Friday, February 19, 2016

Your friend probably didn't just get robbed in a foreign country

It happens often.  Imagine that you receive an email from a friend or colleague claiming that he or she is stranded in a foreign country and desperately needs your help to get home. The email originates from the friend's real email account and may even include the same email signature that your friend uses when emailing you. Thus, you might be inclined to believe that the email was legitimate, at least at first glance. However, the emails are a clever scheme by Internet criminals designed to trick people into sending them money.

Many different versions of these scam attempts have been seen. Names and other details differ depending on who's email account the scammers have hijacked, as do the countries where the "friend" is supposedly stranded. The amounts of money requested in the messages may also differ. But, in spite of such superficial differences, all such messages are versions of the same basic scam. Sadly, many people have become victims of this scam and lost money to these criminals.

If you get an email from a friend who needs you to send them money quickly while they are on vacation, be very suspicious. If they really are on vacation, find a different way to try to contact your friend to find out if this email really came from them.  But you can probably rest assured that your friend probably didn’t just get robbed in a foreign country. :)


Call Back Scams...

Employees continue to be targets of call back scams…

In some call back scams, the scammer calls its target person or company from a certain phone number and then hangs up before the phone is answered (before it goes to voicemail). Sometimes the scammer will text its phone number to its target person. The goal with this type of scam is to arouse curiosity, to get the target person to wonder “hmmm…who was that?” and call the number back. When the person calls the number back, sometimes it ends up being a premium service number and their phone bill is charged accordingly.

In the most recent scam attempt, an employee at work was targeted by a Capital One fraud phone scam. The caller left a voicemail requesting a call back, and this call wasn’t expected at all. These scams try to make you unnecessarily concerned about your account and its status, and return the call using the phone number given. The scammer will then try to socially engineer you into giving up your account information.

Be very careful about phone numbers that call your telephone and hang up, or leave a message that you definitely aren’t expecting. Always verify who called before returning the call. In the case of scams such as the Capital One attempt, calling the legitimate telephone number on your card or statement is always the best way to verify.

Of course, I prefer Grumpy Cat’s approach… ;)

Thursday, February 18, 2016

A quick analysis of a suspicious email...

This other day, I received the email below that is a good potential “phish” example.  It was suspicious to me because I didn’t expect it, and it has the big “Activate your account” button on it, which always makes me nervous



I hovered my mouse over the “Activate your account” button, and it showed this URL:

https://click.secure.castlighthealth.com/?qs=e44686b30557b0270415b9d9b54f0dc364469df8a750e6b8e9211d38a52bf60f7eabf3c8b5a4501c
 

Hmmm….doesn’t match calperscompare.com.  Not sure about this one.  However, I noticed that the email spells out the actual website, so I could manually enter www.calperscompare.com 


Before doing so, however, I entered www.calperscompare.com into one of my favorite URL checking sites, URLVoid.com .  It reported no reputation concerns with the website (0 out of 29 is good :).

I then manually entered www.calperscompare.com in my browser, and the site appears legit.  To be double-sure, I searched for “Calpers Compare” on the calpers.ca.gov website, and it checks out.

Hope you enjoyed this example of investigating a suspicious email as much as I did!  ;)







Password Reuse...

Password reuse—using the same password for multiple sites or services—is both rampant and dangerous.

Sites that have either leaked user passwords and/or had attempted account hacking using reused passwords include:

Linkedin Dropbox Hotmail Gmail Yahoo! Amazon

The worst part: Many users whose passwords were leaked had used the same password for all of their site accounts. This meant that one password loss at one site could have granted access to many or all of their accounts.



An Example
Suppose you use the same password on Sony’s PlayStation Network as you use when shopping with Best Buy. Now, suppose that your PlayStation username and password were among the 77 million leaked in April 2011. An attacker could, in principle, use that information to take a good guess at your password for Best Buy.



From a report by John Fontana at ZDNet:
“After months of Best Buy customers reporting compromised accounts, the company has finally confirmed hackers are attacking its online retail site using credentials stolen from other sites. It’s a worst-case scenario, where credentials stolen from one site are used to access other sites, most notably retail or banking sites where hackers can extract some value.”

Now just imagine if an employee did this same thing, using the same password as their employee user account on an outside site?


What should we do?
  • As you should with your personal accounts, don’t use the same passwords for employee accounts, especially for work accounts where the password is stored by a 3rd party outside of your organization. And don’t use your employee account passwords on any personal site.
  • Use a secure password management tool to manage and store all of the passwords for your accounts.
  • Use 2-factor authentication. Read more about 2-factor authentication here: http://www.securingthehuman.org/newsletters/ouch/issues/OUCH-201211_en.pdf

Macro malware continues...

We continue to see an uptick in the number of phishing emails with attachments that have macros in them. Here’s an example of an interesting one:

If you have the default macro setting in office, you would see the following message if you opened the file:



By enabling content (running the macro), your system would become seriously infected.

Here’s the checklist for avoiding these dangerous files:

  • Don’t immediately open attachments that you aren’t expecting. Make sure first that they are from a legitimate source.
  • IF the file asks to enable macros, be sure to verify the file with the sender before doing so.
  • NEVER configure Office to allow all macros to automatically run.

Stay suspicious…


A password quiz..


Here’s a quick password quiz:


Which password below is the hardest to crack but the easiest to remember?
 

  1. Jasmine1
  2. H&1#5dy<?72Rvlt
  3. It’s been a hard days night 4 SueM

If you chose #3, you are a winner.  And you probably use easy-to-remember, hard to crack passphrases (see below for why).

Remember, password managers make remembering a lot of passwords unnecessary.  


Password: Jasmine1
Time to crack: < 1 second
Why it is bad: In a password cracking wordlist

Password: H&1#5dy<?72Rvlt
 

Time to crack: 4 trillion years 
Why it is bad unless you use a password manager: Complex but hard to remember and type
 

Password: It’s been a hard days night 4 SueM 
Time to crack: 7 quattuordecillion years (however long that is ;)
Why it is good: A personalized remember-able passphrase that’s 34 characters long!
 

Data Stealers and the Drive-By Download

Most of you are already aware of “phishing” attempts and “Trojan horses” that deliver malware that can infect your computer. Today I want to introduce you to the “drive-by download”…

What you see on your screen is not always all you are getting when you browse the Internet…

It’s not uncommon to get what you didn’t bargain for. “Drive-by downloads” happen during Internet browsing when your computer downloads, without your knowledge, something that infects your system, usually with the intent to steal your information and your credentials. Many websites are often used as part of a multi-step attack, as seen in the example graphic below:
 


The most common means of infection are from search engine poisoning, malicious forum posts, and malicious advertisements. The computer vulnerabilities that these exploits target commonly include Windows, Java, Flash, and Acrobat software vulnerabilities.

If successful, often a data stealer such as “Zeus” or one of the ever-popular “Exploit Kits” is installed. These tools allow information and credentials to be captured on your computer and sent to an unknown 3rd party.



What can we do to lower the chances of this kind of data theft?

Keep the software on your computer up-to-date
Don’t run vulnerable versions of applications, especially Windows, Java, Flash and Acrobat software. If your computer is up-to-date, these exploits are less effective.

Browse carefully
While not a guarantee, staying on known, good sites and avoiding lesser known sites can lower the risk, and is especially important if you are browsing on a computer that houses or processes sensitive information. In that case, it is better yet to use a different computer to browse the Internet. If possible, limit your browsing at work to sites related to business.

Use a web filter
A web filter will filter known compromised websites. While it can’t catch everything, it does lower the risk significantly. Consider using a web filter at home; free options includes K9 and OpenDNS.

Use updated browsers and operating systems

The latest versions of operating systems and Internet browsers have features for and are designed to better resist these types of attacks.

Don’t surf the web as an “administrator” on your computer
Remember that malware will almost always do as much damage to your computer as your account has permissions to perform. For your home computer, consider browsing the Internet with an account with lesser privileges on your computer. Advanced users should consider browsing using a virtual machine, and using ad blockers and Noscript which can block execution on new or unknown sites.

And don’t forget…Backup your files!
Sooner or later, something bad does happen. Always be sure that you can continue working even if your computer can’t.

Wednesday, February 17, 2016

A very interesting spam email...

As you probably can guess, as a security team we see LOTS of spam email.  And we always encourage avoiding any interaction with them. :)  The email below is no different, and has the obvious markings of being SPAM.  But it has something else very interesting too…



In the orange bar, there is some text.  That text and the contents of the message contain what seems to be a rather good recipe for a salad: 
***************
* tablespoons olive oil
* 1 12tablespoons fresh lemon juice
* 1tablespoon red wine vinegar
* 2garlic cloves, minced
* 1teaspoon dried oregano(Mediterranean is best)
*
** Salad
------------------------------------------------------------
* 1head lettuce, torn into bite-size pieces ((I use Romaine)
* 3large plum tomatoes, seeded and coarsely chopped
* 1English cucumber, peeled and coarsely chopped (the long, thin, almost seedless ones)
* 1medium red onion, cut into thin rings and soaked for 10 minutes in a small bowl of ice water to make it less sharp
* 1small green pepper, cut into thin rings
* 34cup kalamata olive
* 34cup crumbled feta cheese

We think that you will enjoy this.

1. Seed the bell peppers and cut them into 1-inch chunks. Stem the cherry tomatoes and halve one-half of them, leaving the others whole.
2. Peel and thickly slice the cucumbers, and thinly slice the red onions. Cut the feta cheese into 1-inch cubes. Crush and mince the garlic clove.
3. In a large bowl, combine the bell peppers, tomatoes, cucumbers, onions, feta cheese, olives, anchovies and capers and toss together.
4. In a small bowl, whisk together the vinegar, garlic, dill, oregano, salt and pepper. While whisking, slowly drizzle in the olive oil to make a thick dressing.
5. Pour the dressing over the salad, toss and serve now.This is the most delicious salad - fresh and wonderful-tasting. FYI, lettuce can very much be a part of any greek salad - if you want it to. We like lettuce in my family and I often add it. It would not be 'authentic' in a Horiatiki (village) salad, but who cares?
*****************


Why, you ask???  It’s because spammers often fill the content of their emails with unrelated text that will increase the chances of their email getting past anti-spam filters.  Normally, they hide the text in the source of the email, so you can’t see it.  In this case, they must have forgotten to do that…

Remember to think before you click! :)


Those online security questions...

I’ve had a few people ask me about how to best handle online security questions.  You know, the ones they ask so that you can verify your identity if you forget your password, etc.  Security questions are one of the age-old institutions of digital authentication. Their flaws are well documented -- answers are often easy to guess or look up, and companies themselves seem not to take them seriously -- and yet, they're still used everywhere.



 






The most important thing to remember is that when you answer the questions, make sure that the answers can’t be easily discovered by someone else who might want to impersonate you

As an option, here’s how I handle it:  I’ve created a fictional scenario in my mind about how I grew up -- where I lived (or would have liked to), who my best friend was, what my first car was, you get the idea.  And I’ve memorized it (it’s not hard to remember).  Whenever I come across online security questions, I answer the questions using the fake scenario!  None of that info is available to anyone, so they are super secure answers (like my mother’s fake maiden name, etc.).  And no, it has nothing to do with Breaking Bad. ;)



Be safe!

Remember to setup alerts on your bank accounts...

Remember, during security awareness training, when we talked about setting up alerts on our credit card and bank accounts?



Um, ok, good.  Well, it payed off (once again).  Last week I suddenly received 3 of these alerts:


Yikes!  Not me!  I immediately got on the phone to Capital One, where I informed them of the unlawful use.  Someone got my credit card # and made some purchases in Louisiana.  Ultimately Capital One recognized the transactions as suspicious, but I saw it first.  :))   As in any computing activity, alerting and monitoring for the win!!


Total charges they made were around $300, which I’m not responsible for.  That’s why it’s important not to use a debit card for purchases whenever possible.  A bad guy can empty your debit card checking account and the bank isn’t necessarily liable in that instance.  Save your debit card for getting cash at your bank’s ATM.

So be sure to turn alerts on for your credit card and bank accounts!  And enable 2-factor authentication for your online accounts where it is available (see where at https://twofactorauth.org/).

By the way, 300 dollars at a DOLLAR general store???  Wow, that’s some serious stockpiling…


Ransomware Mistakes

It’s all over the news that Hollywood Presbyterian Medical Center has been crippled by a ransomware attack.

As you know, ransomware is software that takes control of your computer (usually by encrypting your files) and demands money before your files can be recovered.




In this case, the attackers are demanding $3.6 million dollars.

Some patients were transported to other hospitals due to the incident. Computers essential for various functions, including CT scans, documentation, lab work, and pharmacy needs are offline.   Hospital workers are unable to gain access to important documents, patient data, and emails.  Staff have had to step back in time, firing up fax machines and making more use of pens and paper to keep track of work at the facility.


Unfortunately, these bad things happen.  But it’s the impact that makes the differenceTwo really bad things make this hospital incident so big:
  • The user account that succumbed to the ransomware appears to have access to a lot of computers and data, allowing the ransomware to easily spread through all of their systems.
  • According to the Atlantic, “While it’s unlikely that the facility will pay millions of dollars to restore its databases and systems, it’s in desperate straits without a backup of its patient files. Unless law enforcement can break the encryption keeping the data hostage, the hospital may be forced to start from scratch.”
How do we limit the damage in an incident such as this?
  • Limit access appropriately.  As we learned in security awareness training, don’t do casual Internet browsing or email using an account that has access to your entire infrastructure.  Visualize what might happen if your business were hit, and implement proper access controls to limit the damage.
  • Make sure you have current backups and that your work is being backed up in a location where ransomware doesn’t have access (if you store your files on enterprise network shares or home directories and they are backed up to tape, the backups are inaccessible to ransomware and normally can be restored).  And always perform exercises in restoring, so you can be sure your backups are working and you can do it in an emergency.
And, of course, avoid opening anything unexpected or unknown at all times.



Stay safe. 

Tuesday, October 20, 2015

Don't give others power over you...


Sure, people regularly irritate us all.  Each of us has at least one person who we could call our "thorn in the flesh."  That's life, and it is part of all of life.  But what I've learned over the years is that changing my behavior because of another persons behavior has never served me well.  That's because if I do I have given that person power over me.

An simple example of this concept is being irritated by an action of another driver on the road.  We often get angry, maybe shout, and all the while the other driver just simply moves along completely ignorant of our disdain. But our blood pressure has risen and our mood affected. It's kind of a waste.



While this concept applies to all aspects of life, I will focus on folks who live and work in IT, since it's where I spend the most of my time.

I'm continually amazed at how many people stunt their careers by choosing not to work with others simply because people irritate them so much.  I've seen promising IT folks become as bad of an HR burden as those that they dislike, because they are so heavily affected by the behavior of others.

I know this from experience.  I've had events in my career where I've tried to aggressively make a statement regarding someone's behavior, or gone off on someone just to prove my point.  In each case, I was the one who ended up paying for it, and ultimately they were not worth it.

I've seen it in IT circles over and over again.  Someone's behavior, speech, or what they outwardly represent so annoys someone that they often become like that person. A great example of this was a coworker some years ago that had tremendous potential for leadership.  He was and is an extremely talented individual.  Yet this person let everyone's behavior bother him so much that he himself became uncooperative, difficult to deal with, and anything but a team player. Nobody wanted to deal with him as a result.

Here's what is interesting, and it's true over and over again: His behavior did not in any way change the behavior of those who annoyed him.  Instead, the behavior of others changed him.  And for the period of time he was employed there, it hurt his internal career opportunities significantly.  As a result of his reactions, nobody wanted to deal with him. In essence, he had given those people power over him, and it hurt his career and his life at that time.



Fortunately, this individual eventually grew through this.  He learned that by giving people that much power over him that he was only hurting himself, not doing what is best for him.  He has since gone on to be quite successful elsewhere in the industry. 

Since then, I've had the fortunate opportunity to counsel many with these thoughts, and hopefully have been able to help them.  While individuals who work for a company are there to serve that company, I tell them that in order to do that well, they must also serve themselves, and one of the ways to do that is by being as free as possible from the negative power of others.  Think of it as a game: Even though this mostly isn't true, visualize that people that are irritating you are doing everything they can to give themselves power over you. And if you let them do that and it affects your behavior, they win.  In turn, if you focus on serving yourself, doing what is best for you and your career and not let those people bring you down into their "trap", then you win.

It's a game we all have to play all of our lives.  Whether it's a co-worker, a boss, a politician, these folks will (mostly unintentionally) "try" to control us.  And we have to constantly fight that control.  We can't surrender that power to them.

The same principle, by the way, applies to forgiveness.  If we can't forgive, ultimately we are the ones that are damaged.




For me personally, my life goal is to become truly free.  Free from fear, free from the power of others, freely forgiving, completely letting go.  This is a huge part of this goal, and by writing this I am in no way saying I've mastered it.

There's an old saying, "Don't own what you don't control."  While I'm not endorsing the enabling of behavior, if you can't change it positively or have a positive influence, don't let it own you.  The most powerful thing you can do to a person is ignore them.  While I'm not saying that's easy to do with co-workers, the principle that applies is to do everything you can to "take the high road" and try your best to not give them power over you.



Saturday, July 18, 2015

Drive your computer using your valet key

A long time ago in a galaxy far, far away, there was me, pre-CSO, doing lots of vulnerability scanning and reporting.  A big part of that was (and still is) helping our many businesses prioritize the patching of these vulnerabilities in order to protect their most important data.

I would examine system vulnerabilities and focus primarily on the ones that were externally exploitable (called "level 5 vulnerabilities", the most severe in our vulnerability management software).  Important, of course, because allowing an attacker into a system easily isn't a good thing.  Other vulnerabilities, including "local privilege escalation vulnerabilities" -- vulnerabilities that allow someone who is already on a computer to use an exploit to escalate their privileges to a higher level, such as "Administrator" -- were a lower priority.  Why?  Because I didn't realize how important these vulnerabilities are.

In the years following, I have learned penetration testing.  I've had the opportunity to participate in many "capture the flag" exercises, including SANS NetWars Continuous, SANS Holiday Hack Challenges, exploitable virtual machines and online capture the flag games.  Man, I've learned a bunch.  And I continue to have many opportunities to apply this learning in my daily work.



One of the important things I've learned is that successful penetration testing relies heavily on "local privilege escalation."  I often gained access to an account or computer but did not have the privileges necessary to access the real gold, such as password hashes, domain credentials, databases, etc. ("flags"). It finally hit me that local privilege escalation vulnerabilities ROCK!  A simple software exploit got me all the privileges I needed.  From an impact perspective, they are about as dangerous as external vulnerabilities since they allow an attacker much easier access to the crown jewels of an enterprise.

Many (if not most) users already make this job easy for an attacker.  They do their daily web browsing or email reading using an account that either has full administrative access to their computer, or worse yet, full access to business information that has great value.  Those who "drive their daily computer use" using an account that they also use to administer their servers and services should be very afraid.  Most of the systems we see compromised have been when the user is browsing the web, downloading software, clicking on email links or opening email attachments.  Often times the attacker is given access to the computer with the same level of privileges as the victim user.  If the user has high-level privileges already? As I've often stated with joy while doing pen testing, "we have WINNER!" :)  It's like landing a nice mountain trout on your first fly.


Since then, as part of my regular live awareness courses I talk about this particular variation of "least privilege."  Using real attack demonstrations I try to show how much easier it is for an attacker to steal the good stuff from users who insist on "convenience" at the expense of security.  For this year's training, the best mental illustration I've been able to come up with is the concept of a valet key.

A valet key is a key for your car that is different from your normal car key.  Valet keys usually can unlock the driver's side door and start the car, but the can't unlock the trunk or the glove box. This key is normally used when someone else operates your vehicle, such as a valet parking attendant. They aren't perfect (they don't prevent a vehicle from being stolen), but they do make it harder for someone who has the key to access your valuables in the trunk or your glove box.


Using this example, this year's awareness training emphasizes "driving your day-to-day computer use using your valet key."  That "key" is your account, in this case.  If an attacker compromises that key, it can be much harder for them to access your "valuables". 

How does one drive their day-to-day computer use using a valet key?  By using an account that doesn't have local administrative privileges.  By using a separate, higher privileged account for accessing valuable information or for managing servers and services.  Or even by ensuring that in order to use their higher privileges, two factor authentication is required.  And not using their "higher privileged key" for anything other than what it is for.

Sure, it's an inconvenience if you need to fish for your "higher privileged key" when you need to access your valuables, or plug it in each time you need to do something that has greater importance, like installing software.  But along with the importance of keeping your computers patched and protected from those awesome local privilege escalation exploits, driving your computer with your valet key will make it tougher for the bad guys to succeed.