Google Search

Showing posts with label Military. Show all posts
Showing posts with label Military. Show all posts

Wednesday, June 12, 2013

Mobile device security in the US military comes under fire

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

On March 26th, the Inspector General released a report on the effects of BYOD (bring your own device) on the U.S. military.

Inspector General report

Among the report's findings:

Mobile devices were not secured to protect stored information.The US Department of Defense (DOD) did not have ability to wipe devices that were lost or stolen.Sensitive data was allowed to be stored on commercial mobile devices acting as removable media.DOD did not train users and did not have them sign user agreements.The Army CIO was unaware of more than 14,000 mobile devices used throughout the Army.

Ouch.

This from an entity that seems to have policies and regulations for everything.

The Army did implement a good policy regarding geotagging a while back, realizing the risk that came with soldiers taking pictures that automatically had location information embedded in metadata.

Location smartphone. Image from ShutterstockHowever, given the lack of management of the devices, how would the military know for sure that the geotagging has been disabled?

And if the United States Army, with all the endless policies, is having a difficult time with BYOD, how is a small or medium-sized business going to cope?

Why does this all matter?

Answer: Data loss. Stolen data is massive business for the bad guys. A phone left in a cab or at an airport can be a goldmine of sensitive information. Consider the case of the US Secret Service contractor who left two tapes of sensitive data on the DC Metro train.

What crook wouldn't have loved to have gotten a hold of two databases full of juicy personal information of agency employees, contractors and possibly informants? It's just another example that even the most "security conscious" people have forgetful moments, or moments of distraction and can easily leave something behind.

Last year, Sophos did an informal study and found that 42% of lost mobile devices aren't protected with any security measures.

Now of that number, 20% had access to business email, which could contain confidential information. Small businesses are even more at risk - just because you are small doesn't make you less of a target.

We have written several articles about handling smartphones in a business before and have provided some sage advice within about how to implement BYOD, but how do you create a BYOD policy?

Where's the best place to start? Sophos CTO Gerhard Eschelbeck outlines the following tips in a recent whitepaper.

Mobile post it. Image from Shutterstock7 steps to a BYOD security plan

Identify the risk elements that BYOD introduces. Measure how the risk can impact your business and map the risk elements to regulations, where applicable.Form a committee to embrace BYOD and understand the risks, including business stakeholders, IT stakeholders and information security stakeholders.Decide how to enforce policies for any and all devices connecting to your network including mobile devices (smartphones), tablets (e.g., iPad) and portable computers (laptops, netbooks, ultrabooks).Build a project plan to include these capabilities: Remote device managementApplication controlPolicy compliance and audit reportsData and device encryptionAugmenting cloud storage securityWiping devices when retiredRevoking access to devices when end-user relationship changes from employee to guestRevoking access to devices when employees are terminated by the companyEvaluate solutions. Consider the impact on your existing network and how to enhance existing technologies prior to next step.Implement solutions. Begin with a pilot group from each of the stakeholders' departments. Expand pilot to departments based on your organizational criteria. Open BYOD program to all employees.Periodically reassess solutions. Include vendors and trusted advisors. Look at roadmaps entering your next assessment period. Consider cost-saving group plans if practical.

Regardless of how big or small your 'army', securing your organization's devices and the data on those devices is at the front line of maintaining a strong IT security defense.

Follow @SophosLabs
Follow @NakedSecurity

Smartphone map and mobile note images from Shutterstock


View the original article here

Tuesday, April 30, 2013

No, Iran didn't really hack and down a foreign military spy drone

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

A report by the Islamic Republic News Agency this weekend raised eyebrows, as it appeared to claim that Iran's Revolutionary Guard Corps had managed to hack and down a foreign spy drone.

Iranian news story

"A foreign spy drone was hacked outside the field of Payambar-e Azam 8 wargames on Saturday," reporters were told.

The official FARS news agency told a similar story, adding that the revolutionary guard were in possession of pictures taken by the drone and hoped to release them to the world's media.

FARS story

IRGC Hunts Alien UAV over Wargame Zone
TEHRAN (FNA)- The Islamic Revolution Guards Corps announced that it has hunted an alien Unmanned Aerial Vehicle (UAV) after the drone neared the IRGC's current wargames zone in Southern Iran.

"On the first day of Payambar-e Azam 8 (The Great Prophet 8) wargames, the IRGC's electronic warfare systems detected signals showing that alien drones were trying to enter the country (airspace)," Spokesman of the Wargames General Hamid Sarkheili told reporters on Saturday evening.

"Then our experts could bring down an alien drone over the wargames zone," he added.

Sarkheili said the IRGC is now in possession of the pictures taken by the drone and will release them if Okayed by the country's senior commanders.

However, you shouldn't be too quick to take these headlines at face value.

Because, as a corrected Reuters report makes clear, the downed enemy spy drone was hypothetical - a real drone was not hacked and brought down by Iranian forces.

In short, it was all part of Iran's war games, and the media were mislead by the testosterone-fueled bravado of those taking part.

That's not to say, of course, that real drones cannot be hijacked by hackers.

Last year, researchers at the University of Texas at Austin hacked and hijacked a drone in front of a group of dismayed Department of Homeland Security officials who had dared them $1,000 to do it.

Follow @gcluley

UAV image, courtesy of Shutterstock.


View the original article here

Monday, August 13, 2012

Poisoned DOC file used in targeted malware attack against military contractor

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Gas mask. Image from ShutterstockExperts at SophosLabs are recommending that businesses and organisations check that they are keeping up-to-date with their security patches, in the light of a malware attack that was seen today - targeting a defence contractor.

The attack is similar in nature to one which SophosLabs intercepted a couple of years ago, where a malicious PDF file claiming to be about the Trident D-5 missile, launched from nuclear submarines, was sent to a military contractor.

The latest attack was sent to the contractor - whose name is not being made public by Sophos - embedded inside a file called Details.Doc, attached to the following email:

Targeted email attack

Dear Sir,

It is so nice to contact you!

We write to inform you that we are some question for your.
View attached document for the detail.
Looking forward to hearing from you soon!

Many thanks and best regards!

trav.whan

The email pretends to be from a YAHOO.COM.TW address but the headers show that emails did not come from YAHOO.

Part of the email's header

The IP is actually from a personal computer:

Received: from travwhanpc (61-220-44-2xx.HINET-IP.hinet.net [61.220.44.2xx])

The email's attachment - titled Details.doc - exploits the CVE-2012-0158 vulnerability.

Unusually, the file really is an OLE2 format DOC file, despite the majority of files exhibiting this vulnerability being RTF files.

The boobytrapped file tries to drop and execute executable code (in the form of an .EXE file) which will install the 'PittyTiger' backdoor onto the victim's Windows PC.

Malicious code hex dump

SophosLabs has released detection for the DOC file as Troj/DocDrop-AF and the EXE as Troj/BckDrPT-AA.

SophosLabs have seen large number of files exploiting the CVE-2012-0158 vulnerability being emailed to companies in a diverse number of sectors - not just those in defence.

The Microsoft security patch, MS12-027, has been available for 3 months now and there are really no excuses for not having applied it.

Follow @SophosLabs

Gas mask image from Shutterstock.


View the original article here

Monday, August 22, 2011

Hackers go after military computers

Published: Aug. 20, 2011 at 9:20 AM

SEOUL, Aug. 20 (UPI) -- South Korean military officials say hackers have attacked their computer systems 37 times since May, and six times so far this month.

The military warned all staff to refrain from opening e-mails from "navyojo@hanmail.net," which contains an attachment, that if opened could infect the user's computer with a code that can steal information from the computer, the Yonhap News Agency reported Saturday.

"We have spotted 10 cases of hacking attempts originating from overseas each in May and June. In July, there were 11 such cases and so far this month, six more attempts have been detected," an unnamed official said.

The malicious e-mails might have been sent by North Korean hackers, some speculated. There have been no information losses so far, the official said.

The United States and South Korea are conducting their annual computer simulation joint military exercise, called "Ulchi Freedom Guardian." The drill started its 11-day run Tuesday.


View the original article here

Friday, July 1, 2011

Hackers Steal Info on Military, Defense Personnel

Email addresses and names of subscribers to DefenseNews, a highly-regarded website that covers national and international military and defense news, were accessed by hackers and presumed stolen, Gannett announced yesterday.

DefenseNews ' subscribers include active and retired military personnel, defense contractors and others in both the U.S. and other countries' defense establishments.

"We discovered that the attacker gained unauthorized access to files containing information of some of our users," said Gannett Government Media, an arm of the media chain that publishes not only DefenseNews, but also the Military Times and Federal Times sites, as well as a number of military-specific magazines and journals, ranging from the Army Times to the Intelligence, Surveillance and Reconnaissance Journal.

In a message posted to its site Monday , Gannett acknowledged that the accessed information included first and last names, email addresses, account passwords, and duty status branch of service for military personnel.

Gannett urged registered users to reset their site passwords, "as well as your other online accounts, particularly those that use the same email address used for your Gannett Government Media Corporation account."

The attack was first detected June 7.

One security expert said it was possible the attack against DefenseNews and the other sites Gannett operates was targeted, perhaps by state-backed hackers. "It's hard to know if this was just part of the general ransacking of sites, or an attempt to obtain valuable information for spear-phishing," said Anup Ghosh, the founder and CEO of Web security firm Invincea.

Ghosh said it's likely the attack was deliberately after the names and email addresses of people in the defense industry and military.

"This is a pretty selective group," Ghosh said of the DefenseNews account holders, and would be restricted in scope to the military-industrial [establishment]. It would be very attractive from a nation-state point of view."

He based the last observation on the fact that hackers-for-profit are unlikely to go after such names and addresses. "But nation-state [hackers] are after military and defense intellectual property, and designs and plans."

The stolen information would make the perfect fodder for future "spear phishing," the kind of attacks that target individuals within an organization by crafting convincing messages, often with embedded links or attached files that direct recipients to malicious sites or plant malware directly on PCs to, for instance, gather more information or gain greater access to a network.

Spear phishing attacks have been blamed for a number of recent high-profile attacks, including ones against the International Monetary Fund (IMF) and senior government officials through Gmail.

Military contractors, most notably Lockheed , have also been attacked this year, although not necessarily through spear-phishing tactics.

"With this information, spear phishers could create pretty convincing messages [to these individuals]," said Ghosh, who said that click-through rates in such attacks can reach as high as 20%, meaning one-out-of-five people click on a link, open a file attachment or disclose other personal information.

Ghosh also noted that defense agencies and militaries are careful not to reveal contact information for their workers or personnel, for just that reason. "I wouldn't have thought to target a publication like this," said Ghosh. "It was actually very clever."

Gannett has sent emails to subscribers whose information was accessed, and warned them against falling for any spear phishing schemes.

"You should delete any unusual or suspicious emails without opening them and should not click on any links embedded in a message that appears suspicious once you have opened it," the company told subscribers in a copy of the email obtained by Computerworld.

DefenseNews has not said how many account records were accessed by attackers, and did not return a call for comment Tuesday.

Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at @gkeizer or subscribe to Gregg's RSS feed . His e-mail address is gkeizer@computerworld.com .

Read more about cybercrime and hacking in Computerworld's Cybercrime and Hacking Topic Center.

Computerworld
For more enterprise computing news, visit Computerworld. Story copyright © 2011 Computerworld Inc. All rights reserved.


View the original article here