Search This Blog

Showing posts with label name. Show all posts
Showing posts with label name. Show all posts

Monday, February 20, 2012

Criminals Exploit Stolen Customer Data

Excerpt from an article in The New York Times
Monday, February 20, 2012

Criminals Exploit Stolen Customer Data From Stratfor 

By SOMINI SENGUPTA

It began as a case of political hacktivism. Late last year, under the banner of the loose collective known as Anonymous, hackers broke into the systems of Stratfor Global Intelligence Service, a company that analyzes geopolitical risks worldwide. They stole the names, e-mail addresses and credit card numbers of thousands of its subscribers and posted them online for all to see.

That information apparently became lucre for criminals with commercial goals. Stratfor customers began receiving e-mails from what, at first glance, looked like Stratfor. An attached PDF file came with what looked like Stratfor letterhead. It warned of the risk of "harmful software" and asked the user to download an antivirus program by clicking on an embedded link. As it turns out, the link downloaded a piece of malicious software. It was detected by Microsoft's Malware Protection Center, which posted about it on its blog this week.

It's a classic example of what is known as social engineering -- tricking unsuspecting Internet users into downloading malware that can in turn be used to extract financial gain. The social engineering messages are often disguised as e-mails from friends and associates.

Friday, February 17, 2012

Facebook and Pseudonyms

Excerpt from an article in The New York Times (The New York Times Company)
- Clipping Loc. 2817-45 | Added on Friday, February 17, 2012, 11:37 AM

New Facebook Policy on Made-Up Names Lets Gaga Be Gaga

By SOMINI SENGUPTA

SAN FRANCISCO — On Facebook, celebrity has its privileges — including the right to use a made-up name.

Facebook has been strict about pseudonyms, saying that its site is intended for real people using their real identities. The policy even applied to people like Stefani Germanotta and Calvin Broadus, otherwise known as Lady Gaga and Snoop Dogg. They were allowed to use their stage names on fan pages, but not on their personal accounts.

Now, in what could be a bid to attract more celebrities, Facebook on Thursday introduced a change that allows some users to go by their established, well-known pseudonyms on their personal Facebook pages.

Facebook staff will check that the page in question belongs to the Stefani Germanotta that the world knows as Lady Gaga, as part of a broader program to verify the identities of well-known people and weed out impostors.

Thursday, February 9, 2012

Sandia to Help IT Professionals w/ DNS Vulnerabilities

News release from Sandia Labs:

January 11, 2012


Sandia cyber project looks to help IT professionals with complex Domain Name System (DNS) vulnerabilities

LIVERMORE, Calif. — Sandia National Laboratories computer scientist Casey Deccio has developed a visualization tool known as DNSViz to help network administrators within the federal government and global IT community better understand Domain Name System Security (DNSSEC) and to help them troubleshoot problems. (Click here to see a short video of Deccio discussing the DNSViz tool.)
DNSViz
Sandia computer scientist Casey Deccio developed a software tool called DNSViz to help network administrators with Domain Name System (DNS) vulnerabilities. DNSViz provides a visual analysis of the DNSSEC authentication chain for a domain name and its resolution path in the DNS namespace. 

DNSSEC is a security feature mandated for all federal information systems by the White House’s Office of Management and Budget (OMB). The 2008 mandate requires that “the top level .gov domain will be DNSSEC-signed, and processes to enable secure delegated sub-domains will be developed.”

The entity that serves to translate the hostname of a Uniform Resource Locator (URL) into an Internet Protocol (IP) address is known as the Domain Name System (DNS). A DNS “lookup” is a prerequisite for doing almost anything on the Internet, including Web browsing, emailing or videoconferencing.

Although the mandate made perfect sense, said Deccio, there soon emerged a problem when .gov organizations actually began deploying DNSSEC.

“DNSSEC is hard to configure correctly and has to undergo regular maintenance,” he said. “It adds a great deal of complexity to IT systems, and if configured improperly or deployed onto servers that aren’t fully compatible, it keeps users from accessing .gov sites. They just get error responses.”

The still-new DNSSEC security feature is designed to allow user applications like Web browsers to ensure that the IP addresses they have received from the DNS have not been “spoofed” by anyone with ill intent. As such, Internet-connected systems within the government can verify that the responses are authoritative and have not been altered. Still, the hiccups with implementing DNSSEC convinced Deccio that there was a need for a tool like DNSViz.

DNS, said Deccio, is inherently insecure. Without DNSSEC, tampering by third-party attackers could go undetected, thus redirecting online communications to unwanted destinations. This represents a particularly troublesome problem for .gov addresses owned by government organizations guarding national security information and other vital data.

Deccio believes DNSSEC is of little use if network administrators don’t know how to configure or use it.
He describes DNSViz as a “tool for visualizing the status of a DNS zone.” It provides a visual analysis of the DNSSEC authentication chain for a domain name and its resolution path in the DNS namespace, made available via a Web browser to any Internet user at http://dnsviz.net/. It visually highlights and describes configuration errors detected by the tool to assist administrators in identifying and fixing DNSSEC-related configuration problems.

DNSViz brings together all the components that work together for DNSSEC to function properly into a single graphical representation. The resulting visualization is a collection of configuration data and relationships that are otherwise difficult to assemble, assess and understand.

To help network administrators in their DNSSEC deployment, Sandia’s DNSViz tool functions in two primary ways: It actively analyzes a domain name by performing pertinent DNS lookups and it makes the analysis available via the Web interface. The active analysis occurs periodically to build a history of DNSSEC deployment over time and provide a historical reference for DNS administrators.

Currently, the Web interface is the primary source for viewers to observe data, though Deccio intends to expand DNSViz functionality to allow access via other means. For example, alert mechanisms might be used to inform affected parties, and application programming interfaces (API) can be designed to allow administrators to programmatically access the information instead of manually browsing the DNSViz website.
Deccio has the tool running in the background on Sandia/California’s servers, monitoring a list of some 100,000 DNS names. It performs an analysis a couple times each day and offers a situational awareness of what the DNS configuration for each name looks like from top to bottom.

Though the functionality provided by DNSViz could potentially be included in a marketable software product that’s sold by a for-profit company, Deccio says he envisions it as an open-source tool available to anyone who needs it. With further funding, he hopes to expand the tool so that it can analyze DNS health and security on a continuous basis, essentially creating a full-blown monitoring system that is scalable, versatile and more informational.