Monday, February 23, 2009
Yves Saint Laurent Auction: Record Brancusi, Matisse, Mondrian Sales (SLIDESHOW)
Posted using ShareThis
Friday, February 20, 2009
Unsafe At Any [Connection] Speed
by Kevin M Nixon, MSA, CISSP®, CISM®, CGEIT®
Introduction
I was surprised and very concerned at the number of responses I received to my article regarding a Blended Hack Attack. The article was about how Hackers tricked people into going to a website to check to see if they had received a Parking Ticket.
Now, the creativity of combining a Social Engineering attack with a fake website is amazing but what really got me going were the number of people that think that using Apple's Macintosh system is "protection" against an attack.
I also realized that when one can remember the evolution of a hardware platform from an 8-bit processor chip with a dual 8" floppy storage system to the Mega Systems of today; that proves one thing. I’m getting old!
Yes, A Mac Can Be Hacked and Infected Just Like PCs
Prior to January 1984, Apple had the Apple I, Apple II, and the Apple III. There were no hard drives they ran on Dual 8" Floppy disks. The Apple I and II were Command Line systems. No Mouse here. The motherboard contained a single MOS 6502 8-bit chip! Steve Wozniak modified a version of BASIC and after using the booting with the floppy, the Boot Disk was removed and then the single application floppy was inserted into A: and the ONLY Commercially Off The Shelf application was Visicalc. Apple-II improved speed by using the memory in the CRT device. When the Apple III was released it came with Visicalc pre-burned on the chip.
Then the world changed on January 22, 1984 during the 3rd quarter of Super Bowl XVIII when Apple unveiled the Macintosh 128K. This was the first MAC. Up till then the devices were all named Apple.
Two days after the 1984 ad aired, the Macintosh went on sale. It came bundled with two applications designed to show off its interface: MacWrite and MacPaint.
Apple is a vertically integrated product, meaning that Apple controls every aspect of the product including the operating system. The OSX operating system will only work on Apple computers.
Despite the $1.5 Million spent on the Super Bowl Ad plus an additional $2.5 Million spent for a 39 page advertising brochure in Newsweek, Apple continued to struggle, due to various problems, such as lack of OS compatible application software, the monochrome-only display and the closed architecture.
Apple eventually gained success as a result of its introduction of desktop publishing (and later computer animation) through Apple's partnership with Adobe Systems which introduced the laser printer and Adobe PageMaker. Indeed, the Macintosh would become known as the de-facto platform for many industries including cinema, music, publishing and the arts.
Apple did briefly license some of its own application designs, but Apple did not allow other computer makers to "clone" the Mac until the 1990s, long after Microsoft dominated the marketplace with its broad licensing program. By then, it was too late for Apple to reclaim its lost market share.
At the 1997 Macworld Expo, Steve Jobs announced that Apple would be entering into partnership with Microsoft. Included in this was a five-year commitment from Microsoft to release Microsoft Office for Macintosh as well a US$150 million investment in Apple. It was also announced that Internet Explorer would be shipped as the default browser on the Macintosh.
Today, a modern Mac can boot on a Windows operating system with the boot camp utility, which lets you chose between OSX and Windows when starting the computer.
A PC is a generic architecture design of hardware that will allow a Linux or Windows operating system to boot.
PC manufactures' rely on OEM software, and do not vertically integrate their products.
As a result of the interoperability of PC architecture, PC's have around 95% market share, this is good news for the availability of software, and bad news for the availability of viruses.
The 2 Minute Mac-Hack
(source: Mac Hacked In Under 2 Minutes )
Within 2 minutes, of directing a MAC to a Web site that contained exploit code, the computer was under the hacker's control.
The hacker (Charlie Miller) was given a $10,000 cash prize AND was quickly given a nondisclosure agreement to sign, and he's not allowed to discuss particulars of his bug with anyone but Apple.
The Contest rules stated that the hacker could only take advantage of software that was preinstalled on the Mac, so the flaw he exploited must have been accessible by, or possibly inside, Apple's Safari browser.
So is an Apple Mac immune to Hacks, Worms or a Virus? NO!
Every Mac owner needs to be just as concerned as a PC owner.
If a Mac was not able to be hacked or infected why would the Apple Support Website publish Security Update Patches? Mac owners should review the following pages at Apple support and update and patch just like 95% of all computer owners!
From the Apple Support Website:
Apple Security Updates
Apple security updates (25-Jan-2005 to 21-Dec-2007)
Apple security updates (03-Oct-2003 to 11-Jan-2005)
Apple security updates (August, 2003 and earlier)
VirusBarrier X5
© Copyright 2009 – Kevin M. Nixon – All Rights Reserved – See: Information Security Resources
(This article may be reprinted in whole or in part only with proper attribution to the author.)
Parking Ticket Leads to PC Virus Attack
by Kevin M Nixon, MSA, CISSP, CISM, CGEIT
At 11:47 AM CST – 02-20-09 I posted this story on Daily Kos and my comment meter went off the scale. People just couldn’t believe that something like this could be true.
I have to give a “SHOUT OUT” to my friend “Sparky” (Shannon Myers-Leitz at GotMetrics.com) for sharing this story.
Firewalls. Corrupted files. Spam with bad code. Those were the traditional vectors hackers used to plant malware on a system or gain access to a workstation. Now they just give you a parking ticket.
Last week the SANS Internet Storm Center discovered a case in Grand Forks, North Dakota where yellow card-like fliers presumed to be parking tickets were found on cars in a parking lot.
The would-be tickets read: "PARKING VIOLATION: This vehicle is in violation of standard parking regulations."
The card then instructs the ticket recipient to visit a specified Web Site. From this point, hackers count on law-abiding users to go home and log on where, strangely enough, they'll see a picture the parking lot where their car was. A few clicks later, a fake Internet Explorer security alert pops up asking the user if they'd like to do a quick antivirus scan. The infection starts from there.
Lesson learned: Go Green! Take Public Transportation.
Forensics of the Hack
With the “Parking Ticket” in hand, lawful citizens went to the website only to discover a photo of their car!
The picture displayed was of cars in that location (not the ticket holders car) with the prompt to use the Picture Search Tool. This leads the person to believe that they can search through a series of photos looking for their car. So CLICK, and then the fun begins.
The Picture Search Tool is know as a Browser Help Object (BHO). The BHO seemed to wait for the user to browse the Internet a bit, and then brings up a pop-up with a fake security alert:
The initial program installed itself as a browser helper object (BHO) for Internet Exploter that downloaded a component from childhe.com and attempted to trick the victim into installing a fake anti-virus scanner from bestantispyware securityscan.com and protectionsoft warecheck.com.
Attackers continue to come up with creative ways of tricking potential victims into installing malicious software. Merging physical and virtual worlds via objects that point to websites is one way to do this. I imagine we'll be seeing such approaches more often.
© Copyright 2009 – Kevin M. Nixon – All Rights Reserved – See: Information Security Resources
(This article may be reprinted in whole or in part only with proper attribution to the author.)
Thursday, February 5, 2009
Appointment Of Geithner Clears Economic Landscape – Old “Shrubs” First To Go!
by Kevin M Nixon, MSA, CISSP®, CISM®, CGEIT®
Timothy Geithner becomes 75th Treasury Secretary
When the dust from the departing helicopter finally settled, America realized that the old“shrubs” of the last 8 years had been replaced with the seeds of new growth opportunities! Secretary of the Treasury, Timothy Geithner will most certainly review the current state of affairs and enact some significant new enhancements.
Reporters (and our friends) at InfoSec News alerts at infosecnews.org picked up on a story by William Jackson at GCN.org which discussed a January 2009 General Accounting Office report citing some “significant holes in the security of systems protecting financial data”.
Despite the enactment of the USA PATRIOT ACT, which was to strengthen the Banking Secrecy Act and both of which were supposed to follow the Federal Information Security Management Act (FISMA), when all that helicopter dust finally settled, an audit showed that all of the puzzle pieces had been placed on the table, but none of the old guard had done anything to actually make the security really work.
A Quick Summary
The Financial Crimes Enforcement Network (FinCEN), a bureau within the Department of the Treasury, relies extensively on its own computer systems, as well as those at the Internal Revenue Service (IRS) and the Treasury Communications System (TCS), to administer the Bank Secrecy Act (BSA) and fulfill its mission of safeguarding the U.S. financial system from financial crimes. Effective information security controls over these systems are essential to ensuring that BSA data, which contains sensitive financial information used by law enforcement agencies to prosecute financial crime, is protected from inappropriate or deliberate misuse, improper disclosure, or destruction.
GAO evaluated whether security controls that effectively protect the confidentiality, integrity, and availability of the information and systems that support FinCEN’s mission have been implemented. To do this, GAO examined security policies and controls for systems at three organizations.
The three organizations [under the Treasury Department control] implemented many information security controls [in support of FISMA] to protect the information and systems that support FinCEN’s mission. For example, IRS controlled changes to a key application and FinCEN segregated areas of its network. Nonetheless, the organizations had inconsistently applied or not fully implemented controls to prevent, limit, or detect unauthorized access to this information and these systems (as effective as installing a big bomb proof door between 2 plate glass windows).
The organizations did not always (1) implement user and password management controls for properly identifying and authenticating users, (2) restrict user access to data to only what was required for performing job functions, (3) adequately encrypt data, (4) protect the external and internal boundaries on its systems, and (5) log user activity on databases. Furthermore, weaknesses in which systems were insecurely configured and patches were not applied to critical systems also existed. As a result, sensitive information used by the federal government, financial institutions, and law enforcement agencies to combat money laundering and terrorist financing is at an increased risk of unauthorized use, modification, or disclosure.
The Big Picture
Following the enactment of the USA PATRIOT ACT, the system was supposed to track and alert various law enforcement and regulatory agencies when certain suspicious financial transactions were occurring, as in “money laundering”. The system works nicely, however, not all cash transactions over $10,000 are neither, illegal or nefarious and therefore controlling who inside the Treasury, the IRS or external law enforcement still needs to be controlled. After all, some of that information happens to pertain to law abiding citizens.
Hopefully under the new administration, “common sense and good judgment” will return to the department and perhaps some of the habits which have become customary over the last few years will be tossed out like old shrubs.
Who would ever have thought at Tim Geithner as Secretary of Treasury might actually become know as “Landscaping Czar” in charge of getting rid of “old shrubs”?
For a complete copy of the GAO Audit report refer to GAO Publication #09-195 on the official Government Accounting Office Site or Click on the Box below:
© Copyright 2009 – Kevin M. Nixon – All Rights Reserved – See: Information Security Resources
(This article may be reprinted in whole or in part only with proper attribution to the author.)
Saturday, January 31, 2009
Economic Hardship: How High’s The Water Mama? - A story of Rain, Fame and Gain!
By Kevin M. Nixon, MSA, CISM®, CISSP®, CGEIT® (pending)
INTRO:
Current Economic events leave all of us with feelings of fear, uncertainty and doubt. This is a look back to January 1937, and how Johnny Cash's parents & hundreds of others endured the loss of every material possession following the Great Flood and in the middle of the Great Depression. To honor his parents, Johnny Cash wrote & recorded "Five Feet High and Risin'".
Watch the Video, read the article, look at the news and then think of two other people that might gain from your help because they might be more uncertain than you. Looking forward to your comments & feedback.
Seventy-two (72) years ago this week the Great Ohio River Flood of January 1937 surpassed all prior floods during the previous 247 years of modern occupancy of the Ohio River Valley. The overall geological evidence suggests the 1937 flood outdid any previous flood with 70% of Louisville submerged, causing 175,000 residents to flee.
According to NOAA’s National Weather Service office in Louisville, KY, 90% of Jeffersonville, Indiana was flooded. One contemporary source estimated that damage was done to the tune of $250,000,000 (1937 dollars)...that's over $3.3 billion in current dollars!! (US Dept of Commerce & the National Oceanic and Atmospheric Administration.)
Through the camera lens: The Great Flood of 1937
These historical photos are copyrighted by and property of the Louisville Courier-Journal.
At Louisville, the crest of the 1937 flood is still a full ten feet higher than the second highest crest, set in 1945! At McAlpine Lock, the 1937 flood crested at 85.4 feet. By way of comparison, today flood stage is 55 feet, and the current normal water stage is around 28 feet. Louisville received fifteen (15) inches of rain in only twelve 12 days, from the 13th to the 24th of January, 1937. More than 19 inches of rain fell over the course of the month and there was no measurable snowfall during the entire month.
So why is a security geek going on about a flood?
I often find myself thinking and working through difficult or stressful problems concerning a new governance, risk and compliance regulation or a new security threat by thinking about them as images and/or sounds. Additionally, part of my daily ritual, despite where I may be working around the world, is to set aside 2 hours for myself as "my CNN Time". I almost go through a form of withdrawal unless I watch Larry King, Anderson Cooper and Erica Hill.
I find that in spite of the current headlines, politics or grim economic outlook, Larry, Anderson and Erica always manage to capture an angle on a topic that all other news professionals completely miss. Over the last 2 weeks, as world economic news has grown increasingly more somber, I realized that I kept "hearing" the phrase "How high's the water mama?".
Apparently, my personal form of sardonic humor often kicks in to counteract sinking into complete melancholy. This week, in an effort to finally shake the tune which seemed to be conspiring against me, I decided to research the background and motivation of Johnny Cash when he wrote and recorded "Five Feet High and Risin'" in October 1959.
As I had suspected, it was the result of Johnny Cash watching his parents struggle to take advantage of a 1935 "New Deal" farm program that provided them with 20 acres of land and a 5 room house. Just as everything was beginning to improve, the Great Flood of January 1937 completely devastated the Cash family. Left only with determination Johnny's mother and father had to begin again with even less than before. Before reading this article, please view this really great YouTube video.
"Remembering The Great Flood of 1937" - 72 Years Ago
Ian (aka, misteralmuranas710)
YouTube Video by:
Music by: Johnny Cash, Recorded Oct. 25, 1959
Factoids:
Johnny Cash was born J. R. Cash in Kingsland, Arkansas (February 26, 1932) to Ray and Carrie (Rivers) Cash, and raised in Dyess, Arkansas. Cash was given the name "J.R." because his parents could not agree on a name, only on initials. Cash died September 12, 2003 in Nashville, TN.URL: http://www.youtube.com/v/2qFLnwiP7jQ&hl=en&fs=1
Assuming you have followed directions, and have viewed the video, you should have a better understanding of how the 1937 flood, a Johnny Cash song and the current economic headline are all related. Four (4) very significant issues were revealed this week. Under each new economic is an associated verse from the song, which are used to emphasize the gravity of our current crisis. With each event of the past week, the US slowly ebbed higher and higher toward "Economic Flood Stage".
- This week Monday, Tuesday and Wednesday (1/26, 1/27, and 1/28), over 100,000 US Workers have already been given notice of layoff or impending layoff;
How high's the water, mama? Two feet high and risin'
How high’s the water, papa? Two feet high and risin'
We can make it to the road in a homemade boat
That's the only thing we got left that'll float
It's already over all the wheat and the oats,
Two feet high and risin'
- As of December 31st 200, 3.2 million households submitted foreclosure filings;
How high's the water, mama? Three feet high and risin'
How high’s the water, papa? Three feet high and risin'
Well, the hives are gone, I've lost my bees
The chickens are sleepin' In the willow trees
Cow's in water up past her knees,
Three feet high and risin'
- At 10:00 a.m. EST, Wednesday, January 28th 2009 the US Bureau of Labor Statistics announced that for all of 2008, the total number of mass layoff events was 21,137, and that first time unemployment claims reached their highest annual levels - 2,130,220. The national unemployment rate was 7.2 percent in December.
How high's the water, mama? Four feet high and risin'
How high’s the water, papa? Four feet high and risin'
Hey, come look through the window pane,
The bus is comin', gonna take us to the train
Looks like we'll be blessed with a little more rain,
Four feet high and risin'
- As of 5:00 p.m. EST, Wednesday, January 28th 2009, the Open Security Foundation and the Privacy Rights Organization had recorded a significant increase of private & confidential data breaches.
If you didn't look at the amount of potential data exposed, the potential total Thursday, 1/29 exceeded >105 Million Records< and that was just during January 2009.
Very simply put, in just 28 days the total number of data records exposed in 2009 is equal to 83.25% of the entire sum total of the years 2005 through 2008.
How high's the water, mama? Five feet high and risin'
How high's the water, papa? Five feet high and risin'
Well, the rails are washed out north of town
We gotta head for higher ground
We can't come back till the water comes down,
Five feet high and risin'
Well, it's five feet high and risin'
Well, it's five feet high and risin'
In 90 days, the numbers of data records potentially exposed has been an increase of over 100%. Only in America could we fail so successfully that we actually doubled our losses! Don't you just wish that we could make those kinds of returns on homes for sale or interest on money locked in banks.
On January 6th, 2009 also known as the Feast of the Epiphany (Christian Liturgical Calendar) around 5 Million records (or that’s what they estimate) were being routed from the 3rd largest Credit Card Clearinghouse in the United States to the Ukrainian mob!
The US Company, Check Free Corp. (now owned by FISERV) and some of the banks that use its electronic bill payment service say that criminals took control of several of the company's Internet domains and redirected customer traffic to a malicious Web site hosted in the Ukraine. The company believes that about 160,000 consumers were exposed to the Ukrainian attack site. However, because the company lost control of its Web domains, it doesn't know exactly who was hit. And so, Check Free must warn a much larger number of customers.
SPECIAL HEALTH WARNING: Before reading the following paragraph please be seated and remove all sharp pointed objects from the area.
On January 20th 2009, Chairman and CEO, Robert O. Carr of Heartland Payment Systems of Princeton, NJ finally let the “cat out of the bag” after being hounded by IT Security and Compliance professionals for several weeks!
Heartland Payment Systems who is an automated credit clearinghouse member of First Data Corporation (the largest Credit Card Processing facility in the United States) began “looking into things”, after being alerted by Visa and MasterCard of suspicious activity surrounding processed card transactions, the company last week found evidence of malicious software that compromised card data that crossed Heartland's network. This incident may be the result of a global cyber fraud operation.
Heartland processes over 100 million transactions per month. It is not clear to the officers or executives if Social Security Numbers or financial account numbers were exposed.
Why didn't those Payment Card Industry-Data Security Standards which are required controls not stop this from happening? Well, standards have "no force of law". They will continue to have no teeth, until the President and Congress enacts laws that criminally punish company executives that allow the business they control to use weak or no security controls to protect us.
Stockholders have some legal recourse, but the every day, middle class American who simply carries a credit card to pay for gas or groceries ends up with the "fuzzy end of the lollipop!
As of 6:00 p.m. EST, January 28th 2009, the Washington Post reported the following item on this continuing story:
“The data stolen includes the digital information encoded onto the magnetic stripe built into the backs of credit and debit cards. Armed with this data, thieves can fashion counterfeit credit cards by imprinting the same stolen information onto fabricated cards.”
Although according to the Washington Post article, a spokesman for Heartland says “that without a card present” it would be very difficult to process charges to an account.
For the record, it should be noted that if all of the “digital information encoded on the magnetic stripe” than the Card Verification Value otherwise known as a CVV number, is also present on the magnetic stripe.
The credit card processing authority would “assume” that the card had actually been “eyeballed and ID was checked”, leaving the poor consumer and the merchant or place of business on the hook for all of the charges.
If you think we have a credit-banking problem now, just remember all of those fine IT Security folks that no longer have jobs protecting your good name, because the executives were in on the take from the very beginning.
So next time you reach for your credit card, just start humming to yourself How high's the water, mama? Five feet high and risin' and remember the Great Flood of 1937 - along with 2 of the companies that let us float all the way down stream!
© Copyright 2009 – Kevin M. Nixon – All Rights Reserved (This article may be reprinted in whole or in part only with proper attribution to the author.)
