donderdag 10 januari 2013

DigiD doet het weer

DEN HAAG - Burgers kunnen donderdagochtend weer hun DigiD gebruiken. De dienst was een dag buiten gebruik in verband met een veiligheidslek. 

 

Dat lek zat niet in DigiD zelf, maar in het softwareplatform waarop de dienst is gebouwd.
Het lek werd in de nacht van dinsdag op woensdag ontdekt, waarna DigiD direct werd platgelegd. Voor zover bekend is er geen misbruik van gemaakt.
DigiD is een afkorting van digitale identiteit. De overheid kan hiermee de identiteit van de burger controleren.
Met een gebruikersnaam en wachtwoord kunnen mensen terecht bij ruim 500 organisaties die overheidstaken uitvoeren, zoals de Belastingdienst, het Kadaster en Studielink, maar ook bij gemeenten, provincies en waterschappen.

Wachtwoorden

Tijdens de storing is een reclamebureau met bijna dezelfde naam, Digi-D, overspoeld met persoonlijke gegevens van mensen, meldt Webwereld.
Het bedrijf krijgt al jaren lang gebruikersgegevens binnen van mensen die het bedrijf verwarren met de overheidsdienst. In totaal zijn er al 13.000 privacygevoelige gegevens zoals burgerservicenummers en wachtwoorden binnengekomen bij Digi-D.
Vorig jaar startte het bedrijf een website om mensen hiervoor te waarschuwen.

Bron: Nu.nl

 

woensdag 9 januari 2013

DigiD offline na lek in platform

DEN HAAG - DigiD wordt uitgeschakeld nadat er een lek in de beveiliging van een platform is ontdekt.  

Het probleem speelt in de ontwikkelomgeving Ruby. "Er is een ernstig lek gevonden en dat willen we meteen dichten", bevestigt een zegsman van Logius, de verantwoordelijke overheidsdienst voor DigiD, tegenover NU.nl.
Omdat het lek zo ernstig is, kan niet worden uitgesloten dat er misbruik van DigiD wordt gemaakt. Daarom is besloten de dienst plat te leggen en noodmaatregelen te treffen.

Logius zegt hard te werken aan een oplossing en na het testen en installeren kunnen burgers zich weer bij de overheid aanmelden.

Bron: Nu.nl

Hackers lijven webservers in voor DDoS-botnet

Hackers breken in op webservers om deze in te zetten voor een DDoS-aanval, meldt een Amerikaans beveiligingsbedrijf. Via brakke sites wordt de server overgenomen om een vloedgolf requests te sturen.
In plaats van het rekruteren van vrijwilligers die sites DDoS'en of het inzetten van botnets om nietsvermoedende gebruikers te laten meewerken, stappen de cybervandalen over op het inlijven van webservers om het vuile werk op te knappen. Beveiligingsbedrijf Incapsula heeft de laatste maanden gezien hoe websites worden overgenomen om een DDoS-aanval uit te voeren.

Adminwachtwoord 'admin'

Een van de sites die meewerkte aan een DDoS-aanval op Amerikaanse banken was twijfelachtig beveiligd. Het administratiewachtwoord was simpelweg 'admin', waardoor ongenode gasten doodsimpel de site konden inzetten voor een aanval op websites. Het cybertuig eigende zich de website toe om http- en udp-pakketjes te versturen naar de sites van onder meer HSBC en PNC Financial Services.
De aanval kon worden tegengehouden voor die goed en wel begon, omdat het beveiligingsbedrijf de ingevoegde backdoor ontdekte. Ronen Atias van beveiligingsbedrijf Incapsula schrijft dat het inlijven van webservers als zombies in een DDoS'end netwerk een logische stap is.
"Hackers hebben liever webservers dan pc's", schrijft Atias. "Dit zijn meestal krachtigere machines met toegang tot een kwaliteitsnetwerk van de hoster en veel webservers kunnen worden gekaapt door een beveiligingslek in een van de sites."

'Geen boze hackers'

De groep die Amerikaanse banken probeert neer te halen zou dezelfde club zijn die nog altijd protesteert tegen de controversiƫle internetfilm 'Innocence of Muslims'. "Deze aanvallen zullen doorgaan totdat de nare film van internet wordt verwijderd", stelde de groep in september in een boodschap op Pastebin.
Maar volgens de New York Times gaat het hier niet om zomaar boze hackers, maar zit Iran achter het platleggen van Amerikaanse sites. Dat heeft een computerdeskundige en voormalig overheidsfunctionaris aan de krant bevestigd. "Er bestaat bij de overheid geen twijfel over dat Iran achter deze aanvallen zit", aldus de deskundige.
Het voornaamste bewijs voor deze bewering is dat de aanval veel geavanceerder is dan de DDoS-aanpak van het gemiddelde hackerscollectief. Daarnaast hebben de aanvallers geen winstoogmerkt, wat een kenmerk is van een cyberaanval van een overheid.

Cyberdieven liften mee

De cybervandalen toonden zich al eerder creatief door een opt-in botnet te gebruiken, waardoor botnetbeheerders zich bij de DDoS-actie konden voegen door hun zombies in te zetten voor de aanval. Met succes legden ze op deze manier Chase.com van de bank J.P. Chase Morgan plat.
Een bijkomend probleem van de DDoS-aanvallen is dat cybercriminelen kunnen meeliften met zo'n operatie. Als een IT-afdeling zich bezighoudt met het afslaan van de DDoS - vooral op slecht bezette tijdstippen als vrijdagmiddag - kunnen cybercriminelen hun slag slaan via een andere ingang. Beveiligingsdeskundigen waarschuwen daarom ict'ers om tijdens een DDoS-aanval op de hoede te zijn voor andere venijnige haakjes.

Bron: Webwereld

donderdag 3 januari 2013

Opnieuw certificatenverlener gehackt

AMSTERDAM - Een Turkse certificaatdienstverlener blijkt in december een tijd valse certificaten te hebben uitgegeven. Inmiddels hebben Google, Mozilla en Microsoft actie ondernomen. 

 

Google meldt op 24 december te hebben ontdekt dat valse certificaten van het internetbedrijf werden goedgekeurd door Turktrust. Hierdoor leek het voor gebruikers alsof er een vertrouwde verbinding was met Google, terwijl dat niet het geval was.
Het eerst certificaat dat Google ontdekte bleek al in augustus 2011 te zijn gemaakt. Het duurde echter tot december 2012 tot het voor het eerst richting computergebruikers werd misbruikt. De dag na de ontdekking heeft Google het certificaat voor de Chrome-browser geblokkeerd.

Op 26 december werd geconstateerd dat een tweede nepcertificaat in omloop was. Ook dit certificaat is geblokkeerd in de webbrowser. Later deze maand zal Google een update sturen om bepaalde certificaten van Turktrust niet meer te vertrouwen.

Update

Ook Microsoft heeft inmiddels de lijst met vertrouwde certificaten van een update voorzien.  Mozilla, de maker van de Firefox-webbrowser, heeft het vertrouwen in de twee valse certificaten eveneens opgezegd.
Gebruikers van Windows 8, Windows Phone 8 en Windows Server 2012 krijgen de updates automatisch, terwijl andere gebruikers de updates zullen moeten ophalen.

Turktrust

Het bedrijf Turktrust is een soort onderaannemer om vertrouwde certificaten uit te geven. Daardoor kunnen ze een website met een versleutelde verbinding als echt waarmerken.

Microsoft stelt dat het bedrijf zegt dat er abusievelijk twee autoriteiten zijn aangemaakt waar de nepcertificaten zijn verstrekt. Volgens Google is dit een zeer ernstig beveiligingsincident.

Diginotar

Het incident heeft gelijkenis met Diginotar, omdat het nepcertificaat dat in het oog sprong bij Diginotar *.google.com waarmerkt. Precies dat is ook het geval bij Turktrust. Dat Google het heeft ontdekt via browserverkeer betekent dat er kennelijk daadwerkelijk misbruik van het certificaat is gemaakt.
Als een gebruiker met een nepcertificaat naar een site gaat, is het mogelijk om internetcriminaliteit te plegen. In het geval van Diginotar ging het om de Iraanse overheid die in staat was het versleuteld verkeer naar Iran op te vangen.
Op de website van Turktrust is geen melding van het incident te vinden. Volgens Google zijn andere certificaten van Turktrust nog wel te vertrouwen.

Bron: Nu.nl

 

maandag 31 december 2012

New 0-day Vulnerability in Internet Explorer

Microsoft just made public advisory 2794220 for a new vulnerability that affects Internet Explorer 6, 7 and 8. Yesterday Fireeye had published a post on their blog describing an active attack on that vulnerability hosted on the Council of Foreign Relation's (CFR) website, which they believe to have been active since Dec 21st. The attack on CFR's site is targeted, works only against IE 8 and uses Adobe Flash to setup the environment necessary.

Internet Explorer 9 or 10 are not affected by this vulnerability and upgrading to these versions of IE is a good option for individual users. IT admins that cannot up[garde that fast, should take a look at the EMET toolkit which Microsoft has been listing as a defensive workarounds for this attack and as well as the last IE 0-day in September (2757760). 

Microsoft's SRD blog post goes over the technical details of the current attacks and provides some insight how the attackers circumvent IE's built-in protection mechanisms by using a components from Flash, Java and Office.

maandag 3 december 2012

Spear Phishing Remains Preferred Point of Entry in Targeted, Persistent Attacks

Persistent targeted attacks against the government, financial services, manufacturing and critical infrastructure take on many characteristics. Attackers can have different backgrounds and motivations, and the tools they use can range from commodity malware to zero-day exploits.

One characteristic that’s consistent throughout most of these campaigns against high profile organizations is the initial means of infiltration—spear phishing.


Nine times out of 10, attackers walk into an organization right through the front door of its Exchange Server, crafting convincing email messages purportedly from a trusted source that either trick the victim into opening an infected attachment or visiting a website where credentials are stolen, or malware is surreptitiously installed on the visitor’s machine. In any event, the first wave of the targeted attack kicks off from a lowly email.

Even the most security conscious organizations in the world such as RSA Security, which was infiltrated nearly two years ago by hackers after the source code of its flagship SecurID authentication token, are liable to fall victim to a spear phishing message.  Why? Because spear phishing works.
Spear phishing as a craft has improved tenfold over what it was a half-decade ago when messages were shady even to the untrained eye. The grammar in the messages was bad, the spelling even worse. Sometimes company logos were out of date, and messages just wouldn’t pass the smell test. Now it’s nigh impossible to sniff out phony messages from the real deal. Humans trust email as a platform, and that’s their first downfall, experts say.

“Most organizational management and security teams understand what spear phishing is. The problem is they do not know how, or do not have the time and resources, to teach people what phishing is and how to detect or defend against it,” said Lance Spitzner, a SANS Institute instructor and inventor of the honeypot. “As such, they continue to be highly vulnerable to spear phishing attacks.”

Spitzner is a big proponent of awareness training inside organizations, training them not only what phishing attacks look like, but what to do if they’re phished.
“Spear phishing works because people have not been trained on how to detect such attacks. Even if they do fall victim, if people can figure out after the fact they did something wrong and then report it right away, this is still a win,” Spitzner said. “If you teach people even the basics that email is an attack platform, and simple steps to detect common attacks, you can still have a dramatic impact.”
Enterprises, however, are losing that fight. A Trend Micro research paper revealed that 91 percent of targeted attacks observed between February and September of this year involved spear phishing. Attackers involved in nation-state sponsored APT-style attacks prefer spear phishing as a means for reaching high-ranking executives or technology managers with privileged access to high-value systems.

The majority of spear phishing messages (94 percent), meanwhile, contain malicious yet common file types as attachments, i.e., PDFs, Excel spreadsheets or Word documents. Rarely are executable files send via email attachments since most security systems will detect these; if they are sent, they’re usually compressed and sent in a password-protected archive file such as .zip or .rar.
“People normally share files (e.g., reports, business documents, and resumes) in the corporate or government setting via email,” the Trend Micro report said. “This may be due to the fact that downloading off the Internet in such a setting is frowned upon. That is why a higher number of spear-phishing emails with attachments are sent to targets in the corporate or government sector. “

Government agencies and activist groups are the most targeted via spear phishing, Trend Micro said. Most often, members of these types of organizations have some type of biographical information available online either on agency websites or social media pages, treasure troves for attackers mining for organizational data to be used in social engineering.
“In a lot of cases, these emails are not true spear phishing. The attacker may simply customize the ‘From’ address to match the victim organization or include the company name in the subject line,” Spitzner said. “The state of awareness is so poor that even basic spear phishing is effective.  Long story short, it does not take a lot of time.”

Prior to a spear phishing campaign, attackers invest time doing reconnaissance prior to an infiltration. They scour social media sites, or purchase stolen information underground to profile an organization and understand exactly whom they want to target with a phishing message. This person would have access to systems or files of most interest to a particular mission.
Once inside, victims are often infected with a remote access Trojan (RAT) that gives an attacker a persistent backdoor into a network. The RAT can communicate with the attacker and send back system information, legitimate credentials and more that would allow the infiltrator to pivot from system to system until they land on the information they’re after.

“Our findings highlight how spear phishing aids APT attacks because of the vast amount of information available at the touch of our fingertips,” Trend Micro said. “Organizations should strive to improve their existing defenses and take into careful consideration what types of and how much information they make available online.”

Spear phishing is a different animal than a generic spam campaign pushing illicit pharmaceuticals, for example Spitzner said the best defense is continuous training inside an organization.
“We patch computers at least once a month, so too should you teach people in your awareness program. Far too many organizations take a compliance approach and teach people only once a year,” Spitzner said. “Active internal phishing assessments also work well.  You do not need to spend a lot of money on these.”

A recent private summit sponsored by RSA Security also pointed to the effectiveness of people-focused breach prevention programs.
“Many of the preventative security measures discussed at the Summit focused on people, not systems,” RSA said in a report on the summit. “Delegates generally observed a trend toward treating internal employees as ‘a less trusted space."

Bron: Threatpost

vrijdag 9 november 2012

Update: Adobe Working to Confirm New Reader Zero-Day Sandbox-Bypass Exploit

Adobe said today it has been in contact with the Russian security company Group-IB, which discovered a zero-day vulnerability in Adobe Reader and yesterday reported the existance of a pricey exploit circulating on the black market.
The exploit, according to Group-IB, bypasses Adobe’s sandbox protection in Reader, and is selling for upwards of $50,000. Group-IB head of international projects Andrey Komarov said attackers are using malformed PDF documents with specially crafted forms to get shellcode on compromised machines.

"We received a response from Group IB this morning and are now in communication so we can make a determination on whether or not this is in fact a vulnerability and a sandbox bypass," said Adobe senior manager of corporate communications Wiebke Lips.
While the exploit is expensive and currently has limited availability underground, Komarov said, it has been added to the Black Hole Exploit Kit. Version 2.0 of Black Hole was released in September with a host of new features, including random domain generation and exploits targeting Java and other methods used to execute drive-by downloads and other Web-based attacks. Given the exploit's lack of general availability, it's unlikely it has been added to the commercial version of Black Hole, and more likely a customized version.

“For now, this flaw is distributed only in small circles of the underground but it has the potential for much larger post-exploitation methods,” Komarov said.

Komarov added that there are limitations to the exploit. He said a successful exploitation requires the user to close and restart their browser.

“The vulnerability has a very significant vector to be spread with bypassing of the internal Adobe X sandbox, which is appealing for cybercrime gangs because in the past there was no documented method of how to bypass it with shellcode execution,” Komarov said.
Adobe recently upgraded Reader XI and Acrobat XI with better sandbox functionality and a feature that forces DLLs loaded by those applications to use address space layout randomization (ASLR), a capability that reduces the risk of memory corruption attacks. Sandbox protection processes untrusted content before it’s exposed to the underlying system.

Krebs on Security reported that the author of Black Hole confirmed the exploit was in circulation and not widely available. He added that the Black Hole author was hopeful to include it in the exploit kit soon. Regardless, should the attack find its way into an available exploit kit, it would put any number of large enterprises, manufacturers, government agencies and military organizations at risk. Zero-days such as this one are central to targeted attacks against high-value intellectual property.

“The good news is that the exploit costs $50,000, which limits the purchase of it to defense contractors, nation states and some criminal organizations that may be able to recoup the cost of purchase,” said Marcus Carey, security researcher with Rapid7. “It’s good that Group-IB has publicly disclosed this vulnerability in Adobe, and hopefully Adobe will be able to get their hands on this exploit and patch it as soon as possible to safeguard customers.”

Carey advises users who do not need the Adobe plug-in to disable it and be cautious about opening PDF attachments.
“Once this exploit is available to the public, there is potential for it to be added to Black Hole and other exploit kits and it may even be improved from its current state for malicious intent to address multiple platforms,” Carey said.

Bron: Threatpost