If you are like most people and myself, you do not go into a bank and have a conversation with a teller when you make a deposit or withdrawal. You probably do not write paper checks and sign them. You have an app on your phone to access your bank account and use one of the thousands of automated teller machines (ATM), around the world to move money in and out of your accounts.
The financial world is very different with the advent of the internet and near real-time information. Gone is the time when Leonardo DiCaprio Frank Abagnale Jr. can forge checks and cash them at banks around the country. Today’s verification systems will flag the bad check immediately through online record matching. All of this information flying between branches and banks through the network depends on security technologies to protect the money as well as the personal information tied to all of the bank accounts and transactions.
Financial institutions have a responsibility to protect sensitive information on their systems and through their networks. The business must protect the data at rest, the data in transit, and the systems holding and transmitting the data.
Data at rest
Encryption algorithms and hashes are used to obscure the data within the applications and databases. There are many methods to protect the databases varying from field level encryption to solutions that encrypt the entire database. The method used often depends on the application requirements and how often individual records within the database are being updated.
All financial and personal information within these databases are vulnerable. The encryption protects the data even if the database is stolen by a malicious person. Without the proper key or credentials, the hacker will not be able to decipher the contents of the database
Data in transit
For the past 20 years, SSL/TLS has been the encryption standard for communications over the network. The algorithms to encrypt the data have advanced as computer technologies have improved over the years. Today, the internet is using the RSA algorithm with 2K keys to encrypt data on the network. Elliptic curve cryptography (ECC) is emerging as a new standard with 256-bit keys to address the advancements in computing power.
The encryption standards and keys are important because the data is most vulnerable when it is in transit. The original data is often unencrypted so it is important for the network transport protocol to provide security and encryption. This is like taking a valuable item out of the secure vault and transporting it within a protected armored car to the destination, hopefully another vault. SSL/TLS is the armored car for the internet.
Systems accessing data
The data is not the only concern for financial institutions. They need to be concerned with the applications and tools that have access to the data. If the vault is compromised, it does not matter how strong or secure the armored car is. This is most likely what happened in the recent Equifax case. They used an application that had a vulnerability that the hackers exploited to access the data.
Businesses often assume that the applications accessing the data are secure. There are two problems with this assumption. First, as in the Equifax case, the application is not secure. There are vulnerabilities in software that can be exploited to access sensitive information. Applications need to be validated through a process to ensure that they are secure.
The second problem is that people access the data through the applications. People are the weakest link in the security chain. They can accidentally share their credentials, download malware, or expose sensitive data. Policies and security technologies need to be implemented to minimize the potential negative impact of an inadvertent or intentional mistake that a person makes.
Inspecting and securing the data
The application delivery controller (ADC) provides three key functions to secure the data within the financial institution. As a reverse proxy or load balancer, the ADC is a key network component to make the application data available and secure.
The ADC is the SSL/TLS termination point for the network communications. It needs to offer high performance encryption and decryption while supporting today’s RSA encryption standard and tomorrow’s ECC algorithm. Over 50% of the internet is encrypted today, and it is assumed that the financial services traffic percentage is higher due to its sensitivity.
Inbound SSL inspection solutions are necessary to protect the applications from threats. As the encryption termination point, the ADC can steer the decrypted content to different security solutions to inspect the traffic before it reaches the application. Financial institutions may use web application firewalls (WAF), next generation firewalls, intrusion prevention systems (IPS), and/or data loss prevention (DLP) technologies to protect their applications and servers.
Finally, the ADC provides outbound SSL inspection capabilities to protect the people from the internet threats. Outbound SSL inspection solutions decrypt and steer traffic between the users and the internet to security solutions. The security solutions look for malware, phishing sites, and other internet threats to protect the users and their internal systems.
Financial data is sensitive and vulnerable with the potential to affect every single person, if exposed. All businesses involved in the financial services industry must do their due diligence and ensure that appropriate architectures and solutions are put in place to protect the information that they manage. It is almost impossible to do too much to protect this information. If they do not take a fresh look at their security policies and practices, the Equifax breach may be the tip of the iceberg.
Source: radware
Financial Institutions Must Protect the Data Like They Protect the Money
GOOGLE WARNS OF DOS AND RCE BUGS IN DNSMASQ
Seven flaws in what is known as Dnsmasq can be exploited by attackers who can use the bugs to carry out remote code execution, information exposure or a denial of service attacks against affected devices.
Google researchers identified the flaws in a research paper published Monday, the same day a patch for affected hardware arrived. Google also published proof-of-concept code to demonstrate the flaws and is urging hardware vendors to deploy patches as soon as possible.
Dnsmasq is open-source software that can be found in Android OS and Mac OS X. It’s also included in popular desktop Linux distributions including FreeBSD, OpenBSD and NetBSD, and in home routers, IoT devices and for tethering of smartphones and portable hotspots, said Google.
“During our review, the team found three potential remote code executions, one information leak, and three denial of service vulnerabilities affecting the latest version at the project git server as of September 5th 2017,” wrote researchers behind the Google Security Blog.
The Dnsmasq software package acts as a local domain name system (DNS) helping devices identify other devices and route traffic within small networks. “(Dnsmasq) is designed to be lightweight and have a small footprint, suitable for resource constrained routers and firewalls,” the maintainer of Dnsmasq, Simon Kelley, said.
On Monday, Kelley announced a fix for the vulnerability that includes upgrading to Dnsmasq version 2.78. All versions of Dnsmasq 2.77 and prior contain the multiple vulnerabilities.
“I’ve just released dnsmasq-2.78, which addresses a series of serious security vulnerabilities,” Kelley said. “Some of these, including the most serious, have been in Dnsmasq since prehistoric times, and have remained undetected through multiple previous security audits.”
According to Google, its Android partners have or will receive a patch as part of the October Android security update released Wednesday.
Google said the Dnsmasq vulnerabilities can be triggered remotely via DNS and dynamic host configuration protocol (DHCP) that could lead to the remote code execution, information exposure and denial of service conditions.
DNS attacks can be problematic for companies ill equipped to mitigate against them, a survey of firms said last month.
“Despite heightened DDoS attacks, many companies have inadequate defenses when it comes to DNS security,” the study, carried out by security firm Infoblox said.. The study found one-third of “professionals” surveyed doubt their company can defend against a DNS attack.
In the case of Dnsmasq, the three remote code execution vulnerabilities (CVE-2017-14491, CVE-2017-14492 and CVE-2017-14493) are tied to heap buffer overflow and stack buffer overflow errors through DHCP and DNS.
Another three vulnerabilities (CVE-2017-14495, CVE-2017-14496 and CVE-2017-13704) are denial of service bugs caused by invalid boundary checks, bug collisions and memory leakage.
The bug for the information leak (CVE-2017-14494) can be exploited to bypass the address space layout randomization (ASLR) memory protection function and allows remote attackers to obtain sensitive memory information via vectors involving handling DHCPv6 forwarded requests, according to the Common Vulnerabilities and Exposures (CVE) description.
Source: threatpost
NETGEAR FIXES 50 VULNERABILITIES IN ROUTERS, SWITCHES, NAS DEVICES
Netgear recently issued 50 patches for its routers, switches, NAS devices, and wireless access points to resolve vulnerabilities ranging from remote code execution bugs to authentication bypass flaws.
Twenty of the patches address “high” vulnerability issues with the remaining 30 scored as “medium” security risks. Netgear posted advisories for the bugs to its website over the last two weeks.
Network security firm Beyond Security is credited by Netgear for discovering several of the vulnerabilities patched last week. One of the issues was a command injection vulnerability in the ReadyNAS Surveillance Application running on versions prior to 1.4.3-17 (x86) and 1.1.4-7 (ARM). A command injection attack can execute arbitrary commands on host operating systems via vulnerable applications that facilitate the passing of unsafe user supplied data (forms, cookies, HTTP headers) to a system shell.
“These are all vulnerabilities caused by what appears to be inadequate verification of user input, oversight on what should and should not require authentication, and improper mechanism of enforcing security on users accessing their product web interface,” Noam Rathaus, founder and CTO of Beyond Security said. “I believe much of Netgear products share the same codebase and same underlying code structure which is what causing many of their products to be vulnerable.”
In addition to Beyond Security, researcher Martin Rakhmanov of Trustwave, and researcher Maxime Peterlin with ON-X Security are also credited for finding vulnerabilities in Netgear products.
“Some of the issues reported are pretty severe,” said Rakhmanov. One of those vulnerabilities (PSV-2017-1209) is a command injection security vulnerability tied to 17 consumer routers running vulnerable firmware.
“This vulnerability would allow any local user to take full control of the router,” Rakhmanov said. “Luckily ‘Remote Administration’ is not turned on by default, but if it were turned on manually this could make the router vulnerable to anyone on the Internet.”
Netgear told Threatpost that most of the vulnerabilities and patches disclosed last week were reported via the company’s bug bounty program,launched in January in partnership with Bugcrowd. Since inception, the company has made several disclosures via the program, including a password bypass bug found in hundreds of thousands of Netgear routers reported earlier this year.
In this most recent wave of disclosures, affected products range from networking gear used in IoT applications such as the ProSAFE M4300 Intelligent Edge Series switch to a consumer-grade Netgear D6400 Wireless Router.
“We are taking the security of our products very seriously and have been working closely with Bugcrowd to help monitor instances of potential security vulnerabilities,” said a Netgear spokesperson. “We work with Bugcrowd to identify potential vulnerabilities and release fixes in bulk, which is why you saw the quantity you did come across last week.”
The company said it is working on an automated processes for a more even distribution of disclosures in the future.
Netgear has faced criticism in past by Beyond Security’s Rathaus for allegedly dragging its feet when it comes to acknowledging technical claims of a vulnerability and the subsequent coordinated advisory.
From Trustwave’s vantage point Netgear is on the right track. “We’ve been working with Netgear through their responsible disclosure process for quite some time and watched them mature tremendously including their current participation in bug bounty programs,” Rakhmanov said.
Netgear isn’t the only networking equipment firm scrambling to patch bugs over the past year. Last month, independent researcher Pierre Kim found a wireless router made by D-Link had nearly one dozen critical vulnerabilities. In April, researchers at IOActive found more than 20 Linksys router models vulnerable to attacks that could allow a third party to reboot, lock out and extract sensitive router data from affected devices. ASUS reported in May vulnerabilities in 30 models of its popular RT routers.
Rathaus blames router and IoT vendors that, he claims, for years have put little effort into security, testing and hardening of products.
“Today using sites such as Shodan you can locate hundreds to hundreds-of-thousands of devices all vulnerable to serious bugs that allow compromising of the device without requiring any authentication or any information beside the IP address of the device,” Rathaus said.
Rathaus said researchers at the firm have reported 60 similar authentication bugs this year alone.
“Every once in a while something unique (a new type of vulnerability) shows up, but in numerous cases it’s the same type of vulnerabilities over and over again,” he said. “Vendors are not spending enough time tracking down these bugs before the product becomes public.”
Source: threatpost
FIVE CRITICAL ANDROID BUGS GET PATCHED IN OCTOBER UPDATE
Four critical vulnerabilities were reported by Google Monday as part of its October Android Security Bulletin. In all, 14 patches were issued for corresponding vulnerabilities, ranging from critical to high.
The relative low bug count for the month of October is due to the fact this month Google announced it would handle security bulletins differently. It introduced a separate monthly Pixel/Nexus Security Bulletin that covers bug fixed for these specific devices.
The Android Security Bulletin will continue to report on partial patch levels and complete patch levels monthly. But because of this change Google only reported just over a dozen vulnerabilities for the month of October.
Three of the vulnerabilities, rated critical, are tied to remote code execution bugs found in the Android media framework. Another two critical vulnerabilities are related to Qualcomm components.
The Android Security Bulletin also contains a fix for the Dnsmasq software flaws impacting Android OS and also Mac OS X, various Linux distributions and routers and IoT devices.
Google said one of the most severe bugs this month was an escalation of privileges (EoP) vulnerability (CVE-2017-0806) impacting Android versions 6.0 (Marshmallow) through its most recent Android 8.0 (Oreo) OS. According to Google, the vulnerability “could enable a local malicious application to bypass user interaction requirements in order to gain access to additional permissions.” That could lead to further attacks.
Other “severe” bugs, according to Google, included two vulnerabilities found in Android kernel components that could enable a local malicious application to execute arbitrary code within the context of a privileged process.
One of the two EoP vulnerabilities is CVE-2017-7374 and impacts the Android filesystem. According application security firm F5 Networks, the bug is a use-after-free vulnerability in cryptographic file system (fs/crypto/) in the Linux kernel. It allows local users to cause a denial of service condition or possibly gain privileges by revoking keyring keys being used for file systems ext4, f2fs, or ubifs encryption. That can cause “cryptographic transform objects to be freed prematurely,” F5 Networks said.
A second severe vulnerability includes the EoP CVE-2017-9075, also tied to the Android kernel and the network subsystem. “An unprivileged local user could use this flaw to induce kernel memory corruption on the system, leading to a crash. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believe it is unlikely,” wrote security experts at Brocade.
The October bulletin also includes a bevy of fixes on the hardware side of the house, including patches for drivers for MediaTek and Qualcomm hardware.
Two of the Qualcomm vulnerabilities are critical. CVE-2017-11053 is a fix for an issue with the system-on-a-chip driver that allows remote code execution. A second Qualcomm vulnerability (CVE-2017-9714) addresses a bug in the network subsystem and blocks privilege escalation.
The last patch, rated as high severity, is tied to a MediaTek system-on-a-chip driver vulnerability (CVE-2017-0827). Google says the flaw could enable a local malicious application to execute arbitrary code within the context of a privileged process.
As for the Pixel/Nexus Security Bulletin, Google lists 38 security vulnerabilities. The company says the vulnerabilities impact the Android OS and components manufactured by Broadcom, HTC, Huawei, Motorola and Qualcomm.
“Security vulnerabilities that are documented in (the Android) security bulletin are required to declare the latest security patch level on Android devices. Additional security vulnerabilities that are documented in device / partner security bulletins are not required for declaring a security patch level,” Google said of the new bulletin.
Source: threatpost
Cybersecurity researchers warn Facebook users to beware Faceliker malware
As nowadays social media is an inseparable part of society’s social life, naturally scammers prey for victims online. Phishing messages[1] or compromised web links can easily trick unsuspecting users into providing sensitive information or installing dangerous malware on their computers unknowingly.
There’s plenty of space for discussions about fake news on social media that users are likely to click, especially if they see their friends liking such posts. However, such fake news are often promoted by bots or accounts compromised by Faceliker malware.
McAfee experts[2] have spotted an unexpected surge of Faceliker Trojan, a malicious virus that takes control over Facebook accounts and uses them to promote certain content on social media. The security firm claims that the malicious virus takes 8.9% of 52 million new malware samples in the Q2 of 2017.[3] Experts suggest that the rise of Faceliker significantly influenced the overall growth of newly discovered malware.
Modus operandi of the virus
According to the research team from the aforementioned security firm, Faceliker compromises victims’ devices as soon as they visit a malicious domain online. The malware tricks people into thinking that they like things they want when the virus actually redirects the click and likes an entirely different thing on Facebook instead. This way, the click-fraud Trojan[4] falsifies likes on content it seeks to promote.
VirusActivity experts advise[5] that users who have noticed suspicious content appearing in their feeds should immediately check their activity logs on Facebook to see whether there were some unauthorized attempts to use their accounts for promoting particular online content.
In case the user detects some suspicious activity, an immediate Facebook virus removal is required, as well as actions to protect user’s account. The first thing victims should do is to run a system scan using up-to-date anti-malware software, and secondly, changing Facebook passwords. Besides, users can un-like the content that was liked without their consent.
Facebook malware more dangerous than it seems
Although Faceliker virus does not infect victim’s device or distribute malicious links, it operates silently and without user’s knowledge. Besides, liking and promoting vague content online using victim’s account without one’s knowledge is an illegal activity. Therefore, Faceliker removal is a highly suggested option.
Since Facebook is one of the most popular social network platforms available today, criminals rush to take the opportunity and spread malicious viruses via it. In case you noticed that your friend shared a suspicious link or sent you a message that looks fishy, warn your friend using a different contact method (phone call or message) and let them know what happened to their accounts. They might not be aware of Facebook virus acting on their behalf online.
Source: 2-spyware
Send nudes? That’s what nRansom asks in exchange to your locked files
Nude photos – as digital currency
A few days ago, virus researchers had a good laugh after they found nRansom ransomware. Not only the ransom message evoke smile after seeing its logo with the Thomas the Tank, but the demands are hilarious and absurd as well. Unlike typical ransomware, for instance, Ykcol (new Locky) which again raised the price up to 0.5 bitcoins, this malware asks for 10 your nude photos. Is it a new generation ransomware or a mere prank?
nRansom – hackers’ sort of “vacation”?
However, 10 nude photos are only the beginning of the story. The perpetrators instruct victims to send the photos to 1_kill_yourself_1@protonmail.com. They continue making fun of users by stating that they will not reply instantly.
What is more, the felons mention that they will verify the photos. However, the methods of such verification indeed spark intrigue. Even if victims risk sending the compromised material, the hackers will send you the decryption key and still publish the photos on the dark web.
Interestingly, the developers launched a second version after a couple of days since the original version appeared. The latest edition functions via nRansom2.exe file and asks you to kill 10 people, send the video as well as 20 personal nudes. The email address changes to 2_kill_yourself_2@india.com.
This type of ransomware may indeed seem funny, but not for the victims of the threat. However, they may not know the fact that nRansom virus is actually a screen locker rather than a file-encrypting threat. The unlock code was 12345, though it seems to have ceased functioning anymore as well as the first email address is shut down.
At the moment, there are no reports about the victims (on the other hand, who would confess?). While this malware is a buggy screen locker, the fact that the fraudsters continue generating new versions of this prank might be worrying.
A prank to direct attention from bigger cyber issues?
Looking from IT researchers’ perspective, nRansom screen locker is indeed an easy virus to crack. Now their attention rests on Locky which continues rampaging in the new form of Ykcol version. CryptoMix devs also restlessly generate new versions the latest being Shark virus.
The “white hats” also have to solve the riddle how cyber criminals managed to corrupt CCleaner v5.33 version.
As users find themselves in the midst of these cyber wars, they have to pay attention to these tips:
update system and security tools
avoid installing programs which are issued by “unknown publishers”
verify the sender of an email attachment
double-check and inquire your friend about the sent video link on a social media
Source: 3-spyware
Credit card thieves are getting smarter. You can, too
Card skimmers have gotten so advanced, even experts may be fooled. But there's a way to spot at least some of them.
With one swipe of a credit card, you've just paid for some gas. You may also have given thieves some very valuable information.
That's if you've just fallen victim to a skimmer.
Card skimmers, which steal your credit or debit card data when you swipe at payment and money machines, have been around for nearly a decade, disguised so you don't know you're being duped. The devices have evolved, though, and researchers say they're now at the point where you really, really can't tell the difference.
Plus, they've swept across the United States at an alarming rate. The number of breached ATMs increased sixfold from 2014 to 2015 and rose again in 2016 by 30 percent, according to FICO, an analytics software company. In June of this year, the Federal Trade Commission put out a public warning, with tips on how you can avoid having your card information stolen.
Hackers have figured out how to create virtual skimmers -- malware that's installed remotely -- which let them steal card information without even touching the ATM, fuel pump or other device. It's an evolution from the physical skimmers, where thieves had to walk up to a machine to plant their hardware hack. In January 2016, one hacking campaign that used virtual skimmers across multiple ATMs netted thieves $13.5 million euros, security firm Trend Micro discovered.
Skimmers are getting harder and harder to notice, according to Mark Nunnikhoven, Trend Micro's vice president of cloud security. "If a machine has been compromised with software," he said, "there's no way you're able to tell."
As if you didn't already have enough to worry about when it comes to computer security.
This year alone has brought a number of threats from all kinds of angles. A few months back, ransomware took over PCs around the world, holding them hostage for payment, and that likely won't be the last time. Just last week, word came that some versions of the popular CCleaner software had been infected with malware.
Then on the credit card front, there's that massive Equifax hack, which coughed up sensitive information on nearly half the US population.
Yikes.
When 100 credit card numbers can be sold online for $19 a bundle, it's easy to see the appeal for cybercriminals. Credit card information is feeding an entire illicit ecosystem, with some thieves even opening online schools to teach the hackers of the future.
Hackers can create virtual skimmers by breaking into a bank's network -- for instance, by tricking an executive into providing access, as Nunnikhoven has seen. Instead of compromising physical ATMs one at a time, hackers can steal from multiple ATMs all at once. And there's less risk of getting caught.
"ATMs are really just very simple computers that happen to be attached to a box full of cash," Nunnikhoven said. "We have enough problems securing computers that aren't attached to cash."
The gas station problem
Banks are working to stay a step ahead of the thieves, with techniques like introducing chips on cards, which are more secure than the magnetic stripes. New rules are helping, too. As of October 2015, any stores still using old swipe terminals became liable when fraud occurs. That got businesses adopting the new tech pretty quickly. But take note: The rule doesn't apply to gas stations until 2020.
Which means thieves who used to target random ATMs in stores are now swarming to gas pumps instead.
"We're seeing an uptick of skimmers becoming more common at fuel stations," said Angel Grant, director of fraud and risk intelligence at security firm RSA. "We anticipate this to continue to grow."
At gas stations, the skimmers can be installed on card readers in less than 30 seconds, and they'll record all your card data for collection by the bad guys. It's an easy gig: Those pumps are often unattended late at night, and thieves can plug in their skimmers while pretending to get gas.
The skimmer stores the data, and the scammers return to grab the stolen credit or debit card numbers over Bluetooth, without touching the pump again.
Gas station owners aren't likely to rush to make changes. It's more expensive to upgrade pumps than ATMs.
Fighting back
On Reddit, it's a thing now to see posts of people finding card skimmers by fidgeting with the card reader on an ATM and sometimes snapping it right off. But there's an alternative: A programmer at SparkFun Electronics created an app to save you from having to brutalize your local cash machine.
Because the majority of these skimmers use Bluetooth for harvesting the stolen data, your phone should be able to detect them easily. Nathan Seidle, SparkFun's founder, created the Skimmer Scanner app to automatically detect the skimmer's Bluetooth signal, which is most noticeable at gas pumps.
The Boulder-based company worked with local police in Colorado to take a look at a popular skimmer in the region, a module called the HC-05. These modules are typically used for DIY educational projects to provide Bluetooth capabilities on homemade gadgets. But they're also extremely common for credit card skimmers, and cost only $3 each.
"They're obviously mass produced," Seidle said. "It's so cheap that they can just pepper these things all over the place."
Because these skimmers are a bargain, their Bluetooth names can't be changed -- it's always HC-05. They also have a hard-coded default password: "1234." In other words, their weak spot is the same one that can get you in trouble with lots of the gadgets in your home.
The Skimmer Scanner looks for connections with that name; then attempts to connect with the default password, the same way the thief who planted it would. The app then sends the letter "P" as a command to the Bluetooth device, and if it's a skimmer, it'll send back "M." The system has been able to detect skimmers at distances between 5 and 15 feet.
The Android app is available on the Google Play store for free, and in open-source format on Github.
Researchers said the app is a great step in fighting back, given how common the HC-05 Bluetooth module is, but it's not going to stop all skimmers.
Eventually, too, once hackers realize how dumb those Bluetooth modules are, Nunnikhoven said, they'll move onto something that isn't as detectable.
"There's a limited lifetime on apps like Skimmer Scanner," he said. "The attackers are always changing their tactics to avoid getting caught."
Source: CNET
Intel Tiger Lake CPUs to come with Anti-Malware Protection
Intel’s Tiger Lake CPUs will come with Control-flow Enforcement Technology (CET), aimed at battling common control-flow hijacking attacks. I...
-
Last April, Steven Schoen received an email from someone named Natalie Andrea who said she worked for a company called We Purchase Apps. She...
-
Intel’s Tiger Lake CPUs will come with Control-flow Enforcement Technology (CET), aimed at battling common control-flow hijacking attacks. I...
-
By Carl Herberger This is Part 2 of our series on the top 5 most dangerous DDoS attacks and how you can successfully mitigate them. ATTAC...