-how. It is fairly easy to clog a phone line by simply calling it over and over again. Attackers employ VoIP automation scripts to dial the victim's phone number, hang up, and then redial repeatedly, overwhelming the line and making it impossible for other calls to come through. And because the attackers are able to use spoofed numbers, it is difficult for the victim to differentiate between a TDoS call and a real call.


In the most recent TDoS attacks, that targets were emergency services, such as ambulance or air ambulance services. For organizations like these, it is critical that phone lines remain open and available to ensure prompt response to emergency situations. This is where the major concern lies in these types of phone system attacks.

Share This on Twitter | Share This Link on Facebook | Share This on Linkedin 

Employees admit to accessing or stealing private company information


      
   In a survey of 1,000 employers by LogRhythm, 80 percent do not believe any of their workers would view or steal confidential information, while three quarters (75 percent) admitted to having no enforceable systems in place to prevent unauthorised access to company data by employees. Interestingly, a third of those employers believe that they do not need such systems at all. In addition, around two thirds of companies surveyed (60 percent) do not regularly change passwords to stop ex-employees being able to access sites or documents. However, in a corresponding survey of 2,000 employees, 23 percent admitted to having accessed or taken confidential data from their workplace, with one in ten stating that they do it regularly. The most accessed confidential data related to details of colleague salaries (38 percent) and details of colleague bonus schemes (23 percent). 94 percent of those who had accessed confidential information or stolen company data had never been caught.

“There is a clear gap between businesses’ internal security procedures and the harsh reality of employee behaviour,” said Ross Brewer, vice president and managing director for international markets at LogRhythm. “In an era where data breaches are considered inevitable, and with the government urging for greater consideration of cyber threats within businesses, the amount of employers who are doing nothing about unauthorised access across their networks – and the even higher number who don’t perceive any risk at all when it comes to employee data theft – is staggering.” “Even more worrying than the lack of systems in place to stop employees stealing data is that many organisations still have no idea what’s happening on their networks at all. With recent government proposals to increase the sharing of cyber threat intelligence among businesses, the first stage must be to ensure that more employers have the right level of visibility to track suspicious or abnormal behavior on their own networks – but this is clearly not happening,” continued Brewer.

When asked, more than a quarter (27 percent) of employers could not identify the biggest threats to their confidential data, while 14 percent did not even know whether employees have stolen data – even though they believe employees would do so. “It’s one thing to place too much trust in your employees and consequently neglect to enforce any systems monitoring unauthorized access and stealing of data. However, the fact that 14 percent of employers think their employees would steal data, and yet have no idea whether or not this has actually happened to them, is simply unacceptable. One of the main reasons why the ‘era of the data breach’ is now hitting hard and fast is that organizations just don’t have the level of visibility into their IT networks needed to secure their ever growing infrastructures. Employers therefore need to ensure they are proactively monitoring every single activity that occurs across their entire IT estate – both from the inside and the outside – rather than placing too much trust in reactive perimeter defenses or security strategies focused on securing particular areas of the IT estate, which don’t give organisations any insight into anomalous network activity,” continued Brewer.


Share This on Twitter | Share This Link on Facebook | Share This on Linkedin