Showing posts with label policy. Show all posts
Showing posts with label policy. Show all posts

Wednesday, December 12, 2012

Ransom hackers encrypt medical centre's entire database

An Australian medical centre is reported to be considering paying a ransom demand of $4,000 AUD (US$4215) after blackmailers broke into the organisation’s servers and encrypted its entire patient database.

 If crime doesn't pay, why is this clinic considering making it profitable? Paying ransom only perpetuates the problem. Instead they should be spending the money on securing their systems. The clinic should be asking themselves:


  1. Why should I make this crime profitable for the attacker? 
  2. How do I know they will provide the password and instructions for decrypting the data? 
  3. How do I know that if I decrypt the database, the data hasn't been tampered with? 
  4.  If I pay the ransom, what is to stop them from increasing the demand lest they publish the data online?
  5. What is a better plan for securing the systems and moving on? 


They already lost once. If they don't bite the bullet and move on, they risk losing again and again. They would also be giving the attackers valuable incentives for attacking more sites.

Tuesday, March 20, 2012

The Pwn Plug is a little white box that can hack your network

Built by a startup company called Pwnie Express, the Pwn Plug is pretty much the last thing you ever want to find on your network—unless you've hired somebody to put it there. It's a tiny computer that comes preloaded with an arsenal of hacking tools. It can be quickly plugged into any computer network and then used to access it remotely from afar. And it comes with "stealthy decal stickers"—including a little green flowerbud with the word "fresh" underneath it, that makes the device look like an air freshener—so that people won't get suspicious.

Tuesday, June 28, 2011

DMCA Takedown

Today we had to send out a DMCA Takedown Notice to a site that has stolen from me and my consulting firm twice in the past. Now we're in for round 3. We aren't sure what kind of nonsense game these charlatans are playing, but this time we decided an immediate takedown at the ISP level was required.

It is impossible to tell how much damage The Management Group have caused their unwitting customers. Even more pathetically, they appear to sell their lies to the US Government. I wonder if there are laws against that.

By openly stealing my content and making false claims about the origin of my published work, these guys do a disservice to all in the Information Security industry, and especially to their customers and partner organizations.

---- letter body follows ----

I am the sole copyright owner of the text content and IP rights being infringed at:

http://www.mgt-gp.com/articles/view/information-security-servicecapabilities
https://www.gsaadvantage.gov/ref_text/GS35F0658N/GS35F0658N_online.htm

The owner of these sites has been asked to remove this content twice in the past. After first claiming that he indeed is the writer of the Offensive Operations Model (A claim falsely repeated throughout the above named websites), the owner said he would remove the content and the fraudulent claims that he is the developer of the model. The Offensive Operations Model is a model I wrote in 1998 and was published by the IEEE in 2004, and is available online from many sites who do properly credit me as the author and developer. The owner of these above referenced sites has no right to abuse my copyrights in this manner. The entirety of text content on these pages was written by myself years before they appeared on these websites. After several phone calls from myself to the owner of these pages, the text disappeared only for a short time, and has at some point resurfaced with nothing more than a cosmetic makeover. This is now my THIRD time approaching these people about the offending content. I am willing to provide absolute proof via the WAYBACK MACHINE on archive.org which demonstrates clearly that the entirety of the text content of these pages was written by myself years before they began appearing on these 2 sites in question. Comparing this way shows the exact month and year that this person began stealing my work. The Offensive Operations Model that this person claims he wrote, is available from the IEEE website, and of course is listed with my name as the author.

Here is a link to an article I wrote about this thievery back in 2006. You will notice the mgt-gp site is specifically referenced. The link I proviced no longer works since the owner did change the URLs after I phoned him repeatedly. 

http://penetrationtestdotcom.blogspot.com/2006_10_01_archive.html

Please note: At the time I initially caught this person stealing my content, there were 7 other sites infringing my content in the same manner. All sites removed the content without question, save for the owner of these two sites listed above. He is not only cheating me by claiming copyright to the Offensive Operations Model. He also cheats his customers since in our phone conversation in 2006 it was clear he didn't even know really what the Offensive Operations Model was.

This letter is official notification under the provisions of Section 512(c) of the Digital Millennium Copyright Act (“DMCA”) to effect removal of the above-reported infringements. I request that you immediately issue a cancellation message as specified in RFC 1036 for the specified postings and prevent the infringer, who is identified by its Web address, from posting the infringing text and references to the Offensive Operations Model to your servers in the future. Please be advised that law requires you, as a service provider, to “expeditiously remove or disable access to” the infringing content upon receiving this notice. Noncompliance may result in a loss of immunity for liability under the DMCA.

I have a good faith belief that use of the material in the manner complained of here is not authorized by me, the copyright holder, or the law. The information provided here is accurate to the best of my knowledge. I swear under penalty of perjury that I am the copyright holder.

Please send me at the address noted below a prompt response indicating the actions you have taken to resolve this matter. If this DMCA Takedown Notice needs to be sent to any other parties, please let me know who they are.

-----

DMCA takedown template written by attorney Carolyn E. Wright.

Wednesday, March 2, 2011

Apparently all today's Infosec news is a result of Anonymous' exploits

The servers at Morgan Stanley were broken into. I bet you already guessed it was the Chinese yet again.

It's getting very fashionable to blame the Chinese for most hacks against American computer systems these days. But this is news for an actually interesting reason. We would not have known about it if it wasn't for the emails Anonymous exposed from a company humorously referred to in media as "a cyber-security company working for the bank." Whoever they might have been.

Leaked emails seem to be the current source of daily news these days. It sure is more interesting than watching CNN.

Saturday, February 26, 2011

Hacking group infiltrates gas companies, hangs around for a while

An amateur Chinese hacking group infiltrated several of the world's largest petrochem companies (BP, Exxon Mobil, Shell, and others). McAfee, no stranger to creating cute names for anything that can bring them a little media, dubbed the attack "The Night Dragon", and says they were "very unsophisticated" and "incredibly sloppy". They admit that the group has pwned the systems in question for as long as 5 years. And how were these naive slow-witted clods were able to maintain their pwnership of said systems with McAfee on hand monitoring them? McAfee, in their infamous defeatist style, suggest the reason is that "the environments and security controls these days are so complex it is very easy for them to slip under the radar of visibility".

Really, McAfee? Maybe we should all just give up now then. Perhaps the reality is that the petrochem industry simply do not have their security controls in check, with knowledgeable people supporting an effective set of standards, policies and procedures. Someone's been paying a lot of money for McAfee to hang around doing nothing but watching a bunch of Chinese kids hacking their customer's network.

In the 3 years Mcafee has been monitoring them, all they can really say about them is that the "sloppiness" that exposed the hacker's Asian heritage was the use of known chinese hacker tools, and the attacks all occurring during Beijing's 9-5 business hours. Brilliant sleuthing!

Surely they could have fixed the security issues instead, and helped built them a real security capable governance team. How about putting a stop to the attack back in 2009 when it was discovered, instead of waiting for the story to become newsworthy?

I call it a failure for both McAfee and the PetroChem industry.

Tuesday, February 22, 2011

Why Penetration Testers Need To Remember The Good Old Days

As a penetration test trainer to fortune 500 companies, I often see a few students in the class phase out and stare off with glossy-eyed disinterest when I cover legacy systems and protocols. Examples of these "boring" topics include Windows NT, WEP, and ancient attacks like the 'Ping of Death'. They ask me "Why do we need to learn this stuff when it was fixed years ago?"

The answer is simple: History repeats itself. Just like these students aren't interested in learning from the past, there is a world of developers out there that exhibit the same disinterest. They're churning out vulnerable code with all kinds of old-school vulnerabilities, and the testers, having also slept through that part of the class, barely know how to detect them.

A subject I almost never see covered in Penetration Test / Hacking type courses in general, is the lowly modem. The rationale seems to be that modems are rarely used within the corporate environment, and when they are, a VPN is deployed. VPN security is well understood, and most (definitely not all) companies that use VPN do utilize them reasonably well. But the VPN does not cover all the layers. The modem is still just as vulnerable to attack as always.

To demonstrate why ignoring technical pieces of our computing legacy is tragic, one just has to look at a recent case in New Hampshire. Asu Pala resurrected an ancient idea: use malware to reconfigure modems to dial through a premium rate service.

The damage? In the nearly 5 years his attack ran, Pala made himself a neat $8 million.

The fact is, old equipment and operating systems abound on the Internet, and they nearly always can be found even within organizations who push policies on eradicating them. On top of that, younger developers who do not know their security history tend to repeat the mistakes that were made before their time.

0-day attacks nearly always have some relationship to the old attacks that we like to think don't occur anymore. Penetration testers who are not acquainted with the legacy security issues are likely to be blind to them when they occur.

Friday, October 15, 2010

Information Security Strategy Generator

I don't usually post sites with swearing all over them, but this one was too good to pass by.

The site whatthefuckismyinformationsecuritystrategy.com automagically generates realistic sounding security strategies. Just hit reload to generate a new one. They pay people good money to come up with these kinds of statements.

I got this: Monitor vendor access and restrict personal use of computing resources by removing admin rights on critical assets

Thursday, September 2, 2010

Pentagon Going Postal

The Pentagon is contemplating an aggressive approach to defending its computer systems that includes preemptive actions such as knocking out parts of an adversary's computer network overseas. Of course, this doesn't come without a laundry list of issues that have to be dealt with first.

Thursday, August 19, 2010

Are You Working With a REAL Security Expert?

The attrition.org website has been posting exposés of security "veterans" who sound like they've been around the block, and seemingly single-handedly invented the information security industry. However, even some of the so-called famous experts are charlatans at best, ripping off their customers and potentially causing them more harm than good.

One example provided is Dr. Ali Jahangiri, who's entire career is so dubious that not only is his resumé in question, entire books that he has "authored" appear to have been entirely plagiarized. Much of the information is so out-of-date that it would only be of interest in a historical sense if this information wasn't already widely available on the Internet for free. Worse, they demonstrate that his Information Policy Templates, which sell for $150 / CD, are all ripped from various places freely available on the Internet, save for 2.

I don't fully agree that everyone on the list is a charlatan, though. For example, professional social engineer Ira Winkler is on the list merely for having a larger-than-life ego. It fails to recognize that extreme self-confidence is a requirement for any social engineer, which makes this hardly a surprise.

What differentiates consultants like Ali from the bad guys? If their credentials don't add up, and their work seems to be ripped off from someone else and repackaged as something new, you may have hired a thief into a position of trust. They haven't only ripped off their sources, they're also stealing your money.

Friday, July 30, 2010

Trojan Cell Phone Apps

First the iphone and now android phones have been center focus for trojan applications that collect personal data and send it off to some nefarious foreign server. One of the trojan apps is a simple desktop wallpaper manager.

Ever wondered why some companies have such strict policies about what you may or may not install on  your company-issued cellphone?