Showing posts with label networking security. Show all posts
Showing posts with label networking security. Show all posts

Monday, June 1, 2015

BBC: 'Moose' malicious worm targets home routers


28 May 2015 BBC

Medical equipment may also be vulnerable to attacks by the Moose worm, warn security experts
A malicious worm that targets poorly protected home routers has been uncovered by security researchers.
The "moose" malware tries to take over home routers by trying thousands of weak passwords.

Once it has taken over a device, the worm grabs login details when people visit Twitter, Facebook, Instagram, YouTube and other social sites.

These credentials are then used to artificially inflate followers and viewer numbers.

"This threat is all about social network fraud," said researchers Olivier Bilodeau and Thomas Dupuy from security firm Eset in a report detailing their findings.
Aggressive attack

The malicious program got its name because the file containing its attack code is called elan - French for moose.

The malicious worm travels the internet "aggressively" seeking out vulnerable devices. So far, said the pair, some of the routers made by Actiontec, Hik Vision, Netgear, Synology, TP-Link, ZyXEL, and Zhone have been found to be vulnerable to moose.

In their analysis, the two researchers saw the worm being used to set up bogus accounts on social network sites and then use stolen credentials to add fake "likes" and "follows" to those accounts.

Fake likes and follows for Twitter, Vine and Instagram accounts were added via moose
Instagram, Twitter and Vine were the three sites most widely abused by this bogus liking system, said the researchers.

The pair said it was hard to gauge the exact numbers of routers that had been compromised because of the steps moose's creators took to prevent detection. In addition, they said, the company hosting the command-and-control system for moose were very uncooperative.

Despite these problems, the researchers estimate that tens of thousands of routers are potentially vulnerable to moose and many of those devices might already be infected. Moose was first spotted in mid-2014 and has been active ever since, said Mr Bilodeau and Mr Dupuy.

They added that the weak passwords that moose exploited were used on many different devices not just home routers. They warned that medical equipment and smart home systems might also be susceptible to infection by moose.

In their analysis, the researchers gave advice about how to spot moose and said people should update default login systems to avoid its attentions.

Tuesday, May 26, 2015

HTTPS-crippling attack threatens tens of thousands of Web and mail servers


Diffie-Hellman downgrade weakness allows attackers to intercept encrypted data.


by Dan Goodin - May 19, 2015 10:54pm PDT  Ars Technica


Wikipedia

Tens of thousands of HTTPS-protected websites, mail servers, and other widely used Internet services are vulnerable to a new attack that lets eavesdroppers read and modify data passing through encrypted connections, a team of computer scientists has found.

The vulnerability affects an estimated 8.4 percent of the top one million websites and a slightly bigger percentage of mail servers populating the IPv4 address space, the researchers said. The threat stems from a flaw in the transport layer security protocol that websites and mail servers use to establish encrypted connections with end users. The new attack, which its creators have dubbed Logjam, can be exploited against a subset of servers that support the widely used Diffie-Hellman key exchange, which allows two parties that have never met before to negotiate a secret key even though they're communicating over an unsecured, public channel.

The weakness is the result of export restrictions the US government mandated in the 1990s on US developers who wanted their software to be used abroad. The regime was established by the Clinton administration so the FBI and other agencies could break the encryption used by foreign entities. Attackers with the ability to monitor the connection between an end user and a Diffie-Hellman-enabled server that supports the export cipher can inject a special payload into the traffic that downgrades encrypted connections to use extremely weak 512-bit key material. Using precomputed data prepared ahead of time, the attackers can then deduce the encryption key negotiated between the two parties.

"Logjam shows us once again why it's a terrible idea to deliberately weaken cryptography, as the FBI and some in law enforcement are now calling for," J. Alex Halderman, one of the scientists behind the research, wrote in an e-mail to Ars. "That's exactly what the US did in the 1990s with crypto export restrictions, and today that backdoor is wide open, threatening the security of a large part of the Web."

It wasn't supposed to be this way

FURTHER READING

STOP THE PRESSES: HTTPS-CRIPPLING “FREAK” BUG AFFECTS WINDOWS AFTER ALL

Microsoft advisory dramatically raises the number of vulnerable end-user devices.Ironically, Diffie-Hellman is supposed to provide an additional layer of protection because it allows the two connected parties to constantly refresh the cryptographic key securing Web or e-mail sessions. The so-called perfect forward secrecy that Diffie-Hellman makes possible significantly increases the work of eavesdropping because attackers must obtain the key anew each time it changes, as opposed to only once with other encryption schemes, such as those based on RSA keys. Logjam is significant because it shows that ephemeral Diffie-Hellman—or DHE—can be fatal to TLS when the export-grade ciphers are supported. Logjam is reminiscent of the FREAK attack that also allowed attackers to downgrade HTTPS connections to 512-bit cryptography.

According to this informational site established by the researchers, only Internet Explorer has been updated to protect end users against Logjam attacks. The researchers said they have been working with developers of major browsers and that Chrome, Firefox, and Safari are also expected to implement a fix that rejects encrypted connections unless the key material contains a minimum of 1024 bits. Updates are expected to be available in the next day or two, and possibly much sooner. Information on vulnerable end-user e-mail programs wasn't available at the time this post was being prepared.

According to the researchers, an estimated 8.4 percent of the top 1 million Web domains are vulnerable, and 3.4 percent of HTTPS-supported websites overall are susceptible. E-mail servers that support simple mail transfer protocol with StartTLS, secure POP3, and IMAP are estimated to be vulnerable in 14.8 percent, 8.9 percent, and 8.4 percent of the cases respectively.

To exploit vulnerable connections, attackers must use the number field sieve algorithm to precompute data. Once they have completed that task, they can use it to perform man-in-the-middle attacks against vulnerable connections in real time. Using academic-level hardware, the researchers required just two weeks to generate data needed to attack the two most commonly called prime numbers 512-bit Diffie-Hellman uses to negotiate ephemeral keys. Those two data sets allow the attackers to compromise about 92 percent of sites supporting the export cipher. It wouldn't require much additional work to generate data needed to attack the remaining sites.
Snowden revelations revisited

The work required to precompute data needed to attack 768- and 1024-bit primes is orders of magnitude harder, but the researchers said the load is nonetheless within the means of state-sponsored eavesdroppers. In a research paper titled Imperfect Forward Secrecy: How Diffie-Hellman Fails in Practice, the researchers speculate the technique may be the means the National Security Agency reportedly uses to routinely break millions of encrypted connections. Documents leaked by former NSA subcontractor Edward Snowden revealed the mass crypto attacks but didn't say how they're carried out. Besides attacking HTTPS-protected Web and e-mail sessions, the researchers said, the same technique may be used to break SSH and VPN connections, too.

"The technical details of our attack have also let us look at some of the leaked NSA documents in a new light, and give an explanation consistent with the documents and our experiments of how the NSA might be breaking certain crypto protocols on a wide scale," Nadia Heninger, a scientist at the University of Pennsylvania and an author of the paper, wrote in an e-mail.

In the short term, the researchers recommend all server administrators disable support for the DHE_EXPORT ciphersuites that allow Diffie-Hellman connections to be downgraded. The researchers have provided a guide with step-by-step instructions for securely deploying Diffie-Hellman in TLS. And of course, they also strongly encourage all end users to install browser and e-mail client patches that enforce minimum restrictions on the primes used to negotiate ephemeral keys. Over the longer term, they say, developers should transition to so-called elliptic curve Diffie-Hellman key exchange, since the scheme is less vulnerable to precomputed attacks.

Logjam continues a trend begun a few years ago of using catchy words or phrases to name vulnerabilities or the attacks that exploit them. Thankfully, this vulnerability disclosure wasn't accompanied by a logo, and the dedicated website offers a wealth of important information without any hype. Halderman told Ars the name is a pun on the "discrete log" mathematical operation used to break the weak keys. "But the name is also an allusion to the fact that these '90s-era export ciphers are part of an immense amount of technical debt that's built up in our crypto protocols," he added in an e-mail. "There's just too much dead wood that's accumulated over the years."

’90s-style security flaw puts “millions” of routers at risk


Flawed NetUSB driver found in Netgear, D-Link, TP-Link devices, and more.


by Peter Bright - May 20, 2015 5:10pm PDT Ars Technica

As companies continue to beat the Internet of Things drum, promoting a world when every device is smart, and anything electronic is network connected, we have some news that shows just what a horrible idea this really is. A security firm has found that a Linux kernel driver called NetUSB contains an amateurish error that can be exploited by hackers to remotely compromise any device running the driver. The driver is commonly found in home routers, and while some offer the ability to disable it, others do not appear to do so.

NetUSB is developed by Taiwanese company KCodes. The purpose of the driver is to allow PCs and Macs to connect to USB devices over a network, so that these devices can be shared just by plugging them into a Wi-Fi router or similar. To do this, a driver is needed at each end; a client driver on the PC or Mac, and a server driver on the router itself.

This router-side driver listens to connections on TCP port 20005, and it's this driver that contains a major security flaw. SEC Consult Vulnerability Lab, which publicized the problem, discovered that the Linux driver contains a simple buffer overflow. As part of the communication between client and server, the client sends the name of the client computer; if this name is longer than 64 bytes, the buffer overflows. The company says that this overflow can be exploited to enable both denial of service (crashing the router) and remote code execution.

In its write up of the bug, the researchers described the issue as something of a throwback, writing "the '90s are calling and want their vulns back, stack buffer overflow." Simple stack buffer overflows in widely deployed software are these days relatively unusual, as developers have become somewhat more conscientious of the danger they represent. But clearly not every developer has gotten the message yet.

SEC examined firmware for many SOHO routers, finding the flawed code in products from D-Link, Netgear, TP-Link, Trendnet, and ZyXEL. Ninety-two different products, including many current generation models, were found to include the bad code (a full list is available in the advisory. A further 21 other vendors also appear to ship NetUSB products; SEC did not check those vendors' firmwares, so the dangerous driver is likely to be found in more than just those 92 devices. SEC estimates that millions of devices are affected.

Exposure will vary from device to device, as not all routers will necessarily have the bad driver loaded and running. But many do. Worse, they may have no good way of disabling it; Netgear told SEC that even with NetUSB functionality disabled through the router's configuration UI, the driver is still loaded, and there is no ability either to disable it or to block access to port 20005 in the firewall.

TP-LINK intends to issue firmware updates for most of its affected devices by the end of the month. The response from other vendors appears to be less satisfactory, with no clear timeline for issuing fixes, nor even a commitment to fix the flaw (or create a way to disable the problem driver).

Will Internet of Things devices fare any better than routers? We're not going to hold our breath. It's almost certainly going to suffer the same propensity for sharing code and inadequate upgrade process. The result is unlikely to please anyone other than hackers.



Peter Bright / Peter is Technology Editor at Ars. He covers Microsoft, programming and software development, Web technology and browsers, and security. He is based in Houston, TX.@drpizza on Twitter

Wednesday, October 15, 2014

CyberWatch: Securing the Internet of Things Twitter Chat

October 16th, 3p.m. EDT


INTERNET of THINGS: the ability of objects and devices to transfer data

Just as critical infrastructure is essential to helping Americans live their everyday lives, a growing Internet of Things is changing the way we use technology and helping people live more efficiently. The Internet of Things encompasses the devices that are embedded with computers and, through a combination of sensors, connectivity to the Internet, and human activity, work to connect our lives to the digital world. Simply put, we are connected and online 24/7 even when we're not at a computer.

Join in a Twitter Chat:

Securing the Internet of Things

October 16, 2014, 3p.m. EDT

Host: Stop.Think.Connect. (@STOPTHINKCONNECT)

Use #ChatSTC and #NCSAM to join

www.cyberwatchcenter.org

Friday, October 3, 2014

CSSIA: Palo Alto Networks Essentials 1 & 2: FIREWALL Installation, Configuration & Management

CSSIA is proud to announce being a Palo Alto Networks Academy partner. Essentials 1 and 2: Firewall Installation, Configuration, and Management (PAN EDU-201 and 205)

This virtual training sessions will be held December 8th - 12th via WebEx from 9:00 a.m. - 4:30 p.m. CT. You will be receiving further information from Lynn Dohm (lynn.dohm@morainevalley.edu) 2 weeks prior to the session starting.

This course will be taught by a Palo Alto Networks Instructor via WebEx sessions. This one week VIRTUAL class will be 3 days on Essentials 1 and 2 days on Essentials 2.

If you are FACULTY at a credit-bearing institution, this course is FREE-OF-CHARGE. If you are faculty at a NON-credit-bearing institution, this course is $500. Your payment MUST be received upon registration or you will automatically be taken off the course roster.

These courses are made available by CSSIA for all Palo Alto Networks Inc.'s Authorized Academy Center (AAC) Instructors. Currently, we would also like to extend the invitation to all instructors who are interested in learning more about Palo Alto Networks technology.

The following may register: - All Palo Alto Networks Authorized Academy Center (AAC) instructors. - Any instructor whose college would like to become an academic partner of Palo Alto Networks. - All instructors who are interested in learning more about Palo Alto Networks firewalls.

This event is Online
Start Date: Dec 8 2014 9:00AM
End Date: Dec 12 2014 12:00AM

Presented by
CSSIA
http://www.cssia.org
View Details

Tuesday, July 22, 2014

EFF's Open Wireless Router tech aims to increase network security, spur Wi-Fi sharing

PC World


Lucian Constantin
Jul 21, 2014 12:37 PM

Advocacy group the Electronic Frontier Foundation wants to address the poor security track record of home routers with a new firmware project that will encourage users to share their Internet connection publicly by setting up guest Wi-Fi networks.

The first experimental version of the firmware, called the Open Wireless Router, was released Sunday and is mainly aimed at developers and hackers who can assist with finding bugs and improving the software overall.

The project’s main goals are focused on allowing router owners to securely set up public Wi-Fi networks for passers-by to use, which the EFF and other organizations argue helps conserve radio spectrum, benefits business and economic development and can spark innovation. However, some of the firmware’s other planned features could also improve the overall security of routers that run it, even if their owners don’t decide to share their Internet bandwidth with strangers.

“Most or all existing router software is full of XSS [cross-site scripting] and CSRF [cross-site request forgery] vulnerabilities, and we want to change that,” the EFF said Sunday in a blog post.

While this is generally true, the XSS and CSRF flaws, which allow attackers to hijack authenticated sessions, are actually among the least critical flaws commonly found in routers.

Over the years security researchers found vulnerabilities in routers that would have given attackers full control over many devices from a large number of manufacturers. The issues found included backdoor-like features and hard-coded credentials, traditional buffer overflows and command injection vulnerabilities in the Web-based administrative interfaces or even implementation errors in third-party components like UPnP libraries.

The overall consensus among security researchers is that from a security perspective the code maturity in the home router world is very poor. Adding to that problem is the fact that few router vendors publish detailed security advisories and that updating the firmware is usually a process that requires manual intervention and technical knowledge from users.

The Open Wireless Router firmware will have an automatic update mechanism that will work over HTTPS and will use digital signatures to prevent upstream tampering with the updates, the EFF said. “Firmware signatures and metadata are fetched via Tor to make targeted update attacks very difficult.”

Security researchers also pointed out in the past that many vendors don’t have dedicated security programs in place for properly handling the security vulnerabilities reported to them. Giving the EFF’s history of working with and supporting security researchers it’s likely the organization already knows how to deal with such reports.

Aside from security, the Open Wireless Router firmware promises improved network stability and performance. The firmware “will provide state-of-the-art network queuing, so most users can expect an improved Internet experience—especially with latency-sensitive applications—compared to what commonly available consumer grade routers are delivering today,” the EFF said.

So far the firmware’s “hacker alpha release,” as the EFF calls it, can only be installed on one router model—the Netgear WNDR3800. However, the firmware is based on a custom router software called CeroWrt, which is itself based on OpenWrt, one of the most popular community built router firmware project that supports a wide range of router models from many manufactures.

CeroWrt is also focused on network performance and security. Some of its goals includes proper support for IPv6 (Internet Protocol version 6) and better integration with DNSSEC (Domain Name System Security Extensions).

The EFF will be sponsoring a router hacking contest at the upcoming Defcon 22 security conference in Las Vegas next month together with security consultancy firm Independent Security Evaluators. The contest will reward security researchers for finding and exploiting vulnerabilities in home routers from different manufacturers, including in the Open Wireless Router firmware.

Monday, June 16, 2014

RHT: Network Security Engineer: Protecting Information and the Bottom Line

by Robert Half Technology
June 16, 2014


Network security engineers can expect a 6.6 percent increase in starting pay in 2014.
Hacker attacks and other cyber threats that target networks are ever-present security risks in today’s increasingly interconnected world where more and more sensitive information is being digitized.
“Businesses need to ensure their data is secure and protected at all times, and maintaining network security is a big part of that,” says Dave Kaplan, branch manager for Robert Half Technology in Charlotte, N.C.
Network security engineer salary increasing in 2014

Not surprisingly, perhaps, the network security engineer position is among the top six hot tech jobs for 2014. And many leading employers are prepared to offer higher starting compensation to skilled network security engineers this year. Robert Half Technology’s Salary Guide reports that the average starting network security engineer salary in the United States* is expected to increase 6.6 percent this year — ranging from $99,750 to $131,250. (Use the Robert Half Technology Salary Calculator to find specific salary information for your city.)
What it takes to be a network security engineer
To be a network security engineer, you must have:
  • Strong working knowledge of data and network security technologies
  • A minimum of five years of experience installing, monitoring and maintaining network security solutions
  • A four-year degree in a technical field
  • Excellent organizational, multitasking and communication skills
As a network security engineer, you must be able to translate security policies and procedures into technical architectures. You’re responsible for analyzing network performance, including identifying areas of concern and formulating action plans to remedy those areas. Your duties also include creating and maintaining documentation of network configurations and processes, as well as participating in post-deployment monitoring and testing. You need to plan, test and execute system upgrades as necessary, too.
Aspiring network security engineers: demonstrate your knowledge

Network security engineers are tasked with ensuring networking systems can withstand or speedily bounce back from problems caused by hacker attacks, natural disasters, or other threats and disruptions. That’s why a multifaceted background that includes information technology, information security, networking and engineering experience is important for this role.

Kaplan suggests, “In addition to getting the right educational training, aspiring network security engineers should consider earning in-demand certifications, such as the Certified Information System Security Professional (CISSP) credential or Cisco Certified Network Associate (CCNA) designation.”

Technology is constantly evolving, so it’s imperative that network security engineers do the same when it comes to their skills and knowledge. According to Kaplan, “The best network security engineers strive for lifelong learning. This includes staying apprised of new security solutions hitting the market, devouring security publications to stay in the loop, and taking advantage of opportunities to either pick up new skills or improve those already acquired.”

Look to Robert Half Technology’s latest Salary Guide for job descriptions and starting salaries for a wide range of IT jobs — including network security engineer.

*Network security engineer starting salaries in Canada are projected to increase 6.2 percent in 2014, ranging from $95,000 to $124,500. Figures are in Canadian dollars.




— Robert Half Technology

With more than 100 locations worldwide, Robert Half Technology is a leading provider of technology professionals for initiatives ranging from web development and multiplatform systems integration to network security and technical support. Visit our website at www.rht.com.

Thursday, May 1, 2014

McKinsey: Rising Risks of Cyberattacks



New from McKinsey Quarterly


The rising strategic risks of cyberattacks

As much as $21 trillion in economic-value creation worldwide in the next five to seven years depends on robust cybersecurity. Yet most technology executives believe their companies are losing ground to cyberattackers. more

Our latest thinking, wherever you are. Install the McKinsey Insights app for iPad or Android.

Wednesday, April 23, 2014




Date: April 25, 2014

Time: 10:30 a.m. ET - 12:00 p.m. ET

Cost: Complimentary



About the Webcast

Join technical staff from the Software Engineering Institute (SEI) and Codenomicon during a live-streamed panel discussion on the impact of the recently announced Heartbleed OpenSSL vulnerability along with methods to mitigate and even prevent crises like this in the future. Chris Clark, Security Engineer from Codenomicon, one of the cybersecurity organizations that discovered the Heartbleed vulnerability, will join members of SEI's technical staff from the CERT and Software Solutions divisions and from the SEI's Information Technology department. They will be discussing how software vulnerabilities like Heartbleed can be mitigated through the different phases of the secure software lifecycle using techniques available today. They will also discuss how changes to our current software development and management techniques need to be managed to more effectively reduce the effects of incidents like Heartbleed.

About the Panelists



Will Dormann has been a software vulnerability analyst with the CERT Coordination Center (CERT/CC) since 2004. His focus areas include web browser technologies, ActiveX, and fuzzing. Will has discovered thousands of vulnerabilities using a variety of tools and techniques.

Robert Seacord is a senior vulnerability analyst in the CERT® Program

at the Software Engineering Institute (SEI) in Pittsburgh, PA where he leads the Secure Coding Initiative. Robert is the author of The CERT C Secure Coding Standard (Addison-Wesley, 2008/2nd Ed. 2014) and Secure Coding in C and C++(Addison-Wesley, 2002) as well as co-author of two other books. Robert is an adjunct professor at Carnegie Mellon University.

Christopher Clark, a twenty-two year veteran of the Information Technology world, is a Security Engineer at Codenomicon. Chris utilizes his extensive background and experience to help organizations effectively integrate meaningful security practices into their environments.

Brent Kennedy is a member of CERT's Cyber Security Assurance team focusing on penetration testing operations and research. Brent leads an effort that partners with the DHS National Cybersecurity Assessments and Technical Services (NCATS) team to develop and execute a program that offers risk and vulnerability assessments to federal, state, and local entities.




William Nichols joined the Software Engineering Institute (SEI) in 2006 as a senior member of the technical staff and serves as a Personal Software Process (PSP) instructor and Team Software Process (TSP) Mentor Coach with the TSP Initiative within the Software Solutions Division (SSD).

Jason McCormick has been with SEI Information Technology Services since 2004 and is currently the Manager of Network and Infrastructure Engineering. He oversees datacenter, network, storage, and virtualization services and plays a key role in information security policy, practices, and technologies for the SEI.

Timur Snoke is a Member of the Technical Staff with the CERT® Division Network Situational Awareness team.



Robert Floodeen (Moderator) has worked across federal and Department of Defense operations in the United States. He has led teams performing intrusion detection at the Pentagon, Army Research Lab, and for the Defense Research and Engineering Network (DREN). Additionally, he spent several years managing CSIRT operations for the Defense Threat Reduction Agency.

  https://www.webcaster4.com/Webcast/Page/139/4200

Who Should Attend?

Security Managers and CISOs
CIOs and CTOs
Information Assurance Specialists
System Administrators
Network and IT Managers
Software Developers

Please share with colleagues or interested parties!

Friday, April 18, 2014

WASTC Cisco Regional Academy Conference: Pathways to Success in ICT

                                                                                                      

WASTC
Cisco Regional Academy Conference
Pathways to Success in ICT

Registration Is Now Open And You are Invited To Attend!

The Cisco Western Academy Support and Training Center (WASTC) is pleased to host its Regional Academy Conference, Pathways to Success in ICT, at Cal Poly Pomona, June 16-20, 2014.

  
The event consists of:

·         3 days of Pre-Conference Workshops, June 16-18
·         2 days of Regional Academy Conference, June 19-20


Pre-Conference Workshops
We are very excited to be able to offer (at no additional fee) a number of outstanding pre-conference workshops, in which you can develop in-depth knowledge and skills. For full descriptions go to:  www.wastc.org

·         Cisco IT Essentials, Instructor Training
·         Cisco CCNA1 Introduction to Networks, Instructor Training
·         EMC Cloud Infrastructure and Services (CIS)
·         BIG DATA: Introduction to Talend & Tableau, Business Analytics and Intelligence Tools
·         Linux Essentials Train-the-Trainer Workshop
·         NDG Netlab+ Setup, “Bring your IT Programs Online”
·         VCA (VMware Certified Associate) in Data Center Virtualization and vCloud

These are each valuable, intensive 3-day workshops, and some require pre- or post-work.  The Linux track includes free certification testing.

Academy Conference

The agenda features a daily keynote address, and provides a diverse range of empowering and informative 75-minute breakout sessions, organized in tracks such as:
  • Technical topics, hands-on labs, and best practices [IT-E, CCNA, Wireless, CCNP, Security, Packet Tracer, Wireshark, IPv6…..]
  • Topics related to improving ICT educational pathways and jobs
  • Cybersecurity and cybersecurity competitions
  • New Academy best practices
  • NetSpace
  • Free "LPI Linux Essentials Certificate of Achievement” exam [$110 value]
Each day, you will have time to rub shoulders with other attendees and industry sponsors at a light breakfast and lunch, and we have two social events planned.

·         Welcome & Graduation Reception, June 18, sponsored by MPICT
·         Appreciation Dinner, June 19, sponsored by SIGMAnet

Fee Information

The registration fee for both the Pre-Conference and the Academy Conference is $99 for WASTC academies, and $150 for non-WASTC academies.  You may attend the Pre-Conference, the Academy Conference, or both, for the same registration fee.  Hotel and travel information is on our event website.


Thank you to our sponsors and partners who make this event affordable to all!

For questions, please refer to the event website.

Or you may contact Karen Stanton at karen.stanton@wastc.org

Sunday, March 30, 2014

BBC: Data-stealing Snoopy drone unveiled at Black Hat

28 March 2014 Last updated at 03:07 ET  BBC

By Kim GittlesonBBC reporter, Black Hat, Singapore
Glenn Wilkinson uses a quadcopter drone with the Snoopy software built inside to gather smartphone data

Security firm SensePost has unveiled its Snoopy drone, which can steal data from unsuspecting smartphone users, at the Black Hat security conference in Singapore.
The drone uses the company's software, which is installed on a computer attached to a drone.

That code can be used to hack smartphones and steal personal data - all without a user's knowledge.

It does this by exploiting handsets looking for a wireless signal.

Glenn Wilkinson, who developed Snoopy, says that when the software is attached to a drone flying around an area, it can gather everything from a user's home address to his or her bank information.

"Every device we carry emits unique signatures - even pacemakers come with wi-fi today," Mr Wilkinson tells the BBC.

"And - holy smokes, what a bad idea."

'The machines that betrayed their masters'
Many smartphone users leave the wireless option constantly turned on on their smartphone. That means the phones are constantly looking for a network to join - including previously used networks.

"A lot of [past] network names are unique and it's possible to easily geo-locate them," says Mr Wilkinson, who explains Snoopy uses a combination of the name of a network a user is looking for as well as the MAC address that uniquely identifies a device to track a smartphone in real-time.

Snoopy can identify the exact location and user information of a specific smartphone

Beyond that, Snoopy demonstrates how someone could also impersonate one of those past networks in a so-called karma attack, in which a rogue operator impersonates a past network that a user then joins, thinking it is safe.

I've gathered smartphone device data from every security conference 
that I've been at for the last year and a half”
Glenn Wilkinson Sensepoint

Once the user has joined the disguised network, the rogue operator can then steal any information that the user enters while on that network - including e-mail passwords, Facebook account information, and even banking details.

This is why Mr Wilkinson says that smartphones and other devices that use wireless technology - such as Oyster cards using RFID (radio frequency identification) or bank cards with chips - can betray their users.

'Am I on candid camera?'

Mr Wilkinson - who began developing the Snoopy software three years ago as a side-project - gave the BBC a preview of the technology ahead of its release.

Pulling out a laptop from his bag, Mr Wilkinson opened the Snoopy programme - and immediately pulled up the smartphone information of hundreds of Black Hat conference attendees.

With just a few keystrokes, he showed that an attendee sitting in the back right corner of the keynote speech probably lived in a specific neighbourhood in Singapore. The software even provided a streetview photo of the smartphone user's presumed address.

SensePost has used the Snoopy software attached to cheap commercial drones like DJI's Phantom

"I've gathered smartphone device data from every security conference that I've been at for the last year and a half - so I can see who was at each event and whether or not they've attended multiple events," says Mr Wilkinson.

He then shows this data to conference attendees - who often ask, when presented with a photograph of their home or office, if they're on candid camera.

Bringing awareness

Mr Wilkinson is quick to acknowledge that the Snoopy software is not new technology - but rather, just a different way of gathering together a series of known security risks.

"There's nothing new about this - what's new is that Snoopy brings a lot of the technology together in a unique way," he explains.
Find out more
Drones are controlled either autonomously by on-board computers, or by remote control
They are used in situations where manned flight is considered too dangerous or difficult
Also increasingly used for policing and fire-fighting, security work, and for filming

For instance, the Snoopy software has been ground-based until now, operating primarily on computers, smartphones with Linux installed on them, and on open-source small computers like the Raspberry Pi and BeagleBone Black.

But when attached to a drone, it can quickly cover large areas.

"You can also fly out of audio-visual range - so you can't see or hear it, meaning you can bypass physical security - men with guns, that sort of thing," he says.

It's not hard to imagine a scenario in which an authoritarian regime could fly the drone over an anti-government protest and collect the smartphone data of every protester and use the data to figure out the identities of everyone in attendance.

Mr Wilkinson says that this is why he has become fascinated with our "digital terrestrial footprint" - and the way our devices can betray us.

He says he wants to "talk about this to bring awareness" of the security risks posed by such simple technologies to users.

His advice? Turn off the wireless network on your phone until you absolutely need to use it.

Monday, March 17, 2014

BBC: Who is winning the 'crypto-war'?

15 March 2014 Last updated at 20:12 ET
By Gordon Corera, Security correspondent, BBC News



In the war over encryption between the NSA and privacy activists, who is winning?

Ladar Levison sits exhausted, slumped on a sofa with his dog Princess on his lap. He is surrounded by boxes after he moved into a new house in the suburbs of Dallas, Texas, the previous day.

He describes his new home as a "monastery for programmers". Levison and co-workers plan to live and work there as they create a new email service which will allow people to communicate entirely securely and privately. His goal, he says, is to "spread encryption to the masses".

It is a new email service because Levison himself shut down his old one - called Lavabit - after a visit from the FBI.

It began with a business card in May of last year. They were after the communications of one of his clients. Levison cannot say who it was but everyone knows it was Edward Snowden who had just left the country with a stash of secret documents and was using his Lavabit email to communicate.


A tussle with the FBI led to a court ordering Levison to hand over the keys to his email service. He feared it would leave all his 400,000 users vulnerable so he came up with a plan. The keys consisted of thousands of seemingly random characters. Rather than hand them over in electronic form, he printed them out. In tiny type. And then handed over the piece of paper.

"I met the FBI agents in the lobby and I handed them the envelope and the FBI agent held it up to the light, wiggled it back and forth and was like 'Are these the keys?' And I said yeah. I just printed them out. He was like 'Oh'. So he wrote out a receipt for one sealed white envelope."

Levison knew that it would take time for the FBI to input the keys and that gave him the chance to shut down his entire system. He had named his machines after his ex-girlfriends and describes the process of pulling the plug as a "surreal experience… seeing all of the lights continue to blink out in the ether as all the users tried to continue to access their email even though the systems had been turned off."



At the heart of Ladar Levison's case is a question. Do we want our communications to be entirely private so that absolutely no-one apart from the recipient can know what's being said? Or are we prepared to allow the state access - for instance when it says it is investigating crime or protecting national security? That issue has come to the forefront now because of Edward Snowden. But what's known as the crypto-wars have in fact been going on for 40 years.

You could date the start to a meeting at Stanford University in California in 1976. On one side of the table were a pair of mathematicians - Martin Hellman and Whit Diffie. On the other were a team from the federal government - including the NSA.

Hellman and Diffie believed that a proposed federal standard to encrypt data had been deliberately weakened by NSA to allow its supercomputers to break into communications. There had also been suspicions of so-called back doors which would allow the NSA secret access. In an increasingly heated exchange the two sides argued over how much computing power would be needed to break the proposed standard. "My view at the time was that I was Luke Skywalker in Star Wars," Hellman tells me in his home on the sprawling Stanford Campus, "and NSA was Darth Vadar."

Soon after that meeting, Diffie and Hellman revolutionised the world of codes by publishing a paper outlining a concept known as "public key cryptography". Until then the process of encrypting information was something only governments did, but public key offered the chance for ordinary people to be able to communicate securely.

Adm Bobby Ray Inman took over as NSA director in 1977. He found his staff worried by the intrusion into what had been their domain. "The great worry was that this effort would produce cryptographic systems that they couldn't break and it wasn't just worry about drug dealers and the rest of that," he told me in his office in Austin Texas. "It was that they could be picked up by foreign countries." Inman decided the two sides needed to talk and went to see Hellmann, which led to a dialogue between the NSA and the academic community.

But encryption was spreading. Commercial companies began developing products they wanted to sell - and export. And activists began building systems for people to use - the most significant being Phil Zimmermann, whose PGP encryption programme ended up being distributed for free over the early internet. The FBI and NSA began to worry. "It turns out that the biggest, most enthusiastic market for strong encryption are people who have a lot to hide," says Stewart Baker who took over as NSA's top lawyer in 1992 and who cites criminals, including paedophiles, as well as foreign spies as those who used the new systems. Those opposing the NSA argue though that these concerns should not trump the public's right to privacy.

But by the end of the 1990s, encryption was out there and the crypto-wars looked to have been won. At least that is how it seemed at the time.



At the annual RSA Security Conference in San Francisco a few weeks ago attendees got to choose a film to eat their popcorn in front of on cinema night. They picked Enemy of the State, a Will Smith thriller featuring rogue agents from the NSA.

Edward Snowden has become an enemy of the state but to many privacy activists, it is the state - and specifically the NSA - which is the enemy.

The issues raised by Snowden - especially the claim that the NSA had worked to defeat encryption - hang over the meeting. A session on random number generators turns into a discussion as to whether the generators have been rigged by the NSA to provide a backdoor.

"The government lost the crypto-wars," leading cryptographer and NSA critic Bruce Schneier explains in the margins of RSA. "Crypto is now freely available but in a sense they won because there are so many ways at people's data that bypass the cryptography.

"What we're learning from the Snowden documents is not that the NSA and GCHQ can break cryptography but that they can very often render it irrelevant… They exploit bad implementations, bugs in hardware and software, default keys, weak keys, or they go in and break systems and steal data."

The National Security Agency's data Centre in Utah

The NSA has long shrouded itself in secrecy. But in recent months it has realised it needs to fight its corner. I was allowed into its headquarters in Fort Meade, Maryland, for an overview of its work - but without any recording devices. In a downtown Washington hotel though, I did speak to Chris Inglis, who stepped down as deputy director of the NSA. He is a man who is careful with his words but his anger at Edward Snowden's revelations lie just beneath the surface. "There's a sense of betrayal that someone appointed himself judge and jury," he says, adding that America's adversaries will now have a "greater sense" how to avoid the NSA's attention.

What is encryption?

The digital scrambling of source material, turning it into "ciphertext" - what appears to be a garbled stream of characters that is only supposed to become understandable if a piece of information called a "key" turns it back into its original form


He argues that "NSA does not have backdoors into the world's encryption writ large".

The NSA's "principal forte" he says "is trying to find those things that are either inherent, accidental or merely the slips and pratfalls of people who don't implement these things properly."

As to the claim that vulnerabilities are inserted into commercial systems to make them exploitable, Inglis does not deny the possibility but suggests such techniques would only be used selectively. "Any activity of that sort would then in my view be focused on a very specific target - probably tactically focused and only for those legitimate purposes." The NSA has defensive and offensive roles - with securing national security information as well as stealing that of others - but the tension between these roles has been highlighted by the increasingly widespread use of commercial cryptography, including by the government itself.

Encryption is invisible but it is everywhere today. Every time you bank or buy something online, when you make a call on your mobile or when your key fob opens your car. Crypto may be out there. But the crypto-wars - the battle between those who believe privacy is king, and those who support the state's right to listen in - are only going to grow fiercer.

Listen to Gordon Corera's report on Crypto-wars on BBC Radio 4 on Sunday 16 March at 13:30 GMT or catch up afterwards on iPlayer

Follow @BBCNewsMagazine on Twitter and on Facebook

Monday, March 3, 2014

BBC: Hackers take control of 300,000 home routers

3 March 2014 Last updated at 11:13 ET


It is not yet clear what the attackers plan to do with their network of hijacked routers

A world-spanning network of hijacked home routers has been uncovered by security researchers.

The network involves more than 300,000 routers in homes and small businesses that have been taken over through loopholes in their core software.

Discovered by researchers at Team Cymru, the network is thought to be one of the biggest involving such devices.

It is not yet clear what the people behind the attack intend to do with the collection of compromised routers.

In a research paper describing its findings, Team Cymru said it had first seen routers from several different manufacturers being compromised in January 2014.

These first victims had been in Eastern Europe, but now most of the machines were in Vietnam with the rest scattered around Europe as well as a couple of other countries, said Team Cymru.

Once routers were taken over, internal instructions were changed so they no longer asked servers at their owner's ISP for help looking up the location of websites they regularly visit.

This would mean that the attackers could re-direct people to anywhere they wanted, inject their own adverts into web pages people visit or poison the search results they get.

Instead, these queries were routed through two IP addresses overseen by a hosting company in south London. That company has yet to respond to a request for comment.

Team Cymru researcher Steve Santorelli said the reason for creating the network of hijacked routers was still "mysterious" as the attackers did not seem to have abused their control for malicious ends.

The attack had some similarities with an incident seen in Poland, which involved hijacked home routers being re-directed to malicious websites controlled by hi-tech thieves keen to grab online bank login credentials, said Mr Santorelli.

"It's a definite evolution in technology - going after the internet gateway, not the end machine," Mr Santorelli told the BBC in an email. "We see these leaps in concepts every few years in cybercrime."

Team Cymru had contacted law enforcement about the attack and informed ISPs with a lot of compromised customers, he said.

Wednesday, November 13, 2013

Here Come the WiFi Drones


Dan Jones, Mobile Editor, 11/11/2013, LightReading
By the fall of 2015, nonmilitary unmanned aircraft (drones) are set to be flying in US airspace, and at least some will be equipped with WiFi and other communications equipment. This scenario could stir up new issues around security and privacy on terra firma.

Last week, the Federal Aviation Administration sent its plan for the "safe acceleration of the integration of civil UAS [unmanned aircraft systems] into the National Airspace System" (NAS) to several government transportation committees. The plan calls for commercial drones to be flying "not later than September 30, 2015" and earlier if possible.

The agency says drones could be used for anything from crime scene investigations to border patrol and search and rescue missions. The New York Police Department has already expressed interest in using unmanned aircraft as a surveillance tool. The FAA is also expecting drones to be used in agricultural applications.

At least 81 public organizations in the US have applied for special certification from the FAA to fly drones in domestic airspace, according to a list obtained by the Electronic Frontier Foundation . These include universities and local police and fire departments.

The FAA is defining -- and refining -- a plan for the safe integration of drones into US airspace. Operator training and collision sensors are seen as crucial, given the many types and sizes of drones expected to arrive in US airspace.

Such measures are important for flight safety. CNN reported this spring that a mysterious drone came within 200 feet of a commercial jetliner above John F. Kennedy Airport in New York. Drones could damage or down commercial aircraft by crashing into them or being sucked into a jet engine of the plane, depending on the unmanned craft's size.

The privacy issues around the use of drones are cloudier. The FAA states in the report:

Although there is no Federal law that specifically addresses privacy concerns with respect to civil UAS operations, many states have laws that protect individuals from invasions of privacy which could be applied to intrusions committed by using a UAS.
Integrating public and civil UAS into the NAS carries certain national security implications, including cyber and communications security, domestic framework for US government operations, national airspace and defense, airman vetting/general aviation, and privacy concerns. In coordination with the National Security Staff at the White House, the FAA is working in conjunction with relevant agency partners on an Interagency Policy Committee to address these issues.

This could lead to some interesting concerns about WiFi snooping and other communications surveillance using drones, particularly in the current climate. The burgeoning hobbyist industry for small drones has already shown how easy it is to install WiFi as a control mechanism on remote controlled aircraft. Hobbyist drones can already be flown in the US at 400 feet and below and within sight of the operator. Companies such as Parrot SA make WiFi-equipped quadricopters for drone fanciers.

Adam Conway, vice president of product management at Aerohive Networks Inc. , told us his company has already been experimenting with a WiFi access point in a drone. It flew a drone a few hundred feet above Sunnyvale, Calif., with a hotspot with a 4G module on board and got connected. Such temporary WiFi could obviously provide connectivity in disaster recovery situations and remote areas. However, there are many ways to use WiFi for snooping on other 802.11 users.

Brendan O'Connor, a law student at the University of Wisconsin at Madison and a researcher at the consulting firm Malice Afterthought, recently demonstrated the capabilities of CreepyDOL, a tiny and cheap WiFi sensor that can gather information about iPhone users as they walk around their neighborhood. Google (Nasdaq: GOOG) is battling a class action after it collected unencrypted WiFi data when its Google Maps cars took more than just snaps of areas around the world.

With ever-quieter drones being developed, it's possible to see how unmanned aircraft could be used as a surveillance and data collection tool in US airspace in the coming years. And it's hard to imagine that the topic of spying and snooping won't still be high on the public agenda come September 2015. (See: Another Day, Another Domestic Spying Revelation.)

— Dan Jones, Mobile Editor, Light Reading

Tuesday, October 22, 2013

New CompTIA Certification Addresses Mobile App Development Security

Press Releases, Oct 15, 2013, CompTIA

New CompTIA Certification Addresses Mobile App Development Security

CompTIA Mobile App Security+ for Android and iOS available worldwide

Downers Grove, Ill., October 15, 2013 – CompTIA, the non-profit association for the global IT industry, today introduced a new skills certification designed to raise security awareness and preparedness in the mobile app development universe.

CompTIA Mobile App Security+ is a vendor-neutral certification that validates the skills required to securely create a mobile application, while also ensuring secure network communications and backend web services. CompTIA today launched two unique editions of the certification exam – for native Android and iOS mobile applications.

“Mobile apps numbering in the millions are downloaded daily on smart phones, tablets and other mobile devices,” said Terry Erdle, executive vice president, skills certification, CompTIA. “But too often, in the dizzying race to bring new apps to market quickly, security considerations are an afterthought. With these new certifications we aim to bring the security focus back to where it belongs – in the starting blocks of mobile app development.”

Candidates for the CompTIA Mobile App Security+ credential will come from several job roles, such as mobile app developers, software developers, applications development managers and network security developers. The certification is best suited for individuals with at least 24 months of application development experience.

Areas covered in the exams include:

• Principles of secure application development
• Security models of Android and iOS devices
• Common threats to mobile app security
• Web services security models and vulnerabilities
• Secure coding techniques
• Common implementations of cryptography
• Encryption for storage and communications

Complete exam objectives for CompTIA Mobile App Security+ are available on the CompTIA Certification website.

Courseware for CompTIA Mobile App Security+ is available through Logical Operations. Their Mobile App Security courses cover mobile app security from the perspective of the software developer. Students learn secure programming practices for mobile app development, as well as specific security threats and countermeasures. Students implement countermeasures within actual apps using native software development tools.

With more than 1.8 million certifications awarded, CompTIA is the leading provider of vendor-neutral skills certifications for the world’s IT workforce. Visit CompTIA Certifications to learn more.

In addition to certifications for individual IT professionals, CompTIA offers other mobility-specific initiatives, including training for IT channel companies involved in or interested in offering mobility solutions to their customers; the CompTIA Mobility Community, a group of industry thought leaders who are shaping the mobility market; and leading market intelligence and research on mobility topics and trends.

About CompTIA
CompTIA is the voice of the world’s information technology (IT) industry. Its members are the companies at the forefront of innovation; and the professionals responsible for maximizing the benefits organizations receive from their investments in technology. CompTIA is dedicated to advancing industry growth through its educational programs, market research, networking events, professional certifications, and public policy advocacy. To learn more, visit www.comptia.org, http://www.facebook.com/CompTIA and http://twitter.com/comptia.

Contact:
Steven Ostrowski
CompTIA
630-678-8468
smostrowski@comptia.org

Friday, October 18, 2013

Large DoS Attacks More Than Quadruple in 2013: Study

 By Robert Lemos | Posted 2013-10-17 eWeek

 

The majority of denial-of-service attacks now exceed 1G bps, according to a new report from Arbor Networks. While the vast majority of denial-of-service attacks continues to be the typical background "noise" of rival gamers, online criminals and Internet vandals causing problems for each other, the more serious, higher-bandwidth attacks have quadrupled, according to a quarterly report released Oct. 16 by Arbor Networks.

Denial-of-service (DoS) attacks exceeding 20G bps, which will overwhelm almost any online service's bandwidth, more than quadrupled so far in 2013, compared with the previous year, according to the network management firm. While the attacks account for only approximately 1 percent of all data floods, the increase in large-bandwidth DoS attacks suggests that more serious groups are now using denial of service as a common tactic.

The surge in the number of "over 20G bps attacks shows that you have a lot of activity driven by other motivations," Dan Holden, Arbor's director of security research, told eWEEK. "That number increasing that much is showing that there is a lot of growth in more serious attack motivations."

Denial-of-service attacks are increasingly used as part of hacktivism and cyber-criminal campaigns in a variety of ways. Extortion scams used packet floods to overwhelm online gambling, retail and other sites that quickly lose money if their customers cannot connect; paying the ransom will allegedly stop the attacks, for a while. Online thieves use DoS attacks to distract defenders at financial institutions, so they are less vigilant during account thefts. Hacktivists, such as the al Qassam Cyber Fighters, disrupted financial institutions to incur costs to Western companies.
Yet most attacks are gamers who use short DoS attacks to kick opponents offline during a game, rival cyber-criminal organizations who seek advantage in the underground and Internet vandals who do it for fame. These "short, sharp" attacks have dominated packet floods, according to Holden. While the bandwidth used by the average DoS attack jumped 78 percent, seven out of every eight attacks lasts less than an hour."Historically, most of your DDoS [distributed denial of service]... is gamers and is very typical of what we all did on IRC [Internet Relay Chat] in the '90s," Holden said. Online arguments among early hackers occasionally devolved into battles to kick each other offline. "If you have enough bandwidth at home, or a small botnet, you can easily take someone offline."

Attacks that used bandwidth of more than 10G bps accounted for more than 4 percent of all attacks, while the largest confirmed DoS attack topped 191G bps, according to Arbor. Those more serious packet floods lasted 2 hours and 17 minutes on average, the report stated.

While larger-bandwidth attacks are becoming the norm, Holden pointed out that the increases are partially offset by the growth in capacity of the Internet. In many ways, attackers have to increase the size of their attacks just to have the same impact as in the past, he said.

Wednesday, October 2, 2013

U.S. Agencies Revamp Standards for Cybersecurity Program

Chronicle of Higher Education (09/30/13) Megan O'Neil 

The U.S. National Security Agency (NSA) and the Department of Homeland Security (DHS) are releasing new curriculum standards for the joint National Centers of Academic Excellence cybersecurity program. The designation currently covers 181 cyber­-security programs at colleges and universities, and the overhaul will require institutions to reapply for the program. "Every cybersecurity professional that comes out of college and takes a job is a win for the government, whether they work for John Deere, Boeing, or Target," says DHS cybersecurity­-education awareness branch chief Robin Williams, noting that global cybercrime costs $388 billion annually. "We are losing intellectual property. We are losing our nation's work and our nation's vision and our nation's ingenuity because we are not able to protect it." The Centers of Academic Excellence label carries prestige for colleges and universities, helping attract students and federal scholarships and grants. However, the program's former training guidelines, the Committee on National Security Systems standards, were criticized for recommending that students learn how to execute specific technical functions. In addition, critics argued that too many programs received the designation, thereby lessening its value. NSA and DHS have changed the standards to include new knowledge units with a core curriculum and additional, optional units that colleges can implement to promote specialties.