skip to main |
skip to sidebar
Todd Schriber is US Rep Rehberg's press aide (he has since been fired). He contacted attrition.org (of all places) to try to solicit a hacker to change his GPA. What follows is a truly classic piece of social engineering. It includes a reference to the Avian Network Protocol (RFC 1149), pictures of squirrels, and has the best movie-style hacker-babble I've ever seen.
Shouldn't need anything else. Have had a chance to set up a couple of IDS/IPS evasion bots, perimeter scanning came up clean. Small SQL injection issue merged with XSS shows that the backend database may be either 768-bit encrypted or a simple 3DES matter, but a little more time should take care of that issue. Once the tables are writable to sa, should be ready to jump in and jump out with no problem. One of their systems caught an early sniff, but was shut down with a smurf.
For the non-technical: trust me, the above makes absolutely no sense whatsoever. Which makes it funny, because good old Todd swallows it hook, line, and sinker.
My day job is in Information Security. Normally, I don't talk so much about that here. I get more than enough of that topic during work and with my off-hours research.
That being said, I would like to address an article that was linked to in one of the myriad of security related mailing lists I belong to. The article in question is by Greg Meckbach in IT Business titled There are only two IT network security issues.
Just from the title alone I could see I was going to have issues with this article. Some of the points are valid, such as the fact that physical security is not the domain of Information Security. Except he talks about IT managers not specifically Information Security (which is an entirely different beast). What follows is a post I sent to the security mailing list I got the link from. I have changed it somewhat, due to the fact that I am grammar impaired and I have had more time to think on this topic. However, the primary point I was trying to make is unaltered.
I agree with some of what Mr. Meckbach said, but a couple statements he made struck me as wrong (or perhaps mislabelled).
If a criminal could steal something as a result of hacking into a network, that again is a management problem. It's the manager's job to make sure sensitive information is not stored on accessible drives.
Wouldn't this fall under the category of "spying", which he specifically names as one of the two concerns?
Anyway, what does he recommend "management" do? (and which management? Operations, IT, HR?) Reduce the distribution of sensitive business information to sneaker-net? Create a secondary network which would require multiple NICs and custom config to guarantee one network cannot see another (even then, comprise a dual homed host and even that's useless), or require users to have a separate workstation for each isolated network?
The fifth issue - compliance with securities regulations - is supposedly one of the security problems with instant messaging, because some IM programs do not have an archiving capability, which would allow investigators to check every record of an employee's correspondence.
While this may be a problem, it's not a security problem. Letting employees communicate, without monitoring that communication, is the business manager's problem, not the IT manager's problem.
Mr Meckbach seems to be confusing IT management with Information Security. Yes, the decision to archive and monitor IM may ultimately be an executive-level decision, but the implementation is most definitely the communications group's responsibility (which would fall under IT). The actual risk assessment and use of mitigating controls in an attempt to pro-actively prevent or limit the type of information transmitted using IM, without a doubt, is an IS concern.
For any business that is concerned about these things, risk assessment is a major part of the security framework. And a company's Information Security team plays a large part in risk assessment and mitigation. IS's primary function is to allow the business to conduct it's day-to-day operations with as little risk as necessary. IS involves more than just securing a network and attached hosts.
Information Security is about information. While the majority of IS does involve technological systems and solutions, it also involves things like standards and practices, security policies, compliance, and risk assessment. I have seen the attitude expressed in this article before, but usually it comes from people that don't seem to understand the security is not an end unto itself. It is the means in which a company can conduct its business with relative safety.
While I do believe a line to be has to be drawn somewhere (unless we want to drown in unnecessary work), Mr. Meckbach seems to have a too strict a definition of what IS should encompass.
This is disturbing enough.
Authorities in northern New Mexico have stumbled onto what appears to be classified information from Los Alamos National Laboratory while arresting a man suspected of domestic violence and dealing methamphetamine from his mobile home.
Sgt. Chuck Ney of the Los Alamos Police Department said the information was discovered during a search last Friday of the man's records for evidence of his drug business.
Police alerted the FBI to the secret documents, which agents traced back to a woman linked to the drug dealer, officials said. The woman is a contract employee at Los Alamos National Laboratory, according to an FBI official who spoke on condition of anonymity because of the sensitive nature of the case.
You know after the Schroedinger's Hard Drive incident (first they were lost/stolen, then determined to never have existed), the ease of wandering into the facility, and other security gaffs, I'm no longer surprised at anything that happens at Los Alamos. Well, I take that back. I would be surprised if the only news that came out of there was actually science related and not about yet another security breach.
But this... this is what bothers me.
"Los Alamos has always seemed to be rewarded for its screw-ups," Brian said. "We're waiting with baited breath to see if anything has changed."
What is it you ask? Is it that I disagree with this statement? That I agree with this statement?
Neither.
Look at the quote again. Now read this site.
It's bated! Bated, you illiterate mockery of a journalist! Not baited. What, did he eat a worm, hence getting worm breath, hence baiting his breath to attract birds?
I thought if you were a journalist, you were required to have at least a passing familiarity with the English language. Thanks for making everyone who read your article just a little bit dumber.
God, I hate journalists almost as much as I do politicians.
UPDATE:
CNN, which is carrying the same AP article has the correct usage. But the FOX article, which is linked above, still has the incorrect usage. It looks like CNN had access to a dictionary.
This has got me a little concerned.
On October 17, 2006, an Islamist website posted a message titled "You Can Spy on the Enemies' Airports Directly by Controlling the Cameras' Direction." The message contains a link to a screen showing what it claims to be a live view of various areas within Anchorage International Airport via several cameras (http://209.193.48.89/view/index.shtml). The message gives directions for how to control the cameras and promises to provide links in the future for other airports as well.
The sample screen-shots on that page are from "Ted Stevens Anchorage International Airport". I thought one of the requirements of having a place named after you was being dead (or is it for his father?)
The TSA and Homeland Security like to tout their initiatives to prevent unlikely movie-style terrorist plots and waste time foiling unlikely binary explosives. How about they spend just a teeny amount on securing our nation's airport computer networks?
The new arena of war and agression is the Internet. And the new special forces in this theater are the hackers (for good or ill).
And if you don't beleive that Islamic terrorists do not have people actively attacking our network infrastructures... well, I have a bridge in Alaska I want to sell you.
Sounds like there's not a whole lot of work pressure at the Dept of the Interior.
Computer-use logs revealed more than 4,732 entries relating to sexually explicit Web sites and gambling sites. Some computers accessed sex sites for 30 to 60 minutes during the test period.
Department of the Interior. Don't they deal with parks and Jack Abramoff Native Americans?
Despite these ongoing issues, the department is sensitive to Internet misuse, having had several employees convicted in the past for various offenses, including possession of child pornography. The department has appropriate-use policies in place and conducts regular training, although it does not have a system[-]wide monitor or blocking system yet. Some bureaus within the department do use such tools, and there are plans to provide them department[-]wide.
Well, policies are a first step. But for them to be effective, they need to be enforced. Here's a case where a centralized security management system would come in handy. All the information from various monitoring and security tools gets aggregated in one place. With the correct data mining techniques you would be surpirsed and the kind of information and conclusions that can be pulled.
I don't see this improving any time soon. They got an "F" on the government's security audit in 2005 (so did Homeland Security -- yikes!). Unfortunately, I have a feeling they'll concentrate on only the perimeter, as most people mistakenly do. Not a bad thing, but we like to call that crunchy on the outside -- chewy in the middle in my business.
Regardless, they have these slope-brow, lazy-ass freaks playing games and wanking to porn when they should be doing their job. It sounds a lot like economic agency models (PDF file) at work. (via Prof. Bainbridge's article on Casino Dealers). It looks like there's no incentive here to do real work. Nor much punishment to correct behavior (unless you download child-porn -- people tend to get worked up over that). Most government employees get paid no matter what their level of performance.
Perhaps I should get off my high horse. Because, I am supposed to be... uh... working right now.
Phishing
Everyone has seen these emails. Messages from PayPal, EBay, a credit card company, or a bank. It's been happening for years, and a small percentage of users still fall for this trick. Here are some key indicators that an email message is actually a phishing attempt.- Lack of personalization: These are emails that start "Dear Bank Customer". You are a customer, but they don't know who you are? Puh-lease.
- Grammar and spelling: I would think that a financial institution would probably have someone fairly fluent to compose messages for the public. Some emails have an odd cadence to them, also. This is usually indicative of a non-native English speaker applying his (or her) native language's grammar rules to English (or they used Google Translate).
- Lack of Branding: There's no brand awareness in the email. No logos, copyright/trademark information. Although this has changed over the years. Savvy scammers have been creating very convincing layouts.
There are other indicators that are there, but difficult to discern unless you have some technical background. But all is not lost. There are a couple rules of thumb that you can apply:- Never, and I mean never, click on a link in an email. If you need to go into your portal, be it a bank or EBay, open a new browser and type the address in or use your bookmark to go directly to the site.
- If a site is asking for information like CC number, PIN, CCV, etc... close your browser immediately. Unless, of course, you are legitimately using this information at an online store.
For much more information, please look at this site.
419 Scams
These scams are named after the relevant section of the Nigerian Criminal Code regarding "Advance Fee Fraud." These are the emails offering you an incredible job, an opportunity to launder money to keep it from corrupt governments, a bequest left in a will, and lottery winnings. These are all fake.
They usually involve long drawn out email and phone conversations to work out the details of the monetary transfer of millions of dollars to the victim's bank account. Of course, first the victim has to send an account number along with bank routing details. After that, the victim's account is plundered and the scammer is never heard from again. Sometimes, the less ambitious scams will instead ask for a money order of hundreds or thousands of dollars to help facilitate the transfer (for bribes, regulatory fees, bank fees, whatever the scammer can dream up). Again, after the money is on the way, the scammer disappears into the murky depths of the Internet, never to be heard from again.
Sometimes it can be more serious. The scammer will draw the victim deeper into the web, sometimes convincing them to meet in some supposedly neutral city to complete the transaction. They are then taken for whatever they have (credit cards, money, cameras, jewelry). At times this involves assault, kidnapping (for ransom), and even murder.
If you get email like this, delete it. These are fake. Every. Single. One.
You can't get something for nothing.
For more information see this site.
To read about 419ers getting the tables turned, go here.