Tuesday, October 4, 2016

Source: Who Makes the IoT Things Under Attack? — Krebs on Security

As KrebsOnSecurity observed over the weekend, the source code that powers the “Internet of Things” (IoT) botnet responsible for launching the historically large distributed denial-of-service (DDoS) attack against KrebsOnSecurity last month has been publicly released. Here’s a look at which devices are being targeted by this malware.
The malware, dubbed “Mirai,” spreads to vulnerable devices by continuously scanning the Internet for IoT systems protected by factory default usernames and passwords. Many readers have asked for more information about which devices and hardware makers were being targeted. As it happens, this is fairly easy to tell just from looking at the list of usernames and passwords included in the Mirai source code.
iotbadpass-pdf
In all, there are 68 username and password pairs in the botnet source code. However, many of those are generic and used by dozens of products, including routers, security cameras, printers and digital video recorder (DVRs).
I examined the less generic credential pairs and tried to match each with a IoT device maker and device type.  As we can see from the spreadsheet above (also available in CSV andPDFformats), most of the devices are network-based cameras, with a handful of Internet routers, DVRs and even printers sprinkled in.
I don’t claim to have special knowledge of each match, and welcome corrections if any of these are in error. Mainly, I turned to Google to determine which hardware makers used which credential pairs, but in some cases this wasn’t obvious or easy.
Which is part of the problem, says Will Dormann, senior vulnerability analyst at the CERT Coordination Center (CERT/CC).
“Even when users are interested in and looking for this information, the vendor doesn’t always make it easy,” Dormann said.
Dormann said instead of hard-coding credentials or setting default usernames and passwords that many users will never change, hardware makers should require users to pick a strong password when setting up the device.
Indeed, according to this post from video surveillance forum IPVM, several IoT device makers — including HikvisionSamsung, and Panasonic — have begun to require unique passwords by default, with most forcing a mix of upper and lowercase letters, numbers, and special characters.
“As long as the password can’t be reversed — for example, an algorithm based off of a discoverable tidbit of information — that would be a reasonable level of security.” Dormann said.
Some readers have asked how these various IoT devices could be exposed if users have configured them to operate behind wired or wireless routers. After all, these readers note, most consumer routers assign each device inside the user’s home network so-called Network Address Translation (NAT) addresses that cannot be directly reached from the Internet.
But as several readers already commented in my previous story on the Mirai source code leak, many IoT devices will use a technology called Universal Plug and Play (UPnP) that will automatically open specific virtual portholes or “ports,” essentially poking a hole in the router’s shield for that device that allows it to be communicated with from the wider Internet. Anyone looking for an easy way to tell whether any of network ports may be open and listening for incoming external connections could do worse than to run Steve Gibson‘s “Shields Up” UPnP exposure test.



 Read Complete Article here. 

Tuesday, September 27, 2016

Verisign Distributed Denial Of Service (DDoS) Trends Report Q2 2016 PDF

Verisign Distributed Denial Of Service (DDoS) Trends Report Q2 2016 PDF



EXECUTIVE SUMMARY 

This report contains the observations and insights derived from distributed denial of service (DDoS) attack mitigations enacted on behalf of, and in cooperation with, customers of Verisign DDoS Protection Services from April 1, 2016 through June 30, 2016 (“Q2 2016”) and the security research of Verisign iDefense® Security Intelligence Services conducted during that time. It represents a unique view into the attack trends unfolding online, including attack statistics and behavioral trends for Q2 2016.


Saturday, September 24, 2016

Source: Why the silencing of KrebsOnSecurity opens a troubling chapter for the ‘Net | Ars Technica

RISK ASSESSMENT

Why the silencing of KrebsOnSecurity opens a troubling chapter for the ‘Net
“Free speech in the age of the Internet is not really free,” journalist warns.

DAN GOODIN - 9/23/2016, 4:58 PM


For the better part of a day, KrebsOnSecurity, arguably the world's most intrepid source of security news, has been silenced, presumably by a handful of individuals who didn't like a recent series of exposés reporter Brian Krebs wrote. The incident, and the record-breaking data assault that brought it on, open a troubling new chapter in the short history of the Internet.

The crippling distributed denial-of-service attacks started shortly after Krebs published stories stemming from the hack of a DDoS-for-hire service known as vDOS. The first article analyzed leaked data that identified some of the previously anonymous people closely tied to vDOS. It documented how they took in more than $600,000 in two years by knocking other sites offline. A few days later, Krebs ran a follow-up piece detailing the arrests of two men who allegedly ran the service. A third post in the series is here.

On Thursday morning, exactly two weeks after Krebs published his first post, he reported that a sustained attack was bombarding his site with as much as 620 gigabits per second of junk data. That staggering amount of data is among the biggest ever recorded. Krebs was able to stay online thanks to the generosity of Akamai, a network provider that supplied DDoS mitigation services to him for free. The attack showed no signs of waning as the day wore on. Some indications suggest it may have grown stronger. At 4 pm, Akamai gave Krebs two hours' notice that it would no longer assume the considerable cost of defending KrebsOnSecurity. Krebs opted to shut down the site to prevent collateral damage hitting his service provider and its customers.

"It's hard to imagine a stronger form of censorship than these DDoS attacks because if nobody wants to take you on then that's pretty effective censorship," Krebs told Ars on Friday. "I've had a couple of big companies offer and then think better of offering to help me. That's been frustrating."


FURTHER READINGSpamhaus DDoS grows to Internet-threatening sizeUntil recently, a DDoS attack in excess of 600Gb was nearly impossible for all but the most sophisticated and powerful actors to carry out. In 2013, attacks against anti-spam organization Spamhaus generated headlines because the 300Gb torrents were coming uncomfortably close to Internet-threatening size. The assault against KrebsOnSecurity represents a much greater threat for at least two reasons. First, it's twice the size. Second and more significant, unlike the Spamhaus attacks, the staggering volume of bandwidth doesn't rely on misconfigured domain name system servers which, in the big picture, can be remedied with relative ease.


Thanks, Internet of things

Instead, the attacks against KrebsOnSecurity harness so-called Internet-of-things devices—think home routers, webcams, digital video recorders, and other everyday appliances that have Internet capabilities built into them. Manufacturers design these devices to be as inexpensive and easy-to-use as possible. Consumers often have little technical skill. As a result, the devices frequently come with bug-ridden firmware that never gets updated and easy-to-guess login credentials that never get changed. Their lax security and always-connected status makes the devices easy to remotely commandeer by people who turn them into digital cannons that spray the Internet with shrapnel. On Thursday, security firm Symantec cataloged 11 different families of IoT malware that do just that.

"The current IoT threat landscape shows that it does not require much to exploit an embedded device," Symantec researchers wrote in the report, which was headlined "IoT devices being increasingly used for DDoS attacks." "While we have come across several malware variants exploiting device vulnerabilities—such as Shellshock or the flaw in Ubiquiti routers—the majority of the threats simply take advantage of weak built-in defenses and default password configurations in embedded devices."

The growing supply of IoT malware is creating a tipping point in the denial-of-service domain that's giving relatively unsophisticated actors capabilities that were once reserved only for the most elite of attackers. And that, in turn, represents a threat to the Internet as we know it.

FURTHER READINGSecurity reporter tells Ars about hacked 911 call that sent SWAT team to his house (Updated)"The biggest threats as far as I'm concerned in terms of censorship come from these ginormous weapons these guys are building," Krebs said. "The idea that tools that used to be exclusively in the hands of nation states are now in the hands of individual actors, it's kind of like the specter of a James Bond movie."

Krebs said he has explored the possibility of retaining a DDoS mitigation service, but he found that the cost—somewhere between $100,000 and $200,000 per year for the type of always-on protection he needs against high-bandwidth attacks—is more than he can afford. For the past four years, he received pro bono help from Prolexic, which was later acquired by Akamai. Over that time, the service has defended KrebsOnSecurity against what he estimates are hundreds of attacks. The latest round has brought that relationship to an end. Krebs said he hopes to be back online later Friday with the help of a service he declined to discuss on the record. Still, he said, he's not sure how long the new arrangement will last.

Of course, if a ragtag band of quasi-hackers can disrupt KrebsOnSecurity, they can disrupt plenty of other sites, too. And this should concern not just the Googles, Apples, and Microsofts of the world but their everyday users as well. Krebs said the threat "screams out" for the kind of industry-wide collaboration that's come together to counter previous threats, including the DNS spoofing bug researcher Dan Kaminsky disclosed in 2008, the Conficker worm that infected huge swaths of the Internet the same year, or the GameOver botnet from last year. Sadly, Krebs said he sees no signs of such cooperation now.

"Free speech in the age of the Internet is not really free," he said. "We're long overdue to treat this threat with a lot more urgency. Unfortunately, I just don't see that happening right now."

Story corrected to change gigabytes to gigabits.

DAN GOODINDan is the Security Editor at Ars Technica, which he joined in 2012 after working for The Register, the Associated Press, Bloomberg News, and other publications.



Tuesday, August 30, 2016

Source: What is your phone telling your rental car? | Consumer Information

August 30, 2016

When I rent a car, it’s fun to get all the bells and whistles – like navigation, hands-free calls and texts, streaming music and even web browsing. But did you know that cars with these features might keep your personal information, long after you’ve returned your rental car? Here are some things to keep in mind when renting a connected car.
What happens when you rent a connected car? When you use the car’s infotainment system, it may store personal information. It may keep locations you entered in GPS or visited when travelling in the rental car – like where you work or live. 
If you connect a mobile device, the car may also keep your mobile phone number, call and message logs, or even contacts and text messages. Unless you delete that data before you return the car, other people may view it, including future renters and rental car employees or even hackers.
If you decide to rent a connected car, here are some steps you can take to protect your personal information:
  • Avoid connecting your mobile phones or devices to the infotainment system just for charging. It’s safer to use a cigarette lighter adapter to charge devices, instead of the car’s USB port. Why? In some cases, the USB connection may transfer data automatically.  
  • Check your permissions. If you do connect your device to the car, the infotainment system may present a screen that lets you specify which types of information you want the system to access. Grant access only to the information you think is necessary – if you just want to play music, for example, you don’t need to okay access to your contacts.
  • Delete your data from the infotainment system before returning the car. Go into the infotainment system’s settings menu to find a list of devices that have been paired with the system. Locate your device and follow the prompts to delete it. The owner’s manual and the rental car company may have more information about how to delete your data.
Want to learn more about how your personal information is shared and used every day? Watch this short video.
Sharing Information: A Day in Your Life
Every day, you share information about yourself with businesses and their affiliates. In fact, you might not realize just how often it happens.

Tagged with: caronline safetyprivacytechnologyWi-Fi


Sunday, August 28, 2016

Source: Inside ‘The Attack That Almost Broke the Internet’ — Krebs on Security

In March 2013, a coalition of spammers and spam-friendly hosting firms pooled their resources to launch what would become the largest distributed denial-of-service (DDoS) attack the Internet had ever witnessed. The assault briefly knocked offline the world’s largest anti-spam organization, and caused a great deal of collateral damage to innocent bystanders in the process. Here’s a never-before-seen look at how that attack unfolded, and a rare glimpse into the shadowy cybercrime forces that orchestrated it.
The following are excerpts taken verbatim from a series of Skype and IRC chat room logs generated by a group of “bullet-proof cybercrime hosts” — so called because they specialized in providing online hosting to a variety of clientele involved in spammy and scammy activities.
Gathered under the banner ‘STOPhaus,’ the group included a ragtag collection of hackers who got together on the 17th of March 2013 to launch what would quickly grow to a 300+Gigabits per second (Gbps) attack on Spamhaus.org, an anti-spam organization that they perceived as a clear and present danger to their spamming operations.
The attack –a stream of some 300 billion bits of data per second — was so large that it briefly knocked offline Cloudflare, a company that specializes in helping organizations stay online in the face of such assaults. Cloudflare dubbed it “The Attack that Almost Broke the Internet.
The campaign was allegedly organized by a Dutchman named Sven Olaf Kamphuis(pictured above). Kamphuis ran a company called CB3ROB, which in turn provided services for a Dutch company called “Cyberbunker,” so named because the organization was housed in a five-story NATO bunker and because it had advertised its services as a bulletproof hosting provider.
Kamphuis seemed to honestly believe his Cyberbunker was sovereign territory, even signing his emails “Prince of Cyberbunker Republic.” Arrested in Spain in April 2013 in connection with the attack on Spamhaus, Kamphuis was later extradited to The Netherlands to stand trial. He has publicly denied being part of the attacks and his trial is ongoing.
According to investigators, Kamphuis began coordinating the attack on Spamhaus after the anti-spam outfit added to its blacklist several of Cyberbunker’s Internet address ranges. The following logs, obtained by one of the parties to the week-long offensive, showcases the planning and executing of the DDoS attack, including digital assaults on a number of major Internet exchanges. The record also exposes the identities and roles of each of the participants in the attack.
The logs below are excerpts from a much longer conversation. The entire, unedited chat logs are available here. The logs are periodically broken up by text in italics, which includes additional context about each snippet of conversation. Also please note that the logs below may contain speech that some find offensive.



Friday, August 26, 2016

Source: The top three ways to avoid fraud | Consumer Information





In pretty much every article and blog post we put out, you’ll find tips to help you avoid scams. The idea is that, if you can spot a scam, and know how to avoid it, you and your money are more likely to stay together.
Today, we’re releasing a brochure that distills those tips down to the top 10 ways to avoid fraud. This brochure – available online and in print – is your one-stop resource to help you spot imposters, know what to do about robocalls, and how to check out a scammer’s claims.
Here are three things that can help you avoid scammers who try to call you:
  1. Hang up on robocalls. If you pick up the phone and hear a recorded sales pitch, hang up and report it to the FTC. These calls are illegal. And plentiful. Don’t press 1, 2 or any number to get off a list or speak to a person. That just means you’ll get even more calls.
  2. Don’t trust your caller ID. Scammers can make caller ID look like anyone is calling: the IRS, a business or government office…even your own phone number. If they tell you to pay money for any reason, or ask for your financial account numbers, hang up.  If you think the caller might be legitimate, call back to a number you know is genuine – not the number the caller gave you.
  3. Talk to someone. Before you give up money or information, talk to someone you trust. Scammers want you to make decisions in a hurry. Slow down, check out the story, search online – or just tell a friend. We find that people who talk to someone – anyone – are much less likely to fall for a scam.
For seven more tips to help protect yourself and loved ones from fraud, read on – or order your free copies of 10 Things You Can Do to Avoid Fraud to share in your community. And if you spot something that looks like a scam, report it to the FTC.
Tagged with: imposterrobocallscamtelemarketing


Wednesday, August 17, 2016

Source: Big banks join forces to fight cyber crime | Imperva Cyber Security Blog

Source: Big banks join forces to fight cyber crime | Imperva Cyber Security Blog



August 15, 2016



Big banks join forces to fight cyber crime

34347209_mWall Street Journal and Fortune recently reported that eight of the largest U.S. banks are forming an alliance to better combat the growing threat of cyber-attacks targeting the financial services industry. The new group, which is in the early stages of development, includes J.P. Morgan Chase, Bank of America and Goldman Sachs.
Specifically, the group will share threat information with each other, develop comprehensive cyber-attack response plans and conduct cyber war games that simulate attacks. The group will operate under the umbrella of the larger Financial Services Information Sharing and Analysis Center (FS-ISAC).
Cyber Security a Top Priority
This new group underscores the importance of cyber security for the financial services industry, which has long been in the cross-hairs of cyber-attacks. Consider the following:
While this new alliance consists of big banks, who have more complex environments, smaller financial service firms are not immune to cyber-attacks. As larger banks and financial institutions strengthen their defenses, cyber criminals will move downstream seeking easier targets. Regional banks, credit unions and smaller investment houses must make cyber security a top priority as well.
Sharing Threat Information Improves Security
35327594_mLet’s face it. The financial services industry (one could argue all industries) is fighting an asymmetric cyber war. The threats are ever-present and ever-changing. Cyber-attacks have become more sophisticated andindustrialized with attackers selling their services on the Dark Web. Security professionals are constantly a step behind attackers.
To get in front of growing cyber threats, financial services organizations must make a concerted effort to share cyber threat information. Sharing threat intelligence helps the financial services industry stay on top of new attacks, limit the causalities from emerging threats, and shortens the useful lives of attacks against banks and other financial firms.
Imperva recognizes the power of leveraging threat intelligence to improve security. We arm ourindustry-leading web application firewall with real-time threat intelligence. These threat intelligence feeds combine globally crowd-sourced data and research from the Imperva Defense Center.
Crowd-sourcing threat intelligence is vital because no single security team can stay abreast of today's dynamic threat landscape. Pooling the collective resources and knowledge across the financial services industry helps prioritize the threats to your institution, alleviates thecybersecurity skills shortage and significantly improve your institution’s security posture.
As a market leader in data and web application security, Imperva helps financial services organizations around the world protect against escalating cyber threats. Learn more about how our industry-leading data and web application security solutions can help your institution.

BookMark