Google Search

Thursday, June 13, 2013

Spring ushers in US tax scam season

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

US tax season. Image from ShutterstockIn the US, it's spring, aka tax fraud season.

To remind taxpayers to be on the lookout for scams ranging from identity theft to return-preparer fraud, the Internal Revenue Service (IRS) on Tuesday posted its Dirty Dozen list of tax scams for 2013.

The IRS compiles the list every year. It notes that taxpayers can expect the scams any time of year, but many of the schemes peak now, during filing season.

Steven T. Miller, IRS acting commissioner, noted that scams come in many forms, so be careful with trickery over email, in person, over the phone, or even via tweet.

He says:

Don't let a scam artist steal from you or talk you into doing something you will regret later.

The IRS's list of top scams includes both the ones that victimize taxpayers and the ones that taxpayers themselves attempt.

Here are the top scams that try to victimize us. For the full list of scams, check out the IRS's dirty dozen.

Identity theft

Multiple identities. Image from Shutterstock.The most common scam on the IRS's list is identity theft. Scammers use email, websites, tweets, phone calls or faxes to reach victims.

Or, more creatively still, at least in the UK, scammers in 2011 claimed to offer a refund from the utility company British Gas.

The scam deliberately avoided asking victims to go online - after all, most people know better than to input personal information into what could be a phishing site.

Instead, to claim the refund, you needed to prove your identity by faxing over a copy of your ID. You'd think that reliance on such antiquated technology as a fax machine would fail to trick most people and companies, but unfortunately, it succeeds with too many.

Once a crook has managed to swipe personal information such as name or tax payer ID, they often use it to file a fraudulent tax return and claim the refund.

In fact, during 2012, the IRS says it prevented $20 billion in bogus returns from going through, many related to identity theft. That's an increase from 2011, when they squelched $14 billion in bogus returns.

To help protect us from identity thieves, and to find out what to do if you think you've already been victimized, the IRS provides these identity protection tips.

Phishing

Bear in mind, the IRS doesn't ask for personal or financial information by email - or by any electronic means, for that matter, whether via text messages or social media channels.

SophosLabs is already detecting IRS spam email.

Both of the sites in question are now down, but one sample told intended victims that their "Federal Tax Regular transaction Appeal [insert phony but official-looking ID number here] recently was NOT ACCEPTED". The message included a link to where victims could supposedly enter information to re-submit their appeal.

IRS tax scam 1

The other scam purportedly offered free tax forms and publications via an enclosed link.

IRS tax scam 2

If you receive an unsolicited message that appears to be from either the IRS or an organization closely linked to the IRS, such as the Electronic Federal Tax Payment System (EFTPS), report it by sending it to phishing@irs.gov.

Return preparer fraud

The IRS says some 60 percent of taxpayers will use tax professionals to prepare their returns this year. A few bad apples are crooks, which can result in refund fraud or identity theft.

Taxpayers should only use preparers who sign the returns they prepare and enter their IRS Preparer Tax Identification Numbers (PTINs).

For more tips on choosing a preparer and for red flags about the unscrupulous ones, visit www.irs.gov/chooseataxpro.

“Free money” from the IRS and tax scams involving social security

Bag of money. Image from Shutterstock.These are really despicable scams, as they prey on low-income or elderly taxpayers.

Crooks use flyers and ads for "free money" from the IRS, suggesting that the taxpayer can file a tax return with little or no documentation. They've been leaving these come-ons in community churches around the US.

The schemes promise refunds to people with little or no income.

The IRS says this about the scams:

They build false hopes and charge people good money for bad advice including encouraging taxpayers to make fictitious claims for refunds or rebates based on false statements of entitlement to tax credits.

For example, some promoters claim they can obtain for their victims, often senior citizens, a tax refund or nonexistent stimulus payment based on the American Opportunity Tax Credit, even if the victim was not enrolled in or paying for college. Con artists also falsely claim that refunds are available even if the victim went to school decades ago. In the end, the victims discover their claims are rejected. Meanwhile, the promoters are long gone.

Other tax scams involve social security, luring the unsuspecting with promises of non-existent refunds or rebates, or tricking taxpayers into filing inflated claims for legitimate refunds or rebates.

Be careful. Intentional mistakes can result in a $5,000 penalty.

US tax refund form. Image from ShutterstockUnfortunately, this is only a slice of the tax scam pie.

As we noted back in January, malware posing as income tax email was already being widely spammed out.

Be vigilant, don't click on phishy links, and don't fall for official-sounding callers, texts, tweets or email. Keep an eye out particularly for friends and relatives who might not be savvy about scams.

Happy tax season, and may your refund be as fat as the robin's first worm.

Follow @LisaVaas
Follow @NakedSecurity

Tax on calendar, tax refund form, multiple identities and bag of money images from Shutterstock.


View the original article here

Wednesday, June 12, 2013

Mobile device security in the US military comes under fire

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

On March 26th, the Inspector General released a report on the effects of BYOD (bring your own device) on the U.S. military.

Inspector General report

Among the report's findings:

Mobile devices were not secured to protect stored information.The US Department of Defense (DOD) did not have ability to wipe devices that were lost or stolen.Sensitive data was allowed to be stored on commercial mobile devices acting as removable media.DOD did not train users and did not have them sign user agreements.The Army CIO was unaware of more than 14,000 mobile devices used throughout the Army.

Ouch.

This from an entity that seems to have policies and regulations for everything.

The Army did implement a good policy regarding geotagging a while back, realizing the risk that came with soldiers taking pictures that automatically had location information embedded in metadata.

Location smartphone. Image from ShutterstockHowever, given the lack of management of the devices, how would the military know for sure that the geotagging has been disabled?

And if the United States Army, with all the endless policies, is having a difficult time with BYOD, how is a small or medium-sized business going to cope?

Why does this all matter?

Answer: Data loss. Stolen data is massive business for the bad guys. A phone left in a cab or at an airport can be a goldmine of sensitive information. Consider the case of the US Secret Service contractor who left two tapes of sensitive data on the DC Metro train.

What crook wouldn't have loved to have gotten a hold of two databases full of juicy personal information of agency employees, contractors and possibly informants? It's just another example that even the most "security conscious" people have forgetful moments, or moments of distraction and can easily leave something behind.

Last year, Sophos did an informal study and found that 42% of lost mobile devices aren't protected with any security measures.

Now of that number, 20% had access to business email, which could contain confidential information. Small businesses are even more at risk - just because you are small doesn't make you less of a target.

We have written several articles about handling smartphones in a business before and have provided some sage advice within about how to implement BYOD, but how do you create a BYOD policy?

Where's the best place to start? Sophos CTO Gerhard Eschelbeck outlines the following tips in a recent whitepaper.

Mobile post it. Image from Shutterstock7 steps to a BYOD security plan

Identify the risk elements that BYOD introduces. Measure how the risk can impact your business and map the risk elements to regulations, where applicable.Form a committee to embrace BYOD and understand the risks, including business stakeholders, IT stakeholders and information security stakeholders.Decide how to enforce policies for any and all devices connecting to your network including mobile devices (smartphones), tablets (e.g., iPad) and portable computers (laptops, netbooks, ultrabooks).Build a project plan to include these capabilities: Remote device managementApplication controlPolicy compliance and audit reportsData and device encryptionAugmenting cloud storage securityWiping devices when retiredRevoking access to devices when end-user relationship changes from employee to guestRevoking access to devices when employees are terminated by the companyEvaluate solutions. Consider the impact on your existing network and how to enhance existing technologies prior to next step.Implement solutions. Begin with a pilot group from each of the stakeholders' departments. Expand pilot to departments based on your organizational criteria. Open BYOD program to all employees.Periodically reassess solutions. Include vendors and trusted advisors. Look at roadmaps entering your next assessment period. Consider cost-saving group plans if practical.

Regardless of how big or small your 'army', securing your organization's devices and the data on those devices is at the front line of maintaining a strong IT security defense.

Follow @SophosLabs
Follow @NakedSecurity

Smartphone map and mobile note images from Shutterstock


View the original article here

Tuesday, June 11, 2013

Firefox 20 arrives - new version, some security improvements, no known vices

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Firefox 20.0 was released today.

The buglist page enumerates 3054 official changes.

Despite the title buglist, these aren't all flaws that needed fixing.

The updates run from the benign-sounding bug #819202 ("attempting to open a new public window when a private window is focused opens a new private window") to enhancement #800085 ("complete gecko testing for identity SignInToWebsiteController").

Amongst this month's changes, however, are eleven patched vulnerabilities.

All of them, at least at the time of writing, are shown on the official vulnerabilities page with their Security Advisory links coloured in red, denoting a Critical impact:

Update. The colours on the Firefox vulnerabilities page have been fixed. Things now look a lot less dramatic from a security point of view! (2013-04-02T22:31Z)

Red-coloured vulnerabilities officially denote bugs that:

can be used to run attacker code and install software, requiring no user interaction beyond normal browsing.

Mozilla, however, has been unkind to itself, because drilling in to each MFSA (Mozilla Foundation Security Advisory) item tells a slightly different story, with the real vulnerability severity counts as follows:

Bugs at the high level, usually coloured orange in Mozilla's security rainbow, aren't to be sneezed at, as they typically lead to data leakage or cross-site scripting. But they don't offer attackers RCE, or remote code execution.

And yellow-coloured moderate bugs, in Mozilla's words, would be critical or high but for the fact that they:

only work in uncommon non-default configurations or require the user to perform complicated and/or unlikely steps.

Additionally, one of the bugs rated critical (MFSA 2013-035) only affects Linux users who have the Intel Mesa graphics drivers installed - the rest of us can stand down from RCE alert.

Firefox 20.0 also has a couple of feature enhancements thrown in for good measure, and Mozilla seem pretty proud of these:

A download manager that's a little clickable arrow rather than a new browser window.Per-window private browsing so you don't need to exit and restart Firefox to switch from stateful to private use.

By the way, I recommend setting Firefox to delete as much of your history as you can bear to lose (notably including cookies) whenever you exit, as it gives you that bit less to worry about next time you start up the browser.

If you use Private Browsing all the time, your "delete history on exit" settings are effectively maximised, because Firefox doesn't keep any history as you browse.

If you choose to let Firefox remember some or all your browsing history as you go along, you can use the Clear history when Firefox closes setting in the Preferences|Privacy pane to ensure your history is deliberately discarded once you exit from the Firefox application.

And lastly, there's an enhancement described as the "ability to close hanging plugins, without the browser hanging."

Mozilla refers to this as a new feature, which it may well be, though if you wanted to be unkind, you might prefer to think of it as merely overdue.

Regular readers will know I'm a Firefox early adopter, and the 20.0 update hasn't given me any surprises: my favourite add-ons still seem to work, and this article was prepared after updating.

So there you have it: new version, some security improvements, no known vices.

Follow @duckblog


View the original article here

Monday, June 10, 2013

Many Amazon S3 cloud storage users are exposing sensitive company secrets, claims report

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Leaky bucket. Image from ShutterstockApproximately one in six buckets Amazon S3 storage buckets (of the 12,328 identified) are leaking sensitive data and company secrets, claims a new report.

Amazon Simple Storage Service (S3) is a web services interface for storing and retrieving static data from Amazon's cloud that gives developers a way to store and access, for example, server backups, company documents, web logs, and publicly visible content, including images and PDFs.

Such content is organized into "buckets", accessible at predictable URLs.

Here's the type of bucket information to which any interested party (or e-scumbag prone to network attack or black market vending) has free and open access if users have set the buckets to public access, according to Rapid7 Senior Security Consultant Will Vandevanter:

Personal photos from a medium-sized social media serviceSales records and account information for a large car dealershipAffiliate tracking data, click-through rates, and account information for an ad company’s clientsEmployee personal information and member lists across various spreadsheetsUnprotected database backups containing site data and encrypted passwordsVideo game source code and development tools for a mobile gaming firmPHP source code including configuration files, which contain usernames and passwordsSales “battlecards” for a large software vendor

Rapid7 Senior Security Consultant Will Vandevanter

Those are just some of the materials that Vandevanter, assisted by HD Moore and inspired by Robin Wood, gathered from 1,951 buckets they found open to public scrutiny.

The sheer number of files made it unrealistic to test the permissions of every single object, so a random sampling was taken instead. All told, we reviewed over 40,000 publicly visible files, many of which contained sensitive data.

Roughly, that's about one in six buckets that have been "left open for the perusal of anyone that's interested," he says.

Defining the security risks, Vandevanter says, is a no-brainer:

A list of files and the files themselves - if available for download - can reveal sensitive information. The worst case scenario is that a bucket has been marked as 'public', exposes a list of sensitive files, and no access controls have been placed on those files.

In situations where the bucket is public, but the files are locked down, sensitive information can still be exposed through the file names themselves, such as the names of customers or how frequently a particular application is backed up.

This isn't Amazon's fault, mind you. Amazon S3 buckets' default setting is private. Buckets set to "public" will list all files and directories to anybody who asks.

By default, buckets will have one of two predictable, publicly accessible URLs, Vandevanter says.

Using the two URL syntaxes he provides, users will either be denied access by a private bucket, or they'll be peering into the first 1,000 objects stored in a public bucket.

As for remedies, this one is straightforward, Vandevanter writes: "Check your buckets. If they're open, determine whether the content is something you don't mind exposing."

If your content should be kept private, check out Amazon's tutorial on how to lock it down.

Unfortunately, making a bucket private now doesn't extend to bucket versions stored away in Google indexing.

Time machine. Image from Shutterstock

Vandevanter recommends the Internet WayBackMachine to find previously open buckets. Also, he used a modified version of @mubix’s Metasploit module to find "a few hundred" currently private buckets that were previously open.

Here are Amazon's instructions on how to manage access control lists for objects in buckets.

Amazon, clearly, isn't at fault, as Vandevanter points out. The company has set the buckets to private by default, and it's published plenty of resources to instruct users on how to keep data safe.

A spirited discussion on Slashdot questions a) whether Vandevanter is vulnerable to prosecution over the classic security technique of testing doorknobs to see which are open and b) whether this is news at all, rather than a case of RTFM (Caution: Link may be NSFW).

In my opinion, a) let's hope not; enough already with the overzealous prosecutions of hackers a la Weev and Schwartz, et al. and b) that sounds about right.

Follow @LisaVaas
Follow @NakedSecurity

Will Vandevanter whiteboard image courtesy of Rapid7.
Leaky bucket and time machine images from Shutterstock.


View the original article here

Saturday, June 8, 2013

17-year-old arrested for hacking into phones, stealing and distributing explicit images of children

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Text message

A US teenager has been charged with distributing child pornography he allegedly hacked out of minors' cellphones with a bogus mobile text ad that installed phone-controlling malware.

Michael William Cook, 17, of Acworth, Georgia, was arrested on March 13 on eight counts of cruelty to children and one count of sexually exploiting children.

Cobb County Police Sgt. Dana Pierce told news outlets that Cook was arrested the previous Wednesday while at school.

Police accused Cook of posting photos of his victims to a child pornography website between November 2012 and January 2013.

According to 9News.com, Sgt. Pierce claimed that Cook sent text messages to victims from a company called "Maxi Focus Photography".

When victims clicked on a link in the text message, it installed malware that essentially gave Cook access to all information stored on the phones.

Twitter Facebook

That includes access to victims' accounts on social network sites, such as Facebook and Twitter, as well as sexually explicit photos stored on the phones.

Cook allegedly downloaded offensive pictures and sent them to pornographic websites, Pierce said.

Police seized Cook's computer from his home in order to search for more photos and, potentially, more victims.

Police as of March 18 knew of eight victims, the youngest of whom is 14 years old.

Unfortunately, as Sgt. Pierce told a 9News.com reporter, even if police find all the victims, it will be difficult to figure out who they are:

"The problem we're going to have is, with those images, to be able to identify positively the victim."

Police are asking anyone who's corresponded with Maxi Focus Photography to call the Cobb County Police Department's Crimes Against Children Unit at (770) 801-3470.

Clicking on unexpected links, whether they come to our cellphones or our inboxes, is always risky behavior.

But so is the simple act of snapping a naked photo in digital form on a device that's connected to the internet.

When children do it, they put themselves at risk of unintended exposure, humiliation or serious bullying that could end tragically.

If the charges against Cook prove well-founded, this case is, unfortunately, just one more example that parents can point to while they try to steer their children away from such risky behavior.

Parents, please speak to your kids about the risks involved and encourage them to stay safe online with these tips.

Follow @LisaVaas
Follow @NakedSecurity


View the original article here

Friday, June 7, 2013

iOS 6.1.3 security flaw allows passcode lock bypass... again [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Passcode bypassiOS 6.1.3 has only just been released by Apple, and already a security hole has been followed - allowing anyone to bypass the passcode lock on iPhones, and access private data on the device.

Embarrassingly for the Cupertino company, one of the main reasons for installing iOS 6.1.3 was that it promised to fix other security flaws that allowed the lock screen to be bypassed.

The flaw was found by "videosdebarraquito", who seems to be making a hobby of embarrassing Apple by uncovering lock bypass flaws. In a video he demonstrates that it's not particularly complicated to avoid the iOS 6.1.3 passcode lock if you have physical access to the device and a widget for removing the SIM card.

Here is videosdebarraquito's video, where he demonstrates how the passcode can be bypassed:

It appears that circumventing the passcode lock can allow an unauthorised party access to the device's photo gallery and use the phone.

The good news is that this security flaw can be easily prevented. The passcode bypass relies upon use of the "Voice Dial" feature of iPhones, which is disabled on devices using Apple's Siri voice recognition feature.

If you *aren't* using Siri, then the recommendation is to disable "Voice Dial". If you do that, your device shouldn't be prone to this passcode bypass.

Disable the Voice Dial option

You can disable "Voice Dial" on your iPhone by going to Settings / General / Passcode Lock. (Note that if you have Siri enabled you won't see an option for "Voice Dial" there, as it has been automatically disabled).

Easy as it is to avoid this flaw putting your iDevice at risk, it's still embarrassing for Apple as it comes so soon after other passcode lock bypasses were publicised.

Let's hope that Apple fixes this flaw soon, and shuts a permanent door on passcode lock bypasses.

Follow @gcluley

View the original article here

Wednesday, June 5, 2013

Anatomy of a bug: Battlefield: Play4Free hole allows dodgy updates to go unnoticed

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

A pair of Maltese vulnerability researchers have revealed a security hole in the game Battlefield: Play4Free from digital games giant EA.

The vulnerability takes advantage of the fact that different versions of Windows deal in different ways with erroneous input to the system function used to start new processes.

It's also a timely reminder to programmers that compatibility across many years' worth of operating system versions can come with an unexpected cost.

I shan't repeat the entire exploit (you should read the authors' original paper for that), but the jiggery-pokery goes something like this:

1. Tell the game's browser plugin to use the builtin "Game Updater" feature.

2. Trick the Game Updater into thinking it is connecting to one of a small list of official, trusted servers.

3. Send the Game Updater to a bogus updater site instead.

4. Instruct it to use TFTP to download and run a reverse shell program instead of a real update.

A reverse shell is a program that runs CMD.EXE, the Windows command prompt, on the victim's computer. The reverse shell then connects the command prompt's input and output to a network socket, not to the local keyboard and screen. This network socket is itself connected to a remote server specified by the attacker. So, when CMD.EXE starts and the network connection is made, the command prompt appears on the attacker's screen, not the victim's.

It's called "reverse" because the network connection is sneakily made outwards from the victim to the remote attacker, unlike a legitimate login, which is usually made inwards. Many firewalls don't regulate outbound connections as strictly as inbound ones, which are often prohibited altogether.

It's called a "shell" because that's the traditional Unix name for a command prompt.

The devious part of the security bypass here is the trickery in step 2.

The Game Updater has its own allowlisting feature which is supposed to restrict updates to a small set of websites. (The authors list just ten different names.)

But the allowlisting check is based upon a command line passed from the game's browser plugin to the Game Updater component via the Windows system function CreateProcessW().

And that's where the authors spotted an anomaly.

Windows itself limits the CreateProcessW() command line to a rather old-school 32 kilocharacters.

But the Windows documentation doesn't actually define what happens if your lpCommandLine string is too long; it says only that:

The maximum length of this string is 32,768 characters, including the Unicode terminating null character.

According to the authors of the vulnerability paper, only Windows Vista and later actually treat overly-long command lines as erroneous.

On Windows XP and Server 2003 (but you don't play online games from the server room, do you?), a superlong command line is quietly pruned back to fit into the limit.

Modifying the user's input and then processing it without notification is almost always the wrong thing to do.

If there is something wrong with your input, it should not be trusted and that fact should be reported.

So, on Windows XP, the attackers were able to bypass the allowlist check by tricking the calling process into padding out the command line so that the hostname part ended up more than 32,768 characters along in memory.

The browser plugin then faithfully reported the attacker's dodgy hostname, blissfully ignorant that the next process in the chain would never see the offending data.

The wrong hostname would be checked against the allowlist and would falsely pass the checks.

Note that if you don't play Battlefield: Play4Free, or you aren't running Windows XP, you aren't at risk here.

Four days ago, however, 950,631 people were signed up to play, and as many as 39.5% were still on Windows XP.

Let's call that 40% of one million people, a population that could make quite a handy botnet if the worst came to the worst.

So, if you are an XP-based Battlefield: Play4Free player, be sure to keep your eyes open for an update from EA!

Follow @duckblog


View the original article here