Sunday, January 23, 2011

The 12 information security principles for information security practitioners


The 12 Principles


The 12 information security principles for information security practitioners are outlined under three main categories – support the business, defend the business, and promote responsible security behaviour – with an objective and detailed description for each principle:




Thursday, October 7, 2010

Computer Monitoring Tools

As security professionals we all know when our computers are trying to tell us that there is something wrong.  We also have our own techniques for poking around "under the hood" looking for trouble before it gets out of hand.  Like car enthusiasts, we know what each rattle and noise means and we take steps to correct the problem early.  But what about our parents and extended family members who don't have the same skills?  Like the temperature gauge or "check engine" light in your car, how does a typical user know that something is wrong?
Most newer operating systems have a system health and monitoring capability.  For example, in Windows 7 you do this:
  • Log on as a local administrator on your computer, click Start, and then click Performance and Information Tools.
  • Under Advanced Tools, select Generate a system health report.
And in Windows XP you take these steps:
  • Log on as a local administrator on your computer, click Start, and then click Help and Support.
  • Under the Pick a task, click Use Tools to view your computer information and diagnose problems.
  • In the Task pane, click My Computer Information, and then click View the status of my system hardware and software.

Wednesday, October 6, 2010

Recognizing phishing and online scams

Recognizing phishing and online scams. Which is an interesting discussion. For example, would phishers still bother if no one clicked and freely entered their credit card and personal information? Would 419 scammers bother if no one responded to their messages? Since there is a profit motive behind the miscreants actions if there were a diminishing return, or the actual possibility or prosecution, would we continue to see so many of their emails and web sites? Philosophical questions aside, in oder to reduce the harm of scammer and phishers the people receiving the bait need to be able to recognize the messages as such and not respond or click.


Don't click or respond to the following:
  • If the message does not appear authentic, it probably isn't.
  • If it sounds too good to be true, it is.
  • Do the content of the message appear in search engine results?
  • If you hover your mouse over the link does your browser or security software silently scream at you?
  • Seeing silly typos, formatting, or grammatical errors a professional would not make.
  • If the message asks you to send your information to them, rather than the other way around.
  • If you don't have an account with the company supposedly sending the email!

Here are some useful links:

http://www.microsoft.com/protect/fraud/phishing/symptoms.aspx
http://www.us-cert.gov/reading_room/emailscams_0905.pdf
http://www.gongol.com/howto/recognizephishing/
http://www.surfnetkids.com/safety/how_to_recognize_phishing-21760.htm

Tuesday, October 5, 2010

Cyber Security Awareness - Securing the Family PC

So today let's look at some common sense advice about the family computer. Yes, we all know the mantra about keeping the anti-virus software updated and the system patched (we'll talk more about that in a few days) but what else should we be doing? Some of the things that I recommend for the family PCs I work on include:

  • Keep all computers in full view (no hidden machines, no illusion of privacy)
  • Document computer details in writing (serial number, software, receipts, BIOS password, etc.) and keep the documentation in a fireproof box or safe
  • Use an uninterruptable power supply (UPS) for PCs, laptops have their own built-in UPS - the battery
  • Keep all of the hardware and software manuals, plus any software CDs/DVDs in one place that is easy to find
  • Use a cable lock to keep intruders from stealing the computer should there be a break-in
  • Throw a towel over the webcam (better: unplug the webcam)
  • Unless it needs to always be on, consider turning it off when not in use
  • Keep plenty of room around the PC so that air can flow through to cool it

Tuesday, September 28, 2010

Zeus In The Mobile (Zitmo): Online Banking’s Two Factor Authentication Defeated

During the weekend, in our monitoring of the Zeus botnet, my colleague Kyle Yang stumbled upon an unexpected payload: a brand new mobile malware piece we named SymbOS/Zitmo.A!tr (Zitmo standing for “Zeus In The MObile”), likely aimed at intercepting confirmation SMS sent by banks to their customers. This also caught the eye of s21sec with a nice analysis you should read.


Basically, the ZeuS network initiated some social engineering operations (via injection of HTML forms in the victims’ browser) to get the phone number and phone model of its infected victims. Based on that info, it sends an SMS with a link to the appropriate version of the malicious package (a Symbian package for Symbian phones, a BlackBerry Jar for BlackBerry phones etc).

This malicious package is still under investigation, but given the context, it is logical to believe it is aimed at defeating SMS-based two-factor authentication that most banks implement today to confirm transfers of funds initiated online by their end users, and that currently impedes the plunging of infected users’ online accounts by Zeus masters (Note: although it was possible before, with man-in-the-middle attacks, it required the victim to initiate a financial transfer in the first place).

On the technical side, this malware is not altogether that much ‘unexpected’ because, since SymbOS/Yxes, we always said somebody would use web servers to distribute platform-specific malware to victims. Yet, it is the first time we acknowledge the technique to be used by a real gang.

So far, we have seen that:
» the Symbian version is correctly signed, using the Express Signed program, once more. Symbian has been notified, but meanwhile, please beware this certificate hasn’t been revoked yet:

Serial Number: 61:f1:00:01:00:23:5b:c2:79:43:80:40:5e:52

C=AZ, ST=Baku, L=Baku, O=Mobil Secway, OU=certificate 1.00,

OU=Symbian Signed ContentID, CN=Mobil Secway» the malware creates its own malicious database on the phone, where it stores all information it steals (contact first and last names for instance, phone numbers) and needs. This database is named NumbersDB.db, and contains 3 tables:
» tbl_contact with 4 columns: index, name, descr, pb_contact_id.
» tbl_phone_number with 2 columns: contact_id, phone_number
» and tbl_history with 6 columns: event_id, pn_id, date, description, contact_info, contact_id.

The malware searches those tables using standard SQL queries.
» the malware sends SMS messages. In particular, it sends a message to a phone number located in the United Kingdom to notify that the malware has been successfully installed (”App installed ok”).

"27/09/2010","12:09","Short message","Outgoing","App installed ok","+44778xxxxxxx"

(NOT SENT - OFFLINE)Additionally, as explained by s21sec, the malware seems to be able to answer to a few commands such as ’set admin’, which might be particularly dangerous: anyone sending a “set admin” SMS to your infected phone may be able to take control of it. We’re of course investigating this, as well as the rest.

Tuesday, September 7, 2010

Worst U.S. military security breach ever

A malware-laden flash drive inserted in a laptop at a U.S. military base in the Middle East in 2008 led to the "most significant breach of" the nation's military computers ever, according to a new magazine article by a top defense official.

The malware uploaded itself to the U.S. Central Command network and spread undetected on classified and unclassified computers creating a "digital beachhead, from which data could be transferred to servers under foreign control," William J. Lynn III, U.S. deputy secretary of defense, wrote in his essay in the September/October issue of Foreign Affairs.

"It was a network administrator's worst fear: a rogue program operating silently, poised to deliver operational plans into the hands of an unknown adversary," he wrote. This previously classified incident was the most significant breach of U.S. military computers ever, and it served as an important wake-up call. The Pentagon's operation to counter the attack, known as Operation Buckshot Yankee, marked a turning point in U.S. cyberdefense strategy."


Read more: http://news.cnet.com/8301-27080_3-20014732-245.html#ixzz0ypX371xv

Monday, August 9, 2010

Epic -A Browser Made For Indians By Indians

Epic -A Browser Made For Indians By Indians

Meet Epic, Your New Best Friend.The first-ever web browser for India,The world’s only antivirus browser.Yeah it’s true EPIC Web browser which is developed by and indian company called Hidden Reflex,and these guys are really making waves across the web Epic is Powered by the open-source Mozilla platform