Wednesday, December 3, 2008

Security News Feed Wednesday 12/03/08

(U) Animal Rights Extremists Target UCLA Researcher in Arson Attack
LA Times
29 NOV 2008Animal rights activists destroyed one vehicle and badly damaged two others in a Palms-area arson attack last week, authorities said. The incident occurred Nov. 20 and appears to be part of a botched attempt to target a UCLA animal researcher, authorities said. Activists with the group Students and Workers for the Liberation of UCLA Primates claimed responsibility for the attack, stating on an animal rights website that the destroyed car belonged to Goran Lacan, a UCLA "vivisector." But on Friday, Los Angeles Police Department investigators said none of the cars belonged to Lacan. The attackers, they said, targeted the wrong home and doused the wrong car with fuel before setting it on fire. Anti-animal research extremists have increasingly targeted UCLA faculty and researchers with harassment. Past actions include firebombing a UCLA commuter van, flooding a UCLA scientist's home and placing a firebomb in the home of a UCLA researcher's neighbor. The Nov. 20 incident is being investigated by the FBI, the LAPD and the UCLA police. At UCLA, Chancellor Gene Block released a statement condemning the acts. "They are willing not only to risk the lives of those who spend their careers working to help others, but also the lives of the unsuspecting general public, including children," Block said.






Botnet master sees himself as next Bill Gates
... Now working for a small New Zealand software company, Walker has become a minor celebrity in his home country. He was profiled this week on New Zealand's TV3 60 Minutes program, which described him as "the teenage boy with a brain that's one in a billion."

Walker, who was known online as Akill, and in his hometown of Whitianga as Snow, comes across as a typical geek in the report. An early reader who loved books, he was diagnosed with Asperger syndrome as a child. He was teased so mercilessly at school that his mother eventually decided to home-school him. By 15, he was drawn to computer programming and was often spending eight to 10 hours on the computer after school.






Chinese city requires Net cafes to use legitimate software
Chinese news reports estimated that up to 600 Internet cafes in Nanchang, a city of around 4 million people, are affected by the order, which aims to stamp out the use of pirated software in local Internet cafes.





U.S. report sees major terror attack by 2013, ignores cyberattack risk
In stark and certain terms, a Congress-mandated commission today warned that the world's nations face the threat of a major terrorism attack using biological and nuclear weapons by 2013. The commission's report, titled "The World at Risk," skips over the threat of cyberattacks and focuses almost exclusively on nuclear and biological weapons.





Feds nab more members of alleged identity theft gang
Federal authorities say they have taken another step toward busting a multinational identity theft ring that is alleged to have used stolen personal data to withdraw millions of dollars from home equity line-of-credit accounts at dozens of financial institutions in the U.S., including some of the country's largest banks.

Four individuals were arrested last week in connection with the alleged scheme, which has resulted in more than $2.5 million being stolen from the affected financial institutions, according to law enforcement officials. Another $4 million worth of attempted withdrawals by the gang were unsuccessful, the U.S. attorney's office in New Jersey said in announcing the arrests last Wednesday (download PDF).






Will Mac Become a Virus Trap?PC World - 1 hour, 18 minutes ago
Apple has backed off its suggestion that Macs require antivirus software. Yesterday, the computer maker suffered a public relations nightmare after an article was discovered on the company's site encouraging Mac users to install antivirus software. Less than 24 hours later, Apple has quietly removed this recommendation from its KnowledgeBase.






http://lists.vmware.com/pipermail/security-announce/2008/000046.html
VMware Security Advisory
Advisory ID: VMSA-2008-0019
Synopsis: VMware Hosted products and patches for ESX and ESXi
resolve a critical security issue and update bzip2
Issue date: 2008-12-02
Updated on: 2008-12-02 (initial release of advisory)
CVE numbers: CVE-2008-4917 CVE-2008-1372






5 Must-Do Cyber Security Steps for Obama
As President-Elect Obama focuses on two wars and a hemorrhaging economy, security experts are urging him to address five weak security links in America's cyber infrastructure that threaten the nation's defenses and financial institutions.
Read more






Who Falls for those Nigerian 419 Scams Anyway?
This is the story of a woman who sent the scammers $400K:

She wiped out her husband's retirement account, mortgaged the house and took a lien out on the family car. Both were already paid for.

For more than two years, Spears sent tens and hundreds of thousands of dollars. Everyone she knew, including law enforcement officials, her family and bank officials, told her to stop, that it was all a scam. She persisted.

Spears said she kept sending money because the scammers kept telling her that the next payment would be the last one, that the big money was inbound. Spears said she became obsessed with getting paid.

An undercover investigator who worked on the case said greed helped blind Spears to the reality of the situation, which he called the worst example of the scam he's ever seen.






Outraged aussies will hold simultaneous protests across Australia in opposition to the government's plans for mandatory ISP internet content filtering. The plan will introduce nation-wide filtered internet using blacklists operated by a government agency, away from public scrunity. Politicians and ISPs will join protesters in the streets to voice their opposition to the government's plan, which has ploughed-ahead, despite intense criticism that the technology will crippled internet speeds and infringe on free speech.Opponents said the most accurate filter chosen by the government will incorrectly block up to 10,000 Web pages out of 1 million.






Ant recommends a Wired piece on the background story of the Kaminsky DNS bug and its (temporary) resolution, decreasing the odds of a successful breach from 1 in 2^16 to 1 in 2^32. We've discussed this uber-hole a number of times. Wired follows the story arc from before Kaminsky's discovery of the bug to his public presentation of it in Las Vegas.






Online market share of the dominant Windows operating system has taken its biggest monthly fall in years to drop below 90%, according to Net Applications Inc. Computerworld reports that Microsoft's flagship product has been steadily losing ground to Mac OS X and Linux, and is at its lowest ebb in the market since 1995. 'Mac OS X... [ended] the month at 8.9%. November was the third month running that Apple's operating system remained above 8%.' The stats show that while some customers are 'upgrading' from XP to Vista, many are jumping ship to Apple, while Linux is also steadily gaining ground. A Net Applications executive suggests the slide may be caused by many of the same factors that caused the fall in Internet Explorer use. 'The more home users who are online, using Macs and Firefox and Safari, the more those shares go up,' he said. November has more weekend days, as well Thanksgiving in the US, a result that emphasizes the importance of corporate sales to Microsoft.






Remote searches of suspect computers will form part of an EU plan to tackle hi-tech crime. The five-year action plan will take steps to combat the growth in cyber theft and the machines used to spread spam and other malicious programs. It will also encourage better sharing of data among European police forces to track down and prosecute criminals. Europol will co-ordinate the investigative work and also issue alerts about cyber crime sprees.






Vista SP2: What's inside?
Mary Jo Foley: Microsoft is adding to Windows Vista SP2 features such as built-in Hyper-V hypervisor, a Windows Vista Feature Pack for Wireless, and improved power settings for Windows Server 2008.
Ed Bott: Vista SP2, Microsoft's back on track
New virtualized sandbox, Vista SP2 and other PDC-week leftovers






Device Designed To Annoy Young People Can Now Annoy Everyone
from the bzzzz dept
We've written about the Mosquito device a few times in the past. Originally launched back in 2005, the device emitted a high pitched annoying noise that could only be heard by those under 25 (or thereabouts). As people get older, we lose the ability to hear noises at higher pitches. So the device tried to take advantage of this, so that shopkeepers could use the device to ward off loitering kids. It was pretty obnoxious, though it hardly seemed like a violation of human rights, as some claimed. If annoying a certain age group with sound is a human rights violation, I'd imagine playing certain types of music would be seen as a human rights violation.

Of course, some kids realized that rather than being a violation of their rights, such a noise could be used to their advantage. Some turned the noise from the Mosquito into a ringtone that their parents and teachers couldn't hear.

However, the makers of the device have apparently released a new version of the Mosquito that has an option where the pitch is lowered a bit so that it can annoy pretty much everyone. You've got to imagine that such a product is not targeted at shop owners and the like this time around, unless they'd prefer no business whatsoever. It seems that right now the new version is being used in places like parking garages, where actual customers are quick to leave anyway, and proprietors are trying to get homeless people to move along. Of course, as with any such thing, there's apparently a group of folks who are pushing for legislation to ban the devices. It's difficult to see why such legislation is needed. Eventually, people will realize that driving people away from a business probably isn't a very good business idea.





UK Says You Can't Have Some Kinds Of Porn, But It Determines What Kinds






Christmas worm uses McDonalds and Coca Cola as bait






Writing an Effective Security Policy (Part 1)
by Ricky M. Magalhaes
Articles / Misc Network Security
How to write an effective security policy.






China Aggressively Pursuing Cyber Warfare Says 2008 U.S.-China Economic & Security Review Commission By Grey McKenzie 11/24/2008

Monday, December 1, 2008

Security News Feed Monday 12/01/08

New Windows worm builds massive botnet The worm exploiting a critical Windows bug that Microsoft patched with an emergency fix in late October is now being used to build a new botnet, a security researcher said today. Read more...






London hospitals almost back online after worm infection
Three London hospitals whose computer systems were infected with a relatively old worm are now almost back online.

About 5,000 PCs at St. Bartholomew's, the Royal London Hospital and The London Chest Hospital were hit in mid-November by an infection of Mytob, a worm that e-mails itself to other PCs and can be used to put other malicious software on a machine.

About 97% of those PCs are now clear of Mytob, according to a statement issued Friday. The remaining PCs, which are located in nonclinical areas, should soon come back online.

As a precaution, all of the PCs were shut down after the infection was discovered. The infection affected computers used to admit patients, and the hospitals diverted emergency patients to other facilities for a short time.





Antivirus no defense against botnets, says vendor





Think digital, not analog, when it comes to risk
The amount of money and labor that financial institutions have spent on securing their perimeter makes them a less fruitful target for cybercriminals. But it's the small to midsize businesses that are the seldom-discussed goldmine now, said an executive at Symantec Corp.

From a hacker's point of view, larger organizations in the financial services sector may offer the biggest bang for their efforts considering the amount of sensitive data they transact, but SMBs lack the resources to protect their perimeters, said Symantec's Dean Turner, director for global intelligence network.

"Your small-medium business owner is the accountant, he's the CEO, he's the IT guy, the sales guy, the chief cook and bottle washer," said Turner. "And that's a lot on one person's plate."

Turner was referring to a recent report by Symantec titled "Report on the Underground Economy" that discusses a thriving ecosystem of cybercriminals advertising and selling stolen data like credit card information and financial accounts to meet demand.
...






Estonian ISP cuts off control servers for Srizbi botnet
Srizbi is considered one of the more powerful botnets, with at least 450,000 PCs infected. It is estimated that half of the world's spam originated from computers infected with Srizbi. Spam remains a profitable business for cybercriminals.

But spammers lost control of Srizbi when the ISP that previously hosted its command-and-control servers was cut off from the Internet. McColo Corp., whose servers are based in San Jose, was cut off by its upstream providers earlier this month after being exposed by computer security experts and The Washington Post.

That left spammers unable to control Srizbi-infected computers. But Srizbi's code contained a fallback mechanism in which spammers could reconnect with the stranded machines if such a scenario occurred.
...






Investigation compiles grim catalog of NHS data breaches
The U.K.'s National Health Service (NHS) has lost confidential medical records and personal details of thousands of patients, according to an investigation into how the health service handles data.

Research showed that a series of losses and thefts had potentially exposed the private details of 10,000 patients around the country. The figures, obtained through a Freedom of Information request made by the Liberal Democrats, revealed incidents of data loss dating back as far as 2006.

In some cases, the patient record loss was so serious that 25 patients were visited by the police and NHS management.






Malware is Getting Smarter, CA Warns PC World - 1 hour, 38 minutes ago
Online attacks will be dominated by smarter malware and bots targeting Web users ranging from gamers and social network users to the elderly and unsuspecting parents.





How Spyware Nearly Sent a Teacher to Prison PC World - 1 hour, 56 minutes ago
If there's a poster child for the dangers of spyware, it's Julie Amero.

ERIC SAYS: She still lost her teaching credential and her job.





Europe to get cybercrime alert system CNET - Mon Dec 1, 10:02 AM ET
Europe is getting a cybercrime alert system as part of a European Union drive to fight online criminals.





Mobile Handsets Becoming A 'Smoking Gun' Dec 01,2008
Rise in mobile devices in the enterprise adds new challenges to incident response





Facebook Wins $873 Million Lawsuit Against SpammerNov 25,2008
Spammer remains on the lam, but courts hope big award will scare others






Input filtering and escaping in SQL injection mitigation
While teaching the defensive web app security classes with SANS, I often hear "I have been filtering/escaping quote character for years to prevent SQL injection, it had worked flawlessly." That's one of the common statement I get when I sell the idea of parameterized queries. We know by now that filtering single quote does not prevent all SQL injection, but how big is the risk?

I have been doing some SQL injection research with the fine folks from Security Compass on MS SQL server. Depending on your setup, you might be more vulnerable than you think. What characters do people normally filter or escape for preventing SQL injection? Maybe quote and semi-colon? Bad news, depending on your setup, you maybe very vulnerable even after filtering those characters.
...






Register: Sony rootkit functionality found in security product

November 30, 2008 — CSO — According to The Register, a Chinese development company behind infamous Sony USB rootkit software has embedded similar functionality in the network security product HKTL-BRUDEVIC.





Does the Drew verdict make ToS breakers potential felons?
Legal observers worry that the verdict in a high-profile cyberbullying case will make crimes of ToS violations.





Apple: Mac Users Should Get Antivirus Software
Permalink
In a notable shift, Apple is now recommending that Mac users install anti-virus software to help users secure their systems.

In a technical note quietly published to its support site on Nov. 21, Apple issued the following advice:

"Apple encourages the widespread use of multiple anti-virus utilities so that virus programmers have more than one application to circumvent, thus making the whole virus writing process more difficult."





BotHunter aims to find bots for freeNews Brief, 2008-11-25
A technology firm publicly releases its tool for hunting down compromised machines within computer networks.

Tuesday, November 25, 2008

Security News Feed Tuesday 11/25/08

Former Hunton Partner Gets 70 Months for Child Porn on Firm Laptop
http://www.law.com/jsp/article.jsp?id=1202426266809&rss=newswire

A former Hunton & Williams partner was sentenced Monday to 70 months in federal prison for using his firm's laptop to download and store videos of child pornography.

The lawyer, Emerson Briggs, who made partner at Hunton & Williams in 2003, pleaded guilty in September to one count of receiving child pornography. Judge Colleen Kollar-Kotelly of U.S. District Court for the District of Columbia also sentenced Briggs, 41, to 10 years of supervised release and ordered him to pay a $12,500 fine.

Briggs has been in custody since his plea hearing. Steptoe & Johnson partner Bruce Bishop, who represented Briggs, declined to comment. Briggs is "ashamed and remorseful about his past actions," his wife wrote in a letter to the judge. Briggs entered counseling after losing his job at Hunton & Williams.






TPM 1.2 specifications moves forward to become ISO/IEC standards






Lenovo Service Disables Laptops With Text Message Lenovo on Tuesday announced a service that allows users to remotely disable a PC by sending a text message.





Bug allowed free access to Sirius radio service





U.S. agency sees robots replacing humans in service jobs by 2025





Update: FTC asks Supreme Court to review Rambus antitrust case





Facebook wins $873M judgment in spam suit
Facebook won a case against a spammer who was ordered to pay the social-networking giant $837 million in damages.





Verizon cans workers who snooped Obama's cell phone, CNN reports
Any CIO knows you can't have staffers perusing records -- especially the president-elect's -- but this applies to all of us.





Holiday Travel: Ways to Keep Your Laptop, Privacy Safe





Microsoft's Ballmer ordered to testify in 'Vista Capable' suit





Hands-off hackers: Crooks opt for surgical strikes AP - Mon Nov 24, 7:16 AM ET
SAN JOSE, Calif. - Internet criminals have been getting more "professional" for years, trying to run their businesses like Big Business to get better and more profitable at selling stolen data online. Now the bad guys of the cyber-underworld are exhibiting other unexpected traits: remarkable patience and restraint in stalking their victims.





Pentagon bans computer flash drives AP - Fri Nov 21, 4:35 PM ET
WASHINGTON - The Pentagon has banned, at least temporarily, the use of external computer flash drives because of a virus threat officials detected on Defense Department networks.





Virus strikes some Pentagon computers: official AFP - Fri Nov 21, 1:13 PM ET
WASHINGTON (AFP) - Some Defense Department computer networks have been infected with a "global virus" and steps are being taken to mitigate it, the Pentagon said Friday.





Can Obama Keep His BlackBerry?
Analysis: Any responsible enterprise has security measures to handle mobile devices, so Obama should be able to take his BlackBerry into the West Wing with a little planning.





Tech Insight: Free Network Tool Shows The Bigger PictureNov 21,2008 A hands-on look at the new NetWitness Investigator network analysis tool and how it can team with Wireshark






Large quantity SQL Injection mitigation
As botnets and other automated tools are hammering at websites trying to exploit SQL injection vulnerabilities, site operators are trying hard at defending their websites. ASProx and other botnets were hitting hard at the ASP + MS SQL platform, millions of websites fell victims to the SQL injection vulnerabilities already. Although there has been a decline of wild SQL scanning by ASPRox type of botnet, we are still not in the clear yet. The unauthenticated portion of some sites might be secure, but the authenticated portion might be totally vulnerable. Since most scans only target what can be seen by Googlebots, there are still tons of web pages out there vulnerable waiting for exploitation.






Why Mass. 201 CMR 17 Deadline Was Extended
Companies that live or do business in Massachusetts have a few extra months to meet compliance deadlines for the state's tough 201 CMR 17 data protection law. The simple reason: Too few understand the law to meet the original January deadline (Part 1 in a series).
Read more





Two Weeks Out, Spam Volumes Still Way Down
Permalink
A full two weeks after a Web hosting firm identified by the computer security community as a major host of organizations engaged in spam activity was taken offline, the volume of spam sent globally each day has yet to bounce back.

The block graph over at e-mail security firm IronPort suggests that the company blocked around 35 billion spam messages on Monday. Prior to hosting provider McColo's shutdown, IronPort was flagging somewhere around 160 billion junk e-mails per day.

A quick glance at the volume flagged by Spamcop.net shows that they're still detecting well below half of the spam volumes they were just two weeks ago.





... the US National Telecommunications and Information Administration has gotten plenty of feedback on its call for comments on securing the root zone using DNSSEC. The comment period closed yesterday, and more than 30 network and security experts urged the NTIA to implement DNSSEC stat. There were a couple of dissenting voices and a couple of trolls.
Read More





Symantec is warning of a sharp jump in online attacks that appear to be targeting a recently patched bug in Microsoft's Windows operating system, an analysis that some other security companies disputed. Symantec raised its Threat Con security alert level from one to two because of the attacks, with two denoting 'increased alertness.' The attacks spotted by Symantec target a flaw in the Windows Server Service that Microsoft says could be exploited to create a self-copying worm attack.
Read More





Cybercriminals release Christmas themed web malware exploitation kit






From an unclassified DHS Report: Between 1993 and 2007, at least 16 confirmed ricin incidents involving domestic extremists have occurred; none resulted in any fatalities.

Tuesday, November 18, 2008

Security News Feed Tuesday 11/18/08

I wanted to gather a collection of recent news together regarding device encryption. There are new laws going into effect in Nevada and Massachusetts that may affect how data for their citizens are handled.





Massachusetts encryption law even stricter than Nevada’s
Written by Dan Blacharski on October 24, 2008

I recently wrote about Arizona’s new law concerning encryption of personal data. Several states are enacting similar legislation, and encrypting such data is becoming a de facto national policy. Most recently, Massachusetts issued new regulations on the same subject last month, and that state’s laws will take effect on January 1, 2009.

The Massachusetts legislation, known as the Standards for the Protection of Personal Information of Residents of the Commonwealth, is very far-reaching and considered the strictest regulations to date. The new law adds to Massachusetts’ already stringent security regulations, by requiring all portable personal data about any Massachusetts resident to be encrypted. This applies to data transmitted over public networks, or that is stored on a laptop, or on any type of removable memory device. The law requires other mandatory security procedures, including updated user authentication and authorization.

There is a technical difference between Nevada’s and Massachusetts’ statute in how encryption is defined. For the Nevada law, “encryption” is defined as the use of a protective or disruptive measure, including cryptography, enciphering, encoding, or a computer contaminant, to render data unintelligible. The Massachusetts statute is more specific, stating that “encryption” is an algorithmic process that requires a confidential process or key to decode. Some have argued that since the Nevada law does not use the word “algorithmic,” then password-protection is adequate to adhere to the letter of the law.

Also, the laws differ in scope. Nevada’s law focuses on the electronic transmission of data, while Massachusetts also includes portability. Accordingly, if you have data on a resident of Massachusetts on your hard drive, even if you do not send it via email or over the Internet, you still must encrypt that data.





New Data Privacy Laws Set For Firms
WSJ October 16, 2008

Alicia Granstedt, a Las Vegas-based hair stylist who works for private clients and on movie sets, never worried about conducting most of her business through email.

Ms. Granstedt regularly receives emails from customers containing payment details, such as credit-card numbers and bank-account transfers. Since she travels frequently, she often stores the emails on her iPhone.

But a Nevada law that took effect this month requires all businesses there to encrypt personally-identifiable customer data, including names and credit-card numbers, that are transmitted electronically.

After hearing about the new law, Ms. Granstedt started using email-encryption software, which requires her clients to enter a password to read her messages and send responses. It is a hassle, "but I can't afford to be responsible for someone having their identity stolen," she said.

Nevada is the first of several states adopting new laws that will force businesses -- from hair stylists to hospitals -- to revamp the way they protect customer data. Starting in January, Massachusetts will require businesses that collect information about that state's residents to encrypt sensitive data stored on laptop computers and other portable devices. Michigan and Washington state are considering similar regulations.

While just a few states have adopted such measures so far, the new patchwork of regulations is something many businesses will have to navigate, since the laws apply to out-of-state companies with operations or customers in those states.

That's one reason the Massachusetts law has the attention of Andrew Speirs, information security officer for National Life Group, an insurance company based in Montpelier, Vt. "We do business in all 50 states so we're definitely reviewing it," he said. Mr. Speirs said that National Life has a program in place to protect data, but that the Massachusetts law "is a little more particular" than other state laws. He is checking his company's program for any holes.

...





https://blogs.sonnenschein.com/icdp/Lists/Posts/Post.aspx?ID=21
Sonnenschein Nath & Rosenthal LLP

Massachusetts Rules Require Protection of Personal Information; Nevada Law Requires Encryption of Personal Information
On Sept. 19, 2008, the Massachusetts Office of Consumer Affairs and Business Regulation (“OCABR”) issued final rules governing how businesses must protect and store personal information. The rules take effect January 1, 2009. Under the rules, businesses that own license, store, or maintain personal information of a Mass. resident must develop and implement a written information security program and implement certain system security measures, including encryption of personal information during transmission (to the “extent technically feasible”) and encryption of personal information stored on laptops and other portable devices. A copy of the rules can be found on the OCABR website.

A Nevada statute (N.R.S. 597.970) that takes effect October 1, 2008 requires businesses “in this State” to encrypt all customer personal information (other than facsimiles) that is electronically transmitted “outside the secure system of the business.” The statute refers to Nevada's data breach statute for the definition of "personal information," which is defined as first name or first initial and last name in combination with any of the following elements: SSN; driver’s license or ID card number; or account number, credit card number or debit card number, in combination with any required security code, access code or password that would permit access to the person’s financial account. (N.R.S. 603A.040) The statute does not include a definition of what it means to be a "business in this state," thus making it unclear as to whether the statute would only apply to businesses physically located in the state or to all entities conducting business with Nevada residents.

Both the Massachusetts regulations and Nevada encryption statute are part of a growing trend in state legislation (and industry standards) to require businesses to implement certain controls to protect personal information. A number of states (including California and Nevada) have statutes in place requiring entities that maintain records containing personal information state residents to implement and maintain reasonable security measures to protect those records from unauthorized access, acquisition, destruction, use, modification or disclosure. Likewise, the Payment Card Industry Data Security Standard (“PCI DSS”) also requires all entities processing credit card payments to implement an array of security controls, including firewalls, access controls, monitoring, and encryption of cardholder data during transmission and storage. The message is clear: entities must implement reasonable security controls to protect personal data.





State Data Encryption Laws Ready to Take Effect
http://www.scottandscottllp.com/main/state_data_encryption_laws.aspx

By now, many U.S. businesses (hopefully) have taken steps to familiarize themselves and to contend with the patchwork quilt of state laws that sets forth standards regarding what must be done in the wake of an IT security breach affecting customer data. (Click here for more background on that topic.) While contingency planning in light of these laws (now present in 44 states and the District of Columbia) usually entails some up-front costs in the form of diverted resources and attorney’s fees, the overall cost of implementation has been relatively low. It may be fitting, then, that the perceived benefit of these laws has been similarly minimal, with some estimating only a 2% reduction in identify theft in recent years that can be attributed to data breach notification legislation.

It is perhaps as a result of such low estimated return that some states now are starting to implement tougher standards describing the steps that businesses bust take in order to prevent such breaches from occurring in the first place. Nevada’s law is the first and went into effect on October 1, 2008. Massachusetts is set to follow with a more detailed set of regulations in January, with Michigan and Washington State in the process of considering similar measures.

The Nevada provision is succinct:
A business in this State shall not transfer any personal information of a customer through an electronic transmission other than a facsimile to a person outside of the secure system of the business unless the business uses encryption to ensure the security of electronic transmission.
“Encryption” and “personal information” are defined by reference to other statutes and have meanings similar to those typically used in the notification laws. (See NRS 597.970.)

The effect of the Nevada law is to give a victim of identify theft resulting from data breach a statutory standard of care to enforce against the business that, as a result of negligent (or other) non-compliance with the law, experienced the breach that led to the identify theft in question. Other questions pertaining to the practical implementation of the standard remain, including how to show a causal link between the breach and the ID theft and whether some injury short of ID theft – such as the cost of signing up for credit monitoring – would be support a damages claim sufficient to allow a case to proceed to trial. However, it is clear that companies doing business in Nevada now have a tangible interest in deploying encryption technology to protect the data of customers living in that state.

In Massachusetts, the stakes could be even higher. There, the state’s Office of Consumer Affairs & Business Regulation has adopted regulations, to become effective on January 1, 2009, that provide detailed definitions of the standards businesses must meet in order to bring their data handling technology and protocols into compliance. (See 201 CMR 17.00.) While the Massachusetts regulations’ enabling statute does not create a private cause of action for failure to comply, it does give the state attorney general the authority to file a lawsuit for injunctive relief and, in some cases, civil penalties up to $5,000.00 per violation.

As with the notification laws, there is no unified, federal standard for data handling to pre-empt what may become another medley of state laws for businesses to navigate. If these laws become more commonplace (and it appears that they very well may), it will become even more critical for companies conducting interstate transactions to work closely with counsel in order to ensure their compliance with all applicable data handling standards and safeguards.




Where can I get the latest information on HIPAA?

For the complete HIPAA regulations, visit the Department of Health and Human Services.

To learn more about HIPAA insurance reform or HIPAA administrative simplification, visit Center for Medicare & Medicaid Services (CMS).

To learn more about what the Navy and TMA is doing to comply with HIPAA requirements, visit the Navy Medicine HIPAA site and the TMA HIPAA site.

The WorkGroup for Electronic Data Interchange provides information and white papers on Transactions, Security and Privacy.

Questions about HIPAA regulatory compliance (transactions, code sets, national identifiers, and security) can be directed to the Centers for Medicare and Medicaid (CMS) at 410-786-4232 (local) or 1-866-282-0659 (toll-free).

Monday, November 17, 2008

Security News Feed Monday 11/17/08

Google patches Chrome file-stealing bug





Laid-Off Sysadmin Arrested for Threats to Harm Servers
A systems administrator who was laid off this month by a New York-based financial services firm was arrested in New Jersey last week for allegedly threatening to damage the company's servers if it didn't increase his severance pay.

Viktor Savtyrev, a 29-year-old New Jersey resident, also demanded extended medical coverage and "excellent" job references in e-mails and phone calls to officials at the firm, federal prosecutors said. They declined to identify the firm, but Third Avenue Management LLC confirmed that it is the company involved in the case.






Microsoft: First Exploit Ratings Show Success
Microsoft Corp. last week called its first crack at predicting whether hackers would create exploit code for its software flaws a success -- even though its forecasts were less than 50% accurate.





Can a Cybercrook Get $21,619 off of You?
Too many users neglect their antivirus updates and other cybersecurity measures, a British survey reports.






Wanted: Programmers with Ethics
Morals and ethics join communication and programming skills in a survey of wish lists for IT workers.






A competitor to the free Wireshark packet sniffer program is available for free. It offers some interesting additions beyond the free product. The fully functional and licensed free version of NetWitness Investigator is at: http://download.netwitness.com.





Employees Ignore Online Shopping Risk






Rich Mogull: 7 Infosec Trends for 2009
Shrinking budgets, the collapse of the database security market, DLP going mainstream - the former Gartner pundit places his bets for the coming year. (Part of the What Happens Next security predictions series.)
Read more

Data Loss Prevention goes mainstream. In late 2009 DLP will finally go early mainstream due to the push from the big vendors. Content discovery will drive more deals than network monitoring, and provide more value to most users.







FOIA docs show feds can lojack mobiles without telco help
Documents obtained by civil liberties groups suggest the feds can track cell phone locations without the help of providers.
November 16, 2008 - 10:45PM CT - by Julian Sanchez





Tuesday, November 11, 2008 10:40 AM
MS08-068: SMB credential reflection defense
Today Microsoft released a security update, MS08-068, which addresses an NTLM reflection vulnerability in the SMB protocol. The vulnerability is rated Important on most operating systems, except Vista and Windows Server 2008 where it has a rating of Moderate. This blog post is intended to explain why the issue is less severe on Vista and Windows Server 2008, and provide some additional details to help people determine the risk they face in their environment.

This vulnerability allows an attacker to redirect an incoming SMB connection back to the machine it came from and then access the victim machine using the victim’s own credentials. (Hence the term “credential reflection”). In typical Windows XP configurations where SMB sharing is enabled and the user is a member of the Administrators group, this allows the attacker to easily take over the machine. Public tools, including a Metasploit module, are available to perform this attack.

Typical attack vectors for this vulnerability will leverage HTML either via a web browser or e-mail. Resources within the HTML document (such as IMG tags) can be used to reference a file on the attacker’s machine, and these file are then retrieved using the SMB protocol. The attacker’s machine prompts the victim for credentials and then reflects these credentials to the victim’s machine, gaining access. In cases where the attacker is on the same network as the victim, even “trusted” websites can be leveraged to perform this attack – since network data can be modified before the victim receives it.





Google "Flu Trends" Raises Privacy Concerns

Google announced this week a new web tool that may make it possible to detect flu outbreaks before they might otherwise be reported. Google Flu Trends relies on individual search terms, such as "flu symptoms," provided by Internet users. Google has said that it will only reveal aggregate data, but there are no clear legal or technological privacy safeguards to prevent the disclosure of individual search histories concerning the flu, or related medical concerns, such as "AIDS symptoms," "ritalin," or "Paxil." Privacy and medical groups have urged Google to be more transparent and publish the algorithm on which Flu Trends data is based so that the public can determine whether the privacy safeguards are adequate. At some point aggregate data is identifiable data. Advocacy groups are seeking information on the privacy protections intended to safeguard against abuse or misuse of search information.
Is There a Privacy Risk in Google Flu Trends?, New York Times, November 13, 2008





"NASA has built a new software package to track problems with the Space Shuttle using open source tools from Mozilla. '[Alonso Vera, the lead of the Ames Human-Computer Interaction Group] wouldn't say exactly how much the new systems cost to build, but he said they were an order of magnitude cheaper than what was being used before, closer to $100,000 than the $1 million it would have cost in the past.' The Space Shuttle Endeavor launched successfully on Friday, so the new system is being used to track any problems which may crop up in the current mission. As one commentator pointed out, 'A system like this could save more than money; it could save lives.'"

Read More






"TorrentFreak reports that Toyota's lawyers have recently contacted computer wallpaper site Desktop Nexus in a blatant example of DMCA abuse. Toyota issued a blanket request to demand the immediate removal of all member-uploaded wallpapers featuring a Toyota, Lexus, or Scion vehicle (citing copyright violation), regardless of whether Toyota legally holds the copyright to the photos or not. When site owner Harry Maugans requested clarification on exactly which wallpapers were copyrighted by Toyota, he was told that for them to cite specifics (in order to file proper DMCA Takedown Notices), they would invoice Desktop Nexus for their labor."

Read More





Intrepid iPhone developers bypass security for functionality
The Apple iPhone is vulnerable to a new bug related to the signing of iPhone applications. Applications that are created with the official iPhone SDK need to be cryptographically signed by the author and Apple before they’re allowed into the App store or installed on an iPhone. The digital signing is a security measure that serves two purposes; helping to identify the developer in case of any problems and making sure that an approved application hasn’t been modified.

An iPhone developer discovered the bug while looking for a way to duplicate a feature of Apple created iPhone applications: dynamic default.png files. The default.png file is displayed when an iPhone application is launched and can be used as a static splashscreen. When you quit an Apple created application, it takes a snapshot of the screen when you quit and saves it as default.png within itself. The next time you start the app it loads the new default.png, and everything looks like it was when it was last run. The application hasn’t fully loaded yet, but the saved default.png trick makes it look that way.

Unlike Apple’s apps, those created by other developers can’t modify their default.png files. Since the default.png is stored within the application as a part of itself, it gets digitally signed. Modifying the image file and thus the app, makes the digital signature invalid. An alternative would be to use a default.png in the application’s data directory, but only the file within the application is supported on the iPhone.
...






Cybersecurity advice for President-elect Obama to be previewed at SC World Congress
Greg Masters November 14, 2008
Recommendations from the Commission on Cyber Security for the 44th Presidency will be previewed at the SC World Congress.







Email ruse uses Federal Reserve Bank name to drop PDF exploit
Dan Kaplan November 14, 2008
Bucking the trend of declines in spam this week, a new socially engineered attack is making the rounds.






Black Friday Takedown Notices Hitting Mailboxes
While retailers don't anticipate a widely profitable Black Friday, they're already rounding up the lawyers to threaten websites who publish pre-released sale prices for the day after Thanksgiving shopping stampede.

Consider Wal-Mart, which has already begun sending takedown notices demanding the online removal of their Black Friday ads. Wal-Mart and a host of other retailing concerns perform this act every year ahead of Black Friday.






PLA armor brigade exercise fails due to computer virus
According to news.ifeng, an unidentified PLA armor brigade was the victim of a computer virus that caused electronic ammunition resupply orders to show up blank. During the force-on-force, Red and Blue exercise, operations were hampered due to a computer virus that left the main attack force without ammunition resupply.

During the exercise, the Red Army basic command post, command and control station, received information from the main attack force that 3/4 of their ammunition had been depleted. A resupply order was immediately sent to the rear command post. However, after transmission, the order form appeared blank.

Ten minutes later, the main attack force once again sent a request for ammunition resupply. They were told to wait, that the request for resupply had already been processed. In the end, the main attack force had no hope of getting their ammunition. The ammunition was exhausted, people died and the exercise was lost.

NOTE: When the article states that people died, they are speaking in terms of the exercise. There were no actual fatalities.

Friday, November 14, 2008

Security News Feed Friday 11/14/08

Google patches Chrome file-stealing bug Google has patched its Chrome browser to prevent attackers from stealing files from PCs running the open-source app. Read more...





Apple plays catch-up, ads anti-fraud safeguard to Safari
Apple yesterday added anti-phishing protection to Safari, the last major browser to receive the feature that blocks known identity-stealing sites.





Data pain: University of Florida warns 333,000 dental school patients of breach






Storage, security raises issues for telepresence
Telepresence, the high-end form of videoconferencing now coming from several vendors, is the first technology that might let enterprises easily record high-quality versions of all their meetings, essentially with the press of a button.

Though recording and playback features for these systems are still emerging, some issues are already being raised, including storage capacity, liability and playback quality. Those problems may grow as more enterprises seek to cut back on travel and bring dispersed teams together through telepresence.





Sysadmin under house arrest for blackmailing finance company






New US travel security measure takes effect Jan 12AP - Fri Nov 14, 7:40 AM ET
BRUSSELS, Belgium - U.S. officials say Europeans and others who travel visa-free to the United States must start registering their trips electronically as part of a new online security screening process which takes effect Jan. 12, 2009.






AVG Offers Free Subscription for Deleting Key File PC Magazine - Thu Nov 13, 6:40 PM ET
Security vendor AVG said Thursday that the company will offer a free year of service, after its antivirus software misidentified a key Windows system file as malware.






Despite Risks, Employees Still Holiday Shop at Work
As Cyber Monday approaches, research suggests a majority of workers will use their work computer to shop this holiday season. But despite the continued growth in online shopping, employees and business still don't understand the risk.






One Million UK Kids Make Illicit Online Purchases
Parents unaware kids are using their credit cards.






Researchers Find Flaws In Microsoft VoIP AppsNov 14,2008
Vulnerabilities could lead to denial of service attacks, researchers say







Widespread Account-Sharing Threatens Corporate Security, RevenuesNov 13,2008 Many users break security defenses by simply handing over their credentials to colleagues, friends, experts say






MS08-068: SMB credential reflection defense
Today Microsoft released a security update, MS08-068, which addresses an NTLM reflection vulnerability in the SMB protocol. The vulnerability is rated Important on most operating systems, except Vista and Windows Server 2008 where it has a rating of Moderate. This blog post is intended to explain why the issue is less severe on Vista and Windows Server 2008, and provide some additional details to help people determine the risk they face in their environment.

This vulnerability allows an attacker to redirect an incoming SMB connection back to the machine it came from and then access the victim machine using the victim’s own credentials. (Hence the term “credential reflection”). In typical Windows XP configurations where SMB sharing is enabled and the user is a member of the Administrators group, this allows the attacker to easily take over the machine. Public tools, including a Metasploit module, are available to perform this attack.

Typical attack vectors for this vulnerability will leverage HTML either via a web browser or e-mail. Resources within the HTML document (such as IMG tags) can be used to reference a file on the attacker’s machine, and these file are then retrieved using the SMB protocol. The attacker’s machine prompts the victim for credentials and then reflects these credentials to the victim’s machine, gaining access. In cases where the attacker is on the same network as the victim, even “trusted” websites can be leveraged to perform this attack – since network data can be modified before the victim receives it.






"Monty Python's 'Dead Parrot sketch' — which featured John Cleese — is some 1,600 years old. A classic scholar has proved the point, by unearthing a Greek version of the world-famous piece. A comedy duo called Hierocles and Philagrius told the original version, only rather than a parrot they used a slave. It concerns a man who complains to his friend that he was sold a slave who dies in his service. His companion replies: 'When he was with me, he never did any such thing!' The joke was discovered in a collection of 265 jokes called Philogelos: The Laugh Addict, which dates from the fourth century AD. Hierocles had gone to meet his maker, and Philagrius had certainly ceased to be, long before John Cleese and Michael Palin reinvented the yarn in 1969."







Exploit-MS08-067 Bundled in Commercial Malware Kit
Probably the most widely reported topic in the Chinese Security community this month will be the availability of a commercial MS08-067 attack pack, customized for Chinese users. On October 26th, 2008, exploit code was posted on to a well-known public repository site. In a few days, malware kit author, WolfTeeth, was quick to sell a MS08-067 port scanning tool with attack capability to his “customers”, using free code from the Internet.






New attack targeting Windows Mobile phones
Angela Moscaritolo November 13, 2008
The attack on Windows mobile devices combines two old techniques used in the PC world.






Net Neutrality Advocates In Charge Of Obama Team Review of FCC






Palin 'Hacker' Trial Pushed Back to May






Chinese hacker attack flowchart

Thursday, November 13, 2008

Security News Feed Wednesday 10/13/08

Visa Tests Credit Card With Random Number GeneratorNov 11,2008
Built-in second factor of authentication could slow online card fraud






November Black Tuesday Overview
MS08-068
The NTLM protocol allows an attacking server to reflect credentials and use them against the client gaining the rights of the logged on user.Replaces MS06-030 and MS05-011.

MS08-069
Multiple vulnerabilities allow memory corruption (code execution with the rights of the logged on user), cross domain scripting and cross domain information leaks.Replaces MS07-042.






Microsoft's exploit predictions are right less than half the time Microsoft says its efforts to predict whether hackers will create exploit code for its bugs are a success -- even though the company got its first monthly forecast right less than half the time. Read more...





Microsoft explains seven-year-old patch delay
In a post to the Microsoft Security Response Center blog, MSRC spokesman Christopher Budd acknowledged the seven-year stretch between the time when the vulnerability was first discussed and when the patch was released. Then he launched into an explanation.
...
Microsoft may have been prompted to act by the appearance earlier this year of an SMB relay attack module for the popular open-source Metasploit penetration and attack framework, argued Schultze. "It looks like exploit code came out in the last four or five months," he said, which made it easier for someone to create the Metasploit module.





IBM's ISS blasts security rival Trend Micro over bugs





Spam plummets after Calif. hosting service shuttered
Spam volumes plunged by more than 40% after a major bot hosting network was shut down, researchers at IronPort Systems Inc. said today.

On Tuesday, McColo Corp. was kicked offline when its primary Internet providers severed its connection to the Web, reported The Washington Post, which led an investigation of the San Jose-based hosting service. According to the newspaper, McColo's clients included cybercriminal groups that ran some of the biggest spam-spewing and malware-spreading botnets.
...
"McColo was the hosting firm for some of the biggest spam botnets, including Srizbi and Rustock,"






Ancient IBM drive rescues Apollo moon data
Thankfully, the tapes stored at Sydney University were still available. However, what was not readily available was a IBM 729 Mark V tape drive needed to read the data.

The IBM 729 magnetic tape drive was used by IBM from the late 1950s through the mid-1960s. It used a half-inch magnetic tape that was up to 2,400 feet in length on a reel measuring up to 10.5 in. in diameter.







AVG Antivirus Update Mistakenly Deletes System FileNewsFactor - Tue Nov 11, 4:50 PM ET

An update for the AVG 8 antivirus software for Windows 2000, XP and Vista released Saturday mistakenly warned that the Windows system file user32.dll was a Trojan horse. The problem affected the Dutch, French, Italian, Portuguese and Spanish versions.






How Recessions Make Good People Do Bad Things In a corporate environment, we tend to trust our co-workers -- but we might want to fight our instincts on this one.






Survey: Most Data Security Risks Internal One in 10 employees surveyed admitted stealing data or corporate devices, selling them for a profit, or knowing fellow employees who did.






Federal Reserve phishing message leads to pornography.November 11, 2008
Phishing messages sent by the Srizbi botnet appears to be a pornographic advertisment.





Survey style Phish targets JPMorgan Chase & Co.






$1 million reward for arrest of cyberextortionists
Dan Kaplan November 12, 2008
A pharmacy benefits firm offers $1 million for information leading to the conviction of a band of data thief extortionists.







A questionnaire being sent to those seeking high-ranking posts in the Obama administration may be the most extensive — some say invasive — application ever.
Questionnaire for Job Applicants (pdf)







Anti-malware testing group release standardsNews Brief, 2008-11-11
A coalition of security-software companies, testing firms and information-technology publications issue two sets of guidelines setting out the responsibilities of each group during software tests.







Marshal, 8e6 Technologies merge to form Marshal8e6
Internet security vendors Marshal and 8e6 Technologies have announced a merger to form a new...