The good guys have always spent time researching to understand how the bad guys operate, in order to turn the tables and catch them. A honeypot is probably the best example of this.
A honeypot is a system that purposely appears to be super-vulnerable to the attackers who eventually find and attack it, while the good guys watch and learn. In theory, what they learn is used to develop newer and better tools. While this has utterly failed in the Antivirus world, it has been a fairly successful strategy in the hacking world.
In a decidedly Spy vs. Spy revelation, it seems that attackers are using honeypots to catch infosec researchers. The Zeus bot makes use of a fake administrator interface, complete with a guessable password and trivial SQL vulnerability meant to alert the attackers to the investigation so they can respond accordingly.
Some news, views and musing about things going on in the Information Security World.
Friday, November 5, 2010
Friday, October 22, 2010
Man In The Browser (MITB) Attacks
A new botnet named Feodo has been discovered. It doesn't seem to have much new about its internal workings, but the linked article gives a good description of how Man In The Browser attacks work.
Feodo rewrites specific banking app web pages in order to add input fields, such as PIN numbers and other personal information, that the bank wouldn't normally request on the unmodified version of the page.
Feodo rewrites specific banking app web pages in order to add input fields, such as PIN numbers and other personal information, that the bank wouldn't normally request on the unmodified version of the page.
Key Words:
0-day,
credit card fraud,
hacking,
security controls,
trojan
Friday, October 15, 2010
Information Security Strategy Generator
I don't usually post sites with swearing all over them, but this one was too good to pass by.
The site whatthefuckismyinformationsecuritystrategy.com automagically generates realistic sounding security strategies. Just hit reload to generate a new one. They pay people good money to come up with these kinds of statements.
I got this: Monitor vendor access and restrict personal use of computing resources by removing admin rights on critical assets
The site whatthefuckismyinformationsecuritystrategy.com automagically generates realistic sounding security strategies. Just hit reload to generate a new one. They pay people good money to come up with these kinds of statements.
I got this: Monitor vendor access and restrict personal use of computing resources by removing admin rights on critical assets
Microsoft Hopelessly Battles with an Angry Dragon Inside Its Own Network
Ok, the headline is exaggerated, but only a bit.
Microsoft's squeaky-tight security was bypassed by hackers who subsequently used their uber-hardened servers to send spam about cheap viagra, penis enlargement, and other services that don't come with a dubious EULA. Oh, and they even launched an attack against an information security blogger.
I can't wait to hear the spin on this one.
Microsoft's squeaky-tight security was bypassed by hackers who subsequently used their uber-hardened servers to send spam about cheap viagra, penis enlargement, and other services that don't come with a dubious EULA. Oh, and they even launched an attack against an information security blogger.
I can't wait to hear the spin on this one.
Tuesday, October 5, 2010
Antivirus Companies Finally Do Something About Their Own Website Security
In an industry where security companies have gotten rich enough to practice what they preach, you'd expect them to be setting the example when it comes to secure coding practices. It's the age old story about the cobbler's kids wearing crappy shoes.
You would expect security companies to hire coders that have at least a basic knowledge to do their jobs securely. How is it that so many such company websites would be afflicted with something as blatant as Cross-Site Scripting flaws? What makes this worse is that some of these companies offer secure web hosting, and post bulletins about other company's security issues! Someone isn't doing their homework.
Some of the companies that should know better: Symantec, Eset, and Panda.
You would expect security companies to hire coders that have at least a basic knowledge to do their jobs securely. How is it that so many such company websites would be afflicted with something as blatant as Cross-Site Scripting flaws? What makes this worse is that some of these companies offer secure web hosting, and post bulletins about other company's security issues! Someone isn't doing their homework.
Some of the companies that should know better: Symantec, Eset, and Panda.
Key Words:
0-day,
computer viruses,
hacking,
microsoft,
security controls,
trojan
Friday, October 1, 2010
Tired of the crap "news" websites are posting about Stuxnet?
F-Secure has posted a bit of a FAQ to help people interested in understanding the Stuxnet worm issue to get more realistic information, versus the omg-CNN-style garbage that has been going around so far.
Is it targeting Iranian nuclear plants? We don't know.
All this conjecture reminds me of the days when hundreds of STONED virus variants were running rampant, and McAfee started pretending they were totally different, and gave them fancy names just to make them sound like different beasts. (for example, Michelangelo). The same virus, with 2 or 3 lines changed suddenly became a totally amazing technological advance hell bent on the worse possible destruction. Just sayin...
Is it targeting Iranian nuclear plants? We don't know.
All this conjecture reminds me of the days when hundreds of STONED virus variants were running rampant, and McAfee started pretending they were totally different, and gave them fancy names just to make them sound like different beasts. (for example, Michelangelo). The same virus, with 2 or 3 lines changed suddenly became a totally amazing technological advance hell bent on the worse possible destruction. Just sayin...
Key Words:
0-day,
computer viruses,
physical security,
security controls,
spying,
terrorism,
trojan
Blackberry Encryption Cracked
Elcomsoft, the overseas infosec group who seem to be able to break into just about everything, have now cracked the Blackberry encryption mechanism.
It seems like only yesterday when certain freedom-free countries were complaining that they couldn't read Blackberry messages sent by their own hostile population.
It seems like only yesterday when certain freedom-free countries were complaining that they couldn't read Blackberry messages sent by their own hostile population.
Key Words:
0-day,
encryption,
hacking,
password complexity,
physical security,
privacy,
security controls,
spying,
terrorism
Subscribe to:
Posts (Atom)