Showing posts with label security. Show all posts
Showing posts with label security. Show all posts
Thursday, 28 April 2011
Hide Your Data Through Fragmentation, Not Encryption
The thing about data encryption is that it's basically a flashing neon sign indicating "SENSITIVE DATA HERE!" A new technique lets you secure your data by customizing the way that data is fragmented across your drive.
The new method uses special software to place data on specific parts of your hard disc using a code instead of the disc drive controller chip. Your sensitive data is encoded into a binary value and used to modify the fragmentation patterns of an existing file. The conversion is based on whether or not sequential clusters of data are stored adjacently. If they are, it represents a binary 1; if they aren't, it's a 0.
The system was developed by Hassan Khan and his colleagues at the University of Science and Technology in Islamabad, Pakistan. They say that it can hide a 20MB message on a 160GB hard drive, and detecting its existence would be "unreasonably complex." This is important because the normal methods of encryption are so well known that they're dead giveaways that something is amiss, and often the fact that you have something to hide can be just as damning as the information itself.
This isn't a permanent solution for data security, of course. Now that this type of camouflage is in the field, it won't be long until a detection method is reverse engineered. But research like this is important for everyone—journalists, dissidents, LOIC enthusiasts—who thinks they are at risk of having their drives seized and searched for incriminating information.
[ScienceDirect via New Scientist via Gizmodo]
Tuesday, 12 April 2011
Wireless Security – Choosing the Best Wi-Fi Password
Running through some tests for an upcoming wireless security book and it really brings home the importance of choosing a good password for your Wi-Fi network.
Currently, the best security setting for your home or office Wi-Fi is WPA2.
WPA2 Enterprise is the best if your organization supports it, but WPA2 Personal is great for home and small offices.
Do not use WEP. It has been cracked a long time ago, and an attacker does not even have to crack it, the WEP key can be passed just like NTLM passwords.
The most common technique used for WPA/WPA2 hacking is a dictionary attack.
The attacker captures a WPA password handshake and passes this through a program that will try numerous passwords from a word list.
Here is the key, if the password is not in the word list, they hacker does not get into your system.
Using a lengthy complex password goes a long way in keeping your WPA2 network secure.
A combination of upper/lower case letters, numbers and special characters is the best bet.
Some prefer using a short sentence that means something to them, while replacing some of the letters with numbers and adding in a few extra characters.
I just ran one common word list attack against my WPA2 password. It tried over 1 million word combinations from the list with no dice. My network is still secure!
The more un-dictionary looking your password is, the better!
Building More Secure Passwords
The problem of weak, guessable security passwords isn’t a new one, but it’s not going away.
In fact it’s getting worse, despite pleading from IT professionals to choose tough-to-guess passwords.
Workers are still disconcertingly likely to come up with something like “password1!” or simply attach a few numbers like “123,” to the end of a word.
As users have to create several passwords for different systems and change them every 60 or 90 days, it’s little wonder they default to the least complicated password their systems allow and make only minor variations when forced to change them.
Unfortunately, such passwords are easy to guess. At the other end of the scale are passwords software programs randomly generated, which are difficult for users to remember (leading them to write these passwords down which defeats the effort).
In a recent paper coauthored by Cisco, Florida State University, and Redjack LLC, researchers examined how different password requirements affect password strength — such as requiring a minimal password length or the addition of a special character.
The researchers discovered that such policies usually don’t provide greater security since hackers are well-versed in these tactics and can use them to guess passwords and access accounts.
For instance, hackers know that when users are required to use a special character in a password, they can simply append that character to the end of the password.
A better practice say the researchers, is an external password creation tool that changes a password after it’s created to add a guaranteed amount of randomness — for example, adding two random digits to the end of a password.
This allows users to choose a password that they are likely to remember while making it difficult for hackers to guess.
Another option is to implement a “judgmental” password policy which will reject a password instantly based on its estimated strength and suggest a stronger one.
Or administrators could implement password protection software, which lets users remember only one strong master password, leaving the application to store encrypted passwords.
Excerpted and adapted from the Cisco 2010 Annual Security Report
[infosecIsland]
In fact it’s getting worse, despite pleading from IT professionals to choose tough-to-guess passwords.
Workers are still disconcertingly likely to come up with something like “password1!” or simply attach a few numbers like “123,” to the end of a word.
As users have to create several passwords for different systems and change them every 60 or 90 days, it’s little wonder they default to the least complicated password their systems allow and make only minor variations when forced to change them.
Unfortunately, such passwords are easy to guess. At the other end of the scale are passwords software programs randomly generated, which are difficult for users to remember (leading them to write these passwords down which defeats the effort).
In a recent paper coauthored by Cisco, Florida State University, and Redjack LLC, researchers examined how different password requirements affect password strength — such as requiring a minimal password length or the addition of a special character.
The researchers discovered that such policies usually don’t provide greater security since hackers are well-versed in these tactics and can use them to guess passwords and access accounts.
For instance, hackers know that when users are required to use a special character in a password, they can simply append that character to the end of the password.
A better practice say the researchers, is an external password creation tool that changes a password after it’s created to add a guaranteed amount of randomness — for example, adding two random digits to the end of a password.
This allows users to choose a password that they are likely to remember while making it difficult for hackers to guess.
Another option is to implement a “judgmental” password policy which will reject a password instantly based on its estimated strength and suggest a stronger one.
Or administrators could implement password protection software, which lets users remember only one strong master password, leaving the application to store encrypted passwords.
Excerpted and adapted from the Cisco 2010 Annual Security Report
[infosecIsland]
“Facebook Support. Your password has been changed!” contains trojan
MX Lab, http://www.mxlab.eu, started to intercept a new trojan distribution campaign by email with the subject “Facebook Support. Your password has been changed! ID09687″. Note that the number may change with each email.
The email is send from the spoofed addresses:
account@facebook.com
manager@facebook.com
The message has the following body:
The trojan is known as Gen:Heur.VIZ.2 (BitDefender), Mal/FakeAV-JX (Sophos), Trojan.Generic.Bredolab-2 (ClamAV).
The following files will be created:
%System%\document.doc
Several Windows registry changes will be exectued and the trojan can establish connection with the IP 193.106.34.20 on port 80.
Data can be obtained from following URLs:
Virus Total permalink and MD5: ecc2d442886b7296b5bd7eaeaae0bcea.
[ComputerSecurityArticles]
The email is send from the spoofed addresses:
account@facebook.com
manager@facebook.com
The message has the following body:
Dear user of FaceBook.The attached ZIP file has the name New_Password_IN04393.zip, note that the number at the end will change, and contains the 33 kB large file New_Password.exe.
Your password is not safe!
To secure your account the password has been changed automatically.
Attached document contains a new password to your account and detailed information about new security measures.
Thank you for your attention,
Your Facebook
The trojan is known as Gen:Heur.VIZ.2 (BitDefender), Mal/FakeAV-JX (Sophos), Trojan.Generic.Bredolab-2 (ClamAV).
The following files will be created:
%System%\document.doc
Several Windows registry changes will be exectued and the trojan can establish connection with the IP 193.106.34.20 on port 80.
Data can be obtained from following URLs:
- hxxp://profmiale.ru/TGQW4nHJOS/document.doc
- hxxp://profmiale.ru/TGQW4nHJOS/load.php?file=8
- hxxp://profmiale.ru/TGQW4nHJOS/load.php?file=9
- hxxp://profmiale.ru/TGQW4nHJOS/load.php?file=uploader
- hxxp://profmiale.ru/TGQW4nHJOS/load.php?file=grabbers
- hxxp://profmiale.ru/TGQW4nHJOS/grabbers.php
- hxxp://profmiale.ru/TGQW4nHJOS/load.php?file=0
- hxxp://profmiale.ru/TGQW4nHJOS/load.php?file=1
- hxxp://profmiale.ru/TGQW4nHJOS/load.php?file=2
- hxxp://profmiale.ru/TGQW4nHJOS/load.php?file=3
- hxxp://profmiale.ru/TGQW4nHJOS/load.php?file=4
- hxxp://profmiale.ru/TGQW4nHJOS/load.php?file=5
- hxxp://profmiale.ru/TGQW4nHJOS/load.php?file=6
- hxxp://profmiale.ru/TGQW4nHJOS/load.php?file=7
Virus Total permalink and MD5: ecc2d442886b7296b5bd7eaeaae0bcea.
[ComputerSecurityArticles]
GCHQ says BlackBerry is safest
The UK's National Technical Authority for Information Assurance at GCHQ (CESG) has published smartphone security guidance for public sector workers.
The advice published today covers various phones, including the Apple iPhone, Windows Phone 7 devices, Nokia hardware and BlackBerrys.
Four security procedures documents have been produced, outlining how to best secure any mobile deployment for UK Government departments and organisations on those platforms.
“These security procedures cover architectural issues (such as recommended network layout, recommendations for operational monitoring), configuration advice, user education and training suggestions, and information on residual risks that senior risk owners will need to take into account,” a CESG spokesperson told IT PRO.
“The publication of this risk management advice and guidance is intended to ensure all UK Government organisations have access to the information they need to take educated risk management decisions when deploying remote working solutions using smartphones.”
CESG worked with the telecoms industry to produce the report on how to secure smartphones for remote working, covering lower risk situations.
The guidance document itself was not available to the press.
CESG claimed the document will help many parts of the public sector work more efficiently and effectively, in turn saving money for the taxpayer.
As for more handling serious data, however, the GCHQ body said the only way was BlackBerry.
“The BlackBerry Enterprise Solution from Research In Motion remains the only smartphone system to have been formally evaluated by CESG and is approved to protect material classified up to and including ‘restricted,’” CESG said.
RIM was unsurprisingly buoyant about that particular comment, as a host of supporters talked about BlackBerry security credentials.
“The BlackBerry platform remains, in my opinion, the leader in this respect, providing the highest levels of assurance without the added cost or complexity of needing to bring third-party software into the equation,” said Nick McQuire, director for enterprise mobility at analyst house IDC.
BlackBerry devices are not infallible of course, as the recent Pwn2Own contest highlighted when a Torch 9800 was successfully hacked.
“The reality is that BlackBerry does have more enterprise features and controls such as remote kill, email retention, guaranteed message deliver with application and encryption controls,” said Ron Gula, chief executive (CEO) of Tenable Network Security.
“However, while this is important, a lot of it is just details, and we'll probably see some leapfrogging between the various mobile vendors as they get bitten and react.”
[ITPro]
Friday, 1 April 2011
How to Create and Remember Super-Secure Passwords
How many websites did you visit today that required a password? Probably quite a few.
Do you need a password to access data or email at work? You likely do.
In fact, you may have even needed a password to log on to the computer you’re reading this on right now.
Passwords are the front line of defense in protecting the data on your computer. They keep your kids from hijacking your Twitter account, and keep cybercriminals from gaining access to your bank account.
The problem is that because we need so many passwords today, many of us take the easy way out. We either use the same password for everything, or use very simple, easy-to-remember passwords.
And that’s where we can get into trouble.

The risks of weak or multiple-use passwords
“Let’s say you fall for a phishing attack on Facebook,” explained Beth Jones, senior threat researcher for the information-security firm SophosLabs North America. “They can see your email address and try that same password there.
“If you have sensitive information in your email, such as bank statements or credit-card statements, then the attacker can try that password to access bank accounts or credit-card accounts as well,” Jones said.
“They would have several key pieces of [personal] information… so in theory they could try the ‘forgot username’ on other accounts, such as Twitter, or online games,” she said. “You can see how this snowballs quickly.”
Not only should you have a unique password for each site you log into online, but, as Gunther Ollmann, vice president of research at the Atlanta-based computer-security firm Damballa, pointed out, you should also avoid recycling old passwords.
“Criminals — and unethical web masters — often try to use the passwords that have been taken from one site and use them against other sites, especially if your email address is also known to them,” Ollman explained.
“Each website or application you use should have a different password, and ideally you should not use a predictable algorithm for generating them,” he said. “For example, a bad practice is to use a password that contains the particular website’s name or address in it.”
How to create perfect passwords
So what makes a good, strong password?
“Password strength is measured by two characteristics — length and complexity,” said Josh Shaul, chief technology officer with New York-based Application Security, Inc. and author of Practical Oracle Security: Your Unauthorized Guide to Relational Database Security. “In general, the longer the password, the more difficult it is to guess and the stronger it is.”
Password complexity, he added, means avoiding passwords that can be easily guessed.
“The easiest passwords to remember are simple words, places, dates or easy-to-type text strings,” Shaul said. “Favorite sports teams, cities, names, birthdays and even strings like ‘12345‘ or ‘qwerty‘ are very commonly used. These are all weak passwords.”
Most experts agree on the basics of creating strong passwords. Here are some tips from the Identity Theft Resource Center:
For example, the phrase “I hate to work late” could become “iH82wkl8.”
Or tweak that formula and don’t abbreviate all the words. "This little piggy went to market" might become "tlpWENT2m."
Not sure, even after following those tips, whether your password is strong enough? Go to one of the many websites that will check it for you.
Can’t think of a good password? There are also websites that generate them.
Should you write them down?
So if we need a unique, strong password for nearly everything we do online — check multiple email accounts, use Facebook and Twitter, make comments on CNN, buy something from Amazon — how can we remember them all? Is it okay to write them down somewhere?
Several years ago, the conventional wisdom was to never write down passwords — but that was when most of us only had a few to remember.
Some experts have since changed their minds.
“With today's threat landscape being dominated by password-stealing malware, physically writing down your passwords is becoming more acceptable,” Damballa’s Ollman said.
“The probability of someone breaking into your house and stealing your written-down passwords is considerably more remote than the 1-in-3 to 1-in-4 probability that your computer will fall to a criminal’s malware,” Ollman said.
Jones of SophosLabs sticks to the old advice — don’t write them down.
“This is really not a great idea, particularly for work,” Jones said. “Physical security is just as important as online security.
“Anyone walking by could see the sticky note next to your machine and then break into your accounts (especially if you use the same password for everything),” she added. “The risk is even greater if, as a user, you log into more than one location and have your password written at all those locations.”
Web browsers often ask if they can remember your password for you. Is that safer than writing down your password?
“For some passwords, it may be okay to let the browser remember your password on your personal laptop or home PC,” said Chris Burchett, founder and chief technology officer with Addison, Texas-based information-security firm Credant.
“In general, if the information on the website that requires your password is what you consider to be public, then it may be okay to let the browser remember the password,” Burchett said. “But be careful.
Never let the browser remember passwords to banking websites or other sites where private personal identity information is used or available.”
“Also be careful when using a public-kiosk computer like the ones at the airport. Never let browsers on computers you don't own store passwords,” he added. “In fact, it would be best not to log into any website requiring a password from a computer you don't own.”
Password-management software
Instead, the experts suggest using third-party password-management software, which stores all your passwords in one place and protects them with one very strong master password — the only one you’ll have to remember.
“Managing passwords is a challenge because there are so many online accounts requiring passwords these days,” Burchett said. “Using a password manager to securely generate, store, rotate and supply passwords on demand may be worth considering as long as you remember to make the master password strong enough.”
There are dozens of password managers, both free and inexpensive (none cost more than $30). Some of the better-known ones include Web Confidential, LastPass, KeePass and its Mac/Linux sibling KeePassX. Some run on PCs, others on smartphones, while some are browser plug-ins.
As for the password managers that come with browsers, most of them aren’t very secure. Only Opera and Mozilla Firefox use master passwords, and Firefox’s is turned off by default. (Here’s how to turn it on.)
Now that you’ve read all this, do yourself a favor this weekend. Go through all your online accounts and use these tips to create strong, unique passwords for each one, and then use a password manager to remember them all.
It’ll take less time than you think. Next time a friend or relative has an email account hijacked or gets charged for dozens of iTunes songs he didn’t buy, you’ll be glad you did.
[SecurityNewsDaily]
Do you need a password to access data or email at work? You likely do.
In fact, you may have even needed a password to log on to the computer you’re reading this on right now.
Passwords are the front line of defense in protecting the data on your computer. They keep your kids from hijacking your Twitter account, and keep cybercriminals from gaining access to your bank account.
The problem is that because we need so many passwords today, many of us take the easy way out. We either use the same password for everything, or use very simple, easy-to-remember passwords.
And that’s where we can get into trouble.
The risks of weak or multiple-use passwords
“Let’s say you fall for a phishing attack on Facebook,” explained Beth Jones, senior threat researcher for the information-security firm SophosLabs North America. “They can see your email address and try that same password there.
“If you have sensitive information in your email, such as bank statements or credit-card statements, then the attacker can try that password to access bank accounts or credit-card accounts as well,” Jones said.
“They would have several key pieces of [personal] information… so in theory they could try the ‘forgot username’ on other accounts, such as Twitter, or online games,” she said. “You can see how this snowballs quickly.”
Not only should you have a unique password for each site you log into online, but, as Gunther Ollmann, vice president of research at the Atlanta-based computer-security firm Damballa, pointed out, you should also avoid recycling old passwords.
“Criminals — and unethical web masters — often try to use the passwords that have been taken from one site and use them against other sites, especially if your email address is also known to them,” Ollman explained.
“Each website or application you use should have a different password, and ideally you should not use a predictable algorithm for generating them,” he said. “For example, a bad practice is to use a password that contains the particular website’s name or address in it.”
How to create perfect passwords
So what makes a good, strong password?
“Password strength is measured by two characteristics — length and complexity,” said Josh Shaul, chief technology officer with New York-based Application Security, Inc. and author of Practical Oracle Security: Your Unauthorized Guide to Relational Database Security. “In general, the longer the password, the more difficult it is to guess and the stronger it is.”
Password complexity, he added, means avoiding passwords that can be easily guessed.
“The easiest passwords to remember are simple words, places, dates or easy-to-type text strings,” Shaul said. “Favorite sports teams, cities, names, birthdays and even strings like ‘12345‘ or ‘qwerty‘ are very commonly used. These are all weak passwords.”
Most experts agree on the basics of creating strong passwords. Here are some tips from the Identity Theft Resource Center:
- A password should contain at least eight characters (some experts say 10 or 14 characters is the minimum).
- The password should have at least three of the four following types of characters — upper-case letters (ABC), lower-case letters (abc), numerals (123), and punctuation marks or other special characters (!#$%&*_=+? ).
- If you’re using only one capital letter or special character, don’t make it the first or last character in the password.
- Avoid common names, slang words or any words in the dictionary. Computers can run through entire dictionaries in minutes.
- Don’t include any part of your name or any part of your email addresses.
- Choose an especially strong password for websites that hold especially sensitive personal information — for example, banks or online retailers that store your credit-card information.
- Don’t ever refer to anything that can be learned from your social networking profiles or an Internet search. In other words, don’t make it your favorite band or movie, your pet’s name, your nickname, your phone number or, especially, your birth date.
For example, the phrase “I hate to work late” could become “iH82wkl8.”
Or tweak that formula and don’t abbreviate all the words. "This little piggy went to market" might become "tlpWENT2m."
Not sure, even after following those tips, whether your password is strong enough? Go to one of the many websites that will check it for you.
Can’t think of a good password? There are also websites that generate them.
Should you write them down?
So if we need a unique, strong password for nearly everything we do online — check multiple email accounts, use Facebook and Twitter, make comments on CNN, buy something from Amazon — how can we remember them all? Is it okay to write them down somewhere?
Several years ago, the conventional wisdom was to never write down passwords — but that was when most of us only had a few to remember.
Some experts have since changed their minds.
“With today's threat landscape being dominated by password-stealing malware, physically writing down your passwords is becoming more acceptable,” Damballa’s Ollman said.
“The probability of someone breaking into your house and stealing your written-down passwords is considerably more remote than the 1-in-3 to 1-in-4 probability that your computer will fall to a criminal’s malware,” Ollman said.
Jones of SophosLabs sticks to the old advice — don’t write them down.
“This is really not a great idea, particularly for work,” Jones said. “Physical security is just as important as online security.
“Anyone walking by could see the sticky note next to your machine and then break into your accounts (especially if you use the same password for everything),” she added. “The risk is even greater if, as a user, you log into more than one location and have your password written at all those locations.”
Web browsers often ask if they can remember your password for you. Is that safer than writing down your password?
“For some passwords, it may be okay to let the browser remember your password on your personal laptop or home PC,” said Chris Burchett, founder and chief technology officer with Addison, Texas-based information-security firm Credant.
“In general, if the information on the website that requires your password is what you consider to be public, then it may be okay to let the browser remember the password,” Burchett said. “But be careful.
Never let the browser remember passwords to banking websites or other sites where private personal identity information is used or available.”
“Also be careful when using a public-kiosk computer like the ones at the airport. Never let browsers on computers you don't own store passwords,” he added. “In fact, it would be best not to log into any website requiring a password from a computer you don't own.”
Password-management software
Instead, the experts suggest using third-party password-management software, which stores all your passwords in one place and protects them with one very strong master password — the only one you’ll have to remember.
“Managing passwords is a challenge because there are so many online accounts requiring passwords these days,” Burchett said. “Using a password manager to securely generate, store, rotate and supply passwords on demand may be worth considering as long as you remember to make the master password strong enough.”
There are dozens of password managers, both free and inexpensive (none cost more than $30). Some of the better-known ones include Web Confidential, LastPass, KeePass and its Mac/Linux sibling KeePassX. Some run on PCs, others on smartphones, while some are browser plug-ins.
As for the password managers that come with browsers, most of them aren’t very secure. Only Opera and Mozilla Firefox use master passwords, and Firefox’s is turned off by default. (Here’s how to turn it on.)
Now that you’ve read all this, do yourself a favor this weekend. Go through all your online accounts and use these tips to create strong, unique passwords for each one, and then use a password manager to remember them all.
It’ll take less time than you think. Next time a friend or relative has an email account hijacked or gets charged for dozens of iTunes songs he didn’t buy, you’ll be glad you did.
[SecurityNewsDaily]
Under the phishing filters' radar
Email recipients opening the HTML document in their browsers are, for example, presented with a bogus PayPal form with the usual request to enter their access data due to alleged security issues. As the form is being processed locally on the user's computer, the phishing filter doesn't issue a warning because it only filters external URLs. A click on the "Submit" button then transmits the entered data to a PHP script on a (hacked) server using a POST request. According to M86Security, the browser doesn't warn about this either.
While browsers should at least warn users when sending the data, M86Security stated two potential reasons why they won't: as users don't see the URL they access via POST requests, they can't report it, and consequently the URL is missing in the browser filter's blacklist. The company added that most users can't make anything of the HTML source code that is attached to the email.
Secondly, M86Security said that URLs which lead to a PHP script are very difficult to classify as phishing sites. It is reportedly hard to identify a phishing site without the accompanying HTML code which could, for instance, reveal whether a site pretends to be a banking site. This has apparently caused months-old phishing campaigns to remain undetected. The security firm didn't state whether its assessment only refers to the filter lists maintained for Chrome, Firefox and other browsers, or whether it also includes those of the AV vendors, who maintain separate lists for their own filter products.
[H-Online]
6 Steps to Staying Safe on Social Networks
To get a good sense of why people enjoy online social networking, visit Twitter during the baseball playoffs or during a live broadcast of “American Idol.”
You might be sitting alone on your couch watching the game or the show, but you’re getting the camaraderie of being in a like-minded crowd. You can trash-talk with the person cheering for your opponent, or give a virtual high-five to your “friends.”
The fun part of using online social media is the networking and sharing. However, the dangerous part of using online social media can also be the networking and sharing.

Personal information is exchanged as if the conversation were happening in a private space. But the fact is that you’re really speaking in public.
Depending on the forum and privacy settings, large groups of people you don’t know — possibly even the entire world — might have access to your intimate conversations and off-hand remarks.
Online social media users need to guard private information to stay safe and secure in real life.
Here’s a list of “do’s” and “don’ts” for sharing personal information over social media websites or services.
1. Do take advantage of privacy settings — and encourage your friends to do the same.
A friend of mine had problems with a relative who was following her comments (and making comments of his own) on other friends’ pages, all because her friends — not she — had their sites open to everyone.
2. Don’t announce your vacation plans.
“Vacation photos are a great way to share your family fun with friends, but telling every one of your Facebook friends you’ll be in Bermuda for a week only invites real-life problems. Wait until you’ve returned home to share vacation information online,” said Sarah Carter of Actiance, a Belmont, Calif.-based communications security provider.
Another don’t: Don’t limit this advice to vacations. Practice it any time you plan to be out of the house.
3. Do accept friend requests with caution.
Only accept friend requests from people you know. If you aren’t sure, send a message to ask how you know each other or check them out on Google or Snopes.com to make sure the request isn’t a hoax.
4. Don’t include too much identifying information.
Everybody loves receiving birthday greetings, so go ahead and share the date. But adding the year you were born — along with your full home address, phone numbers and other personal info — gives criminals enough details about you to steal your identity.
5. Do ask questions before clicking a link.
A lot of malware shows up through random links or via status updates on social-media sites. If you aren’t sure about the link, especially if it is a shortened URL, ask the sender if it is legitimate.
6. Don’t automatically trust everyone.
When seeking out victims, criminals often take advantage of the trust levels in social media. They post scams — a popular one is to ask people to send money because the poster is stranded in London. They also disguise themselves as potential friends — “you don’t know me, but we follow the same famous movie star and have lots in common!” — among other devious acts.
[SecurityNewsDaily]
You might be sitting alone on your couch watching the game or the show, but you’re getting the camaraderie of being in a like-minded crowd. You can trash-talk with the person cheering for your opponent, or give a virtual high-five to your “friends.”
The fun part of using online social media is the networking and sharing. However, the dangerous part of using online social media can also be the networking and sharing.
Personal information is exchanged as if the conversation were happening in a private space. But the fact is that you’re really speaking in public.
Depending on the forum and privacy settings, large groups of people you don’t know — possibly even the entire world — might have access to your intimate conversations and off-hand remarks.
Online social media users need to guard private information to stay safe and secure in real life.
Here’s a list of “do’s” and “don’ts” for sharing personal information over social media websites or services.
1. Do take advantage of privacy settings — and encourage your friends to do the same.
A friend of mine had problems with a relative who was following her comments (and making comments of his own) on other friends’ pages, all because her friends — not she — had their sites open to everyone.
2. Don’t announce your vacation plans.
“Vacation photos are a great way to share your family fun with friends, but telling every one of your Facebook friends you’ll be in Bermuda for a week only invites real-life problems. Wait until you’ve returned home to share vacation information online,” said Sarah Carter of Actiance, a Belmont, Calif.-based communications security provider.
Another don’t: Don’t limit this advice to vacations. Practice it any time you plan to be out of the house.
3. Do accept friend requests with caution.
Only accept friend requests from people you know. If you aren’t sure, send a message to ask how you know each other or check them out on Google or Snopes.com to make sure the request isn’t a hoax.
4. Don’t include too much identifying information.
Everybody loves receiving birthday greetings, so go ahead and share the date. But adding the year you were born — along with your full home address, phone numbers and other personal info — gives criminals enough details about you to steal your identity.
5. Do ask questions before clicking a link.
A lot of malware shows up through random links or via status updates on social-media sites. If you aren’t sure about the link, especially if it is a shortened URL, ask the sender if it is legitimate.
6. Don’t automatically trust everyone.
When seeking out victims, criminals often take advantage of the trust levels in social media. They post scams — a popular one is to ask people to send money because the poster is stranded in London. They also disguise themselves as potential friends — “you don’t know me, but we follow the same famous movie star and have lots in common!” — among other devious acts.
[SecurityNewsDaily]
Labels:
Facebook,
information,
likejacking,
links,
privacy,
security,
social networks,
Twitter
Move to criminalise cyber-stalking
More than 80 MPs are calling for an overhaul of stalking laws in a move that could see cyber-stalking made an offence.
The MPs, from all parties, also want police to prioritise complaints of stalking and say the crime needs to be defined in law.
Statistics released by probation union Napo, ahead of a seminar at the Houses of Parliament, show that just 2.2% of all incidences of harassment recorded by police ended in a jail sentence.
Napo said that in 2009 there were 53,000 offences of harassment recorded by police, leading to 6,581 convictions. Out of those convicted, 18.5% were jailed, the union said.
The latest figures from the British Crime Survey showed that up to five million people experienced stalking or harassment every year.
A Napo spokesman said: "It is clear therefore that a very small proportion actually reach court and even fewer receive a custodial sentence."
He added: "The sentencing guidelines need to be reviewed as a matter of urgency. Many victims report that complaints are not investigated thoroughly by the police and prosecutors."
Elfyn Llwyd, Plaid Cymru's Parliamentary Leader, is chairing the Justice Unions' Parliamentary Group seminar. Speakers will include Carol Faruqui and Tricia Bernal, who founded Protection Against Stalking after their daughters were killed. The charity's director of operations Laura Richards will also speak at the event to give guidance to MPs whose constituents are being stalked.
The Napo spokesman said stalking is a "life-changing" event in victims' lives, and added: "Stalking is not defined in law, only harassment is. The police have limited powers to enter and search premises of arrested stalkers. Cyber-stalking, which is now common, is not covered by the Protection from Harassment Act 1997."
A leaflet offering advice to MPs on the subject of stalking, both in person and over the internet, will be launched at the event.
[London Evening Standard]
Friday, 25 March 2011
Password Security - The Only Secure Password Is the One You Can’t Remember
Let's assume you log onto a bunch of different websites; Facebook, Gmail, eBay, PayPal, probably some banking, maybe a few discussion forums, and probably much, much more. Consider a couple of questions:
Let me help demonstrate the problem; I'll show you what happens when you reuse or create weak passwords based on some real world examples which should really hit home. I'll also show you how to overcome these problems with a good password manager so it's not all bad news, unless you're trying to remember your passwords.
The tyranny of multiple accounts
Think about it; how many accounts do you have out there on the internet? 10? 20? 50? I identified 90 of mine recently and there are many more I've simply forgotten about. There is absolutely no way, even with only 10 accounts, you can create passwords that are strong, unique and memorable.
What happens is that people revert to patterns including family names, pets, hobbies and all sorts of natural, somewhat predictable criteria. Patterns are a double-edged sword in that whilst they're memorable, they also predictable so even if the pattern might seem obscure, once it's known, well, you've got a bit of a problem.
Patterns and predictable words are bad, but what's even worse is password reuse. Because we simply end up with so many of the damn things, the problem of memorising them gets addressed by being repetitive. Easy? Yes. Secure? No way.
Continue reading the full article: http://lifehacker.com/#!5785420/the-only-secure-password-is-the-one-you-cant-remember
[Lifehacker]
- Do you always create unique passwords such that you never use the same one twice? Ever?
- Do your passwords always use different character types such as uppercase and lowercase letters, numbers and punctuation? Are they "strong"?
If you can't answer "yes" to both these questions, you've got yourself a problem. But the thing is, there is simply no way you can remember all your unique, strong passwords and the sooner you recognize this, the sooner you can embrace a more secure alternative.
Let me help demonstrate the problem; I'll show you what happens when you reuse or create weak passwords based on some real world examples which should really hit home. I'll also show you how to overcome these problems with a good password manager so it's not all bad news, unless you're trying to remember your passwords.
The tyranny of multiple accounts
Think about it; how many accounts do you have out there on the internet? 10? 20? 50? I identified 90 of mine recently and there are many more I've simply forgotten about. There is absolutely no way, even with only 10 accounts, you can create passwords that are strong, unique and memorable.
What happens is that people revert to patterns including family names, pets, hobbies and all sorts of natural, somewhat predictable criteria. Patterns are a double-edged sword in that whilst they're memorable, they also predictable so even if the pattern might seem obscure, once it's known, well, you've got a bit of a problem.
Patterns and predictable words are bad, but what's even worse is password reuse. Because we simply end up with so many of the damn things, the problem of memorising them gets addressed by being repetitive. Easy? Yes. Secure? No way.
Continue reading the full article: http://lifehacker.com/#!5785420/the-only-secure-password-is-the-one-you-cant-remember
[Lifehacker]
Thursday, 24 March 2011
Mobile Phones are Being Hacked and Cloned
Cloning occurs when hackers scan the airwaves to obtain SIM card information, electronic serial numbers and mobile identification numbers, and then using that data on other phones.
Cloning can happen anywhere, anytime that you’re using your phone. The bad guy simply uses an interceptor, hardware, and software to make a phone exactly like yours.
A few years ago, I was in San Diego on business. Two weeks later I received a call from my carrier alerting me to $1500.00 worth of international calls I had not made. The activity triggered an alert within their system and they shut my account down.
Fortunately for me, my carrier recognized the fraud and relieved me of the charges, rather than me discovering it and having to fight to reverse the charges. Apparently, it was a known issue that scammers in Tijuana were cloning U.S.-based phones.
Anita Davis, another mobile clone victim, wasn’t so lucky. One month, her cell phone bill showed $3,151 worth of calls in one month, to Pakistan, Israel, Jordan, Africa, and other countries.
Anita called her carrier immediately and told them she didn’t know anyone in those countries, or anyone outside the U.S. for that matter.
She says, “They told me I had to have directly dialed these numbers from my cell phone and I needed to make a payment arrangement or they would send my bill to collections.”
After begging and pleading, Anita convinced them to drop the charges.
The extent of your vulnerability varies depending on your phone and the network you’re on. Cloning mobile phones is becoming increasingly difficult, but consumers can’t do anything to prevent it from happening.
The best way to mitigate the damage is to watch your statements closely. The moment you see an uptick in charges, contact your carrier and dispute the calls.
Robert Siciliano, personal security expert contributor to Just Ask Gemalto, discusses mobile phone spyware on Good Morning America. (Disclosures)
[InfoSecIsland]
Cloning can happen anywhere, anytime that you’re using your phone. The bad guy simply uses an interceptor, hardware, and software to make a phone exactly like yours.
A few years ago, I was in San Diego on business. Two weeks later I received a call from my carrier alerting me to $1500.00 worth of international calls I had not made. The activity triggered an alert within their system and they shut my account down.
Fortunately for me, my carrier recognized the fraud and relieved me of the charges, rather than me discovering it and having to fight to reverse the charges. Apparently, it was a known issue that scammers in Tijuana were cloning U.S.-based phones.
Anita Davis, another mobile clone victim, wasn’t so lucky. One month, her cell phone bill showed $3,151 worth of calls in one month, to Pakistan, Israel, Jordan, Africa, and other countries.
Anita called her carrier immediately and told them she didn’t know anyone in those countries, or anyone outside the U.S. for that matter.
She says, “They told me I had to have directly dialed these numbers from my cell phone and I needed to make a payment arrangement or they would send my bill to collections.”
After begging and pleading, Anita convinced them to drop the charges.
The extent of your vulnerability varies depending on your phone and the network you’re on. Cloning mobile phones is becoming increasingly difficult, but consumers can’t do anything to prevent it from happening.
The best way to mitigate the damage is to watch your statements closely. The moment you see an uptick in charges, contact your carrier and dispute the calls.
Robert Siciliano, personal security expert contributor to Just Ask Gemalto, discusses mobile phone spyware on Good Morning America. (Disclosures)
[InfoSecIsland]
TripAdvisor member database breached, part of it stolen
According to Tom Mollerus, TripAdvisor has been contacting its users and notifying them of a breach.
"This past weekend we discovered that an unauthorized third party had stolen part of TripAdvisor's member email list. We've confirmed the source of the vulnerability and shut it down," says Steve Kaufer, co-founder and CEO of TripAdvisor, in the email.
"How will this affect you? In many cases, it won't. Only a portion of all member email addresses were taken, and all member passwords remain secure. You may receive some unsolicited emails (spam) as a result of this incident."
He also made sure to point out that the site does not collect members' credit card or financial information, and that it would never sell or rent its member list.
Information about the incident has already been shared with law enforcement, and an investigations into the breach is ongoing.
Lock Down Your Life: How to Secure Your Home, Auto and Smartphone
The more sophisticated technology gets, the more sophisticated the criminals get.
Because of that, protecting yourself and your family these days involves a lot more than just making sure the front door is locked and that you haven't left the keys in the car.
Smartphone owners, for example, are increasingly the target of the same sorts of attacks and scams — many of which can result in identity theft — that have been plaguing computer users for years.
Users of Android-based phones users recently learned that more than 50 malicious apps had been uploaded to the Android Market app store, and then installed on roughly 260,000 phones within a few days.
(Google yanked the apps from the Android Market, then used its “kill switch” to remotely remove the installed apps from users’ phones; Apple has a similar “kill switch” for iPhones and iPads.)
Landlines can also be hit by scams, such as the call-forwarding *72 attack in which a stranger tricks the victim into forwarding all incoming calls to another number — and then proceeds to rack up charges on the account.
Even cars, which have security systems built into nearly all new models, continue to be a major target. According to the National Insurance Crime Bureau, a vehicle is stolen every 33 seconds in the United States.
And, of course, home break-ins continue. The FBI reports that in 2009, the most recent year with confirmed data, there were 2.2 million burglaries in the U.S., costing victims an estimated $4.6 billion in lost property.
So how can you protect yourself from scams and break-ins?
In addition to writing down the vehicle-identification number of your car and serial numbers for expensive equipment, such as a flat-screen TV or computer, there are several ways to protect everything from your phone to your home using some relatively simple technology.
Smartphones: For your smartphone, first make sure you've enabled password protection. Then consider a "lost phone" tracking app, as well as anti-virus/malware software.
There are several on the market, including one from Lookout Mobile Security. A free version is available for Android and Blackberry phones, and it includes a lost/stolen-phone location service and virus scanning. If you can't get your phone back, it will also remotely wipe your personal info from the device.
Credit: Lookout, Inc.
A premium version, for $29.99 a year, includes privacy tracking and protection.
Vehicles: Car and truck owners can also take advantage of GPS tracking and warning devices. For GM owners, there's the OnStar service, but any car can be outfitted with similar security and tracking features.
LoJack has an Early Warning Package for $995 (installed). If your car is moved, the LoJack network can send a phone, email or text message alert.
Credit: Lojack
However, LoJack is available only in 29 states. For nationwide coverage, there's the Escort EntourageCIS, $400, plus $60 for installation and a $180-a-year subscription.
Credit: Escort, Inc.
Like LoJack, the EntourageCIS can warn a driver via email, text or phone message if a car is moved. More important, if your car is stolen and you don’t respond to alerts, a 24-hour monitoring station will contact local law enforcement and send them after the thieves.
Home: As the summer approaches and more home owners leave for long vacations, alarms and monitoring services can be useful. As an alternative to calling in a professional (and paying monthly fees), you now have the option of installing your own cameras and monitoring equipment.
Among the raft of do-it-yourself equipment now available is the $300 Logitech Alert 750i Master System. The video-based monitoring system can be installed in about 30 minutes and uses a home's electrical circuits to connect to a home network and the Internet.
Credit: Logitech
Using a Web browser, owners can log in any time for free to see and hear what's going on back home, or they can have email alerts sent to them whenever motion is detected.
Some people may find all this monitoring and scanning technology brings with it a touch of paranoia.
But, if you're ever the victim of a burglary or lose your phone, you won't seem so paranoid any more.
[SecurityNewsDaily]
Because of that, protecting yourself and your family these days involves a lot more than just making sure the front door is locked and that you haven't left the keys in the car.
Smartphone owners, for example, are increasingly the target of the same sorts of attacks and scams — many of which can result in identity theft — that have been plaguing computer users for years.
Users of Android-based phones users recently learned that more than 50 malicious apps had been uploaded to the Android Market app store, and then installed on roughly 260,000 phones within a few days.
(Google yanked the apps from the Android Market, then used its “kill switch” to remotely remove the installed apps from users’ phones; Apple has a similar “kill switch” for iPhones and iPads.)
Landlines can also be hit by scams, such as the call-forwarding *72 attack in which a stranger tricks the victim into forwarding all incoming calls to another number — and then proceeds to rack up charges on the account.
Even cars, which have security systems built into nearly all new models, continue to be a major target. According to the National Insurance Crime Bureau, a vehicle is stolen every 33 seconds in the United States.
And, of course, home break-ins continue. The FBI reports that in 2009, the most recent year with confirmed data, there were 2.2 million burglaries in the U.S., costing victims an estimated $4.6 billion in lost property.
So how can you protect yourself from scams and break-ins?
In addition to writing down the vehicle-identification number of your car and serial numbers for expensive equipment, such as a flat-screen TV or computer, there are several ways to protect everything from your phone to your home using some relatively simple technology.
Smartphones: For your smartphone, first make sure you've enabled password protection. Then consider a "lost phone" tracking app, as well as anti-virus/malware software.
There are several on the market, including one from Lookout Mobile Security. A free version is available for Android and Blackberry phones, and it includes a lost/stolen-phone location service and virus scanning. If you can't get your phone back, it will also remotely wipe your personal info from the device.
A premium version, for $29.99 a year, includes privacy tracking and protection.
Vehicles: Car and truck owners can also take advantage of GPS tracking and warning devices. For GM owners, there's the OnStar service, but any car can be outfitted with similar security and tracking features.
LoJack has an Early Warning Package for $995 (installed). If your car is moved, the LoJack network can send a phone, email or text message alert.
However, LoJack is available only in 29 states. For nationwide coverage, there's the Escort EntourageCIS, $400, plus $60 for installation and a $180-a-year subscription.
Like LoJack, the EntourageCIS can warn a driver via email, text or phone message if a car is moved. More important, if your car is stolen and you don’t respond to alerts, a 24-hour monitoring station will contact local law enforcement and send them after the thieves.
Home: As the summer approaches and more home owners leave for long vacations, alarms and monitoring services can be useful. As an alternative to calling in a professional (and paying monthly fees), you now have the option of installing your own cameras and monitoring equipment.
Among the raft of do-it-yourself equipment now available is the $300 Logitech Alert 750i Master System. The video-based monitoring system can be installed in about 30 minutes and uses a home's electrical circuits to connect to a home network and the Internet.
Using a Web browser, owners can log in any time for free to see and hear what's going on back home, or they can have email alerts sent to them whenever motion is detected.
Some people may find all this monitoring and scanning technology brings with it a touch of paranoia.
But, if you're ever the victim of a burglary or lose your phone, you won't seem so paranoid any more.
[SecurityNewsDaily]
Play.com customers receiving malicious emails, Silverpop blamed
"On Sunday the 20th of March some customers reported receiving a spam email to email addresses they only use for Play.com," said John Perkins, Play.com CEO, in a statement issued yesterday. "We reacted immediately by informing all our customers of this potential security breach in order for them to take the necessary precautionary steps.
He also identified the third-party marketing company that handles their communications: it's Silverpop. As you might remember, the compromise of Silverpop's systems has brought about problems to McDonald's, deviantArt's and Walgreens' customers.
"We believe this issue may be related to some irregular activity that was identified in December 2010 at our email service provider, Silverpop," Perkins revealed.
When the Silverpop breach was first revealed, I believed that it would be a good idea for all Silverpop Systems clients - and there are many! - to warn their customers about the possibility of being on the receiving end of malicious spam, and now it seems that I was right.
The only thing that's bothering me is the fact that email addresses belonging to Play.com customers were misused only now - three months after the Silverpop breach was made public. Why did the spammers wait so long?
"Investigations at the time showed no evidence that any of our customer email addresses had been downloaded," said Perkins. Could it be that Play.com's mailing list was stolen in a second breach that happened more recently?
Second hand phones contain extensive personal data
People are unsuspectingly selling their personal information to complete strangers as a new report from CPP finds half (54%) of second hand mobile phones contain extensive personal data.

Second hand mobile phones and SIM cards purchased on eBay and used electronics shops by CPP were examined in a live experiment to see what personal information was available on the handsets and whether it constituted a threat to their former owners' identities.
The experiment revealed 247 pieces of personal data that had been carelessly left on a range of mobile phones and SIM cards. The personal data included credit and debit card PIN numbers, bank account details, passwords, phone numbers, company information and log in details to social networking sites like Facebook and LinkedIn.
In research that supported the experiment, half of second hand mobile owners said they have found personal information from a previous owner on mobile phones and SIM cards they have purchased second hand.
Worryingly, the vast majority (81 per cent) of people claim to have wiped their mobiles before selling them, with six in ten confident they have removed all of their personal information from them. However, the experiment revealed that 54 per cent of mobile phones and SIM cards contained sensitive personal information putting people at unnecessary risk of identity and card fraud.
The variance could be explained by the fact that most people who claimed to have 'wiped' their handsets tried to erase the data manually – a process that security experts acknowledge leaves the data intact and retrievable.
And it seems personal information comes cheap with individuals selling their old handsets and SIMs for an average price of 47 pounds Sterling.
As people rely heavily on their mobile phones to store personal data such as e-mail addresses, social networking log in details, banks account details and even debit and credit card PIN numbers, CPP is calling on people to make sure they remove all of their personal and financial information from their mobile phones and undertake adequate security measures to protect themselves from identity theft.
Senior Vice President of CRYPTOCard Jason Hart said: "The safest way to remove all of your data from a mobile phone or SIM card is to totally destroy the SIM and double check to ensure that all content has been removed from your phone before disposal. With new technology does come new risks and our experiment found that newer smartphones have more capabilities to store information and that information is much easier to recover than on traditional mobiles due to the increase of applications."
[Net-Security]
Second hand mobile phones and SIM cards purchased on eBay and used electronics shops by CPP were examined in a live experiment to see what personal information was available on the handsets and whether it constituted a threat to their former owners' identities.
The experiment revealed 247 pieces of personal data that had been carelessly left on a range of mobile phones and SIM cards. The personal data included credit and debit card PIN numbers, bank account details, passwords, phone numbers, company information and log in details to social networking sites like Facebook and LinkedIn.
In research that supported the experiment, half of second hand mobile owners said they have found personal information from a previous owner on mobile phones and SIM cards they have purchased second hand.
Worryingly, the vast majority (81 per cent) of people claim to have wiped their mobiles before selling them, with six in ten confident they have removed all of their personal information from them. However, the experiment revealed that 54 per cent of mobile phones and SIM cards contained sensitive personal information putting people at unnecessary risk of identity and card fraud.
The variance could be explained by the fact that most people who claimed to have 'wiped' their handsets tried to erase the data manually – a process that security experts acknowledge leaves the data intact and retrievable.
And it seems personal information comes cheap with individuals selling their old handsets and SIMs for an average price of 47 pounds Sterling.
As people rely heavily on their mobile phones to store personal data such as e-mail addresses, social networking log in details, banks account details and even debit and credit card PIN numbers, CPP is calling on people to make sure they remove all of their personal and financial information from their mobile phones and undertake adequate security measures to protect themselves from identity theft.
Senior Vice President of CRYPTOCard Jason Hart said: "The safest way to remove all of your data from a mobile phone or SIM card is to totally destroy the SIM and double check to ensure that all content has been removed from your phone before disposal. With new technology does come new risks and our experiment found that newer smartphones have more capabilities to store information and that information is much easier to recover than on traditional mobiles due to the increase of applications."
[Net-Security]
Wednesday, 23 March 2011
Most users unaware of smartphone security risks
Consumers are indifferent to the many serious security risks associated with the storage and transmission of sensitive personal data on iPhone, Blackberry and Android devices, according to The Ponemon Institute.

Following are three of the most alarming results of the survey:

"The findings of this study signal what could be an overlooked security risk for organizations created by employees' use of smartphones. Because consumers in our study report that they often use smartphones interchangeably for business and personal, organizations should make sure their security policies include guidelines for the appropriate use of smartphones that are used for company purposes," said Dr. Larry Ponemon, chairman and founder of Ponemon Institute.
According to the study, 28 percent of respondents were unaware that using their smartphone for business and personal reasons can put business information at risk.
[Net-Security]
Following are three of the most alarming results of the survey:
- 89 percent of respondents were unaware that smartphone applications can transmit confidential payment information such as credit card details without the user’s knowledge or consent.
- 91 percent of respondents were unaware that financial applications for smartphones can be infected with specialized malware designed to steal credit card numbers and online banking credentials, yet nearly a third (29 percent) report already storing credit and debit card information on their devices and 35 percent report storing “confidential” work related documents as well.
- 56 percent of respondents did not know that failing to properly log off from a social network app could allow an imposter to post malicious details or change personal settings without their knowledge. Of those aware, 37 percent were unsure whether or not their profiles had already been manipulated.
"The findings of this study signal what could be an overlooked security risk for organizations created by employees' use of smartphones. Because consumers in our study report that they often use smartphones interchangeably for business and personal, organizations should make sure their security policies include guidelines for the appropriate use of smartphones that are used for company purposes," said Dr. Larry Ponemon, chairman and founder of Ponemon Institute.
According to the study, 28 percent of respondents were unaware that using their smartphone for business and personal reasons can put business information at risk.
[Net-Security]
Mac OS X 10.6.7 fixes security vulnerabilities
Apple today released Mac OS X 10.6.7 which increases the stability, compatibility, and security of your Mac.

AirPort
A divide by zero issue existed in the handling of Wi-Fi frames. When connected to Wi-Fi, an attacker on the same network may be able to cause a system reset. This issue does not affect systems prior to Mac OS X v10.6.
Apache
Apache is updated to version 2.2.17 to address several vulnerabilities, the most serious of which may lead to a denial of service.
AppleScript
A format string issue existed in AppleScript Studio's generic dialog commands ("display dialog" and "display alert"). Running an AppleScript Studio-based application that allows untrusted input to be passed to a dialog may lead to an unexpected application termination or arbitrary code execution.
ATS
A heap buffer overflow issue existed in the handling of OpenType, TrueType and Type 1 fonts. Viewing or downloading a document containing a maliciously crafted embedded font may lead to arbitrary code execution.
Multiple buffer overflow issues existed in the handling of SFNT tables. Viewing or downloading a document containing a maliciously crafted embedded font may lead to arbitrary code execution.
bzip2
An integer overflow issue existed in bzip2's handling of bzip2 compressed files. Using the command line bzip2 or bunzip2 tool to decompress a bzip2 file may result in an unexpected application termination or arbitrary code execution.
CarbonCore
When used with the kTemporaryFolderType flag, the FSFindFolder() API returns a directory that is world readable. This issue is addressed by returning a directory that is only readable by the user that the process is running as.
ClamAV
Multiple vulnerabilities exist in ClamAV, the most serious of which may lead to arbitrary code execution. This update addresses the issues by updating ClamAV to version 0.96.5. ClamAV is distributed only with Mac OS X Server systems.
CoreText
A memory corruption issue existed in CoreText's handling of font files. Viewing or downloading a document containing a maliciously crafted embedded font may lead to arbitrary code execution.
File Quarantine
The OSX.OpinionSpy definition has been added to the malware check within File Quarantine.
HFS
An integer overflow issue existed in the handling of the F_READBOOTSTRAP ioctl. A local user may be able to read arbitrary files from an HFS, HFS+, or HFS+J filesystem.
ImageIO
A heap buffer overflow issue existed in ImageIO's handling of JPEG and XBM images. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution.
A buffer overflow existed in libTIFF's handling of JPEG encoded TIFF images and CCITT Group 4 encoded TIFF images. Viewing a maliciously crafted TIFF image may result in an unexpected application termination or arbitrary code execution.
An integer overflow issue existed in ImageIO's handling of JPEG-encoded TIFF images. Viewing a maliciously crafted TIFF image may result in an unexpected application termination or arbitrary code execution. This issue does not affect systems prior to Mac OS X v10.6.
Image RAW
Multiple buffer overflow issues existed in Image RAW's handling of Canon RAW images. Viewing a maliciously crafted Canon RAW image may result in an unexpected application termination or arbitrary code execution.
Installer
A URL processing issue in Install Helper may lead to the installation of an agent that contacts an arbitrary server when the user logs in. The dialog resulting from a connection failure may lead the user to believe that the connection was attempted with Apple. This issue is addressed by removing Install Helper.
Kerberos
Multiple cryptographic issues existed in MIT Kerberos 5. Only CVE-2010-1323 affects Mac OS X v10.5.
Kernel
A privilege checking issue existed in the i386_set_ldt system call's handling of call gates. A local user may be able to execute arbitrary code with system privileges. This issue is addressed by disallowing creation of call gate entries via i386_set_ldt().
Libinfo
An integer truncation issue existed in Libinfo's handling of NFS RPC packets. A remote attacker may be able to cause NFS RPC services such as lockd, statd, mountd, and portmap to become unresponsive.
libxml
A memory corruption issue existed in libxml's XPath handling. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution.
A double free issue existed in libxml's handling of XPath expressions. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This issue does not affect systems prior to Mac OS X v10.6.
Mailman
Multiple cross-site scripting issues existed in Mailman 2.1.13. These issues are addressed by updating Mailman to version 2.1.14.
PHP
PHP is updated to version 5.3.4 to address multiple vulnerabilities, the most serious of which may lead to arbitrary code execution.
PHP is updated to version 5.2.15 to address multiple vulnerabilities, the most serious of which may lead to arbitary code execution.
QuickLook
A memory corruption issue existed in QuickLook's handling of Excel files. Downloading a maliciously crafted Excel file may lead to an unexpected application termination or arbitrary code execution. This issue does not affect systems prior to Mac OS X v10.6.
A memory corruption issue existed in QuickLook's handling of Microsoft Office files. Downloading a maliciously crafted Microsoft Office file may lead to an unexpected application termination or arbitrary code execution.
QuickTime
Multiple memory corruption issues existed in QuickTime's handling of JPEG2000 images. Viewing a maliciously crafted JPEG2000 image with QuickTime may lead to an unexpected application termination or arbitrary code execution.
An integer overflow existed in QuickTime's handling of movie files. Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution. For Mac OS X v10.5 this issue was addressed in QuickTime 7.6.9.
A memory corruption issue existed in QuickTime's handling of FlashPix images. Viewing a maliciously crafted FlashPix image may lead to an unexpected application termination or arbitrary code execution. For Mac OS X v10.5 this issue was addressed in QuickTime 7.6.9.
A cross-origin issue existed in QuickTime plug-in's handling of cross-site redirects. Visiting a maliciously crafted website may lead to the disclosure of video data from another site. This issue is addressed by preventing QuickTime from following cross-site redirects.
A memory corruption issue existed in QuickTime's handling of panorama atoms in QTVR (QuickTime Virtual Reality) movie files. Viewing a maliciously crafted QTVR movie file may lead to an unexpected application termination or arbitrary code execution. For Mac OS X v10.5 this issue was addressed in QuickTime 7.6.9.
Ruby
An integer truncation issue existed in Ruby's BigDecimal class. Running a Ruby script that uses untrusted input to create a BigDecimal object may lead to an unexpected application termination or arbitrary code execution. This issue only affects 64-bit Ruby processes.
Samba
A stack buffer overflow existed in Samba's handling of Windows Security IDs. If SMB file sharing is enabled, a remote attacker may cause a denial of service or arbitrary code execution.
Subversion
Subversion servers that use the non-default "SVNPathAuthz short_circuit" mod_dav_svn configuration setting may allow unauthorized users to access portions of the repository. This issue is addressed by updating Subversion to version 1.6.13. This issue does not affect systems prior to Mac OS X v10.6.
Terminal
When ssh is used in Terminal's "New Remote Connection" dialog, SSH version 1 is selected as the default protocol version. This issue is addressed by changing the default protocol version to "Automatic". This issue does not affect systems prior to Mac OS X v10.6.
X11
Multiple vulnerabilities existed in FreeType, the most serious of which may lead to arbitrary code execution when processing a maliciously crafted font. These issues are addressed by updating FreeType to version 2.4.3.
AirPort
A divide by zero issue existed in the handling of Wi-Fi frames. When connected to Wi-Fi, an attacker on the same network may be able to cause a system reset. This issue does not affect systems prior to Mac OS X v10.6.
Apache
Apache is updated to version 2.2.17 to address several vulnerabilities, the most serious of which may lead to a denial of service.
AppleScript
A format string issue existed in AppleScript Studio's generic dialog commands ("display dialog" and "display alert"). Running an AppleScript Studio-based application that allows untrusted input to be passed to a dialog may lead to an unexpected application termination or arbitrary code execution.
ATS
A heap buffer overflow issue existed in the handling of OpenType, TrueType and Type 1 fonts. Viewing or downloading a document containing a maliciously crafted embedded font may lead to arbitrary code execution.
Multiple buffer overflow issues existed in the handling of SFNT tables. Viewing or downloading a document containing a maliciously crafted embedded font may lead to arbitrary code execution.
bzip2
An integer overflow issue existed in bzip2's handling of bzip2 compressed files. Using the command line bzip2 or bunzip2 tool to decompress a bzip2 file may result in an unexpected application termination or arbitrary code execution.
CarbonCore
When used with the kTemporaryFolderType flag, the FSFindFolder() API returns a directory that is world readable. This issue is addressed by returning a directory that is only readable by the user that the process is running as.
ClamAV
Multiple vulnerabilities exist in ClamAV, the most serious of which may lead to arbitrary code execution. This update addresses the issues by updating ClamAV to version 0.96.5. ClamAV is distributed only with Mac OS X Server systems.
CoreText
A memory corruption issue existed in CoreText's handling of font files. Viewing or downloading a document containing a maliciously crafted embedded font may lead to arbitrary code execution.
File Quarantine
The OSX.OpinionSpy definition has been added to the malware check within File Quarantine.
HFS
An integer overflow issue existed in the handling of the F_READBOOTSTRAP ioctl. A local user may be able to read arbitrary files from an HFS, HFS+, or HFS+J filesystem.
ImageIO
A heap buffer overflow issue existed in ImageIO's handling of JPEG and XBM images. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution.
A buffer overflow existed in libTIFF's handling of JPEG encoded TIFF images and CCITT Group 4 encoded TIFF images. Viewing a maliciously crafted TIFF image may result in an unexpected application termination or arbitrary code execution.
An integer overflow issue existed in ImageIO's handling of JPEG-encoded TIFF images. Viewing a maliciously crafted TIFF image may result in an unexpected application termination or arbitrary code execution. This issue does not affect systems prior to Mac OS X v10.6.
Image RAW
Multiple buffer overflow issues existed in Image RAW's handling of Canon RAW images. Viewing a maliciously crafted Canon RAW image may result in an unexpected application termination or arbitrary code execution.
Installer
A URL processing issue in Install Helper may lead to the installation of an agent that contacts an arbitrary server when the user logs in. The dialog resulting from a connection failure may lead the user to believe that the connection was attempted with Apple. This issue is addressed by removing Install Helper.
Kerberos
Multiple cryptographic issues existed in MIT Kerberos 5. Only CVE-2010-1323 affects Mac OS X v10.5.
Kernel
A privilege checking issue existed in the i386_set_ldt system call's handling of call gates. A local user may be able to execute arbitrary code with system privileges. This issue is addressed by disallowing creation of call gate entries via i386_set_ldt().
Libinfo
An integer truncation issue existed in Libinfo's handling of NFS RPC packets. A remote attacker may be able to cause NFS RPC services such as lockd, statd, mountd, and portmap to become unresponsive.
libxml
A memory corruption issue existed in libxml's XPath handling. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution.
A double free issue existed in libxml's handling of XPath expressions. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This issue does not affect systems prior to Mac OS X v10.6.
Mailman
Multiple cross-site scripting issues existed in Mailman 2.1.13. These issues are addressed by updating Mailman to version 2.1.14.
PHP
PHP is updated to version 5.3.4 to address multiple vulnerabilities, the most serious of which may lead to arbitrary code execution.
PHP is updated to version 5.2.15 to address multiple vulnerabilities, the most serious of which may lead to arbitary code execution.
QuickLook
A memory corruption issue existed in QuickLook's handling of Excel files. Downloading a maliciously crafted Excel file may lead to an unexpected application termination or arbitrary code execution. This issue does not affect systems prior to Mac OS X v10.6.
A memory corruption issue existed in QuickLook's handling of Microsoft Office files. Downloading a maliciously crafted Microsoft Office file may lead to an unexpected application termination or arbitrary code execution.
QuickTime
Multiple memory corruption issues existed in QuickTime's handling of JPEG2000 images. Viewing a maliciously crafted JPEG2000 image with QuickTime may lead to an unexpected application termination or arbitrary code execution.
An integer overflow existed in QuickTime's handling of movie files. Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution. For Mac OS X v10.5 this issue was addressed in QuickTime 7.6.9.
A memory corruption issue existed in QuickTime's handling of FlashPix images. Viewing a maliciously crafted FlashPix image may lead to an unexpected application termination or arbitrary code execution. For Mac OS X v10.5 this issue was addressed in QuickTime 7.6.9.
A cross-origin issue existed in QuickTime plug-in's handling of cross-site redirects. Visiting a maliciously crafted website may lead to the disclosure of video data from another site. This issue is addressed by preventing QuickTime from following cross-site redirects.
A memory corruption issue existed in QuickTime's handling of panorama atoms in QTVR (QuickTime Virtual Reality) movie files. Viewing a maliciously crafted QTVR movie file may lead to an unexpected application termination or arbitrary code execution. For Mac OS X v10.5 this issue was addressed in QuickTime 7.6.9.
Ruby
An integer truncation issue existed in Ruby's BigDecimal class. Running a Ruby script that uses untrusted input to create a BigDecimal object may lead to an unexpected application termination or arbitrary code execution. This issue only affects 64-bit Ruby processes.
Samba
A stack buffer overflow existed in Samba's handling of Windows Security IDs. If SMB file sharing is enabled, a remote attacker may cause a denial of service or arbitrary code execution.
Subversion
Subversion servers that use the non-default "SVNPathAuthz short_circuit" mod_dav_svn configuration setting may allow unauthorized users to access portions of the repository. This issue is addressed by updating Subversion to version 1.6.13. This issue does not affect systems prior to Mac OS X v10.6.
Terminal
When ssh is used in Terminal's "New Remote Connection" dialog, SSH version 1 is selected as the default protocol version. This issue is addressed by changing the default protocol version to "Automatic". This issue does not affect systems prior to Mac OS X v10.6.
X11
Multiple vulnerabilities existed in FreeType, the most serious of which may lead to arbitrary code execution when processing a maliciously crafted font. These issues are addressed by updating FreeType to version 2.4.3.
The Seven Deadly Sins of Cybercrime Victims
Like athletes and chess players, cybercriminals are skilled at identifying their targets’ weak points.
Today’s increasingly online and social world offers a host of techniques for preying on potential victims and their weaknesses.
Following are seven weaknesses that you need to watch out for to avoid falling prey to these scams — whether they take the form of emails, social networking chats, or phone calls.
[InfoSecIsland]
Today’s increasingly online and social world offers a host of techniques for preying on potential victims and their weaknesses.
Following are seven weaknesses that you need to watch out for to avoid falling prey to these scams — whether they take the form of emails, social networking chats, or phone calls.
- Lust: Scammers try to tempt users into action by masquerading as an attractive man or woman, particularly on social networks. You should assume that a flirtatious advance from someone you don’t know has a less-romantic purpose behind it.
- Greed: Like the adage says, “If something is too good to be true, it probably is.” If you receive a free iPod offer, or a percentage of a Nigerian wire transfer, resist the urge to make a deal.
- Vanity: Scammers often try to convince potential victims that they have been chosen, that they’re winners, or that they are somehow part of a select group on the receiving end of an exclusive offer. As harsh as it may sound, you should assume you’re not that special.
- Misplaced Trust: In some scams, cybercriminals attempt to convince you that they represent a high-profile brand and therefore can be trusted. Other times, scammers pretend to be a “friend of a friend” so that your trust for your friend extends to this unknown person. Question any message or phone call that plays on a trust relationship.
- Sloth: Criminals rely on our laziness to ensure that poorly written messages and shortened URLs don’t rouse suspicion. For instance, many users will click on a link in an email from their “bank”, instead of calling the bank or visiting the bank’s website to determine if the email is legitimate.
- Excess Compassion: In 2009, one of the most successful scams on Facebook involved criminals hijacking users’ accounts, then posting status updates claiming that the account holder was stranded somewhere and needed money. Many kindhearted people fell for this ploy. Other similar scams involve requesting donations to nonexistent nonprofits when a major disaster occurs, such as the earthquake in Haiti. Maintain a high level of skepticism toward these types of messages.
- Urgency: Hand-in-hand with compassionate pleas are scams that insist on a fast response and tell you to “act now” or “time is running out.” Double-check these requests with the sender or a colleague, and don’t feel pressured to respond immediately.
[InfoSecIsland]
What To Do When Your Identity Gets Stolen
OK, so it happens. A lot. Companies and people don’t always do the right things and sometimes, criminals win. They steal identity data and get the chance to commit massive fraud. We all know about it. We hear the stories and we hear people talking, but we don’t think it will happen to us, until it does.
What now? What should you do when such an event occurs in your life? Well, this great article from our friends over at Help Net Security summarizes best practices for identify theft victims and their support systems as described by the Consumer Federation of America (CFA). I thought the article was not only good content, but an excellent point of reference for folks who might be impacted by identity theft. You should check it out here. Here are some more tips:
- You should also be well aware of your legal rights and responsibilities and not be afraid to engage with your state Attorney General’s office if you suspect vendors are not playing by the rules. You can find a list of state Attorney General contacts here: http://www.consumerfraudreporting.org/stateattorneygenerallist.php
- Legal representation may also be of assistance if the fraud you face is large enough to warrant the cost of representation. Don’t be afraid to engage with an attorney if the fraud costs are large or the legal complexity you face is astounding. Contact your state bar association for information on finding reputable consumer law attorneys in your area.
- If you are considering something like one of these consumer data/life “locking” services or the like, please check out a DIY approach here.
[StateOfSecurity]
HTTPS Is More Secure, So Why Isn’t the Web Using It?
You wouldn’t write your username and passwords on a postcard and mail it for the world to see, so why are you doing it online? Every time you log in to Twitter, Facebook or any other service that uses a plain HTTP connection, that’s essentially what you’re doing.
There is a better way, the secure version of HTTP — HTTPS. That extra “S” in the URL means your connection is secure, and it’s much harder for anyone else to see what you’re doing. But if HTTPS is more secure, why doesn’t the entire web use it?
HTTPS has been around nearly as long as the web, but it’s primarily used by sites that handle money — your bank’s website or shopping carts that capture credit card data. Even many sites that do use HTTPS use it only for the portions of their websites that need it — like shopping carts or account pages.
Web security got a shot in the arm last year when the FireSheep network-sniffing tool made it easy for anyone to detect your login info over insecure networks — your local coffeeshop’s hotspot or public Wi-Fi at the library. That prompted a number of large sites to begin offering encrypted versions of their services on HTTPS connections.
Lately even sites like Twitter (which has almost entirely public data anyway) are nevertheless offering HTTPS connections. You might not mind anyone sniffing and reading your Twitter messages en route to the server, but most people don’t want someone also reading their username and password info. That’s why Twitter recently announced a new option to force HTTPS connections(note that Twitter’s HTTPS option only works with a desktop browser, not the mobile site, which still requires manually entering the HTTPS address).
Google has even announced it will add HTTPS to many of the company’s APIs. Firefox users can go a step further and use the HTTPS Everywhere add-on to force HTTPS connections to several dozen websites that offer HTTPS, but don’t use it by default.
So, with the web clearly moving toward more HTTPS connections, why not just make everything HTTPS?
That’s the question I put to Yves Lafon, one of the resident experts on HTTP(s) at the W3C. There are some practical issues most web developers are probably aware of, such as the high cost of secure certificates, but obviously that’s not as much of an issue with large web services that have millions of dollars.
The real problem, according to Lafon, is that with HTTPS you lose the ability to cache. “Not really an issue when servers and clients are in the same region (meaning continent),” writes Lafon in an e-mail to Webmonkey, “but people in Australia (for example) love when something can be cached and served without a huge response time.”
Lafon also notes that there’s another small performance hit when using HTTPS, since “the SSL initial key exchange adds to the latency.” In other words, a purely security-focused, HTTPS-only web would, with today’s technology, be slower.
For sites that don’t have any reason to encrypt anything — in other words, you never log in, so there’s nothing to protect — the overhead and loss of caching that comes with HTTPS just doesn’t make sense. However, for big sites like Facebook, Google Apps or Twitter, many users might be willing to take the slight performance hit in exchange for a more-secure connection. And the fact that more and more websites are adding support of HTTPS shows that users do value security over speed, so long as the speed difference is minimal.
Another problem with running an HTTPS site is the cost of operations. “Although servers are faster, and implementations of SSL more optimized, it still costs more than doing plain HTTP,” writes Lafon. While less of a concern for smaller sites with little traffic, HTTPS can add up, if your site suddenly becomes popular.
Perhaps the main reason most of us are not using HTTPS to serve our websites is simply that it doesn’t work with virtual hosts. Virtual hosts, which are what the most common cheap web-hosting providers offer, allow the web host to serve multiple websites from the same physical server — hundreds of websites all with the same IP address. That works just fine with regular HTTP connections, but it doesn’t work at all with HTTPS.
There is a way to make virtual hosting and HTTPS work together — the TLS Extensions protocol — but Lafon notes that, so far, it’s only partially implemented. Of course that’s not an issue for big sites, which often have entire server farms behind them. But until that spec — or something similar — is widely used, HTTPS isn’t going to work for small, virtually hosted websites.
In the end there is no real reason the whole web couldn’t use HTTPS. There are practical reasons why it isn’t happening today, but eventually the practical hurdles will fall away. Broadband speeds will improve, which will make caching less of a concern, and improved servers will be further optimized for secure connections.
In the web of the future the main concern won’t just be how fast a site loads, but how well it safeguards you and protects your data once it does load.
Subscribe to:
Posts (Atom)
