Tuesday, September 27, 2016

Verisign Distributed Denial Of Service (DDoS) Trends Report Q2 2016 PDF

Verisign Distributed Denial Of Service (DDoS) Trends Report Q2 2016 PDF



EXECUTIVE SUMMARY 

This report contains the observations and insights derived from distributed denial of service (DDoS) attack mitigations enacted on behalf of, and in cooperation with, customers of Verisign DDoS Protection Services from April 1, 2016 through June 30, 2016 (“Q2 2016”) and the security research of Verisign iDefense® Security Intelligence Services conducted during that time. It represents a unique view into the attack trends unfolding online, including attack statistics and behavioral trends for Q2 2016.


Saturday, September 24, 2016

Source: Why the silencing of KrebsOnSecurity opens a troubling chapter for the ‘Net | Ars Technica

RISK ASSESSMENT

Why the silencing of KrebsOnSecurity opens a troubling chapter for the ‘Net
“Free speech in the age of the Internet is not really free,” journalist warns.

DAN GOODIN - 9/23/2016, 4:58 PM


For the better part of a day, KrebsOnSecurity, arguably the world's most intrepid source of security news, has been silenced, presumably by a handful of individuals who didn't like a recent series of exposés reporter Brian Krebs wrote. The incident, and the record-breaking data assault that brought it on, open a troubling new chapter in the short history of the Internet.

The crippling distributed denial-of-service attacks started shortly after Krebs published stories stemming from the hack of a DDoS-for-hire service known as vDOS. The first article analyzed leaked data that identified some of the previously anonymous people closely tied to vDOS. It documented how they took in more than $600,000 in two years by knocking other sites offline. A few days later, Krebs ran a follow-up piece detailing the arrests of two men who allegedly ran the service. A third post in the series is here.

On Thursday morning, exactly two weeks after Krebs published his first post, he reported that a sustained attack was bombarding his site with as much as 620 gigabits per second of junk data. That staggering amount of data is among the biggest ever recorded. Krebs was able to stay online thanks to the generosity of Akamai, a network provider that supplied DDoS mitigation services to him for free. The attack showed no signs of waning as the day wore on. Some indications suggest it may have grown stronger. At 4 pm, Akamai gave Krebs two hours' notice that it would no longer assume the considerable cost of defending KrebsOnSecurity. Krebs opted to shut down the site to prevent collateral damage hitting his service provider and its customers.

"It's hard to imagine a stronger form of censorship than these DDoS attacks because if nobody wants to take you on then that's pretty effective censorship," Krebs told Ars on Friday. "I've had a couple of big companies offer and then think better of offering to help me. That's been frustrating."


FURTHER READINGSpamhaus DDoS grows to Internet-threatening sizeUntil recently, a DDoS attack in excess of 600Gb was nearly impossible for all but the most sophisticated and powerful actors to carry out. In 2013, attacks against anti-spam organization Spamhaus generated headlines because the 300Gb torrents were coming uncomfortably close to Internet-threatening size. The assault against KrebsOnSecurity represents a much greater threat for at least two reasons. First, it's twice the size. Second and more significant, unlike the Spamhaus attacks, the staggering volume of bandwidth doesn't rely on misconfigured domain name system servers which, in the big picture, can be remedied with relative ease.


Thanks, Internet of things

Instead, the attacks against KrebsOnSecurity harness so-called Internet-of-things devices—think home routers, webcams, digital video recorders, and other everyday appliances that have Internet capabilities built into them. Manufacturers design these devices to be as inexpensive and easy-to-use as possible. Consumers often have little technical skill. As a result, the devices frequently come with bug-ridden firmware that never gets updated and easy-to-guess login credentials that never get changed. Their lax security and always-connected status makes the devices easy to remotely commandeer by people who turn them into digital cannons that spray the Internet with shrapnel. On Thursday, security firm Symantec cataloged 11 different families of IoT malware that do just that.

"The current IoT threat landscape shows that it does not require much to exploit an embedded device," Symantec researchers wrote in the report, which was headlined "IoT devices being increasingly used for DDoS attacks." "While we have come across several malware variants exploiting device vulnerabilities—such as Shellshock or the flaw in Ubiquiti routers—the majority of the threats simply take advantage of weak built-in defenses and default password configurations in embedded devices."

The growing supply of IoT malware is creating a tipping point in the denial-of-service domain that's giving relatively unsophisticated actors capabilities that were once reserved only for the most elite of attackers. And that, in turn, represents a threat to the Internet as we know it.

FURTHER READINGSecurity reporter tells Ars about hacked 911 call that sent SWAT team to his house (Updated)"The biggest threats as far as I'm concerned in terms of censorship come from these ginormous weapons these guys are building," Krebs said. "The idea that tools that used to be exclusively in the hands of nation states are now in the hands of individual actors, it's kind of like the specter of a James Bond movie."

Krebs said he has explored the possibility of retaining a DDoS mitigation service, but he found that the cost—somewhere between $100,000 and $200,000 per year for the type of always-on protection he needs against high-bandwidth attacks—is more than he can afford. For the past four years, he received pro bono help from Prolexic, which was later acquired by Akamai. Over that time, the service has defended KrebsOnSecurity against what he estimates are hundreds of attacks. The latest round has brought that relationship to an end. Krebs said he hopes to be back online later Friday with the help of a service he declined to discuss on the record. Still, he said, he's not sure how long the new arrangement will last.

Of course, if a ragtag band of quasi-hackers can disrupt KrebsOnSecurity, they can disrupt plenty of other sites, too. And this should concern not just the Googles, Apples, and Microsofts of the world but their everyday users as well. Krebs said the threat "screams out" for the kind of industry-wide collaboration that's come together to counter previous threats, including the DNS spoofing bug researcher Dan Kaminsky disclosed in 2008, the Conficker worm that infected huge swaths of the Internet the same year, or the GameOver botnet from last year. Sadly, Krebs said he sees no signs of such cooperation now.

"Free speech in the age of the Internet is not really free," he said. "We're long overdue to treat this threat with a lot more urgency. Unfortunately, I just don't see that happening right now."

Story corrected to change gigabytes to gigabits.

DAN GOODINDan is the Security Editor at Ars Technica, which he joined in 2012 after working for The Register, the Associated Press, Bloomberg News, and other publications.



Tuesday, August 30, 2016

Source: What is your phone telling your rental car? | Consumer Information

August 30, 2016

When I rent a car, it’s fun to get all the bells and whistles – like navigation, hands-free calls and texts, streaming music and even web browsing. But did you know that cars with these features might keep your personal information, long after you’ve returned your rental car? Here are some things to keep in mind when renting a connected car.
What happens when you rent a connected car? When you use the car’s infotainment system, it may store personal information. It may keep locations you entered in GPS or visited when travelling in the rental car – like where you work or live. 
If you connect a mobile device, the car may also keep your mobile phone number, call and message logs, or even contacts and text messages. Unless you delete that data before you return the car, other people may view it, including future renters and rental car employees or even hackers.
If you decide to rent a connected car, here are some steps you can take to protect your personal information:
  • Avoid connecting your mobile phones or devices to the infotainment system just for charging. It’s safer to use a cigarette lighter adapter to charge devices, instead of the car’s USB port. Why? In some cases, the USB connection may transfer data automatically.  
  • Check your permissions. If you do connect your device to the car, the infotainment system may present a screen that lets you specify which types of information you want the system to access. Grant access only to the information you think is necessary – if you just want to play music, for example, you don’t need to okay access to your contacts.
  • Delete your data from the infotainment system before returning the car. Go into the infotainment system’s settings menu to find a list of devices that have been paired with the system. Locate your device and follow the prompts to delete it. The owner’s manual and the rental car company may have more information about how to delete your data.
Want to learn more about how your personal information is shared and used every day? Watch this short video.
Sharing Information: A Day in Your Life
Every day, you share information about yourself with businesses and their affiliates. In fact, you might not realize just how often it happens.

Tagged with: caronline safetyprivacytechnologyWi-Fi


Sunday, August 28, 2016

Source: Inside ‘The Attack That Almost Broke the Internet’ — Krebs on Security

In March 2013, a coalition of spammers and spam-friendly hosting firms pooled their resources to launch what would become the largest distributed denial-of-service (DDoS) attack the Internet had ever witnessed. The assault briefly knocked offline the world’s largest anti-spam organization, and caused a great deal of collateral damage to innocent bystanders in the process. Here’s a never-before-seen look at how that attack unfolded, and a rare glimpse into the shadowy cybercrime forces that orchestrated it.
The following are excerpts taken verbatim from a series of Skype and IRC chat room logs generated by a group of “bullet-proof cybercrime hosts” — so called because they specialized in providing online hosting to a variety of clientele involved in spammy and scammy activities.
Gathered under the banner ‘STOPhaus,’ the group included a ragtag collection of hackers who got together on the 17th of March 2013 to launch what would quickly grow to a 300+Gigabits per second (Gbps) attack on Spamhaus.org, an anti-spam organization that they perceived as a clear and present danger to their spamming operations.
The attack –a stream of some 300 billion bits of data per second — was so large that it briefly knocked offline Cloudflare, a company that specializes in helping organizations stay online in the face of such assaults. Cloudflare dubbed it “The Attack that Almost Broke the Internet.
The campaign was allegedly organized by a Dutchman named Sven Olaf Kamphuis(pictured above). Kamphuis ran a company called CB3ROB, which in turn provided services for a Dutch company called “Cyberbunker,” so named because the organization was housed in a five-story NATO bunker and because it had advertised its services as a bulletproof hosting provider.
Kamphuis seemed to honestly believe his Cyberbunker was sovereign territory, even signing his emails “Prince of Cyberbunker Republic.” Arrested in Spain in April 2013 in connection with the attack on Spamhaus, Kamphuis was later extradited to The Netherlands to stand trial. He has publicly denied being part of the attacks and his trial is ongoing.
According to investigators, Kamphuis began coordinating the attack on Spamhaus after the anti-spam outfit added to its blacklist several of Cyberbunker’s Internet address ranges. The following logs, obtained by one of the parties to the week-long offensive, showcases the planning and executing of the DDoS attack, including digital assaults on a number of major Internet exchanges. The record also exposes the identities and roles of each of the participants in the attack.
The logs below are excerpts from a much longer conversation. The entire, unedited chat logs are available here. The logs are periodically broken up by text in italics, which includes additional context about each snippet of conversation. Also please note that the logs below may contain speech that some find offensive.



Friday, August 26, 2016

Source: The top three ways to avoid fraud | Consumer Information





In pretty much every article and blog post we put out, you’ll find tips to help you avoid scams. The idea is that, if you can spot a scam, and know how to avoid it, you and your money are more likely to stay together.
Today, we’re releasing a brochure that distills those tips down to the top 10 ways to avoid fraud. This brochure – available online and in print – is your one-stop resource to help you spot imposters, know what to do about robocalls, and how to check out a scammer’s claims.
Here are three things that can help you avoid scammers who try to call you:
  1. Hang up on robocalls. If you pick up the phone and hear a recorded sales pitch, hang up and report it to the FTC. These calls are illegal. And plentiful. Don’t press 1, 2 or any number to get off a list or speak to a person. That just means you’ll get even more calls.
  2. Don’t trust your caller ID. Scammers can make caller ID look like anyone is calling: the IRS, a business or government office…even your own phone number. If they tell you to pay money for any reason, or ask for your financial account numbers, hang up.  If you think the caller might be legitimate, call back to a number you know is genuine – not the number the caller gave you.
  3. Talk to someone. Before you give up money or information, talk to someone you trust. Scammers want you to make decisions in a hurry. Slow down, check out the story, search online – or just tell a friend. We find that people who talk to someone – anyone – are much less likely to fall for a scam.
For seven more tips to help protect yourself and loved ones from fraud, read on – or order your free copies of 10 Things You Can Do to Avoid Fraud to share in your community. And if you spot something that looks like a scam, report it to the FTC.
Tagged with: imposterrobocallscamtelemarketing


Wednesday, August 17, 2016

Source: Big banks join forces to fight cyber crime | Imperva Cyber Security Blog

Source: Big banks join forces to fight cyber crime | Imperva Cyber Security Blog



August 15, 2016



Big banks join forces to fight cyber crime

34347209_mWall Street Journal and Fortune recently reported that eight of the largest U.S. banks are forming an alliance to better combat the growing threat of cyber-attacks targeting the financial services industry. The new group, which is in the early stages of development, includes J.P. Morgan Chase, Bank of America and Goldman Sachs.
Specifically, the group will share threat information with each other, develop comprehensive cyber-attack response plans and conduct cyber war games that simulate attacks. The group will operate under the umbrella of the larger Financial Services Information Sharing and Analysis Center (FS-ISAC).
Cyber Security a Top Priority
This new group underscores the importance of cyber security for the financial services industry, which has long been in the cross-hairs of cyber-attacks. Consider the following:
While this new alliance consists of big banks, who have more complex environments, smaller financial service firms are not immune to cyber-attacks. As larger banks and financial institutions strengthen their defenses, cyber criminals will move downstream seeking easier targets. Regional banks, credit unions and smaller investment houses must make cyber security a top priority as well.
Sharing Threat Information Improves Security
35327594_mLet’s face it. The financial services industry (one could argue all industries) is fighting an asymmetric cyber war. The threats are ever-present and ever-changing. Cyber-attacks have become more sophisticated andindustrialized with attackers selling their services on the Dark Web. Security professionals are constantly a step behind attackers.
To get in front of growing cyber threats, financial services organizations must make a concerted effort to share cyber threat information. Sharing threat intelligence helps the financial services industry stay on top of new attacks, limit the causalities from emerging threats, and shortens the useful lives of attacks against banks and other financial firms.
Imperva recognizes the power of leveraging threat intelligence to improve security. We arm ourindustry-leading web application firewall with real-time threat intelligence. These threat intelligence feeds combine globally crowd-sourced data and research from the Imperva Defense Center.
Crowd-sourcing threat intelligence is vital because no single security team can stay abreast of today's dynamic threat landscape. Pooling the collective resources and knowledge across the financial services industry helps prioritize the threats to your institution, alleviates thecybersecurity skills shortage and significantly improve your institution’s security posture.
As a market leader in data and web application security, Imperva helps financial services organizations around the world protect against escalating cyber threats. Learn more about how our industry-leading data and web application security solutions can help your institution.

Thursday, June 30, 2016

Source: Scientology Seeks Captive Converts Via Google Maps, Drug Rehab Centers — Krebs on Security

Fake online reviews generated by unscrupulous marketers blanket the Internet these days. Although online review pollution isn’t exactly a hot-button consumer issue, there are plenty of cases in which phony reviews may endanger one’s life or well-being. This is the story about how searching for drug abuse treatment services online could cause concerned loved ones to send their addicted, vulnerable friends or family members straight into the arms of the Church of Scientology.
As explained in last year’s piece, Don’t Be Fooled by Fake Online Reviews Part II, there are countless real-world services that are primed for exploitation online by marketers engaged in false and misleading “search engine optimization” (SEO) techniques. These shady actors specialize in creating hundreds or thousands of phantom companies online, each with different generic-sounding business names, addresses and phone numbers. The phantom firms often cluster around fake listings created in Google Maps — complete with numerous five-star reviews, pictures, phone numbers and Web site links.
The problem is that calls to any of these phony companies are routed back to the same crooked SEO entity that created them. That marketer in turn sells the customer lead to one of several companies that have agreed in advance to buy such business leads. As a result, many consumers think they are dealing with one company when they call, yet end up being serviced by a completely unrelated firm that may not have to worry about maintaining a reputation for quality and fair customer service.
Experts say fake online reviews are most prevalent in labor-intensive services that do not require the customer to come into the company’s offices but instead come to the consumer. These services include but are not limited to locksmiths, windshield replacement services, garage door repair and replacement technicians, carpet cleaning and other services that consumers very often call for immediate service.
As it happens, the problem is widespread in the drug rehabilitation industry as well. That became apparent after I spent just a few hours with Bryan Seely, the guy who literallywrote the definitive book on fake Internet reviews.
Perhaps best known for a stunt in which he used fake Google Maps listings to intercept calls destined for the FBI and U.S. Secret Service, Seely knows a thing or two about this industry: Until 2011, he worked for an SEO firm that helped to develop and spread some of the same fake online reviews that he is now helping to clean up.
More recently, Seely has been tracking a network of hundreds of phony listings and reviews that lead inquiring customers to fewer than a half dozen drug rehab centers, includingNarconon International — an organization that promotes the theories of Scientologyfounder L. Ron Hubbard regarding substance abuse treatment and addiction.
As described in Narconon’s Wikipedia entry, Narconon facilities are known not only for attempting to win over new converts, but also for treating all drug addictions with a rather bizarre cocktail consisting mainly of vitamins and long hours in extremely hot saunas. The Wiki entry documents multiple cases of accidental deaths at Narconon facilities, where some addicts reportedly died from overdoses of vitamins or neglect:
“Narconon has faced considerable controversy over the safety and effectiveness of its rehabilitation methods,” the Wiki entry reads. “Narconon teaches that drugs reside in body fat, and remain there indefinitely, and that to recover from drug abuse, addicts can remove the drugs from their fat through saunas and use of vitamins. Medical experts disagree with this basic understanding of physiology, saying that no significant amount of drugs are stored in fat, and that drugs can’t be ‘sweated out’ as Narconon claims.”
Read entire article.........



Tags: ,


BookMark