[+] Wayc0de's Blog[+]

Tampilkan postingan dengan label Security Center. Tampilkan semua postingan
Tampilkan postingan dengan label Security Center. Tampilkan semua postingan

29/09/11

Symantec sees surge in morphing malware and JavaScript abuse

A new social engineering technique fools users into thinking they've received a legitimate file from an office printer

Proving that most malicious hackers are more than happy to employ time-tested tactics instead of developing sophisticated new techniques and tools, Symantec has reported a huge spike in generic polymorphic malware (malware that changes shape to bypass detection) spread via good old fashioned socially engineered email messages.

That's not to say that the bad guys aren't innovating at all: "Symantec's Intelligence Report: September 2011" (PDF) noted a new social engineering twist to get users to download dangerous attachments: convincingly masking malicious emails as legitimate messages sent from office printers. The security company also has witnessed more spammers and malware authors using JavaScript to hide their activities.

Generic polymorphic malware variants accounted for 72 percent of all email-borne malware in September, compared with 18.5 percent in August and 23.7 percent in July. "This unprecedented high-water mark underlines the nature by which cyber criminals have escalated their assault on businesses in 2011, fully exploiting the weaknesses of more traditional security countermeasures," wrote Paul Wood, senior intelligence analyst at Symantec.

The challenge for cyber criminals is to dupe victims into downloading and opening dangerous attachments. One new approach entails fooling users into thinking they've received an attachment sent from an office printer that has a scan-to-email capability; this feature enables users to send scanned files directly from a printer to a specified email addresses.

To pull off this dupe, hackers send users malicious emails with Subject lines stating "Scan from" followed by the convincing-looking office-printer information. The message itself contains additional fake details about the so-called scanned file, including a sender's name, the number of pages, the type of file, a device number, and possibly the printer's location in an office.

Symantec sees surge in morphing malware and JavaScript abuse

This is all intended to lull targets into a sense of security such that they'll download the attached file, which turns out to be a zip file with a malicious executable.

"To be clear, office printers and scanners will not send malware-laden files, and many are unlikely to be able to send scanned documents as zip file attachments. No printer or scanner hardware was involved in the distribution process," wrote Bhaskar Krishnappa, malware analyst at Symantec.

Additionally, Symantec reported that spammers and malware authors are increasingly using JavaScript to do their dirty deeds. And they're not just using the language to covertly redirect users to malicious sites; they're using JavaScript to obfuscate entire Web pages. Doing so enables spammers and malware authors to set up their obfuscated pages on free hosting sites without site operators realizing it.

Symantec's September Intelligence Report also covers a vulnerability in the WordPress platform, which spammers are exploiting to compromise Web servers and hide files deep with the WordPress directory structure. The files are basic HTML pages, according to Symantec, that redirects users to the Canadian Health & Care Mall spam website. WordPress-hosted blogs aren't affected by these vulnerabilities, according to the report; only older versions of software downloaded from WordPress.org.

Other findings in Symantec's report include:
  • Spam rates dipped to 74.8 percent in September, a 1.1 percent drop since August
  • One in 447.9 emails were actually phishing attempts, marking a 0.26 percent drop month over month
  • One in 188.7 emails in September contained malware, an increase of 0.04 percent
  • The number of malicious websites blocked daily rose 1 percent since last month, up to 3,474
  • 44.6 percent of all malicious domains blocked in September were new, up 10 percent since August
  • 14.5 percent of all Web-based malware blocked in September was new, down 2.9 percent since last month


 

Read More...

22/09/11

Massachusetts Attorney General, Victim of an iTunes Scam, Says She'll Demand Answers

Massachusetts Attorney General Martha Coakley said on Tuesday that her office would be inquiring into long-standing complaints about fraudulent purchases that leverage Apple's popular online music store.

In a lunchtime address to business and technology leaders in Massachusetts, Coakley said she was a victim of identity theft in recent months, and that her stolen credit card information was used to make fraudulent iTunes purchases. When asked (by Threatpost) about whether such fraud constitutes a reportable event under the Bay State's strict data breach notification law, Coakley said that her office would be looking into that question and demanding answers from Cupertino, California based Apple, which has steadfastly refused to comment, or report the breaches to Massachusetts regulators.

Coakley was speaking before an audience of technology and business leaders at an inaugural lunch for Massachusetts' Advanced Cyber Security Center (ACSC). Coakley said that her investment in protecting consumers from identity theft was personal, acknowledging that her bank account was emptied after cyber criminals stole her debit card information during a ski trip to New Hampshire. It was not the first time Coakley had mentioned the incident in public. After skimming the card info, Coakley said the thieves attempted to use it to purchase a laptop from Dell Computer, which detected the fraudulent transaction and contacted Coakley. Not so Apple, whose iTunes media store was used to make a slew of transactions that emptied the Attorney General's account.

Informed of the well documented pattern of fraud through iTunes, in which stolen credit cards or bogus iTunes gift cards are matched with compromised iTunes accounts and used to purchase merchandise, Coakley said she wasn't aware of the larger pattern, but that it could be a reportable offense under the State's data privacy law. She promised her office would be contacting Apple for more information that very afternoon - a statement that received hearty applause from the audience.

Despite the tough tone, Coakley's speech was tailored more to a business audience wary of burdensome enforcement of State data privacy laws, including the State's data breach notification law and 201 CMR 17, the Massachusetts Data Protection Law. That law took effect in March, 2010 but the first fine under the law was issued in March of 2011 to Briar Group, a Boston-area restaurant chain that showed gross negligence in securing its networks and handling customers' credit card numbers.

Coakley said that companies that attempt, in good faith, to adhere to the State's privacy laws have little to fear in the way of fines or prosecution. However, organizations that flaunt the law or ignore the need for data security should count themselves warned.

Describing her office as the first line of defense for consumers, Coakley said her office was pursuing a "common sense" approach to enforcement and notification. Large breaches, such as the hack of Massachusetts retailer TJX, warrant an all out effort to notify the public. In the case of smaller breaches, Coakley said her office wanted to work with victim organizations to make sure that holes in their defenses and IT security practice are addressed.

The Attorney General said her office has received around 480 data breach notifications so far in 2011, and 1,166 since the law took effect in March, 2010 - suggesting that the incidence of data breaches is holding steady, despite a tough economy. The vast majority of those breaches are small in nature. Eighty two percent of disclosed breaches affected fewer than 100 people, and just 4% affected between 1,000 and 10,000 people. Similarly, hacking incidents only made up a quarter of the reported breaches, with another quarter due to inadvertent human error, Coakley said.

The State's breach notification law, dubbed 201 CMR 17, sets clear guidelines for the types of incidents that constitute reportable breaches. Any incident resulting in "the unauthorized acquisition or unauthorized use of unencrypted data or, encrypted electronic data" that creates a "substantial risk of identity theft or fraud against a resident of the commonwealth" need to be disclosed, as well as combinations of personal information, such as a name and credit card number, must be reported. That would seem to describe the use of Coakley's credit card information on iTunes. However, its is unclear whether Apple actually holds the data used to process the transaction on iTunes, or whether the purchases are merely "pass through" transactions about which Apple has no knowledge or visibility, according to a source within the Attorney General's Office.

nb : threatpost Read More...

21/09/11

Massachusetts Inaugurates New Cyber Security Center

Hundreds of business leaders and academics joined Massachusetts Governor Deval Patrick and Attorney General Martha Coakley to launch the state's Advanced Cyber Security Center (ACSC), one of the first of its kind in the nation.

Speaking at the local headquarters of the MITRE Corporation, Patrick and other leaders said the center would be a new and important bridge between the researchers, government and the private sector that would help address the threat posed by advanced criminal and nation-backed hackers, while spurring technological innovation and economic growth in the region.

Likening the new center to other Administration initiatives to boost Massachusetts' economy, Patrick said the State would benefit from embracing the need for better cyber security and being focused and directing Massachusetts' unique combination of high tech, R&D, public and private resources towards addressing cyber security concerns. Comparing the job of tackling cyber crime to the State's successful, multi-year effort to improve its finances, Patrick said the Bay State was one of the few nationally to sport a AAA credit rating from all three rating agencies. "We didn't get there by luck," he said.

ACSC is set up as a nonprofit corporation that is supported by Mass Insight Global Partnerships. The group is intended to be an umbrella organization for industry, government and academia to work together on fighting advanced cyber threats, with a focus on sharing information about emerging threats and promoting future generations of researchers and cyber security professionals.

Speaking after Governor Patrick, Alfred Grasso, the CEO of MITRE Corp. - a government funded non profit science and technology research firm - cited recent reports about widespread attacks against U.S. private sector firms that McAfee dubbed "Shady Rat." The U.S., he said, was experiencing an unprecedented transfer of intellectual capital and wealth as a result of insidious cyber attacks. The ACSC was part of a nation-wide effort to stop that transfer by adopting a communal approach to cyber threats.

Speaking in a panel discussion, Doug Maughan, director of the Cyber Security Division of the Department of Homeland Security's Science and Technology Directorate said that the U.S. needed to shift from an individual to a collective notion of risk and needed new approach to responding to cyber attacks that emphasized early warning about emerging threats.

Attendees at the event said that the idea of a cyber threat clearing house for private sector firms and public organizations was laudable, but wondered how it would relate to other, similar groups that already exist, including industry-level information sharing and analysis centers (ISACs) and programs like the FBI's Infraguard.

"I want to know if (ACSC) will integrate with programs like Infraguard or replace them," said Daniel Sarazen, a Senior IT Auditor in The University of Massachusetts' Office of the President.

Shane Sims, the Director for Forensics at the consulting firm PriceWaterhouseCoopers said the new center could have a real impact in improving cyber security if it can foster better information sharing among companies that have been hacked, or that suspect they are being targeted.

"History has demonstrated that advanced cyber intrusions cannot be prevented and often go undetected for months to years. Organizations have to increase their cyber visibility in order to reduce it. One method to obtain this visibility is to absorb and operationalize as much threat intelligence as possible," he wrote in an e-mail statement.

While warnings form security vendors are useful, companies are better served by threat intelligence from peers within a given industry, he wrote.

"Having an independent, trusted 3rd party which organizations are willing to push this type of information to and sanitize for dissemination, will hopefully inspire organizations to begin this very important process of sharing threat intelligence quickly. If the ACTC can make it happen, they will be a model which can be replicated across the globe," Sims wrote.

nb : threatpost Read More...