Source Article: http://techre.vu/x1Yq35 (via @TechReview)
IT Security is a dynamic environment, every company/person need to guarantee their assess in order to achieve their goals. This blog focus on that and other topics of security manners, like: Information Security, Ethical Hacking, Vulnerability among others.
26 January 2012
Seven Ways to Get Yourself Hacked
Source Article: http://techre.vu/x1Yq35 (via @TechReview)
17 January 2012
Stratfor reopens website
Stratfor, the Austin company that took its website down on Christmas Day after a hacking attack, has reopened the site with bolstered security.
A hacker group called Anonymous claimed credit for the attack and took credit card information belonging to thousands of customers. Some of those credit cards were used to make donations to non-profit groups, including the Red Cross.
Stratfor, which provides geopolitical analysis, said its servers had been damaged in the attack. The company retailed Sec Theory, an Internet security firm, to rebuild its website, email system and internal infrastructure. It also hired CSID, an Austin company that protects against identity theft, to work with its customers at Stratfor’s expense.
The company also has built a new section of its website to tell its story of the hacking attack. The company said it will move its entire e-commerce process to a highly secure third-party system, which will eliminate the need for Stratfor to store credit card information in-house.
The company also hired Verizon Business to conduct a forensic review of the hack and it continues to cooperate with an FBI investigation.
“We did not encrypt credit card files,” said Stratfor CEO George Friedman of the company’s practice before the attack. “That was our failure. As the CEO of Stratfor, I take responsibility. I deeply regret that this occurred and created hardship for our customers and friends.”
By some estimates about 75,000 customers names, addresses and credit card numbers were exposed. One cyber security analyst, John Bumgarner, told the Los Angeles Times that thousands of those names exposed included military personnel, while 212 email addresses were from the FBI and dozens more from the National Security Agency and the Central Intelligence Agency.
The company said its website will be free and accessible for all on a temporary basis, but it will contain only the company’s most recent reports. All archived files will be gradually restored.
Over the next few weeks, the company will communicate with subscribers about how to obtain new, secure passwords and safely engage in credit card transactions.
Source Article: http://goo.gl/AKoI2
16 January 2012
Man gets a year in prison for hacking, wiping medical competitor's computer
The Atlanta Journal-Constitution
An Atlanta man has been sentenced to serve a year and a month in prison for hacking into a competing medical practice's computer to try to lure away patients.
Eric McNeal, 38, was charged with accessing a computer without authorization, including taking patients' personal information in order to send them marketing materials. He pleaded guilty to the charge on Sept. 28.
According to prosecutors, McNeal, an information technology specialist, worked for Atlanta Perinatal Associates, a medical practice in Atlanta. He left that company in November 2009 and went to work for a competing perinatal medical practice in the same building.
In April 2010, McNeal used his home computer to hack into his former employer's patient database. He downloaded the names, phone numbers and addresses of its patients, and then deleted patient the information from his former employer's system.
McNeal then used the patient names and contact information to launch a direct-mail marketing campaign to benefit his new employer. There is no evidence that McNeal downloaded or misused specific patient medical information, prosecutors said.
“Anyone who gives their personal information to a doctor or medical facility does not expect that their information will be hacked and used to make money," said U.S. Attorney Sally Quillian Yates. "This is cybercrime. Electronic information is bought, sold and stolen, often by someone who knows a system and, with a few keystrokes, makes our community vulnerable.”
Source Article: http://goo.gl/axgwz
13 January 2012
5 reasons cybersecurity matters to small businesses
Summary: Small businesses often think they are ‘too small’ to be worth hackers’ notice, but that assumption could be devastating.
On Christmas Day, perfectly timed for the traditionally slow news week that leads into New Year’s Eve, the cyber hacktivist group Anonymous apparently hacked the Web site and internal servers of security consulting and risk management advisory firm Stratfor.
Soon thereafter, the alleged attackers began publishing all sorts of confidential information, including the names of the company’s clients. What’s more, someone started using the credit card information obtained during the breach to make charitable donations in a vaguely Robin Hood-esque tradition.
Although the subsequent attacks that were threatened apparently have not come to pass, or least haven’t yet been disclosed publicly, the incident caps a year of pretty serious cyberhacking. Sony and RSA were just two of the big companies embarrassed by extremely public incidents. As I was reading up on this topic, I discovered that there were 760 attacks in the past decade by just one Chinese firm. That’s just one nasty organization. That should give you pause, because I can assure you there is more than one person out there in the world who would love to create trouble for your business.
So, even though I’ve already written about essential technologies for investment by small businesses in 2012, security is absolutely positively the most important infrastructure that small companies need to make.
Here are 5 reasons why:
Smaller companies are more likely to be attacked than bigger ones. Don’t believe me? Symantec.com, which keeps statistics on this sort of thing, suggests that 40 percent of attacks are against organizations with fewer than 500 employees, versus 28 percent against bigger companies. Remember, there are lots of people who could make trouble this way. Not just big groups with something to provide like Anonymous or LuluSec, but disgruntled former employees or business partners.
Breaches are potentially business-ending events. Depending on the statistics you believe, the average cost of a breach or cybersecurity incident is about $190,000. Do you have that sort of money to lose? Even more serious: about half of small businesses still don’t back up their data, so what is lost is lost forever. Which means your business might be lost forever. The Federal Communications Commission has published a useful cybersecurity guide you might want to consult.
Can you be sure you are properly controlling the access of your employees and business partners? This will only be a bigger factor, as personal tablets and smartphones become more commonly used as business tools. Improperly managed client-side software is one of the biggest known cybersecurity threat, allowing people to see information that they really shouldn’t be able to see AND allowing rogue malware to enter your infrastructure. I am dealing with an problem like this right now. Even though certain files I post to my non-profit’s web site are “gated,” for some reason, they can be accessed publicly if the right link shows up in a Google search.
Attacks could ruin your company’s reputation. I know that they say all publicity is good publicity, but think about how embarrassed Stratfor must be this week. After all, this is a security consulting company. According to the reports about the incident, the reason that the hackers were able to steal so much data — up to 200 gigabytes — and make use of it was because certain information was not encrypted. Stratfor should have known better, and so should your company.
Your company could be putting its best customers at risk. In assessing the security risks for their business, some owners and managers fail to consider that it isn’t just your own data you need to worry about, it is that of your customers. Anyone involved in healthcare already has this mantra beaten into their brain, but any company that engages in business-to-business activity with much larger businesses needs to consider their needs as the driver for their own security plans.
Article Source: ZDNet... http://t.co/vemfIXLt via @HeathClancy
12 January 2012
5 top cyber threats for 2012
As cybercriminals improve their toolkits and malware, they’re moving away from hacking personal computers to mobile devices, as well as plotting other more sophisticated attacks, according to a report on the top cyber threats for 2012.
“Many of the threats that will become prominent in 2012 have already been looming under the radar in 2011,” Vincent Weafer, senior vice president of McAfee Labs, a technology company and subsidiary of Intel Corp., said in a release
The five top cyber threats as seen by McAfee are:
Attacking mobile devices: Techniques used in the past for online banking, such as stealing from victims while they are still logged on, will now target mobile banking users.
Embedded hardware: Embedded systems, which are designed for a specific control function within a larger system, are commonly used in vehicles, GPS systems, medical devices, routers, digital cameras and printers. Hackers with access to malware that attacks the hardware layer of such systems will gain control and long-term access to the system and its data.
Industrial attacks: Many of the environments where SCADA (supervisory control and data acquisition) systems are deployed — such as water, electricity, oil and gas utilities — don’t have sufficiently stringent security practices, leaving them vulnerable to blackmail or extortion.
"Legalized" spam: While global spam volumes have dropped in recent years, legitimate advertisers are now using the same techniques, such as purchasing email lists of users who have consented to receive advertising, or purchasing consumer databases from companies going out of business. “Legal” spam is expected to grow at a faster rate than illegal phishing and confidence scams on the internet.
Online/frontline hacktivisim: McAffee predicts the true Anonymous group will reinvent itself or die out, and those leading digital disruptions will join forces with physical protesters to target public figures such as politicians and business leaders.
11 January 2012
Biggest security threats in 2012 are cyber espionage, privacy violations
Cyber espionage, along with privacy violations and social networking attacks facilitated by the increased use of mobile and tablet devices, will be the source of increased security threats over the coming months. This was revealed by PandaLabs, Panda Security's anti-malware laboratory in its predictions for top security trends to watch out this year.
Cyber espionage targeting companies and government agencies around the world will dominate corporate and national information security landscapes, and jeopardise the integrity of classified and other protected information. Trojans are expected to be the weapon of choice for hackers focused on these highly-sensitive targets.
"We live in a world where all information is in digital form and is easily accessible if you know how. Today's spies no longer need to infiltrate a building to steal information. As long as they have the necessary computer skills, they can wreak havoc and access even the best-kept secrets of organizations without ever leaving their homes," said Luis Corrons, Technical Director of PandaLabs.
Consumers will continue to be targeted by cyber criminals as they find ever more sophisticated ways to target social media sites for stealing personal data. Social engineering techniques exploiting users' naiveté have become the weapon of choice for hackers targeting personally-identifiable information.
"Social networking sites provide a space where users feel safe as they interact with friends and family. The problem is that attackers are creating malware that takes advantage of that false sense of security to spread their creations," said Corrons.
Article Source: http://flpbd.it/nrq3 #infosec #hack #cybersecurity via @ECCOUNCIL
10 January 2012
What to Do If Your Online Account's Been Hacked.
Dylan Valade owns a Web design and software business. As part of his business, he deals with Web and network security issues every day.
One day, Valade received a confirmation email from a brokerage account letting him know that a trade had been made. That would have been fine, except for one thing.
"In this case, a stock had been sold that I did not sell," Valade said.
Recognizing that the account had been compromised, Valade changed all of his passwords immediately.
"My brokerage account was closed and a new one was opened," he added. "The equities were transferred to the new account, with a new login and password."
Valade's experience happened on a brokerage site, but any online account can be a target.
"The most valuable targets are financial services like PayPal, online bank accounts and investment accounts," explained Morgan Slain of Los Gatos, Calif.-based SplashData. "Facebook, LinkedIn, and other social networking sites are increasingly common targets. Online email accounts, including Gmail and Yahoo! Mail, are often hacked too."
The most sophisticated hackers actually don't target individual accounts, but instead go after repositories of account data on servers owned by large organizations, which is why companies such as Sony and Epsilon, a major email forwarder, are targeted.
What the hackers are looking to steal depends on the type of account they are hacking into. When banks or financial services such as PayPal are targeted, the objective is to steal money.
"But often the hacker has a larger objective than attacking one individual," said Lance James, director of intelligence at New York's Vigilant. "In most cases, they're gaining access to email or social network accounts specifically to enable further distribution of their activity, or to steal information that will give them access to other places — potentially more valuable places. For example, a hacker might conduct a series of intrusions with the aim of getting into an employer's payroll system."
If one of your online accounts has been hacked, it compromises the overall integrity of your computer, James added. This comes with two primary manners of impact.
"First, if there [was] personal or confidential information on that system, the owner must assume it has been hijacked by criminals," he explained. "This could have long-lasting effects including identity theft, credit fraud, bank account theft and misplaced trust between friends and associates.
"Second — in some ways more detrimental in terms of reach — that compromised computer can be used to launch attacks against others, expanding the sphere of impact geometrically," James said. "It is therefore the responsibility of organizations and every individual to take precautions wherever they can."
The surest sign that your account has been compromised is unusual activity.
"For a financial account like PayPal, the most obvious sign that your account has been compromised are suspicious transactions," said Kevin McNamee, security architect at Kindsight of Mountain View, Calif. "You should regularly check your account to look for any unauthorized transactions and report them immediately.
"For social networking services like Facebook," McNamee added, "you may notice unusual activity on your wall, but the most likely indication that something is wrong is when your friends ask why you've been sending them unusual links and email messages."
Some things to look for, according to Chris Boyd, senior threat researcher at GFI Software of Cary, N.C., include:
— Friends are asking you about random requests for money or messages that you've apparently sent them, claiming that you're stranded somewhere – for example, messages saying you got mugged in London. Scammers use this tactic for financial fraud. This is an especially popular tactic where compromised Facebook accounts are concerned, due to exploiting the trust of friends and family.
— Strange messages are posted from your Twitter account promoting websites and offers that you're unaware of.
— You find you're selling items on eBay that you didn't list.
If you find that one of your accounts has been compromised, the first step is to ensure that no additional damage can be done, McNamee suggested.
If you still have access to the account, change the password immediately. And then change the passwords to other online accounts, especially for any accounts that share an email address and/or a password with the compromised account.
Also, said McNamee, contact the organization that operates the service and let them know that your account has been compromised.
"Their website will provide information on how to report a problem and regain control over your account," he said.
If the account that was compromised held any financial data or credit/debit card information, James said it's best to contact the financial institutions and cancel the cards.
Even the most vigilant computer user is at risk for an attack. But Asaf Greiner, vice president of products at Sunnyvale, Calif.'s Commtouch, provided the following tips that will keep your accounts less vulnerable to a hacker:
— Use different passwords for different accounts, so if you lose one, you don't lose them all.
— Use strong passwords (e.g. ones that are hard to guess), especially with more valuable resources, such as bank accounts. When possible, use multiple-factor authentication, as with a code-number-generating token. If you find passwords hard to remember, use a password vault application to remember them for you.
— Install all recommended software patches and updates – and anti-virus software – on machines you manage.
— Don't log into valuable accounts from public machines or from unencrypted Wi-Fi networks.
Article Source: http://www.securitynewsdaily.com/what-to-do-if-your-online-accounts-been-hacked-0897/ vía @Security_SND
Alfredo Cedeno
IT Security Advisor
+61 452 066 638
Sent from my iPad
09 January 2012
Stratfor Hack Shows Even Experts Use Awful Passwords
Credit: Strategic Forecasting, Inc.
Anonymous' massive year-end attack on the global-security consulting firm Stratfor showed that even top-tier executives at the world's largest corporations don't have a clue about the importance of a strong password.
On Dec. 24, Anonymous announced it had hacked into the Austin, Texas, think tank Strategic Forecasting Inc. (Stratfor) and stolen thousands of private email addresses and credit-card details from the firm's clients and recipients of its emailed newsletters, which include Boeing, Bank of America, Chevron, AIG, Sony, HSBC, Wells Fargo, Google, the United Nations and all four branches of the U.S. military.
Five days later, Anonymous published the list of more than 859,311 email addresses, 860,160 hashed passwords, 68,063 credit cards and 50,569 phone numbers, Identity Finder reported.
Stratfor offers free subscriptions to some of its emailed newsletters. Most of its products must be paid for, including in-depth reports and custom consultations.
Cybersecurity expert Johm Bumgarner told the Los Angeles Times that among the email addresses and credit-card numbers were some belonging to former U.S. Secretary of State Henry Kissinger and former U.S. Vice President Dan Quayle. (SecurityNewsDaily could not verify that assertion.)
Using a computer-automated password-cracking tool called Hashcat, the tech-news site the Tech Herald sifted through the leaked logs to see what type of passwords Stratfor's clients and subscribers used to keep their sensitive accounts secure. The results, Tech Herald security editor Steve Ragan wrote, were "both expected and pitiful."
Stratfor clients used easy-to-guess passwords such as, "123456, "11111111," and "123123." Other terribly insecure passwords: "111222333444," "12345678901," "administration," "123456789abc," "12345stratfor," "hello123," "lawenforcement" and "intelligence."
A batch of weak passwords played off the word itself, including, "password1234," "password101," "password123," "password122" and "Password999." In just under five hours, Haschat was able to crack 81,883 of the 860,160 leaked passwords.
"In the time it took to watch a movie, Hashcat smashed more than 80,000 passwords," Ragan wrote. "How many of those cracked passwords and leaked email accounts can be used to stage a larger attack on the organizations contained within the list? We're not going to test that, obviously, but someone will."
Ragan said Stratfor's online registration process recommends users create passwords at least six characters long, including at least one number. Out of all the passwords successfully deciphered, 23,440 consisted of six characters, 15,394 had seven characters and 21,080 had eight characters.
Security experts recommend building long, complex, case-sensitive passwords with multiple characters. Stratfor clients clearly did not heed that advice; only 1,411 of the leaked Stratfor passwords had 11-character passwords. The number of passwords dropped off even more as the character length increased: There were 627 people with 12-character passwords, and only 165 had passwords with 13 characters.
If you're wondering whether your password, email address or credit card information was exposed in Anonymous' attack on Stratfor, Dazzlepod has created a free search tool that will scour the leaked info for you and let you know if you need to worry.

