Saturday, January 23, 2010
Perhaps it's time to regulate Microsoft as critical infrastructure?
My main argument is about the policy of handling vulnerabilities for 6 months without patching (such as the Google attacks 0day apparently was) and the policy of waiting a whole month before patching this very same vulnerability when it first became an in-the-wild 0day exploit (it has now been patched, ahead of schedule).
Microsoft is the main proponent of responsible disclosure, and has shown it is a responsible vendor. Also, patching vulnerabilities is far from easy, and Microsoft has done a tremendous job at getting it done. I simply call on it to stay responsible and amend its faulty and dangerous policies. A whole month as the default response to patching a 0day? Really?
With their practical monopoly, and the resulting monoculture, perhaps their policies ought to be examined for regulation as critical infrastructure, if they can't bring themselves to be more responsible on their own.
This is the first time in a long while that I find it fit to criticize Microsoft on security. Perhaps they have grown complacent with the PR nightmare of full disclosure a decade behind them, with most vulnerabilities now "sold" to them directly or indirectly by the security industry.
Gadi Evron,
ge@linuxbox.org.
Follow me on twitter! http://twitter.com/gadievron
Large Hadron Collider, Nessus, and the InterWebz
Protection against external accessGadi Evron,
‘Redundant installations such as the Simatic S7-400H fault-tolerant type of controllers may offer a high degree of operational safety. But who can guarantee that no one will take over the controller, crash it and compromise its security?’ asks Dr. Stefan Lüders from the computer security team of the IT department at CERN. ‘Most controllers, field devices and even actuators are now directly connected to Ethernet.’
The team led by Dr. Lüders therefore developed a special test bench for dedicated examination of the vulnerability of controllers, SCADA (Supervisory Control and Data Acquisition) systems and other Ethernet-connected devices in the market to cyber-attacks. This not only relates to protection against hackers with more or less criminal intent, but also against viruses and worms that can be introduced through a variety of channels—including USB sticks and CF cards. In contrast to the usual patches that can be installed in an office environment, controllers cannot be easily updated daily with the latest antivirus protection, even if it is available.
As part of the validation of controllers used at CERN, at the test bench on Control System Security at CERN (TOCSSiC), 31 devices from seven manufacturers were systematically tested for penetration resistance with the vulnerability scanners Nessus and Netwox. Taking all different firmware versions into account, this led to 53 tests in total. In addition to interference through overload (Denial of Service, DoS), the tests also included provoked attacks on vulnerabilities in operating systems by infiltration of malicious software and ‘malicious’ manipulation of TCP/IP-based protocols. About one third of the tested devices failed these tests and has shown severe security problems.
Approximately one third of the devices came from the Simatic S7 product series, some with an integrated Ethernet interface, some with separate communication processors, such as the CP 343-1 Lean for the S7-300 series.
The poor test results led to a ‘very productive interaction with Siemens’ and ultimately made ‘Simatic controllers significantly more secure over the years; now they meet the stringent requirements at CERN,’ summarises Dr. Lüders.
ge@linuxbox.org.
Follow me on twitter! http://twitter.com/gadievron
China's CNCERT response to Google
Johannes Ullrich just brought this to my attention on Facebook.
In short, CNCERT wrote that China is the biggest victim of cyber attacks, and that Google lacks evidence to link the recent attacks to China as the perpetrator.
Gadi Evron,
ge@linuxbox.org.
Follow me on twitter! http://twitter.com/gadievron
Saturday, January 16, 2010
Traffic Video Ads Replaced with Porn
Traffic jerked to a standstill as rubbernecking motorists ogled a pornographic clip posted by hackers on big-screen video billboards in Moscow, Russian news agencies reported Friday.Gadi Evron,
The company that operates the billboards, Panno.ru, said hackers were behind a graphic sex video broadcast late Thursday night on two roadside screens along Moscow's Garden Ring Road, one of the city's busiest arteries.
"This was an attack by hackers on the computers, as a result of which one of the commercial video clips was swapped for an indecent video," Panno.ru commercial director Viktor Laptev told RIA-Novosti.
ge@linuxbox.org.
Follow me on twitter! http://twitter.com/gadievron
Friday, January 15, 2010
China Hacks Google, Etc.
The reports, depending on vendor, blame either PDF files via email as the original perpetrator, or lay most of the blame on an Internet Explorer 0day.
Unlike my colleagues (save for the ones reporting), I rather not discuss this too much before more data is available.
Regardless of what really happened, which I hope we will know more on later, these things are clear:
1. Unlike GhostNet, which showed an interesting attack, but unfortunately many of us jumped to conclusions without evidence that it was China behind them -- based on Ethos alone I'd like to think that when Google says China did it, they know. Although being a commercial company with their own agenda, I am saving final judgement.
2. The 0day disclosed here shows a higher level of sophistication, as well as m.o. which has been shown to be used by China in the past.
3. If this was China, which some recent talk seems to make ambiguous, but still likely; they would have more than just one weapon in their arsenal.
4. This incident has brought cyber security once again to the awareness of the public, in a way no other incident since Georgia has succeeded, and to political awareness in a way no incident since Estonia has done.
Gadi Evron,
ge@linuxbox.org.
Follow me on twitter! http://twitter.com/gadievron
Thursday, January 14, 2010
Online Pharmacy Scammer Speaks
http://www.reddit.com/r/IAmA/comments/apcv0/i_was_a_doctor_at_an_online_pharmacy_i_did_not/
A few months a go a "legal" spammer spoke out on IAmA, as well:
http://www.reddit.com/r/IAmA/comments/9xrn1/iama_person_who_sends_spam_email_for_a_living_ama/
Enjoy,
Gadi Evron,
ge@linuxbox.org.
Follow me on twitter! http://twitter.com/gadievron
Tuesday, January 12, 2010
Getting back at the TSA
via AppleGeeks Lite 561.
And indeed, folks on the funsec mailing list had some fun with it.
phester wrote:
I've considered carrying a bag of dildoes when I fly. I imagine a conversation something like this;This was indeed fun, and we had a good laugh. Erik Harrison replied with the often quoted TSA joke:
TSA: What's this?!?
Me: A bunch of dildoes.
TSA: Why are you carrying a bunch of dildoes?
Me: It makes me feel safe.
TSA: How does a bunch of dildoes make you feel safe?
Me: I've been asking the same thing since they created the TSA.
TSA: "Nine times out of ten, it's an electric razor but, every once and a while, it's a dildo. Of course, it's company policy never to imply ownership in the event of a dildo. We have to use the indefinite article. A dildo, never your dildo."After a bit more fun, I responded seriously:
If it was me, I would say it was my dildo every time. It would be interesting to see their faces, but more importantly, if it's not mine, it might be a terrorist who put it in my bag. Bad idea: an exploded bag, a cavity search and 3 hours to 3 days later...But more than the TSA not having a sense of humour, this is really about respect, and about understanding that they can take no chances with you not being serious:
It's great to joke about, but not to practice as a joke. As I said earlier, bad idea.All-in-all, we had a good time playing with this, but we should all keep in mind that regardless of what we may think of the TSA and others around the world, some jokes are just not worth the price of a cavity search -- or at the very least 10 more minutes in line.
Don't mess with:
1. People trying to do their jobs.
2. People who are on alert for criminals and terrorists.
3. People who have the power to arrest you.
4. People who have guns to do their job.
and:
5. People who are forced to check you completely with the mere mention of a joke, as it might not be a joke.
Gadi Evron,
ge@linuxbox.org.
Follow me on twitter! http://twitter.com/gadievron
New subject specific blog from me: Pathos Daily
I decided that with the effort of emailing out links, I can also easily blog them. And so, I started a new blog on this subject matter, to specifically post links to interesting news stories and comic strips.
It is called Pathos Daily, and you can read it at:
http://pathosdaily.blogspot.com/
Gadi Evron,
ge@linuxbox.org.
Follow me on twitter! http://twitter.com/gadievron
Sunday, January 10, 2010
Funny! Mario & Luigi on Omegle: Password Social Engineering
Sometimes learning about security and hacking can come from odd sources. :)
Gadi Evron,
ge@linuxbox.org
Follow me on twitter! http://twitter.com/gadievron
Friday, January 08, 2010
Putting Trojan Horses on Chips!
5 January 2010—In November, engineering students from five top universities gathered at the Polytechnic Institute of NYU, in Brooklyn, N.Y., for the Embedded Systems Challenge. The aim was to test new attacks and defenses against an underappreciated breed of Trojan horse—embedded malware built into integrated circuits.Definitely worth a read!
The winning team’s results, set to appear in journals and at conference proceedings in 2010, reveal how vulnerable many systems are to "chip attacks" The contest also demonstrated the high degree of technical sophistication required for these attacks, making it more likely that attackers will pursue specialized applications, such as sensitive military equipment or high-security financial computers. Attacking Dad’s new Windows 7 PC probably isn’t worth the extreme investment of time and money—especially when cheaper and quicker phishing and software-based malware attacks still work all too well.
Gadi Evron,
ge@linuxbox.org.
Follow me on twitter! http://twitter.com/gadievron
Wednesday, December 30, 2009
Air Travel Security: Practical Industry Suggestions From Us
0. Review useless technologies which are there for beyond the security theater purposes (which do matter) and start eliminating bad projects. Your purpose in security theater was to maintain air travel and keep people calm, right?
1. An investment in better intelligence (no brainer)
2. Create a "always strip-search" list rather than just "no fly" list., so that lesser threats can be dealt with responsibly without compromising the usefulness of the no fly one. I am sure they already have one, but they should layer this rather than deal with extremes.
3. Hire better agents (education/ability... better pay). Should be a small increase per person, but it will cost a lot in total. Then again, how much do all the current b/s additions cost?
4. Yours?
Tactical:
1. Copy Israel's air security training manual for agents. Israel's tactics may not be able to scale to the US level, but the training can.
2. Stop panicking and alienating people, so they are calmer and you can more easily identify suspicious people, so that this new training is more effective. Heck, do it anyway. Send TSA agents to some workshop on being nice. Or make shifts shorter.
3. Put "human sniffer" walk-through machines in every airport, for international flights.
4. Buy the better brand of baggage screening && X-ray machines for international flights (remember the liquid issue with checking for explosives in the last scare?)
6. Yours?
Some of these are very high cost. Some of these are (on scale) very low cost.
Some of these should replace other high-cost idiocies, such as creating two new mega-airports, which is sound security-wise, but will only add an hop to the threat to jump over, with the same silly tests in yet another airport, rather than add a filter. Or full-body scans which will be of limited help, and insult us all.
Follow me on twitter! http://twitter.com/gadievron
Friday, December 18, 2009
Spymaster sees Israel as world cyberwar leader
Reuters reports from the Institute for National Security Studies (INSS), a Tel Aviv University think tank, where Major General Amos Yadlin, IDF chief of military intelligence, spoke:
In a policy address, Major-General Amos Yadlin, chief of military intelligence, listed vulnerability to hacking among national threats that also included the Iranian nuclear project, Syria and Islamist guerrillas along the Jewish state's borders.
Yadlin said Israeli armed forces had the means to provide network security and launch cyber attacks of their own.
He further said, as mentioned in this Israeli publication, that other countries, such as the United States and Great Britain, are establishing units for cyber defense, and that Israel has soldiers and officers on the job.
In fact, just today I heard a lecture by the director of the CIA who, as is general United States policy, places cyber security on the map when discussing issues such as proliferation of nuclear weapons and international terrorism.
HaAretz, an Israeli newspaper, quotes Major-General Yaldin as saying:
"Fighting in the cyber dimension is as significant as the introduction of fighting in the aerial dimension in the early 20th century." (my translation)
If this statement is to be believed, Israel is active in cyberspace. And yet, why would Israel admit that, regardless of if it really happens?
One option is that Israel decided it needs to show that its military is on par with other militaries around the world.
"Preserving the lead in this field is especially important given the dizzying pace of change," Yadlin said.
On the surface, disclosing cyber space activity, which your enemies can develop as well, or push to develop more of, seems silly.
After all, Major-General Yadlin said:
"Cyberspace grants small countries and individuals a power that was heretofore the preserve of great states,"
As Israel, much like the Western world, is very advanced technologically, it is more reliant on computers than many of its enemies and neighbors, and is therefore more at risk from potential cyber attacks. With attacks against Israel's internet presence these last few years, it may not be a silly idea after all.
With the world becoming more aware of threats to computer systems, investment in cyber security rising and more and more security incidents being disclosed; countries around the globe invest in cyber capabilities. Indeed, Israel too, which has been under internet attacks for years, needs to buckle up and do more to combat the threats.
Major-General Yadlin also mentioned cyber attacks fit well with Israel's doctrine for military offensives (mistranslated below as defense). This bit is tricky, and I will try and read between the lines.
"I would like to point out in this esteemed forum that the cyberwarfare field fits well with the state of Israel's defense doctrine,"
While Major-General Yadlin in all probability meant something along the lines of being bold and staying ahead of the curve, as in the same sentence he also spoke of Israeli youth and innovation, mentioning how Israel is often referred to as the "start-up country":
"This is an enterprise that is entirely blue and white (Israeli) and does not rely on foreign assistance or technology. It is a field that is very well known to young Israelis, in a country that was recently crowned a 'start-up nation'."
It is possible, although unlikely, that he meant to indeed discuss Israel's defense doctrine, thus possibly speaking about deterrence in cyberspace.
Deterrence is an integral part of Israel's defense doctrine, with the goal, in broad lines, of widening the window between inevitable Arab attacks by a strong response, some would say a disproportionate one, which will score a quick and decisive victory. Hopefully deterring them from attacking again. This strategy has roots in Israel's history all the way back to Ben Gurion's time and the formation of Israel.
Deterrence on the Internet, however, is mostly nonsense. This due to inability to identify who it is actually attacking you, and then if somehow successful, if it is really them or if their computer has been taken over by yet another attacker. Is someone trying to frame another as your attacker? Is your attacker even a nation-state to begin with, rather than an organization that doesn't care about retaliation?
On the internet, you may know who your enemies are rivals are, but you may never find out who is attacking you. The Internet is perfect for plausible deniability.
If this was the thinking behind the announcement, which I'd like to think is not the case, then the strategy was copied from the United States where this silliness has been going on now for a few years. The US strategic experts have been using Mutual Deterrence (or MAD, Mutually Assured Destruction) for over 70 years now, and feel comfortable with it. Therefore, when they needed to tackle the cyber realm, they immediately started pushing for a deterrence strategy even though cyber experts have been warning about it continually.
Deterrence for the most part, doesn't work online. It is my hope Israel does not repeat the American mistake on this matter and that I am right, and Major-General Yaldin was only speaking of Israel's spirit, where commanding officers lead the charge rather than wait behind.
From a completely different perspective, cyber warfare has been recognized as a strategic weapon on par with weapons of mass destruction for at least two decades. Israel does not admit strategic capabilities such as Nuclear Weapons, if it has them. Should it admit cyber capabilities?
"The potential exists here for applying force ... capable of compromising the military controls and the economic functions of countries, without the limitations of range and location."
While cyberspace is certainly strategic, the analogy to nuclear weapons is relatively weak.
There are obvious differences between the nuclear world and the cyber world, such as with tactical cyber uses of a very targeted nature -- without collateral damage, and in international law governing the proliferation of nuclear arms, while the cyber realm is in its infancy. In fact, the United States, Russia and the United Nations arms control committee are as I write these lines engaged in early discussions on securing cyberspace, and limiting military use of this realm.
When I first heard of the speech by Major-General Yaldin, I was highly disappointed with Israel for taking this route of public disclosure. Now, I am not so sure.
Disclosing that Israel is ready to defend itself and potentially engage its enemies in cyberspace right along-side the physical world, certainly has merit considering recent world events such as the attacks against Estonia and Georgia. I am just left wondering if this indeed discloses a real capability, or is just public relations.
I can personally attest from my years of defending Israel's internet, that Israel is under constant attack in cyberspace, and this intensifies whenever political tensions mount.
"At times it would seem," said Major-General Yaldin, "that our enemies would like to give a special award to Western companies whose products can be bought off-the-shelf at a reasonable price." (my translation)
Regardless, putting cyber security on the agenda along-side with Iranian nuclear weapons, Syria and Islamist guerrillas, is a step in the right direction to defending against the threats of cyberspace.
Gadi Evron,
ge@linuxbox.org.
Follow me on twitter! http://twitter.com/gadievron