Symantec recently issued it's Internet Security Report, which covers the second half of 2007. The key findings in the report are that malicious activity has become web based, attackers are going after end users rather than computers, the underground community is maturing and consolidating and the bad guys are getting better at improvising and adapting.
The report confirms that hacker tool kits are increasingly making it easier for less sophisticated types to effective commit technical crimes. Symantec also believes that these tool kits are being professionally developed, which supports the deduction that the underground community is maturing and consolidating.
Perhaps the availability of tool kits is the reason that a 559 percent increase in phishing websites has been noted?
The report also shows that the bad guys are going after "trusted" sites, such as social networking sites.
The underground economy in stolen financial details is also on the increase. These details, which are sold in Internet forums are getting cheaper. With all the phishing going on coupled with a record amount of data breaches an over abundant supply of stolen information is likely the reason for this. The report found a wide variety of pricing on payment card numbers, ranging from .40 cents to $20 per card.
The easy availability of encoders and other portable payment card technology makes it "too easy" to counterfeit the numbers into realistic looking plastic. In addition to this, there is a thriving market in counterfeit documents, which provides a wide-array of realistic counterfeit identification to vet the counterfeit financial instruments.
Besides identities and payment card details, stolen bank accounts are becoming increasingly available. Symantec attributes the increase in bank account information to a mirror increase in banking trojans over the second half of 2007.
Besides being used to clean out an account, bank account details are useful to criminals when they commit check fraud. Anyone, who follows scams on the Internet, knows that counterfeit checks are being delivered to unsuspecting mules to cash in a variety of advance fee (419) type scams. Please note there are organized gangs, who move from area to area committing check fraud using mules, who know exactly what they are doing, also.
Recently, an International task force monitored the mail and discovered large amounts of counterfeit checks being shipped throughout North America and the European Union.
All in all this report is a very interesting read. If you are a more visual type, Symantec also did a very nice flash presentation on this, which can be seen on the page linked to in the previous sentence.
Showing posts with label computer security. Show all posts
Showing posts with label computer security. Show all posts
Thursday, April 17, 2008
Monday, April 14, 2008
A final (???) salute to Attrition.org's Data Loss Database - Open Source
I came across some pretty sad news on Tom Fragala's blog that Attrition.org was throwing in the towel on their well respected DLDOS (Data Loss Database - Open Source).
In their own words, this is the reason why they are shutting down:
Perhaps, as I lamented in an earlier post, the pay for protection racket is getting a little out of hand? A good example of the frustration Attrition might feel is evidenced by some of the comment spam at the bottom of that post.
Please note for the record that I consider this blog a small one-person effort, which couldn't hope to keep up with the extensive amount of work the Attrition.org team put into maintaining this now "historical database."
Maybe this will be the last time, I can thank them publicly. Saying that, I will do so one last time for all they "did" for who really matters in the growing problem of too much information being stored in not very safe places. If you want to know who I am referring to, all you need to do is look in the mirror.
After all, most us have probably had our information compromised (sometimes more than once) in one of the data breaches catalouged in the Data Loss Database - Open Source.
I guess the old saying is true, "money is the root of all evil."
You can read the post from Attrition on this matter on their site, here.
Update 4/17/08: It appears that the DDLOS database might not be completely inactive. Emergent Chaos and Entering the Networked World are reporting that the database is generating new material.
If you go to Attrition's news page, Lyger has done a post "A new beginning." In it he announces a partnership with a new identity theft protection service:
Hmmmm...I've been looking for an ehtical way to monetize this blog, I wonder if they are accepting affiliates?
In their own words, this is the reason why they are shutting down:
Much like Attrition.org's past defacement mirror, the time has come for us to say "no mas". In the past few weeks, it has come to our attention that too many people are more concerned with making a profit off of our work without any offer of acknowledgement or compensation. For those who aren't familiar with Attrition, we're a non-profit hobby site that takes on "projects" as we see fit, when we want to, and when we have time. For those who *are* familiar with Attrition, you probably know that we don't take kindly to being dealt with unfairly. Commercial entities, including "identity-theft prevention" upstarts and book authors, will gladly contact us, ask for information and advice, and then not even offer us the equivalent of a reach-around when selling their materials. We don't pimp our resources to others; they come to us. Unfortunately, more often than not, they won't even send us a "thank you". We've mentioned it in the past, but we're not going to mention it in the future. This is the last mention.I've often mentioned the fine work the good folks at Attrition did on being a honest (not motivated by money) voice in what most of us agree is a serious problem. Because of this, I've always tried to point people directly to their work.
Perhaps, as I lamented in an earlier post, the pay for protection racket is getting a little out of hand? A good example of the frustration Attrition might feel is evidenced by some of the comment spam at the bottom of that post.
Please note for the record that I consider this blog a small one-person effort, which couldn't hope to keep up with the extensive amount of work the Attrition.org team put into maintaining this now "historical database."
Maybe this will be the last time, I can thank them publicly. Saying that, I will do so one last time for all they "did" for who really matters in the growing problem of too much information being stored in not very safe places. If you want to know who I am referring to, all you need to do is look in the mirror.
After all, most us have probably had our information compromised (sometimes more than once) in one of the data breaches catalouged in the Data Loss Database - Open Source.
I guess the old saying is true, "money is the root of all evil."
You can read the post from Attrition on this matter on their site, here.
Update 4/17/08: It appears that the DDLOS database might not be completely inactive. Emergent Chaos and Entering the Networked World are reporting that the database is generating new material.
If you go to Attrition's news page, Lyger has done a post "A new beginning." In it he announces a partnership with a new identity theft protection service:
Going forward, we would like to announce that we have a new partnership with Identity-Love-Sock, a trusted provider of identity theft prevention services. Not only can Identity-Love-Sock protect YOU from IDENTITY THEFT, it also provides several guarantees for your PROTECTION should YOU be affected by IDENTITY THEFT. With the services provided by Identity-Love-Sock , YOU will NEVER have to WORRY about your IDENTITY being STOLEN, MISUSED, or otherwise COMPROMISED. For more details on how YOU can be COVERED and PROTECTED, please visit Identity-Love-Sock . You'll be glad you did.
Hmmmm...I've been looking for an ehtical way to monetize this blog, I wonder if they are accepting affiliates?
Tuesday, February 05, 2008
Has the European Union become the primary point of origin for spam and scams?
Today, Kelley Conley (manager, Symantec Security Response) announced on their blog that the February State of Spam Report had been posted.
An interesting trend showing that the European Union was now the number one origin point for spam was noted:
Spam doesn't seem to be decreasing, either. January analysis by Symantec revealed that 78.5 percent of all e-mail sent is spam.
Other notable results from the report are that spammers a.k.a. scammers are busy taking advantage of a rumored tax rebate to steal people's identities and using Valentine's day deals to lure men to a dating site.
My guess is that we will see Valentine's day e-cards bearing malicious software pop up in the near future, also. Clicking on one of these normally turns your system into what I refer as a "spam spewing zombie." It's also a good way to have a keylogger implanted (dropped) on your system, which is capable of stealing all your personal and financial information.
Another persistent trend is spam offering too good to be true job offers, which entail tricking someone into laundering the proceeds of Internet crime. If anyone is considering getting involved in this activity, please be aware that I hear people are getting arrested after getting involved in one of these schemes.
Even when people don't get arrested, they end up being responsible for a LOT of money. Their identities are often used to commit more crimes without their permission, or immediate knowledge, also.
In case anyone wants more information on this, I've written a few "tidbits" about this type of scam (spam), which can linked to, here.
Spammers are also exploiting the global immigration issue by offering "too good to be true" offers of visa help in Europe. So far the targets are Russians and Ukrainians, but if this spam (scam) proves profitable, I'm sure it will be marketed (spammed), elsewhere.
Other notable trends noted in the report are new variations of porn scams, weight loss scams involving a promise to alter your genes and offers to turn a "ton of manure" into biofuel.
I found this especially ironic since it describes a great way to describe most spam, "manure." And if 78.5 percent of all e-mail being generated is spam, we are facing tons of "manure" on the Internet on a daily basis!
I guess that means that most spammers are full of "manure."
The full report, which I highly recommend reading can be seen, here.

(Picture courtesy of Josh Bancroft at Flickr)
An interesting trend showing that the European Union was now the number one origin point for spam was noted:
The February State of Spam Report highlights an interesting trend in the shift of spam moving from North America to EMEA. The percentage of spam originating from EMEA has surpassed that of North America, which represents a significant shift in where the bulk of the world’s spam is “supposedly” sent from.Well "supposedly," most of the spam is coming from the European Union. Here is the reason why:
Although it appears that way the very nature of spam distribution makes it difficult to accurately pinpoint the true geographic origin the sender. Spammers often take advantage of tricks that allow them to mask their real location and bypass DNS block lists.
Spam doesn't seem to be decreasing, either. January analysis by Symantec revealed that 78.5 percent of all e-mail sent is spam.
Other notable results from the report are that spammers a.k.a. scammers are busy taking advantage of a rumored tax rebate to steal people's identities and using Valentine's day deals to lure men to a dating site.
My guess is that we will see Valentine's day e-cards bearing malicious software pop up in the near future, also. Clicking on one of these normally turns your system into what I refer as a "spam spewing zombie." It's also a good way to have a keylogger implanted (dropped) on your system, which is capable of stealing all your personal and financial information.
Another persistent trend is spam offering too good to be true job offers, which entail tricking someone into laundering the proceeds of Internet crime. If anyone is considering getting involved in this activity, please be aware that I hear people are getting arrested after getting involved in one of these schemes.
Even when people don't get arrested, they end up being responsible for a LOT of money. Their identities are often used to commit more crimes without their permission, or immediate knowledge, also.
In case anyone wants more information on this, I've written a few "tidbits" about this type of scam (spam), which can linked to, here.
Spammers are also exploiting the global immigration issue by offering "too good to be true" offers of visa help in Europe. So far the targets are Russians and Ukrainians, but if this spam (scam) proves profitable, I'm sure it will be marketed (spammed), elsewhere.
Other notable trends noted in the report are new variations of porn scams, weight loss scams involving a promise to alter your genes and offers to turn a "ton of manure" into biofuel.
I found this especially ironic since it describes a great way to describe most spam, "manure." And if 78.5 percent of all e-mail being generated is spam, we are facing tons of "manure" on the Internet on a daily basis!
I guess that means that most spammers are full of "manure."
The full report, which I highly recommend reading can be seen, here.

(Picture courtesy of Josh Bancroft at Flickr)
Labels:
computer security,
identity theft,
scams,
spam,
symantec
Sunday, January 13, 2008
Blogger exposes security flaws on TSA site
Since 9-11, we've spent billions upgrading security. Here is a sad report about how the TSA (Transportation Security Agency) put up a NOT very secure site with some of the money earmarked for making the nation more secure.
Even worse, it seems it wasn't the TSA didn't even discover the problem themselves. The problem was brought to light by a blogger!
Here is some commentary from the government report that examines this problem:
The first time Chris was considered "notorious" was when he put a fake boarding pass generator on the Internet. This attracted a lot of attention in the press, as well as that of the FBI.
Chris recently moved his blog to a CNet address, which can be seen, here.
Chris recently blogged about this report and added a comment about the lack of spell check being used on the TSA site, "Furthermore, the site was filled with typos and other errors, causing some to wonder whether TSA's site had been taken over by phishers."
The official government conclusion is:
This led me to wonder if the TSA employees involved still have their jobs?
Much to my chagrin, I found my answer on the Committee on Government Oversight and Reforms press release on this matter:
Even worse, it seems it wasn't the TSA didn't even discover the problem themselves. The problem was brought to light by a blogger!
Here is some commentary from the government report that examines this problem:
In October 2006, the Transportation Security Administration launched a website to help travelers whose names were erroneously listed on airline watch lists. This redress website had multiple security vulnerabilities: it was not hosted on a government domain; its homepage was not encrypted; one of its data submission pages was not encrypted; and its encrypted pages were not properly certified. These deficiencies exposed thousands of American travelers to potential identity theft.The "hat tip" on this one belongs to a Chris Soghoian, who is a Ph.D. student at the University of Indiana’s School of Informatics. He used to write on the blog, "Slight Paranoia."
After an internet blogger identified these security vulnerabilities in February 2007, the website was taken offline and replaced by a website hosted on a Department of Homeland Security domain.
At the request of Chairman Henry Waxman, Committee staff have been investigating how TSA could have launched a website that violated basic operating standards of web security and failed to protect travelers’ sensitive personal information. As this report describes, these security breaches can be traced to TSA’s poor acquisition practices, conflicts of interest, and inadequate oversight.
The report reveals that the contract for the website was awarded without taking competitive bids to a company by a TSA employee, who was a former employee of the company designing the site. Even worse, it took months for the security flaws to be noticed and when they were, it was a blogger that brought them to everyone's attention!
The first time Chris was considered "notorious" was when he put a fake boarding pass generator on the Internet. This attracted a lot of attention in the press, as well as that of the FBI.
Chris recently moved his blog to a CNet address, which can be seen, here.
Chris recently blogged about this report and added a comment about the lack of spell check being used on the TSA site, "Furthermore, the site was filled with typos and other errors, causing some to wonder whether TSA's site had been taken over by phishers."
The official government conclusion is:
There were multiple factors that contributed to security vulnerabilities in the TSA traveler redress website. They included poor procurement practices, conflicts of interest, and weak oversight. The result of these shortcomings was that an insecure website collected sensitive personal information from American travelers for months without detection by TSA.
This led me to wonder if the TSA employees involved still have their jobs?
Much to my chagrin, I found my answer on the Committee on Government Oversight and Reforms press release on this matter:
Neither Desyne nor the Technical Lead on the traveler redress website has been sanctioned by TSA for their roles in the deployment of an insecure website. TSA continues to pay Desyne to host and maintain two major web-based information systems: TSA’s claims management system and a governmentwide traveler redress program. TSA has taken no steps to discipline the Technical Lead, who still holds a senior program management position at TSA.Full government report (PDF version, here.
Tuesday, January 01, 2008
Discovering a record amount of information theft only solves half the problem
Has anyone besides me noticed that when data breaches are reported, we see an official statement that the information hasn't been used by identity thieves?
After thinking on that one for awhile, it makes sense that criminals would stop using the information from a data breach after it has been reported.
So far as information used before the breach is discovered, it's pretty hard to prove where the information came from in an identity theft case. With so much compromised information out there, it's nearly impossible to figure out where the point-of-compromise is in any individual case.
When a data breach occurs, a lot of accounts are closed down and everyone who has been compromised runs out and checks their credit reports. Most of the time, free identity theft monitoring is made available to those who have been breached, also.
My guess is that once the stolen information is made public, it's probably dangerous to use. At the very least, it probably doesn't hold the same profit value that it had when no one knew it had been stolen.
For the past week, the news has been awash with the year end statistics on data breaches. By all the recent news accounts, 2007 was a record year.
While reporting data breaches is painful and costly, reporting them probably makes the information a lot harder to exploit for criminal purposes.
Although 2007 was a record number for reported data breaches, very few of criminals stealing the information got caught. Organizations losing the information are starting to be held accountable, but it would be nice to see more of criminals stealing the information brought to justice.
Another thing to consider is that data breaches aren't putting organizations out of business. True, they are costly, but in the end the cost is normally passed on to everyone using their services.
In the end, we are all paying for the cost of fixing data breaches.
And while a record number of data breaches were reported, there would have to be some that no one (except the criminals) know about.
My guess is that there is a lot information theft that is never detected. I would also surmise that this is considered the most valuable information being sold and used by criminals.
Compromised information is normally most effective when the person who it belongs to doesn't know it's being used.
Until we impact both sides of the equation -- the people losing information and punishing the people stealing it -- we are probably going to see news reports reflecting record statistics on the amount of data breaches occurring.
To do this, we need to focus more resources on catching the people stealing the information and enact laws that make it hurt when they get caught.
The last statistic I saw was that less than 1 percent of them get caught, and if they do, they normally get a slap on the wrist. A lot of the reasons for this are insufficient resources to investigate fraud and a lot of cases that are never reported by both organizations and individuals.
AP article (courtesy of the Washington Post) on 2007 data breach trends, here.
Update: Dissent from the Chronicles of Dissent and PogoWasRight left a good comment on this post pointing out that a lot of people did get caught this year. He is right and I did posts on a number of them.
The people out there catching the crooks stealing the data would be able to do a lot more if they were given more resources!
The Chronicles of Dissent has an excellent article on this subject that I highly recommend to anyone interested in the phenomenon of data breaches, here.
After thinking on that one for awhile, it makes sense that criminals would stop using the information from a data breach after it has been reported.
So far as information used before the breach is discovered, it's pretty hard to prove where the information came from in an identity theft case. With so much compromised information out there, it's nearly impossible to figure out where the point-of-compromise is in any individual case.
When a data breach occurs, a lot of accounts are closed down and everyone who has been compromised runs out and checks their credit reports. Most of the time, free identity theft monitoring is made available to those who have been breached, also.
My guess is that once the stolen information is made public, it's probably dangerous to use. At the very least, it probably doesn't hold the same profit value that it had when no one knew it had been stolen.
For the past week, the news has been awash with the year end statistics on data breaches. By all the recent news accounts, 2007 was a record year.
While reporting data breaches is painful and costly, reporting them probably makes the information a lot harder to exploit for criminal purposes.
Although 2007 was a record number for reported data breaches, very few of criminals stealing the information got caught. Organizations losing the information are starting to be held accountable, but it would be nice to see more of criminals stealing the information brought to justice.
Another thing to consider is that data breaches aren't putting organizations out of business. True, they are costly, but in the end the cost is normally passed on to everyone using their services.
In the end, we are all paying for the cost of fixing data breaches.
And while a record number of data breaches were reported, there would have to be some that no one (except the criminals) know about.
My guess is that there is a lot information theft that is never detected. I would also surmise that this is considered the most valuable information being sold and used by criminals.
Compromised information is normally most effective when the person who it belongs to doesn't know it's being used.
Until we impact both sides of the equation -- the people losing information and punishing the people stealing it -- we are probably going to see news reports reflecting record statistics on the amount of data breaches occurring.
To do this, we need to focus more resources on catching the people stealing the information and enact laws that make it hurt when they get caught.
The last statistic I saw was that less than 1 percent of them get caught, and if they do, they normally get a slap on the wrist. A lot of the reasons for this are insufficient resources to investigate fraud and a lot of cases that are never reported by both organizations and individuals.
AP article (courtesy of the Washington Post) on 2007 data breach trends, here.
Update: Dissent from the Chronicles of Dissent and PogoWasRight left a good comment on this post pointing out that a lot of people did get caught this year. He is right and I did posts on a number of them.
The people out there catching the crooks stealing the data would be able to do a lot more if they were given more resources!
The Chronicles of Dissent has an excellent article on this subject that I highly recommend to anyone interested in the phenomenon of data breaches, here.
Friday, December 14, 2007
Symantec reveals how the spammers are trying to steal Christmas
Kelly Conley announced the Christmas edition of Symantec's spam report on the company blog:
This month, three out of every four e-mails sent is spam!
Spammers are even using MP3s, videos, and Google's alerts/searches to spread their seedy marketing ventures to Internet users.
Here are some of the highlights of the end-of-year report:
The current interest in celebrities like Britney Spears, Lindsay Lohan and the Osmonds were used as lures to get people to open spam e-mails hawking "questionably safe" drugs.
Spammers use whatever is trendy, popular or in the news to trick people into clicking on them. Here is one of the sicker examples of this seen recently:
The report concludes it's findings with recognition of anti-spam efforts during the year, such as the FBI's Operation Bot Roast, the SEC's Operation Spamalot, ISP's sharing more information and security vendors employing new spam filter technologies.
We need to remember that spam is the vehicle used to spread 99.9 percent of the questionable marketing and scams on the Internet. Clicking on a spam e-mail can cause a person to become victim of anything from a financial scam to using a unsafe product that is a threat to their personal safety.
These reports serve a purpose, which is to educate the average person on what to watch out for and not click on a spam e-mail in the first place. Since it's Christmas and a lot of us are thinking about the young people in our lives, perhaps this is a good time to educate them on the growing problem of spam on the Internet!
I meet a few older people from time to time that might benefit from the education process, also.
Kelley Conley's blog post announcing the December report, here.
Symantec's December (year end) report on the state of spam, here.
On a lighter note, here is the YouTube video on the 12 days of Christmas Spam:
Here we are the end of another year. As 2007 rolls to a close the December State of Spam Report reviews this past month’s key trends and reflects on some of the year’s most notable spam events and trends.The report notes that Bill Gates' prediction in 2004 that spam would be eradicated has proven not only to be wrong, but that the amount of spam circulating on the Internet has exceeded everyone's expectations (nightmares?).
This month, three out of every four e-mails sent is spam!
Spammers are even using MP3s, videos, and Google's alerts/searches to spread their seedy marketing ventures to Internet users.
Here are some of the highlights of the end-of-year report:
• Penny stocks use Thanksgiving holiday captions in subject line – spammers using common personal Thanksgiving-related words in the subject of emails
• Replica products a favorite for spammers this holiday season – replica gear has always been a spammer favorite. Spammers are marketing their wares using seasonal words in the subject lines of their mailings
• Spam begins to snowball – spammers collecting email addresses by using a funny .gif that shows a snowball hurtling at you through your computer
• Christmas freebie anyone? – spammers taking advantage of the season to market "free" gift cards for well known companies
• Seasonal lotto scams - in a scam targeted at UK end users, spammers have updated a lottery spam email for a Christmas Bonanza special
The current interest in celebrities like Britney Spears, Lindsay Lohan and the Osmonds were used as lures to get people to open spam e-mails hawking "questionably safe" drugs.
Spammers use whatever is trendy, popular or in the news to trick people into clicking on them. Here is one of the sicker examples of this seen recently:
An attack this month preyed on the public interest in the story of the missing British child, Madeleine McCann. The email contained a link to http://madeleine2007.notlong.com/, which redirected to http://internetwonderful.com/madeleine. The second site is designed to look similar to the official McCann family site, www.findmadeleine.com, however, it actually is set up to distribute a virus. The site also contains an unauthorized use of the Symantec logo and a number of Google ads for anti-virus products.
It should be noted that although the spam email also contains a link to the legitimate findmadeliene.com site, there is no connection between the spammers and the genuine site.
The report concludes it's findings with recognition of anti-spam efforts during the year, such as the FBI's Operation Bot Roast, the SEC's Operation Spamalot, ISP's sharing more information and security vendors employing new spam filter technologies.
We need to remember that spam is the vehicle used to spread 99.9 percent of the questionable marketing and scams on the Internet. Clicking on a spam e-mail can cause a person to become victim of anything from a financial scam to using a unsafe product that is a threat to their personal safety.
These reports serve a purpose, which is to educate the average person on what to watch out for and not click on a spam e-mail in the first place. Since it's Christmas and a lot of us are thinking about the young people in our lives, perhaps this is a good time to educate them on the growing problem of spam on the Internet!
I meet a few older people from time to time that might benefit from the education process, also.
Kelley Conley's blog post announcing the December report, here.
Symantec's December (year end) report on the state of spam, here.
On a lighter note, here is the YouTube video on the 12 days of Christmas Spam:
Tuesday, December 11, 2007
Human beings are the reason for most security breaches!
If you think phishing is merely a financial crime, think again. Eleven employees at a nuclear research facility fell for a phishy e-mail, which appears to have been an attempt to steal information.
The New York Times reported:
Although the article suggests China may behind this attempt, the article suggests they have plausible deniability:
I guess it might have been a host of undesirables trying to steal this information. A lot of Internet misfits redirect through China to do their misdeeds on the Internet.
What's scary is that eleven employees at a Nuclear Research Facility clicked on a phisy e-mail and compromised sensitive material.
I recently wrote a post, where an official government audit revealed that 60 percent of IRS employees tested fell for a vishing scheme and gave up sensitive information.
Vishing is stealing information by telephone.
It was recently announced that private investigators are being indicted for vishing infomation in an illegal manner, sometimes referred to as pretexting.
All of these events would suggest that businesses and government organizations have a big opportunity when it comes to raising employee awareness on social engineering schemes that are used to compromise sensitive information.
IT also illustrates that human beings are the common cause for most breaches of security!
New York Times article, here.
Here are the two previous posts on the IRS vishing test and the indictment of private investigators for using social engineering techniques:
IRS audit reveals that the human factor is one the greatest threats to information (computer) security
Private Eyes charged with aggravated identity theft
The New York Times reported:
A cyber attack reported last week by one of the federal government’s nuclear weapons laboratories may have originated in China, according to a confidential memorandum distributed Wednesday to public and private security officials by the Department of Homeland Security.
Although the article suggests China may behind this attempt, the article suggests they have plausible deniability:
Security researchers said the memorandum, which was obtained by The New York Times from an executive at a private company, included a list of Web and Internet addresses that were linked to locations in China. However, they noted that such links did not prove that the Chinese government or Chinese citizens were involved in the attacks. In the past, intruders have compromised computers in China and then used them to disguise their true location.
I guess it might have been a host of undesirables trying to steal this information. A lot of Internet misfits redirect through China to do their misdeeds on the Internet.
What's scary is that eleven employees at a Nuclear Research Facility clicked on a phisy e-mail and compromised sensitive material.
I recently wrote a post, where an official government audit revealed that 60 percent of IRS employees tested fell for a vishing scheme and gave up sensitive information.
Vishing is stealing information by telephone.
It was recently announced that private investigators are being indicted for vishing infomation in an illegal manner, sometimes referred to as pretexting.
All of these events would suggest that businesses and government organizations have a big opportunity when it comes to raising employee awareness on social engineering schemes that are used to compromise sensitive information.
IT also illustrates that human beings are the common cause for most breaches of security!
New York Times article, here.
Here are the two previous posts on the IRS vishing test and the indictment of private investigators for using social engineering techniques:
IRS audit reveals that the human factor is one the greatest threats to information (computer) security
Private Eyes charged with aggravated identity theft
Labels:
computer security,
espionage,
Phishing,
social engineering,
vishing
Sunday, November 25, 2007
BBC article on UK data breach suggests why we are never sure if the information is used by criminals
Now that we KNOW the loss of computer discs containing the vital statistics of 25 million children in the UK wasn't caused by one person, everyone is probably going to start arguing (whether or not?) criminals are using the information.
Even worse, it's now been revealed that unencrypted discs with a lot of personal information were being sent snail mail as a routine method of transport.
Mark Ward at the BBC wrote an interesting article that suggests why we often aren't sure if the information is being used. In the article, he writes:
The bottom line is it can be almost impossible to track any one case of identity theft back to it's source. Furthermore, the criminals selling and buying aren't likely to advertise where they got it from.
Transparency is bad for criminals, also. It tends to get them arrested.
At this point in time, there have been so many data breaches we probably have no idea where the information came from when an identity is stolen.
The BBC article also covers a lot of common sense factors relative to protecting information. Time and time again, we discover that a lot of data breaches could have been prevented by using a little common sense.
The full BBC article (excellent read) can be seen, here.
The Privacy Rights Clearinghouse, Attrition.org and PogoWasRight are my favorite places to TRY to keep up on all the data breaches. As of this writing only PogoWasRight has information on this particular data breach.
Of course, these are only the occurrences that have been reported. My guess is there are probably many more that no one knows about.
Another safe bet is that the next big data breach not reported yet is probably happening right now!
Even worse, it's now been revealed that unencrypted discs with a lot of personal information were being sent snail mail as a routine method of transport.
Mark Ward at the BBC wrote an interesting article that suggests why we often aren't sure if the information is being used. In the article, he writes:
"In the fraud underworld the quality of data directly impacts the flexibility with which they can use it," said Andrew Moloney, financial services market director for RSA Security.
The more data you have around a subject the more different ways you can use that to commit fraud."
There was no evidence yet that the data was being talked about or sold on the fraud boards and net markets that his company monitors, he said.
However, most vendors of stolen data rarely mention where they got it from. Instead, they typically only mention its quality.
The bottom line is it can be almost impossible to track any one case of identity theft back to it's source. Furthermore, the criminals selling and buying aren't likely to advertise where they got it from.
Transparency is bad for criminals, also. It tends to get them arrested.
At this point in time, there have been so many data breaches we probably have no idea where the information came from when an identity is stolen.
The BBC article also covers a lot of common sense factors relative to protecting information. Time and time again, we discover that a lot of data breaches could have been prevented by using a little common sense.
The full BBC article (excellent read) can be seen, here.
The Privacy Rights Clearinghouse, Attrition.org and PogoWasRight are my favorite places to TRY to keep up on all the data breaches. As of this writing only PogoWasRight has information on this particular data breach.
Of course, these are only the occurrences that have been reported. My guess is there are probably many more that no one knows about.
Another safe bet is that the next big data breach not reported yet is probably happening right now!
Sunday, October 07, 2007
The somewhat slow response to the hacking of California.gov
With all the technology that California is famous for, you would think their government websites were state of the art, when it comes to security.
Apparently, this is NOT the case. The result has been a lot of misdirection to sites of a pornographic nature.
Alex Eckelberry, CEO of Sunbelt Software, has been blogging on this subject:
Bezhou Feng at Neowin.net reported that:
While the porn aspect is either amusing, or disgusting (depending on your viewpoint) -- this clearly shows that .gov sites should wake up and listen when experts are trying to tell them something is wrong.
After all, this type of activity could have been something far more serious than something that is disgusting, or amusing!
Of note, as of this writing, I ran a search on Google and the Marin site (TAM) is still misdirecting users to a number of pretty nasty porn sites.
As I've written before -- exercise extreme caution when clicking on porn sites, they often make your computer come down with a virus (or worse)-- especially if "safe surfing practices" aren't being used.
Sunbelt blog post, here.
Neowin.net story, here.
Update 10/09/07: Alex Eckelberry (Sunbelt), who has covered this problem for over a month did (what I consider) an amusing post to follow-up on this one, here.
Alex and his team at Sunbelt are my favorite place to learn about computer security issues. They routinely help a lot of people free-of-charge and are experts in what they do.
Apparently, this is NOT the case. The result has been a lot of misdirection to sites of a pornographic nature.
Alex Eckelberry, CEO of Sunbelt Software, has been blogging on this subject:
Yesterday, we reported on a federal shutdown of “ca.gov” sites to fix a hack.Does anyone besides me wonder if there wasn't much of a sense of urgency on this issue?
Well, we have a little more information on this. It was the Marin County government website that started all of this — something we reported back in September 12th.
Bezhou Feng at Neowin.net reported that:
The shutdown, initiated by the General Services Administration (GSA), a US agency in charge of all top-level ".gov" domains, began at roughly 4:00PM (PST), quickly turning into such a problem that Gov. Arnold Schwarzenegger even considered calling the President himself.
While the porn aspect is either amusing, or disgusting (depending on your viewpoint) -- this clearly shows that .gov sites should wake up and listen when experts are trying to tell them something is wrong.
After all, this type of activity could have been something far more serious than something that is disgusting, or amusing!
Of note, as of this writing, I ran a search on Google and the Marin site (TAM) is still misdirecting users to a number of pretty nasty porn sites.
As I've written before -- exercise extreme caution when clicking on porn sites, they often make your computer come down with a virus (or worse)-- especially if "safe surfing practices" aren't being used.
Sunbelt blog post, here.
Neowin.net story, here.
Update 10/09/07: Alex Eckelberry (Sunbelt), who has covered this problem for over a month did (what I consider) an amusing post to follow-up on this one, here.
Alex and his team at Sunbelt are my favorite place to learn about computer security issues. They routinely help a lot of people free-of-charge and are experts in what they do.
Labels:
alex eckelberry,
california,
computer security,
hacking,
porn sites,
sunbelt blog
Monday, August 06, 2007
Bizzare site asks viewers for money to keep a bunny from being butchered!
I was reading the Sunbelt blog, written by Alex Eckelberry and came across a post he did on a bizzare and pretty sick website.
In Alex's own words:

The whole intent of the site is to get a person to pay to save the bunny.

You can view the Sunbelt blog's entire presentation, here.
Paying to save the bunny isn't recommended and as Alex aptly states, one of the videos depicting a rabbit being skinned is "enough to make you a vegetarian."
This blog, according to a study Jonathan Edwards at Yankee Group has "mojo."
I can see why it does, besides providing a lot of great information, it tends to keep the interest of the people, who read it!
The Sunbelt blog is also an excellent place to keep up on, or learn about computer (information) security issues.
In Alex's own words:
save-me-please(dot)com is a site dedicated to saving a bunny.
We have no idea what this is odd thing is: A joke, a hoax. Or a scam.
The whole intent of the site is to get a person to pay to save the bunny.
You can view the Sunbelt blog's entire presentation, here.
Paying to save the bunny isn't recommended and as Alex aptly states, one of the videos depicting a rabbit being skinned is "enough to make you a vegetarian."
This blog, according to a study Jonathan Edwards at Yankee Group has "mojo."
I can see why it does, besides providing a lot of great information, it tends to keep the interest of the people, who read it!
The Sunbelt blog is also an excellent place to keep up on, or learn about computer (information) security issues.
Saturday, August 04, 2007
IRS audit reveals that the human factor is one the greatest threats to information (computer) security

(Courtesy of Flickr)
A new report issued by the Treasury Department's inspector general reveals that too many IRS employees compromised their user ID and password to an unknown person, who was actually a government auditor posing as a help desk employee.
Sixty percent of the IRS employees fell for the social engineering trick, sometimes referred to as vishing. This isn't the first time a test like this has been conducted. In 2004, 35 percent of the employees tested compromised information and in 2001, the failure rate was 70 percent.
In the recent past, the agency has also been criticized for it's aging computer systems and their name has been spoofed (impersonated) in phishing attacks.
I guess the IRS makes a good story, but they certainly aren't the only government agency, or private entity being compromised by activity like this.
Whether it's vishing or phishing -- where social engineering (fraud, deception etc.) techniques are used to trick people into giving up access to information that should be protected -- human beings are probably the biggest threat to information (computer) security.
True, the results of this report are shocking, but maybe we should listen to what it is telling us? If social engineering didn't work, my guess is that a lot of the current explosion in phishing and vishing activity would go away.
Even when malware, often referred to as crimeware, which steals information using technology is used, a human being has to be lured into clicking on a link, or visiting certain websites for the software to be implanted.
Maybe one of the problems is that people, who fall for these ploys are reluctant to admit they were tricked so easily? I've seen a lot of people fall for social engineering ploys, and not all of them are poorly educated, or what most of us would consider, stupid.
In fact, many us would probably be amazed at exactly who falls for social engineering ploys. Most people would rather remain anonymous because it's embarrassing to admit they were conned into whatever scheme they fell for.
Of course, the people I'm referring to have asked me to respect their privacy, and I'm an advocate of protecting that, along with being kind to victims, also.
Whether it is a government agency, big business, or non profit being targeted, the only thing that is consistent is we see more and more of this activity all the time. Trust me, if it didn't work, the criminals behind it wouldn't be wasting their time doing it.
If the activity is increasing, and social engineering it tied into most of it, the best thing we can do to defeat it, are more tests like these, combined with an effort to make people more aware of the problem.
While the results of this report aren't good, at least they are making the information public and not hiding it. My guess is that IRS employees aren't the only ones, who would fall for something like this.
Education and awareness are key in stopping this problem, which keeps growing by leaps and bounds!
Inspector General (Treasury Department) report, here.
Friday, May 25, 2007
Google launches security awareness effort using the blogosphere
There is another effort to curb fraud, phishing and financial misdeeds in the blogosphere. This week, Google launched a blog called the "Google Online Security Blog," which is designed to protect their users from the sometimes dangerous (murky) waters on the Internet.
In their own words (from their first post):
They have also included a link to a paper, which studies this issue.
Since Google (as far as I know) isn't selling security software, the paper is well worth a read. This isn't to say that a lot of the papers published by security companies aren't relevant, it just means that Google's effort isn't designed to sell security software.
They also point out that most of the sites they investigated that download malware a.k.a. crimeware belong to webmasters, who don't know they've been hacked and are being used to compromise systems.
This post was written by Panayiotis Mavrommatis and Niels Provos of Google's Anti Malware team and includes a link to StopBadware.org. StopBadware.org has a lot of great tips on how to protect and avoid the growing phenomenon of malware (crimeware).
Google's Online Security Blog can be seen, here.
I look forward to seeing what else they come out with!
In their own words (from their first post):
Online security is an important topic for Google, our users, and anyone who uses the Internet. The related issues are complex and dynamic and we've been looking for a way to foster discussion on the topic and keep users informed. Thus, we've started this blog where we hope to periodically provide updates on recent trends, interesting findings, and efforts related to online security. Among the issues we'll tackle is malware, which is the subject of our inaugural post.In this post they discuss "drive by downloads," which install what I call "cybernasties" on systems, often designed to steal personal, or financial details. They point out that Google already warns users of malicious sites in their search results and that users can prevent these sites from loading using Google Desktop Search.
They have also included a link to a paper, which studies this issue.
Since Google (as far as I know) isn't selling security software, the paper is well worth a read. This isn't to say that a lot of the papers published by security companies aren't relevant, it just means that Google's effort isn't designed to sell security software.
They also point out that most of the sites they investigated that download malware a.k.a. crimeware belong to webmasters, who don't know they've been hacked and are being used to compromise systems.
This post was written by Panayiotis Mavrommatis and Niels Provos of Google's Anti Malware team and includes a link to StopBadware.org. StopBadware.org has a lot of great tips on how to protect and avoid the growing phenomenon of malware (crimeware).
Google's Online Security Blog can be seen, here.
I look forward to seeing what else they come out with!
Labels:
badware,
blog,
computer security,
crimeware,
cybernasties,
google,
malware,
stopbadware.org
Saturday, March 10, 2007
Mike Rothman's book on being an effective CSO

Mike Rothman (CSO type and blogger) is now a published author in his own write.
What I like about his blog (in Security Incite) is that it takes a balanced approach to computer security (protecting information). His blog considers the technological, as well as, the social aspects of protecting information.
In my opinion, he takes a balanced (holistic) approach to increasingly important issues surrounding protecting information.
In Mike's own words (from Security Incite):
It is with great pleasure that I announce the availability of The Pragmatic CSO: 12 Steps to Being a Security Master. It's been an interesting process and I learned a lot. I'm sure you will be pleased with the outcome.
With protecting information becoming a huge issue, the fact that Mike approaches the problem via a learning process says a lot. Issues with protecting information change (sometimes daily).
This book is well worth a look at not just by CSO types, but it might be a valuable tool for anyone, who considers information a valuable asset.
Link to information on Mike's new book, here.
Wednesday, February 14, 2007
Spoofed (counterfeit) BBB e-mails contains virus
If you get an e-mail from the Better Business Bureau stating you have received complaints don't click on the link to view them.
Annys Shinn (Washington Post) is reporting:
Wandering to the BBB site to see what they had to say, I found a little more information. Apparently, if you click on the link, it downloads an executable file, believed to contain a virus.
The BBB and others are calling this a phishing attempt, but in phishing the intent is normally to get the user to provide personal, and or financial information to the sender. Since this doesn't seem to be the case, and no one is saying exactly what the executable file (virus) is, this doesn't appear to be phishing.
It will be interesting to see exactly what this executable file does, but some computer viruses (crimeware and malware) download keyloggers, which log a person's keystrokes and are used to steal personal and financial information.
Other computer viruses might turn a computer into a zombie, which allows someone else to use it for their own purposes (sending spam or denial of service attacks). Zombie computers are formed into what is known as botnets (groups of zombie computers), which are used for illicit purposes by their "controller."
You can download a lot of nasty things by clicking on something from someone you don't know. And the people behind it like to spoof well known entities, such as the BBB. Organizations from eBay to the FBI have been spoofed in the past.
Example of spoofed e-mail from the BBB site:
From: operations@bbb.org [mailto:operations@bbb.org]
Sent: Tuesday, February 13, 2007 6:06 AM To: XXXX
Subject: BBB Case #263621205 - Complaint for XXXX
Dear Mr./Mrs. XXXX
You have received a complaint in regards to your business services. The complaint was filled by Mr. XXXX on 02/05/2007/
Use the link below to view the complaint details:
DOCUMENTS FOR CASE #263621205
Complaint Case Number: 263621205
Complaint Made by Consumer Mr. XXXX Complaint
Registered Against: Company XXXX
Date: 02/05/2007
Instructions on how to resolve this complaint as well as a copy of the original complaint can be obtained using the link below:
DOCUMENTS FOR CASE #263621205
Disputes involving consumer products and/or services may be arbitrated. Unless they directly relate to the contract that is the basis of this dispute, the following claims will be considered for arbitration only if all parties agree in writing that the arbitrator may consider them:
- Claims based on product liability;
- Claims for personal injuries;
- Claims that have been resolved by a previous court action, arbitration, or written agreement between the parties.
The decision as to whether your dispute or any part of it can be arbitrated rests solely with the BBB.
The BBB offers its members a binding arbitration service for disputes involving marketplace transactions. Arbitration is a convenient, civilized way to settle disputes quickly and fairly, without the costs associated with other legal options.
Annys Shinn (Washington Post) is reporting:
The Better Business Bureau network was the target of a "spoofing" scam yesterday in which thousands of businesses in the United States and Canada received e-mails encouraging them to download what is thought to be a computer virus.Washington Post article, here.
The e-mails, using the name of the 95-year-old network of nonprofit groups that looks into consumer complaints, told businesses that they were the subject of a complaint and included a link to view related documents. Clicking on the link, however, accessed the address book of an infected computer and distributed the counterfeit e-mail to more recipients, said Steve Cox, spokesman for the Council of Better Business Bureaus.
Wandering to the BBB site to see what they had to say, I found a little more information. Apparently, if you click on the link, it downloads an executable file, believed to contain a virus.
The BBB and others are calling this a phishing attempt, but in phishing the intent is normally to get the user to provide personal, and or financial information to the sender. Since this doesn't seem to be the case, and no one is saying exactly what the executable file (virus) is, this doesn't appear to be phishing.
It will be interesting to see exactly what this executable file does, but some computer viruses (crimeware and malware) download keyloggers, which log a person's keystrokes and are used to steal personal and financial information.
Other computer viruses might turn a computer into a zombie, which allows someone else to use it for their own purposes (sending spam or denial of service attacks). Zombie computers are formed into what is known as botnets (groups of zombie computers), which are used for illicit purposes by their "controller."
You can download a lot of nasty things by clicking on something from someone you don't know. And the people behind it like to spoof well known entities, such as the BBB. Organizations from eBay to the FBI have been spoofed in the past.
Example of spoofed e-mail from the BBB site:
From: operations@bbb.org [mailto:operations@bbb.org]
Sent: Tuesday, February 13, 2007 6:06 AM To: XXXX
Subject: BBB Case #263621205 - Complaint for XXXX
Dear Mr./Mrs. XXXX
You have received a complaint in regards to your business services. The complaint was filled by Mr. XXXX on 02/05/2007/
Use the link below to view the complaint details:
DOCUMENTS FOR CASE #263621205
Complaint Case Number: 263621205
Complaint Made by Consumer Mr. XXXX Complaint
Registered Against: Company XXXX
Date: 02/05/2007
Instructions on how to resolve this complaint as well as a copy of the original complaint can be obtained using the link below:
DOCUMENTS FOR CASE #263621205
Disputes involving consumer products and/or services may be arbitrated. Unless they directly relate to the contract that is the basis of this dispute, the following claims will be considered for arbitration only if all parties agree in writing that the arbitrator may consider them:
- Claims based on product liability;
- Claims for personal injuries;
- Claims that have been resolved by a previous court action, arbitration, or written agreement between the parties.
The decision as to whether your dispute or any part of it can be arbitrated rests solely with the BBB.
The BBB offers its members a binding arbitration service for disputes involving marketplace transactions. Arbitration is a convenient, civilized way to settle disputes quickly and fairly, without the costs associated with other legal options.
Labels:
better business bureau,
botnets,
computer security,
crimeware,
cybercrime,
fraud,
identity theft,
malware,
spam,
spoofing
Subscribe to:
Posts (Atom)
