Google Search

Sunday, September 8, 2013

May Patch Tuesday coming up - Microsoft still not sure if latest 0-day fix will make the cut

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Microsoft's Patch Tuesday for May 2013 will be published in the coming week.

It'll be out on Tuesday 14 May 2013. (Wednesday 14 May for everywhere from about Malaysia eastwards.)

Here's the elevator pitch:

33 vulnerabilities identified and fixed.Ten separate patches.Eight rated Important. (Apply ASAP.) Two rated Critical. (Apply immediately.) A reboot is required.

Loosely translated, Microsoft's interpretation of important means that an exploit against the vulnerability is likely to be found, but you'll probably get some sort of warning, such as a pop-up dialog, if an attacker tries to use it.

On the other hand, critical means not just that a exploit is likely (or already known), but that it can be used silently - what's known as a drive-by install - without popups or any other kind of warning.

The burning question about the May 2013 Patch Tuesday is this: will it fix CVE-??2013-??1347?

This is a remote code execution flaw in Internet Explorer 8 that has already been exploited in the wild to disseminate malware, most notably via a hacked website belonging to the US Department of Labor.

Microsoft has already published a temporary patch for CVE-??2013-??1347 in the form of a Fix it tool, and has announced that it would like to have a permanent patch available in time for the coming patch Tuesday.

As Microsoftie Dustin Childs from the Trustworthy Computing team wrote:

Of note, we are working to have the Internet Explorer Security Update address the issue described in Security Advisory 2847140 [relating to CVE-2013-1347], supplementing the currently available Fix it.

In plain English, that means: "We've got a patch ready. We'd love to ship it out to everyone on Patch Tuesday, but we haven't quite decided whether it's 100% ready yet."

I suggest you assume that Microsoft will miss the Tuesday deadline for the CVE-?2013-?1347 patch, and will publish it in a so-called out of band, one-off update later in May.

In other words, prepare to patch twice in the month.

If Microsoft does hit its deadline, treat it as a handy bonus.

Follow @duckblog


View the original article here

Friday, September 6, 2013

"Casher crew" from global $45m cyberheist busted in New York - 1 dead, 7 face trial

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

When you think of cybercrime, you probably imagine a hacker (or cracker, as many of our readers prefer) sitting far from his victims, breaking in digitally and making off with the valuables in similar fashion.

For many cybercrooks, that is, indeed, how it goes down.

If your goal is to get illicit remote access to a database, for example, and steal a bunch of bank card numbers, you can probably do it without leaving your apartment.

But when your final goal is to turn those bank cards into hard cash, cybercrime and old-fashioned street crime meet.

That's because you can't just click on a virtual on-screen ATM in your bedroom and watch banknotes spilling out of your DVD slot.

When it comes to cash withdrawals, you face the same problems that old-school bank robbers have for hundreds of years.

In the unforgettable words of 1930s Tommy-gun-wielding bank robber Willie Sutton:

Go where the money is...and go there often.

So here's how a modern-day ATM cyber-robbery usually works:

Crooks acquire bank card magstripe details and associated withdrawal PINs.Crooks split up card details and distribute them to on-the-ground teams of "casher crews", or "cashers".Cashers prepare cloned cards using magstriped blanks such as gift cards, phone cards and old hotel keys.

When all the ducks are, so to speak, in a row, then:

Crooks email PIN numbers to the cashers. (Holding these back until the last minute avoids early exposure.)Cashers take to the streets mob-handed and go on a looting spree.

Finally:

The cashers return most of the money to their handlers, often in some already-laundered form such as easily-resold luxury goods. The cashers keep their cut, in money or in kind (supercars seem popular), and wait for a GOTO 4 instruction.

One thing that's important is speed and volume. (Here's an earlier example where WorldPay was hit for $9,000,000 in 12 hours.)

With each ATM typically restricting the amount of money it will dispense in one go (since they can only hold so much), you need to do a lot of transactions.

With a $500 maximum, you need 2000 withdrawals to hit a cool million; pick a bank with an $800 jackpot limit and you're still looking at a workflow of 1250 repetitions of insert card - enter PIN - remove card - take money.

And you can't hang around, because once a crew starts looting, alarm bells are going to start ringing back at bank HQ - much like they used to for Wille "The Actor" Sutton.

A bank that spots an out-of-the-ordinary sequence of transactions might not be able to scramble the cops, especially if the looting is happening in cities all around the world, but it can shut you out if it works out a pattern to your illicit withdrawals.

Anyway, the good news in this is that the US Justice Department's Eastern District of New York has just unsealed an indictment [charges in full here (PDF, 5.8MB)] against eight members of a New York based casher crew who are alleged to have made off with about $2,800,000 in two separate outings.

The alleged crew leader, Alberto Yusi Lajud-Peña, won't stand trial for the rather unfortunate reason that he is dead, murdered in the Dominican Republic last month.

The other seven, if convicted, are looking down the barrel of 17.5 years inside, charged with "conspiracy to commit access device fraud" and money laundering.

They allegedly made large cash deposits, as well as buying luxury items such as a Mercedes Benz SUV, a Porche Panamera, and swanky watches.

The gang certainly paid attention to speed and volume.

The Justice Department has produced a fascinating "crime visualisation" map that makes it clear how systematically cashers go to work. (It also gives a whole new meaning to "On Broadway.")

In the first looting run in December 2012, the crew allegedly hit more than 140 ATMs for an average of about five withdrawals each, pulling out close to $400,000 in under three hours - presumably working with a $500-per-transaction limit.

The second run took place in February 2013, where they seem to have gone for an $800-?per-?transaction value, netting some $2,400,000 over nine-and-?a-half hours in 3000 separate withdrawals.

With eight cashers in action, 3000 transactions in under ten hours is an average of just over 90 seconds per withdrawal.

What made these cyberheists particularly interesting, aside from the speed with which the New York crew were nabbed, is what went on in Step One of the crime.

The crooks didn't just jump on an Underweb forum and buy a bunch of FULLZ, or set up a load of ATM skimmers to accumulate cashcard data and PINs.

It seems that they indirectly targeted two banks in the Persian Gulf - the National Bank of Ras Al-Khaima (RAKBANK), UAE, and the Bank of Muscat, Oman.

They broke into the databases of the companies that handled those banks' debit card business - an unnamed Indian outfit in the case of RAKBANK, and an unnamed US outfit in the case of Bank of Muscat.

Then they orchestrated what is known as an "unlimited operation."

That means they didn't just end up with a motley bunch of debit card account numbers worth an unknown amount each.

Instead, they removed the cards' withdrawal limits and boosted their account balances to the point that the amount available was effectively limited only by the speed of the cashing crews, not by the wealth of the cardholders.

And Step Two didn't just make use of our hapless New York casher crew.

According to prosecutors, the RAKBANK looting raids took place simultaneously in about 20 countries, for an illicit withdrawal total of $5,000,000.

And the Bank of Muscat operation was co-ordinated across some 24 countries, netting an astonishing $40,000,000 in under 24 hours.

Often, we read about bank-related cybercrime prosecuted years in arrears, mainly due to the complexities of working across many jurisdictions and with numerous financial institutions.

This time, the cops (technically, in this case, the US Secret Service) got their man, or at least their alleged men, pretty quickly.

Loretta E. Lynch, the United States Attorney for the Eastern District of New York who announced these arrests, was generous in her praise for the international co-operation received, formally thanking, amongst others:

MasterCard, RAKBANK, and the Bank of Muscat for their cooperation with this investigation, ... law enforcement authorities in Japan, Canada, Germany, and Romania, and ... authorities in the United Arab Emirates, Dominican Republic, Mexico, Italy, Spain, Belgium, France, United Kingdom, Latvia, Estonia, Thailand, and Malaysia.

Quite a list.

Now we shall have to wait and see if any of the carder crews in the other 23 countries, or the cybercrooks behind the "unlimited operation" intrusions, will ever be caught.

Oh, and, if they're caught, what will happen to them - in the WorldPay example above, the Russian hacker behind it all ended up with a suspended sentence.

Follow @duckblog


View the original article here

Wednesday, September 4, 2013

Subway multimillion-dollar hack ringleader pleads guilty

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Credit card terminal. Image from ShutterstockAdrian-Tiberiu Oprea, a Romanian national and the alleged ringleader of the gang responsible for a multimillion-dollar hack of the Subway fast-food chain, has pleaded guilty.

Oprea is accused of crimes committed in a massive payment card data theft scheme that targeted the point-of-sale (POS) systems of hundreds of US stores.

He admitted to one count of conspiracy to commit computer fraud, one count of conspiracy to commit wire fraud, and two counts of conspiracy to commit access device fraud.

According to the authorities, the men targeted vulnerable POS systems via the internet and gained access via remote desktop software that was sometimes secured with weak passwords.

The hackers planted spyware onto the POS systems, which recorded and stored data that was keyed into or swiped through the merchants' POS systems, including credit card data.

The stolen payment card data was then siphoned off to dump sites from where it could be accessed to make unauthorized charges or to transfer funds.

According to the Department of Justice, the scheme affected more than 146,000 payment cards and earned the crooks more than $10 million.

One of Oprea's cronies - 28-year-old Iulian Dolan, of Craiova, Romania - has already pleaded guilty and agreed to a seven-year prison sentence. His sentencing is scheduled for August 15, 2013.

Another gang member - Cezar Butu, 27, of Ploiesti, Romania - was sentenced in January to 21 months in prison.

By the way, there's a film-worthy story (thank you, Eduard Kovacs, for the link) about how the Secret Service lured two of the alleged Subway hackers onto US soil where they could slap some cuffs on them.

Brian Krebs tells the tale, which he got from Michael Shklar, the public defender appointed to Iulian Dolan.

The trick was to promise the men that they'd be showered "with love and riches", Krebs writes.

Secret Service agents tricked Dolan into popping over for a visit by posing as representatives from a casino that was offering him a complimentary weekend getaway, telling him they knew that he gambled online, and that comping him a weekend would give the place "a cosmopolitan feel."

They even purchased his airline ticket.

He arrived, Sklar said, with:

"... some clothes, a cheap necklace, a little bit of money, and three very large boxes of grape-flavored Romanian condoms."

Online love. Image from ShutterstockThen, investigators posed as a comely female tourist whom Butu had met in France a year ago and with whom he'd exchanged email.

Krebs writes that Butu believed he was coming to the US "to meet an independently wealthy Hooters waitress who said she worked at the restaurant chain for the health insurance coverage and because she liked people."

And he believed it.

It's reassuring to know that criminals don't always think with that thing that resides inside their skulls.

Follow @LisaVaas
Follow @NakedSecurity

Image of online love and credit card terminal courtesy of Shutterstock.


View the original article here

An unholy alliance - Fake Anti-Virus, meet Bogus Support Call!

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

I'm sure you're familiar with fake anti-virus scams, or scareware.

That's the stuff that pops up, usually while you're browsing, to warn you about potential security risks.

Would you like a free scan?

Of course you would, and of course there are threats: viruses, spyware, dangerous cookies, sometimes dozens of terrifying malware items that your current security software must have missed.

Would you like to clean up (recommended)?

Well, why not?

Hmm. The cleanup isn't free: you have to pay, but when you do, all the "threats" magically disappear.

Of course, there's no magic, just deceit: the software simply stops lying to you about threats, and sets a configuration setting to remind itself, "This victims's paid up, pretend they're clean."

And I'm sure you're familiar with fake support call scams.

Your phone rings, and it's a surprisingly pushy chap who claims to be "working with Microsoft," or something like it, who has spotted suspicious network activity emanating from your PC.

"Would you like to do a free check for viruses, using diagnostic software built into Windows?"

Of course you wouldn't - who on earth does this guy think he is, calling you out of the blue? - but he's not taking no for an answer, and it's free, and you've got a virus, and what if you get sued for infecting other people, and...

So you reluctantly do the diagnostic test, and of course there's a diabolical virus that your current security software must have missed.

"Would you like to clean up?"

You do? That'll be $275 please. But, look! That terrible virus has gone!

In both cases, you've been offered advice you weren't seeking, from sources you didn't know, that used scare tactics to trick you into paying money for absolutely nothing. Deceit, extortion, fraud.

But it's not all plain sailing for the scammers.

The problem with the cold callers is that, by and large, they're hideously rude bully-boys who sound just as dodgy as they are.

Click. Down goes the phone.

And the problem with scareware popups is that people are getting wise (or at least inured) to their fanciful lies.

Click. Away with the warning dialog.

So it was amusing to have my attention drawn, thanks to Naked Security reader Alain Roy, to a scareware campaign that deliberately, if rather haplessly, tries to fuse these two approaches.

Don't waste your time calling 10,000 people until you find one who is scared enough that you can intimidate them into paying up!

Pre-select your victims by getting them to call you:

(Windows must be more pervasive and perspicacious at finding scareware than I thought - that's Safari on OS X!)

Then you get the traditional bogus security scan you're used to from scareware:

And there's even the legalistic smoke-and-mirrors like the cold callers use. (You'll notice that they hardly ever actually say outright that they work for Microsoft - it's always with Microsoft, or in Windows support, as though that somehow mitigates the arrant dishonesty of everything else they tell you.)

Well, now you know.

The scareware dialog is "not to be taken literally," and has been "modified in multiple ways."

Of course, on the real fake site, the disarmingly accurate Terms and Conditions appear in about 6-point black letters on a dark blue background, and the main way the "story" has been "modified" is to remove all vestiges of truth...

...but it nevertheless brought a wry smile to my weekend.

If you have friends or family who have been pestered to the point of worry by fake support callers, here's a short podcast you might like to get them to listen to.

We make it clear that these guys are scammers (and why), and offer some practical advice on how to deal with them.

(05 November 2010, duration 6'15", size 4.5MB)

Follow @duckblog


View the original article here

Tuesday, September 3, 2013

Sex and the City author hacked, draft of new book is leaked online

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Candace BushnellCandace Bushnell, the author famous for "Sex and the City", has fallen victim to a hacker who not only broke into her Twitter account, but also posted extracts of her as-yet-unfinished next book online.

Although the creator of Carrie Bradshaw seems to have expelled the hacker from her Twitter account, and deleted the offending tweets, an early draft version of what seem to be the first 50 pages of Bushnell's book - currently entitled "Killing Monica" - are available online for anyone to download and read to their heart's content.

Tweet from Candace Bushnell's hacked account

In addition, the hacker has also posted screenshots of private communications from Bushnell's Earthlink account between her, her publishers and her literary agents.

Interestingly, the hacker who is taking credit for the compromise of Bushnell's accounts and the leak of her book draft is "Guccifer".

Regular readers of Naked Security will remember that Guccifer is the hoopy frood who thought it was a good idea to break into accounts belonging to Colin Powell and former US Presidents George H and George W Bush.

Book extract

From the looks of things, Candace Bushnell has been sloppy with her computer security - perhaps choosing an easy-to-guess password, using the same password in multiple places or allowing her password to be phished by a hacker.

But furthermore, the incident underlines the importance of encrypting sensitive documents (such as the first 50 draft pages of an upcoming book) so even if your email account *is* compromised, a hacker won't be able to read any attachments which could be confidential or commercially sensitive.

Nobody likes to be hacked, of course. And it is a criminal act which should be investigated by the authorities. And Bushnell and her publishers have the right to choose how and when extracts from her book are shared with a wider audience.

But you can't help but wonder if Candace Bushnell's publishers might be able to turn a potential disaster into a PR opportunity, and turn around this unfortunate incident and use it as a chance to heighten interest in the famous author's next book.

Follow @gcluley

View the original article here

Monday, September 2, 2013

Seriously, this is how the Syrian Electronic Army hacked The Onion

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

The Syrian Electronic Army hacked into The Onion’s Twitter account on Monday, publishing fake anti-Israeli stories and an anti-Obama "meme" image.

The Onion twitter

Then the satirical news publication kept tongue firmly in cheek with a post, titled "Syrian Electronic Army Has A Little Fun Before Inevitable Upcoming Deaths At Hands Of Rebels":

"We figured that before they bust in here and execute every single one of us, we might as well have a good time and post some silly tweets about Israel from a major media outlet’s feed."

By Wednesday, after it had served up tips to avoid getting hacked,* the Onion's tech team got serious and posted this writeup of how the takeover happened.

In a nutshell, the Onion fell prey to phishing, with three separate methods that breached Onion employees' Google Apps accounts.

Syrian Electronic ArmyThe first attempt came around May 3, when the SEA sent phishing emails to some Onion employees. It included a spoofed link, purportedly to an article about The Onion published by The Washington Post, which actually went through a few redirects before depositing its targets at a site that requested Google Apps credentials before redirecting to a Gmail inbox.

The tech team says that the emails came from "strange, outside addresses" and were sent to just a few employees, making them appear to be "just random noise rather than a targeted attack."

At least one employee fell for it.

After breaching that account, the attackers used it to send the same phishing email to more Onion staff around 2:30 AM on Monday.

Coming from a trusted address, the email got a lot of click-throughs.

Most staffers refrained from entering their login credentials, but two fell for the ruse. Unfortunately, one of the two had access to all of The Onion's social media accounts.

The Onion discovered that at least one account had been compromised and sent out an email asking that all staffers change passwords immediately.

But the attacker used another undiscovered, compromised account to send a duplicate email that again included a link to the phishing page, this time disguised as a password-reset link.

When the attackers sent this duplicate email, they cannily skipped sending it to members of The Onion's tech or IT teams, ensuring it went undetected.

This third and final phishing attack compromised at least 2 more accounts, The Onion reports, one of which was used to further abuse the Twitter account.

The OnionThat's when the editorial team started to publish satirical articles inspired by the attack.

The article about how the SEA would soon be slaughtered provoked the attacker, who began posting editorial emails on their Twitter account.

At that point, The Onion figured it couldn't know whose Google Apps accounts had been hacked, so it forced a password reset on everybody's account.

The Onion published these tips to avoid getting our Twitter accounts hacked. These are the ones that we should all take seriously:

Make sure that your users are educated, and that they are suspicious of all links that ask them to log in, regardless of the sender.The email addresses for your Twitter accounts should be on a system that is isolated from your organization’s normal email. This will make your Twitter accounts virtually invulnerable to phishing (providing that you’re using unique, strong passwords for every account).

[Note: either use a password manager to generate and store passwords or check out Graham Cluley's method to create a strong password.]

All Twitter activity should go through an app of some kind, such as HootSuite. Restricting password-based access to your accounts prevents a hacker from taking total ownership, which takes much longer to rectify.If possible, have a way to reach out to all of your users outside of their organizational email. In the case of the Guardian hack, the SEA posted screenshots of multiple internal security emails, probably from a compromised email address that was overlooked.

*Tips to avoid getting hacked that you should not take seriously, also courtesy of The Onion, via National Public Radio:

Move site to a new web address every few minutes.**Reduce interest in your website by avoiding popular subjects.*** If you receive an email asking for your password, dig deeper by entering information.****

[**This is impossible.]
[***This is inadvisable if you want anybody to read your site.]
[****No, no, no, no, no.]

Follow @LisaVaas
Follow @NakedSecurity


View the original article here

Sony hacking suspect smashes computers to get out of prosecution

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Sony PlayStation NetworkA 23-year-old man suspected of helping to hack into Sony's PlayStation Network got out of being penalized for the crime by smashing his computers and making his hard drives disappear.

Todd M. Miller, of Columbus, in the US state of Ohio, was sentenced on Thursday to a year on house arrest for obstructing a federal investigation and styming an FBI investigation into the hack.

According to The Columbus Dispatch, the judge also sentenced Miller to three years probation and ordered him to get his high-school equivalence certificate.

US District Judge Peter C. Economus said in federal court that Miller was a member of a hacking group called the KCUF clan that, starting in 2008, organized an ongoing attack on Sony’s servers.

The hack took the PlayStation Network offline in April 2011. Sony soon realized that the breach had enabled the attackers to access the personal data, including credit card information, of millions of online gamers.

PlayStation Network maintenance message

The April attack ushered in a series of over a dozen attacks against Sony websites around the world that played out over the following months.

Sony wound up getting fined £250,000 ($383,767) by the UK's Information Commissioner's Office for breaching the Data Protection Act in connection with the hacks.

The FBI initially interviewed Miller in 2011.

When they came back with a search warrant, they found that his hard drives were nowhere to be found and that Miller had smashed his computers.

Without the computers, the FBI didn't have enough to prosecute Miller or another unnamed Columbus man on the hacking charges.

The Columbus Dispatch reports that Miller has a ninth-grade education.

Miller told the judge that he was “immature and ignorant and caught up with the wrong people at the wrong time” when he destroyed his hardware but that he's since learned his lesson and that the judge "will not see [him] again."

Were the FBI to have gotten its hands on the hard drives, Miller would have been facing up to 20 years in prison and a fine of up to $250,000.

Judge Economus said that he saw no purpose to sentencing Miller to prison, given that he has a full-time job and "some stability" after a "tumultuous childhood," the Columbus Dispatch reports.

Your honor, let's hope you're right.

Follow @LisaVaas
Follow @NakedSecurity


View the original article here