Monday, March 9, 2009

New IRS & DOL Guidance On Stimulus Bill COBRA Relief Includes Info For Employers On Claiming Payroll Tax Credit

cindy stamer The Internal Revenue Service (“IRS”) and Department of Labor (“DOL”) have posted limited initial guidance about temporary requirements added to the group health plan medical coverage continuation requirements of the Consolidated Omnibus Budget Reconciliation Act of 1985, as amended (“COBRA”) by the American Recovery and Reinvestment Act of 2009 (“Stimulus Bill”). The IRS guidance provides preliminary information about what employers must do to claim the COBRA premium subsidy payroll tax credit to help offset the cost of providing required COBRA premium discounts for certain involuntarily terminated former employees and their dependents. Most employers were required to begin granting these COBRA premium discounts beginning March 1. Employers must amend their plans to comply with these mandates and, if they wish to seek reimbursement for COBRA Subsidies, must comply with IRS requirements. Meanwhile, group health plan administrators and insurers must take immediate action to provide required notifications and implement other administrative changes necessary to comply with the new rules.


You can learn more about the Stimulus Bill COBRA Amendments and other changes to group health plan requirements by participating in the March 11, 2009 Health Plan Update Teleconference. Register and get other updates at CynthiaStamer.com.

Tuesday, March 3, 2009

NEW WORM Lets Hackers Take Complete Control of User’s Computer

by Kevin M Nixon, MSA CISSP® CISM® CGEIT® 

Social Networking sites (Facebook, MySpace, Bebo, LiveJournal, etc.) are under attack by a variation of the Koobface worm which began to spread in August ‘08.  This new variant, tracked as WORM_KOOBFACE.AZ has the potential of a fast infection rate.  Most importantly, after propagating itself from the infected device, the Worm remains active on the user’s computer transmitting the computer’s data, settings, control information, and system information to over 300 international collection sites.  

Readers should search their computer protection software provider’s website and locate instructions for WORM_KOOBFACE.AZ.  Please note that this is a variation of HTML_KOOBFACE.BA.  The patches and DAT files for the HTML variant do not protect against the WORM variant!

CURRENT FIX:

No Automatic Patches currently available from Protection Vendors.  Manual counter-measures are available.

TYPE MALWARE:

Worm – Self-Spreading
A computer worm is a self-replicating computer program. It uses a network to send copies of itself to other nodes (computers on the network) and it may do so without any user intervention. Unlike a virus, it does not need to attach itself to an existing program. Worms almost always cause at least some harm to the network, if only by consuming bandwidth, whereas viruses almost always corrupt or modify files on a targeted computer.

INFECTION METHOD:

Hyperlink-Social Engineering. 

Computer user receives a message which may contain the subject line “Thiss vvideo witth you on the streeet.”  User may receive the message via a "Online Inbox” located on the social network site, or any online web-based email, smart phone/PDA, or regular email application loaded locally on the computer.

HOW IT WORKS:

The message is sent to you by someone you know.  The hyperlink in the message takes the user to a “fake site” supposedly hosting a video posted by the same “friend known to the user” in a Facebook (or other Social Network) message from.  The message not only contains the hyperlink to the “fake site”, it also displays the “friends” name and photo from the Facebook profile.  A very clever little piece of social engineering.

Although the worm originates from a Facebook account from a person known to the user, the user receiving the message does not need to be a member of Facebook. 

Other origination points include but are not limited to:

  • facebook.com
  • hi5.com
  • friendster.com
  • myyearbook.com
  • myspace.com
  • bebo.com
  • tagged.com
  • netlog.com
  • fubar.com
  • livejournal.com
  • YouTube.com

WHAT IT DOES:

After clicking on the link, the user is redirected to an IP Address which contains the “fake social network friend page”.  Upon arriving at the site, the user is prompted to update the Adobe Flash Player.  The “fake update” installs the worm on the user’s computer. 

WORM_KOOBFACE.AZ propagates through other networking sites by using “cookies” stored on the user’s computer.

The worm connects to a respective site using login credentials stored in the gathered cookies. It then searches for an infected user’s friends, who are then sent messages containing a link where a copy of the worm is downloaded. It also sends and receives information from an infected machine by connecting to several servers.

This allows hackers to execute commands on the affected machine. Currently there are over 300 International data collection sites containing this worm!

© Copyright 2009 – Kevin M. Nixon – All Rights Reserved – See: Information Security Resources
(This article may be reprinted in whole or in part only with proper attribution to the author.)

Friday, February 27, 2009

The Daily Sandbox!: Dan Kaplan & SC Magazine Confirm Yet Another Bank Security Breach

The Daily Sandbox!: Dan Kaplan & SC Magazine Confirm Yet Another Bank Security Breach

Join the Contest! “What To Do With Bernie Madoff”

 by Kevin M Nixon, MSA, CISSP®, CISM®, CGEIT®

It Friday.  We’re all worried about the economic situation, the war, the budget, health care etc.  So to simply provide some much needed stress relief we are holding a Contest on what to do with Bernie Madoff. 

It is a way of taking our anger about everything we all are experiencing and “placing it on Bernie”.  Think of it as “Virtual Voodoo” or a punching bag or the arcade game “Whack-a-Mole”.

Contest participation is open to anyone.  Suggestions are to be submitted in the form of a Comment to my article http://www.dailykos.com/storyonly/2009/2/27/1334/03940/277/702472  Click on VIEW COMMENTS to open the current submissions. 

All suggestions must take into consideration that Madoff’s Crime is not death sentence qualified.  Bernie has to pay for his crimes in a survivable manner.  NOTE:  I said survive not “pain free” or “without slow and lingering suffering”.  Creativity in the imposition of your recommended sentence is important.  Pictures or illustrations can also be submitted.

Our discussion group will assist you with anger "re-management" & “re-direction.  We want true, long lasting satisfaction, seasoned with anticipation and creatively embellished with perhaps some S&M techniques.  We are enhancing our skills at "Displacing Anger"!  This is not a Miss America practice group on "How To Answer Questions Session" that is another Diary Page.

In this session we strive for perfect satisfaction by trading useful information such as:  "How Much Vaseline To Apply Before Entering A Flag Pole Sitting Contest"

Reading materials which may assist you prior to submitting your entry include:  

"Whips, Chains, and Alligator Clips for the Novice"

"Better Health Through Water-boarding"

"Margaret Cho's - Discovering Your Inner Ass-Master"

"Creative Humiliation Techniques - Yes Sir!"

"Spiritual Growth Via Electric Shock Treatments"

"Colonic Irrigation Via Fire-hose: Safe & Effective!"

I’ll keep this running on Bernie until some other form of “pond scum” emerges. 

This is only a way to take your mind off the situation of things around you and relieve some stress.  Go for it!

If you have suggestions for future contests send me an email.

Thanks,
Kevin

 

Talking about Laid-off Workers as Data Thieves?

by Kevin M Nixon, MSA, CISSP®, CISM®, CGEIT®

Bill Brenner is my favorite writer and Senior Editor for CSO Online.  Perhaps that we both share the same opinions about IT Security, Governance, Risk, Compliance and Data Privacy.  I highly recommend any of his articles especially for their complete research, cross-checked facts, and willingness to state an honest opinion.  Bill doesn't "blow with the wind" like so many others.  You may not always agree with a person's comments, however, but keeping an open mind and listening without "tuning out" is the way problems get solved.

I have 3 favorite quotes which everyone in the Data Protection field should print out, put on their office wall by their computer, and read each day.  Here they are:

  1. "Common Sense Ain't Common"
      
    - Will Rogers
  2. "When your talkin' You Ain't Learnin'"
     
    - Lyndon B. Johnson
  3. "Pain makes man think.  Thought makes man wise.  Wisdom make Life endurable."
       - Marlon Brando "The Teahouse of the August Moon"
         1953 Tony Award
    Best Play

The quotes emphasize what I consider the 3 Phases of a Security Issue.  First, make no assumption that every system is operated using common sense and good judgment.  Second, continued education is the foundational corner-stone to any good security practice.  Third, when a security problem eventually does hit (and it will), learn from it!

Thanks for reading. 

Kevin M Nixon, MSA, CISSP, CISM, CGEIT

Waves Turn Rocks To Sand. - Windows Live

Thursday, February 26, 2009

Dan Kaplan & SC Magazine Confirm Yet Another Bank Security Breach

Background
by: Kevin M Nixon, MSA, CISSP, CISM, CGEIT

It has been the mumble in the industry for at least the last 2 weeks, and our hat is off to Dan and SC Magazine for  breaking the news.  This latest breach should make everyone sit up and take notice.  At this point, so many significant payment card industry systems have been compromised, all consumers should consider several things for protection.  Consumers should consider contacting your credit card and bank card issuers and request a new card and transfer activity to the new card and close the previous one.  Another suggestion is to consider placing a “Fraud Alert” in their profiles with each Credit Reporting Agency.

Visa confirms another payment processor breach - SC Magazine
http://www.scmagazineus.com/Visa-confirms-another-payment-processor-breach/article/127725/

Another payment processor has fallen victim to hackers, Visa confirmed on Monday.  Visa and MasterCard are notifying banks about accounts impacted by a "major compromise," unrelated to the massive Heartland Payment Systems incident announced last month, according to a number of credit unions and banking associations.


The hackers apparently breached the processor in the same way they infiltrated Heartland -- by placing malicious software on the network, according to an alert from the Pennsylvania Credit Union Association.  Visa hosted a conference call on Feb. 12 to notify member banks about the breach, which affected transactions made from February to August 2008, the association said. The incident involves account numbers and expiration dates, but no track data was compromised; therefore the attackers would be unable to make counterfeit cards.  The size of the breach appears significant but fewer cards were affected than in the Heartland case, the Community Bankers Association of Illinois said in its own announcement. That breach potentially exposed as many as 100 million accounts.


The victim in this case appears to be a provider that processes online transactions, said David Shettler, vice president and CTO of Open Security Foundation, a nonprofit that researches data breaches.  He told SCMagazineUS.com on Monday that the group has been receiving tips about the breach since Feb. 12, but few details have been confirmed.


"What concerns me is that Visa and MasterCard, they clearly know who it is," Shettler said. "That just won't say anything because the processor hasn't come clean. The sort of feel it gives people is that Visa and MasterCard are covering for some unnamed organization."


Visa and MasterCard began notifying card issuers about affected accounts on Feb. 9 and 13, respectively.  It is unclear whether this processor was compliant with payment industry guidelines, the association said. Heartland was deemed Payment Card Industry Data Security Standard-certified (PCI DSS) when it announced its breach.  This marks the third data-loss incident to impact payment processors in the past three months. In December, RBS WorldPay disclosed a breach that affected some 1.5 million card users. Shettler said cybercriminals are zoning in on these entities because they deal with the most amount of information.


"You can crack into merchants, but that's a limited scope," he said. "If I were the payment card industry, namely Visa and MasterCard, I'd be concerned."


Visa said it was working with business and financial institutions to improve security measures.  “Visa Inc. is aware that a processor has experienced a compromise of payment card account information from its systems," the company said in a statement on Monday. "It's essential that every business that handles payment card information adhere to the highest data protection standards to protect the security and privacy of their customers' financial information."


A representative from MasterCard could not be reached for comment.

Visa confirms another payment processor breach - SC Magazine US

Powered By Blogger