Search This Blog

Showing posts with label password. Show all posts
Showing posts with label password. Show all posts

Monday, March 26, 2012

Senators Want Employers’ Facebook Password Requests Reviewed

Excerpt from an article in

The New York Times
Monday, March 26, 2012

Senators Want Employers’ Facebook Password Requests Reviewed

By THE ASSOCIATED PRESS

Two Democratic senators are asking Attorney General Eric H. Holder Jr. to investigate whether employers asking for Facebook passwords during job interviews are violating federal law, their offices announced Sunday.

Troubled by reports of the practice, Senators Charles E. Schumer of New York and Richard Blumenthal of Connecticut said they were calling on the Justice Department and the Equal Employment Opportunity Commission to begin investigations. The senators are sending letters to the heads of the agencies.

The Associated Press reported last week that some private and public agencies around the country were asking job seekers for their social media credentials. The practice has alarmed privacy advocates, but its legality remained murky.

On Friday, Facebook warned employers not to ask job applicants for their passwords, presumably so they could view applicant profiles on the site. The company threatened legal action against applications that violated its longstanding policy against sharing passwords.

A Facebook executive cautioned that if an employer discovered that a job applicant is a member of a protected group, the employer might be vulnerable to claims of discrimination if it did not hire that person.

Personal information such as gender, race, religion and age are often displayed on a Facebook profile — all details that are protected by federal employment law.

Not sharing passwords is a basic tenet of online conduct. Aside from the privacy concerns, Facebook considers the practice a security risk.

Microsoft Raids Tackle Online Crime

Excerpt from an article in

The New York Times
Monday, March 26, 2012

Microsoft Raids Tackle Online Crime

By NICK WINGFIELD and NICOLE PERLROTH

SEATTLE — Microsoft employees, accompanied by United States marshals, raided two nondescript office buildings in Pennsylvania and Illinois on Friday, aiming to disrupt one of the most pernicious forms of online crime today — botnets, or groups of computers that help harvest bank account passwords and other personal information from millions of other computers.

With a warrant in hand from a federal judge authorizing the sweep, the Microsoft lawyers and technical personnel gathered evidence and deactivated Web servers ostensibly used by criminals in a scheme to infect computers and steal personal data. At the same time, Microsoft seized control of hundreds of Web addresses that it says were used as part of the same scheme.

The sweep was part of a civil suit brought by Microsoft in its increasingly aggressive campaign to take the lead in combating such crimes, rather than waiting for law enforcement agencies to act. The company’s targets were equipment used to control the botnets, which criminals, known as bot-herders, use for ill intent.

Microsoft has a big interest in making the Internet a safer place. Despite inroads made by Apple and others in some parts of the technology business, Microsoft’s Windows operating system still runs the vast majority of the computers connected to the Internet. The prevalence of its software has made Windows the most appealing target for online criminals, and the security holes they discover in the software are a persistent nuisance for Windows users.

Microsoft’s involvement in what had been considered largely a law enforcement function — fighting computer crime — is the brainchild of Richard Boscovich, a former federal prosecutor who is a senior lawyer in Microsoft’s digital crimes unit. That group watches over fraud that could affect the company’s products and reputation.

Friday, March 23, 2012

Why Hackers Set Their Sights on Small Business


If you run a small business, and think that none of your data was of interest to a hacker, consider this: what if a hacker could take stolen bank account or credit card information from your computer and package it with the same information from a hundred or a thousand other small businesses? Would it be worth something then?
"SMBs don't know how defenseless they've become, especially to automated and industrialized attack methodologies by organized crime," Christopher Porter tells PCWorld. Porter, a principal with the Verizon RISK Team, is the author of a new report from Verizon on security risk.
"[Hackers] scan the Internet, looking for remote access services, and then try the default credentials. Once they gain access, they automatically install keyloggers to collect password information [as it's typed in]," Porter says. "Then they send the information it out via e-mail or by uploading it to an FTP server or a web site. They aggregate the data and sell it on the black market."
Hackers could use the keylogger to figure out how access and drain a small business' bank account, but more commonly, Porter said, they'll target point-of-sale systems, as four Romanians did recently. "That kind of attack is increasing, because they're low-risk and low-cost attacks for organized crime." Because they're geographically widespread, it's hard for any one police department to follow up.
For more, click the link below: 


http://www.pcworld.com/businesscenter/article/252302/why_hackers_set_their_sights_on_small_businesses.html#tk.nl_bdx_h_crawl

Thursday, March 22, 2012

IBM X-Force Report: 2011 Shows Progress Against Security Threats But Attackers Adapt

IBM X-Force Report: 2011 Shows Progress Against Security Threats But Attackers Adapt

Emerging Attack Trends include Mobile Exploits, Automated Password Guessing, a Surge in Phishing and Shell Command Injection Attacks


ARMONK, N.Y. - 22 Mar 2012: IBM [NYSE:IBM] today released the results of its X-Force 2011 Trend and Risk Report, which shows surprising improvements in several areas of Internet security such as a reduction in application security vulnerabilities, exploit code and spam. As a result, the report suggests attackers today are being forced to rethink their tactics by targeting more niche IT loopholes and emerging technologies such as social networks and mobile devices.
The X-Force 2011 Trend and Risk Report revealed a 50 percent decline in spam email compared to 2010; more diligent patching of security vulnerabilities by software vendors, with only 36 percent of software vulnerabilities remaining unpatched in 2011 compared to 43 percent in 2010; and higher quality of software application code, as seen in web-application vulnerabilities called cross site scripting half as likely to exist in clients’ software as they were four years ago.  
In light of these improvements, it seems attackers are adapting their techniques. The report uncovers a rise in emerging attack trends including mobile exploits, automated password guessing, and a surge in phishing attacks. An increase in automated shell command injection attacks against web servers may be a response to successful efforts to close off other kinds of web application vulnerabilities.  
The IBM X-Force 2011 Trend and Risk Report is based on intelligence gathered by one of the industry’s leading security research teams through its research of public vulnerability disclosures findings from more than 4,000 clients, and the monitoring and analysis of an average of 13 billion events daily in 2011. 
“In 2011, we’ve seen surprisingly good progress in the fight against attacks through the IT industry’s efforts to improve the quality of software,” said Tom Cross, manager of Threat Intelligence and Strategy for IBM X-Force. "In response, attackers continue to evolve their techniques to find new avenues into an organization. As long as attackers profit from cyber crime, organizations should remain diligent in prioritizing and addressing their vulnerabilities." 
According to the report, there are positive trends as it appears companies implemented better security practices in 2011:  
·         Thirty percent decline in the availability of exploit code – When security vulnerabilities are disclosed, exploit code is sometimes released that attackers can download and use to break into computers. Approximately 30 percent fewer exploits were released in 2011 than were seen on average over the past four years. This improvement can be attributed to architectural and procedural changes made by software developers that help make it more difficult for attackers to successfully exploit vulnerabilities.  
·         Decrease in unpatched security vulnerabilities – When security vulnerabilities are publicly disclosed, it is important that the responsible software vendor provide a patch or fix in a timely fashion. Some security vulnerabilities are never patched, but the percentage of unpatched vulnerabilities has been decreasing steadily over the past few years. In 2011 this number was down to 36 percent from 43 percent in 2010. 
·         Fifty percent reduction in cross site scripting (XSS) vulnerabilities due to improvements in software quality - The IBM X-Force team is seeing significant improvement in the quality of software produced by organizations that use tools like IBM AppScan OnDemand service to analyze, find, and fix vulnerabilities in their code.  IBM found XSS vulnerabilities are half as likely to exist in customers' software as they were four years ago. However, XSS vulnerabilities still appear in about 40 percent of the applications IBM scans. This is still high for something well understood and able to be addressed. 
·         Decline in spam – IBM’s global spam email monitoring network has seen about half the volume of spam email in 2011 that was seen in 2010. Some of this decline can be attributed to the take-down of several large spam botnets, which likely hindered spammers’ ability to send emails. The IBM X-Force team witnessed spam evolve through several generations over the past seven years as spam filtering technology has improved and spammers have adapted their techniques in order to successfully reach readers.  
Attackers Adapt Their Techniques in 2011
Even with these improvements, there has been a rise in new attack trends and an array of significant, widely reported external network and security breaches.  As malicious attackers become increasingly savvy, the IBM X-Force documented increases in three key areas of attack activity: 
·         Attacks targeting shell command injection vulnerabilities more than double - For years, SQL injection attacks against web applications have been a popular vector for attackers of all types. SQL injection vulnerabilities allow an attacker to manipulate the database behind a website. As progress has been made to close those vulnerabilities – the number of SQL injection vulnerabilities in publicly maintained web applications dropped by 46 percent in 2011– some attackers have now started to target shell command injection vulnerabilities instead. These vulnerabilities allow the attacker to execute commands directly on a web server. Shell command injection attacks rose by two to three times over the course of 2011. Web application developers should pay close attention to this increasingly popular attack vector.  
·         Spike in automated password guessing – Poor passwords and password policies have played a role in a number of high-profile breaches during 2011. There is also a lot of automated attack activity on the Internet in which attacks scan the net for systems with weak login passwords. IBM observed a large spike in this sort of password guessing activity directed at secure shell servers (SSH) in the later half of 2011.  
·         Increase in phishing attacks that impersonate social networking sites and mail parcel services – The volume of email attributed to phishing was relatively small over the course of 2010 and the first half of 2011, but phishing came back with a vengeance in the second half, reaching volumes that haven’t been seen since 2008. Many of these emails impersonate popular social networking sites and mail parcel services, and entice victims to click on links to web pages that may try to infect their PCs with malware. Some of this activity can also be attributed to advertising click fraud, where spammers use misleading emails to drive traffic to retail websites.  
Emerging Technologies Create New Avenues for Attacks
New technologies such as mobile and cloud computing continue to create challenges for enterprise security.  
·         Publicly released mobile exploits rise 19 percent in 2011 – This year’s IBM X-Force report focused on a number of emerging trends and best practices to manage the growing trend of “Bring your Own Device,” or BYOD, in the enterprise. IBM X-Force reported a 19 percent increase over the prior year in the number of exploits publicly released that can be used to target mobile devices. There are many mobile devices in consumers' hands that have unpatched vulnerabilities to publicly released exploits, creating an opportunity for attackers. IT managers should be prepared to address this growing risk. 
·         Attacks increasingly relate to social media - With the widespread adoption of social media platforms and social technologies, this area has become a target of attacker activity. IBM X-Force observed a surge in phishing emails impersonating social media sites. More sophisticated attackers have also taken notice. The amount of information people are offering in social networks about their personal and professional lives has begun to play a role in pre-attack intelligence gathering for the infiltration of public and private sector computing networks.  
·         Cloud computing presents new challenges - Cloud computing is moving rapidly from emerging to mainstream technology, and rapid growth is anticipated through the end of 2013. In 2011, there were many high profile cloud breaches affecting well-known organizations and large populations of their customers. IT security staff should carefully consider which workloads are sent to third-party cloud providers and what should be kept in-house due to the sensitivity of data. Cloud security requires foresight on the part of the customer as well as flexibility and skills on the part of the cloud provider. The IBM X-Force report notes that the most effective means for managing security in the cloud may be through Service Level Agreements (SLAs) because of the limited impact that an organization can realistically exercise over the cloud computing service. Therefore, careful consideration should be given to ownership, access management, governance and termination when crafting SLAs. The IBM X-Force report encourages cloud customers to take a lifecycle view of the cloud deployment and fully consider the impact to their overall information security posture.  
"Many cloud customers using a service worry about the security of the technology. Depending upon the type of cloud deployment, most, if not all, of the technology is outside of the customer's control,” said Ryan Berg, IBM Security Cloud Strategist. “They should focus on information security requirements of the data destined for the cloud, and through due diligence, make certain their cloud provider has the capability to adequately secure the workload."  
IBM continues to work with its clients to step up security to address these new areas. Recommendations for helping clients improve the security of their IT department in light of these new threats include: performing regular security assessments; segmenting sensitive systems and information; training end users about phishing and spear phishing and secure computing principals in general, as well as examining the policies of business partners.  
To view the full X-Force 2011 Trend and Risk Report and watch a highlight video please visitwww.ibm.com/security/xforce.     
About the IBM X-Force Trend and Risk Report
The IBM X-Force Trend and Risk Report is an annual assessment of the security landscape, designed to help clients better understand the latest security risks, and stay ahead of these threats. The report gathers facts from numerous intelligence sources, including its database of more than 50,000 computer security vulnerabilities, its global Web crawler and its international spam collectors, and the real-time monitoring of 13 billion events every day for nearly 4,000 clients in more than 130 countries. These 13-billion events monitored each day – more than 150,000 per second – are a result of the work done in IBM's nine global Security Operations Centers, which is provided as a managed security service to clients. 
About IBM Security
With more than 40 years of security development and innovation, IBM has breadth and depth in security research, products, services and consulting. IBM has nine worldwide research labs innovating security technology and nine security operations centers around the world to help global clients maintain an appropriate security posture. IBM Managed Security Services delivers the expertise, tools and infrastructure clients need to secure their information assets from constant Internet attacks, often at a fraction of the cost of in-house security resources. The Institute for Advanced Security is IBM’s global initiative the help organizations better understand and respond to the security threats to their business. Visit the Institute community atwww.instituteforadvancedsecurity.com 
For more information on IBM Security Solutions, please visit: www.ibm.com/security.

Monday, March 5, 2012

The Bright Side of Being Hacked

Excerpt from an article in

The New York Times
Monday, March 05, 2012

The Bright Side of Being Hacked

By SOMINI SENGUPTA and NICOLE PERLROTH

SAN FRANCISCO — Hackers operating under the banner Anonymous have been poking a finger in the eye of one private company after another for two years now.

They steal files from inside corporate computer systems and occasionally, as in the case of Stratfor last week, dump company e-mail online for all to see.

The Stratfor hack, in which Anonymous claimed to have joined forces with WikiLeaks, drove home a clear lesson about the era of ubiquitous “hactivism,” or hacking as a form of protest.

Despite the arrests of dozens of suspected members of Anonymous and its offshoots worldwide, it is far from diminished. Nor have most of its corporate targets been irreparably damaged by the attacks.

Rather, what Anonymous has done, experts said at the big RSA computer security conference here last week, is raise the alarm about the unguarded state of corporate computer systems.

By and large, the Anonymous break-ins take advantage of gaping computer holes and gullible human beings. The hackers ferret out weak passwords and take advantage of unencrypted e-mail stashes. They persuade company employees — one is all it takes — to click on rogue Web sites or divulge a confidential piece of information, in an exercise known as social engineering.

“Anonymous is a wake-up call,” said Roger Cressey, senior vice president of Booz Allen Hamilton, a defense and intelligence contractor that was attacked by the group last summer. “Any company that is patting themselves on the back and saying that they’re not a target or not susceptible to attack is in complete and utter denial.”

More to the point, a company that is a target of Anonymous may also be the target of a far more potent adversary. The social engineering tactics that Anonymous members have repeatedly used are often similar to those used by criminal hackers and state-sponsored actors who penetrate company systems in order to steal valuable secrets, whether for monetary gain or competitive edge.