October 2011 - Posts
Sunbelt security has issued a warning for the ChatSend application. It installs toolbars for all popular browsers and changes the user's home page. It then generates spammed messages extensively within Facebook. It is difficult to remove once installed and should be avoided if offered by any of your Facebook contacts.
Facebook - Avoid ChatSend application
This SecuriTeam post debates some of the pros/cons of corporate security awareness. Some firms rely solely on technology controls while others have a robust user awareness program. Somewhere in the middle is a good balance as both technology and the user play an important role in safeguarding the company's information resources. I would personally vote "YES" having seen direct and measurable benefits from past security awareness campaigns
Corporate Security Awareness - It is worth the effort and cost?
QUOTE: Is security awareness “worth it”? Is security awareness “cost effective”? Well, we’ve been spending quite a lot on security technologies (sometimes just piecemeal, unmanaged security technologies), and we haven’t got good security. Three arguments in favour of at least trying security awareness spending:
1) When you’ve got two areas of benefit, and you are reaching the limits of “diminishing returns” in one area, the place to put your further money is on the one you haven’t stressed.
2) Security awareness is mostly about risk management. Business management is mostly about risk management. Security awareness can give you advantages in more than just security.
3) Remember that the definition of insanity is trying the same thing over and over again, and expecting a different result.
Securiteam blogs has published an excellent security guide for hardening Microsoft's Hyper-V virtual environment
Windows 2008 R2 Hyper-V security Hardening Guide
QUOTE: Virtual Machine Servicing Tool 3.0 helps to update offline virtual machines, templates, and virtual hard disks with the latest operating system and application patches. Authorization Manager provides a flexible framework for integrating role-based access control into applications. It enables administrators who use those applications to provide access through assigned user roles that relate to job functions.
Please be careful with email, weblinks and Facebook as malicious threats are circulating. Several security firms are warning of online dangers:
Halloween 2011 - More online Tricks are circulating than treats
QUOTE: Halloween is fast approaching and it’s that time of the year when scaring people is the most popular form of entertainment. However, not all spooks this season may end up in good-natured merriment. Cybercriminals may take this opportunity to scare users with their tricks, which include spammed messages, poisoned search results, spammed tweets with dubious links and Facebook clickjacking attacks. If not wary of these schemes, users may end up becoming victims of information theft, system infection, and even financial loss.
Below are key security resources for VMware found during recent research:
VMware - Security Blog
VMware - Security Center
QUOTE: VMware offers secure and robust virtualization solutions for virtual data centers and cloud infrastructures, and has both the technology and the processes to ensure that this high standard is maintained in all current and future products. VMware virtualization gives you:
- Secure architecture and design: Based on its streamlined and purpose-built architecture, vSphere is considered by experts to be the most secure virtualization platform.
- Third-party validation of security standards: VMware has validated the security of our software against standards set by Common Criteria, NIST and other organizations.
- Proven technology: More than 250,000 customers—including all of the Fortune 100 as well as military and government installations—trust VMware to virtualize their mission-critical applications.
A new mobile malware threat has surfaced and disguises itself as a legitimate software offering from Opera. It is important to carefully check the authenticity of any software apps installed
Please always be careful of email message links or attachments that may be used to infect your system
Trend Labs - Video of Gadhafi’s Death Being Used for Spam
QUOTE: We’ve been seeing a particular social engineering lure in spam runs in the past, where spammers leverage the death of a known celebrity or political figure. Recent examples of this include the death of Steve Jobs, and Amy Winehouse. In this spam run using Gadhafi’s death, however, a more compelling lure is being used to trick users into downloading malicious files. We found several spammed messages that claim to lead to videos of Gadhafi’s death. It is important to note that videos of Gadhafi’s death do exist, and legitimate news sites like Reuters and The Washington Post tell of the graphic content in the video and even host the said videos on their websites. This existence of real videos of Gadhafi’s death relatively makes it a more compelling lure.
Major news events are often crafted into spam or malicious attacks as noted below:
Spam attack promotes false Charity Fund for Steve Jobs
QUOTE: Even after a few weeks following Steve Jobs’ death, spammers are still taking advantage of his demise. We have previously reported about this in the following blog entries:
This time, we received sample spammed messages promoting a supposed charity fund for young and gifted programmers and Web coders in honor of the late Apple co-founder.
This recent discovery by researchers could benefit future operating systems and security protection products in future
PC Magazine - New Technique Detects Hidden Exploits
QUOTE: Modern operating systems don't make life easy for malware coders. Features like Data Execution Prevention and non-executable memory pages ruin schemes that involve injecting malicious code disguised as data. Modern malefactors have turned to a technique called Return-Oriented Programming (ROP) to get around these restrictions. However, researchers Michalis Polychronakis and Angelos D. Keromytis from Columbia University have invented a way to detect this sneaky technique.
Instead of trying to inject malicious code into the system, the malware writers find the CPU instructions they want in existing processes, typically always-loaded Windows processes. They slip in a list that contains the in-memory addresses of these code chunks, called "gadgets". By forcing execution of the gadgets in a specific order, they build an exploit without ever placing executable code on the system.
This article documents some of the key new features designed into Android version 4.0:
Android 4.0 - Five Features for new mobile O/S
QUOTE: Android 4.0, Ice Cream Sandwich (ICS), is perhaps the most important Android release to date. With this release, Google has brought its tablet Android fork, 3.x, back into sync with its smartphone trunk, 2.x. In addition, all of ICS will soon, as I understand it, be made open source. What that means for you is that independent software vendors (ISV)s can stop wasting time in developing two different versions of programs and focus their energies on making the best possible Android applications. Since, at the end of the day, the success of any operating system is all about its applications, this bodes well for Android. Key categories of improvement include:
1) Better, more universal, interface
2) Better applications.
3) Speech transcription.
4) Better and faster Web browsing
5) Data use monitoring
Put it all together and what do you get? I think you get not just the best Android ever, I think you get the best mobile operating system of them all to date.
Ed Bott's review provides an excellent detailed assessment of the preview version of Windows 8,
A deeper dive into Windows 8: can Microsoft's big bet pay off?
QUOTE: There’s no question that this is a thoughtfully designed, thoroughly engineered release. If you had any doubts, just read through the Building Windows 8 blog, where Windows boss Steven Sinofsky and a parade of program managers have published one epic post after another explaining the history, evolution, and design philosophy that went into every new feature in Windows 8. This deeper dive is divided into four parts:
Page 2: The misunderstood Start screen
No, it’s not the “Metro shell.” It’s a full-screen replacement for the familiar Start menu. Brilliant idea or a bridge too far?
Page 3: What’s next for the Windows desktop?
There are virtually no “immersive,” Metro style apps for the Windows Developer Preview, which means anyone testing this pre-release is going to spend time in an environment that looks an awful lot like Windows 7. So what’s new? And what can we expect to change?
Page 4: To touch or not to touch?
This is the one complaint I’ve heard above all others. Do people really want touchscreens? Will they use them? I share my personal experience with three touch-enabled form factors.
Page 5: Security and reliability - Yeah, I know. Microsoft claims every version of Windows is more secure than the previous one. Windows 8 is no exception, but it pushes some boundaries with new features that have already inspired controversy.
The recent Government Computer News group shared a good write up on the changes associated with the new Metro UI and several more detailed informational links are included from the "Building Windows 8 blog"
Windows 8 - New Metro UI and start screen
QUOTE: Microsoft went a step further than that with the Windows 8 design and laid all of the programs out in a single view on the Start Screen, dropping the taskbar altogether from the Metro UI. That layout, in Microsoft's view, represents "the evolution of the Start menu." In this case, "evolution" means a collection of square and rectangular colored tiles, representing programs, all sitting right on the desktop screen.
Next, Alice Steinglass, group program manager for the core experience evolved team, took up the cause of explaining the Start Screen's design in Windows 8. Her main point is that the Windows 8 Start Screen functions as a sort of "dashboard that helps you stay up to date and connected in a high quality experience substantially improved over the notification tray." The notification tray on the taskbar was simply dropped in the Metro UI because it just added clutter to the desktop. Similarly, Microsoft dropped the folder approach in the start menu because "folders are a way of burying things, not organizing them."
This is an informative and excellent resource to track developments for Windows 8
MSDN - Building Windows 8 BLOG
Duqu is a sophisticated new threat which appears to have been written by the same group who authored Stuxnet (one of the most advanced malware attacks developed to date)
W32.Duqu - Advanced malware threat modeled after Stuxnet
QUOTE: Duqu is essentially the precursor to a future Stuxnet-like attack. The threat was written by the same authors (or those that have access to the Stuxnet source code) and appears to have been created since the last Stuxnet file was recovered. Duqu's purpose is to gather intelligence data and assets from entities, such as industrial control system manufacturers, in order to more easily conduct a future attack against another third party. The attackers are looking for information such as design documents that could help them mount a future attack on an industrial control facility.
Duqu uses HTTP and HTTPS to communicate with a command-and-control (C&C) server that at the time of writing is still operational. The attackers were able to download additional executables through the C&C server, including an infostealer that can perform actions such as enumerating the network, recording keystrokes, and gathering system information. The information is logged to a lightly encrypted and compressed local file, which then must be exfiltrated out.
Privacy invokes the protection of sensitive information as it flows throughout an organization. F-Secure has an interesting article related to the psychology of this process:
F-Secure: Privacy is a way of managing information flow
QUOTE: Why are people so willing to give away their personal information to complete strangers? It's because humans want to share information. And in fact, they share information a lot more freely than other "things" such as goods and services. Which of these are you most likely to provide without thinking much about it?
• To give a stranger directions to the bus stop (information).
• To take a stranger to the bus stop (service).
• To give a stranger bus fare (goods).
If you're like most people, you'll freely give directions, but you'll resist giving away your money. "Managing our privacy" isn't a natural act. What maintained our privacy in the past was that it was generally inconvenient to spy on people. Platforms such as Facebook present a new unique problem and new solutions (filters) are needed, rather than to re-tool old existing filters.
More Posts Next page »